OTL text log response
Here is the OTL.txt log response:
Here is the contents of the OTL text log:
OTL logfile created on: 3/28/2012 9:44:04 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Garry S. Glover\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.01 Mb Total Physical Memory | 152.21 Mb Available Physical Memory | 59.69% Memory free
618.04 Mb Paging File | 486.52 Mb Available in Paging File | 78.72% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 41.56 Gb Free Space | 55.79% Space Free | Partition Type: NTFS
Computer Name: DDQSKV11 | User Name: Garry S. Glover | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/28 21:39:41 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Garry S. Glover\Desktop\OTL.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2001/08/17 23:36:42 | 000,024,064 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\SYSTEM32\devldr32.exe
========== Modules (No Company Name) ==========
MOD - [2012/03/10 21:24:49 | 000,043,520 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CmdLineExt03.dll
MOD - [2011/05/28 14:47:00 | 000,127,376 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 4\ASCv4ExtMenu.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/08/25 18:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2011/05/28 14:46:56 | 000,353,168 | ---- | M] (IObit) [Disabled | Stopped] -- C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled | Stopped] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2003/03/02 13:16:38 | 000,052,736 | ---- | M] (Macrovision) [Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE -- (C-DillaCdaC11BA)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0EA12DEB-9DD0-4F92-8854-8D730B2F6788}\MpKslc492ae9a.sys -- (MpKslc492ae9a)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/02/15 10:15:24 | 000,028,276 | ---- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\MxlW2k.sys -- (MxlW2k)
DRV - [2009/09/04 13:46:04 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/09/04 13:46:04 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008/04/13 14:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys -- (gameenum)
DRV - [2005/08/10 10:06:28 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2005/08/10 08:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/05/16 09:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2003/03/02 13:16:37 | 000,011,376 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\CdaC15BA.SYS -- (CdaC15BA)
DRV - [2002/09/11 02:31:07 | 000,008,552 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2002/06/30 20:50:12 | 000,167,155 | ---- | M] (Conexant Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2002/06/30 20:49:46 | 001,172,416 | ---- | M] (Conexant Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
DRV - [2002/06/30 20:45:12 | 000,594,832 | ---- | M] (Conexant Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - [2001/11/09 07:10:36 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Garry S. Glover\cdrmkaun.sys -- (cdrmkaun)
DRV - [2001/08/17 14:52:24 | 000,038,144 | ---- | M] (HighPoint Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HPT3XX.SYS -- (hpt3xx)
DRV - [2001/08/17 14:28:12 | 000,488,383 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_V124.sys -- (V124)
DRV - [2001/08/17 14:28:12 | 000,050,751 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_TONE.sys -- (Tones)
DRV - [2001/08/17 14:28:10 | 000,542,879 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_MSFT.sys -- (hsf_msft)
DRV - [2001/08/17 14:28:10 | 000,073,279 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_SPKP.sys -- (SpeakerPhone)
DRV - [2001/08/17 14:28:10 | 000,057,471 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_SAMP.sys -- (Rksample)
DRV - [2001/08/17 14:28:08 | 000,391,199 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_K56K.sys -- (K56)
DRV - [2001/08/17 14:28:06 | 000,289,887 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FALL.sys -- (Fallback)
DRV - [2001/08/17 14:28:06 | 000,199,711 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FAXX.sys -- (SoftFax)
DRV - [2001/08/17 14:28:06 | 000,115,807 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FSKS.sys -- (Fsks)
DRV - [2001/08/17 14:28:04 | 000,067,167 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_BSC2.sys -- (basic2)
DRV - [2001/08/17 14:02:32 | 000,008,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\hidgame.sys -- (hidgame)
DRV - [2001/08/17 13:50:26 | 000,731,648 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\NV4.SYS -- (nv4)
DRV - [2001/08/17 13:19:34 | 000,036,480 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sfmanm.sys -- (sfman) Creative SoundFont Manager Driver (WDM)
DRV - [2001/08/17 13:19:28 | 000,006,912 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ctlfacem.sys -- (emu10k1) Creative Interface Manager Driver (WDM)
DRV - [2001/08/17 13:19:26 | 000,283,904 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\emu10k1m.sys -- (emu10k) Creative SB Live! (WDM)
DRV - [2001/08/17 13:19:20 | 000,003,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ctljystk.sys -- (ctljystk)
DRV - [2001/08/17 13:11:42 | 000,029,696 | ---- | M] (CNet Technology, Inc. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DM9PCI5.SYS -- (DM9102) DAVICOM 9102(A)
DRV - [2001/08/17 13:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS -- (EL90XBC)
DRV - [1999/12/17 02:00:00 | 000,006,752 | ---- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\PfModNT.sys -- (PfModNT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.2020search.com/search/9884/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak =
http://about-blank.biz/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.Google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.2020search.com/search/9884/search.html
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://start.earthlink.net
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://start.earthlink.net
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://about-blank.biz/
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar_bak =
http://www.2020search.com/search/9884/search.html
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak =
http://about-blank.biz/
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.att.net
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.Google.com/
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.2020search.com/search/9884/search.html
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant_bak =
http://www.2020search.com/search/9884/search.html
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\SearchScopes\{C18B72AB-610B-4DAD-AE68-2F267C7D2951}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTerms}&fr=chr-atty
IE - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/13 22:19:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/13 22:19:47 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2006/10/24 23:56:10 | 000,003,606 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 69.56.223.196 t.rack.cc
O1 - Hosts: 69.56.223.196
www.alfa-search.com
O1 - Hosts: 69.56.223.196 webcoolsearch.com
O1 - Hosts: 69.56.223.196 in.webcounter.cc
O1 - Hosts: 69.56.223.196 i-lookup.com
O1 - Hosts: 69.56.223.196
www.hand-book.com
O1 - Hosts: 69.56.223.196
www.maxxxhosters.com
O1 - Hosts: 69.56.223.196 allneedsearch.com
O1 - Hosts: 69.56.223.196 best.royalsearch.net
O1 - Hosts: 69.56.223.196 default-homepage-network.com
O1 - Hosts: 69.56.223.196 xwebsearch.biz
O1 - Hosts: 69.56.223.196
www.rightfinder.net
O1 - Hosts: 69.56.223.196
www.search-1.net
O1 - Hosts: 69.56.223.196
www.searchv.com
O1 - Hosts: 69.56.223.196
www.websearch.com
O1 - Hosts: 69.56.223.196 mysearchnow.com
O1 - Hosts: 69.56.223.196
www.therealsearch.com
O1 - Hosts: 69.56.223.196
www.find-itnow.com
O1 - Hosts: 69.56.223.196 super-spider.com
O1 - Hosts: 69.56.223.196
www.searching-the-net.com
O1 - Hosts: 60 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Search Toolbar BHO Object) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - Reg Error: Value error. File not found
O2 - BHO: (AT&&T Toolbar) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - C:\PROGRA~1\ATTTOO~1\ATTTOO~1.DLL File not found
O2 - BHO: (no name) - {55102325-F838-447F-93D7-D03FED8F4C3B} - Reg Error: Value error. File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Search) - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {5C75D98F-A3FF-4C79-A106-7E088D55D5DB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\Toolbar\WebBrowser: (no name) - {5C75D98F-A3FF-4C79-A106-7E088D55D5DB} - No CLSID value found.
O3 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O7 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O9 - Extra 'Tools' menuitem : Turbo Download - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - Reg Error: Value error. File not found
O12 - Plugin for: .PD7 - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll File not found
O15 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..Trusted Domains: ([]msn in My Computer)
O15 - HKU\S-1-5-21-3766738458-558522827-3833581854-1006\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1268618336953 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1268795703686 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6243CE58-9D38-4887-9C21-31FCF61A7D18}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\System32\Userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Garry S. Glover\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Garry S. Glover\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/25 20:37:43 | 000,000,025 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: aux1 - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.ctmp3 - C:\WINDOWS\SYSTEM32\ctmp3.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\L3CODECX.ACM (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)
Drivers32: wave3 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)
Drivers32: wave4 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)
Drivers32: wave5 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/28 21:39:34 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Garry S. Glover\Desktop\OTL.exe
[2012/03/28 08:42:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX7
[2012/03/28 08:37:34 | 004,448,689 | R--- | C] (Swearware) -- C:\Documents and Settings\Garry S. Glover\Desktop\GSG.exe
[2012/03/28 08:28:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX6
[2012/03/28 08:24:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX5
[2012/03/28 08:03:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX4
[2012/03/28 07:57:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX3
[2012/03/27 21:42:36 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/03/27 21:11:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\{281B3A29-FB12-4E82-9845-74079AB37431}
[2012/03/27 21:04:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX2
[2012/03/27 21:03:58 | 009,601,504 | ---- | C] (OPSWAT, Inc.) -- C:\Documents and Settings\Garry S. Glover\Desktop\AppRemover.exe
[2012/03/27 08:01:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2012/03/26 22:38:22 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Garry S. Glover\Desktop\aswMBR.exe
[2012/03/24 17:14:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2012/03/24 17:14:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Garry S. Glover\Start Menu\Programs\Administrative Tools
[2012/03/24 15:01:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\Application Data\Malwarebytes
[2012/03/24 15:00:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/24 15:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/03/24 15:00:02 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/03/24 15:00:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/23 13:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\Local Settings\Application Data\LogMeIn Rescue Applet
[2012/03/23 11:24:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MiniTool Power Data Recovery 6.6
[2012/03/23 11:24:34 | 000,000,000 | ---D | C] -- C:\Program Files\PowerDataRecovery
[2012/03/23 10:54:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\RarSFX1
[2012/03/23 10:52:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\_avast4_
[2012/03/23 10:52:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\_av4_
[2012/03/23 10:46:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\Desktop\RK_Quarantine
[2012/03/22 09:38:37 | 000,000,000 | ---D | C] -- C:\Log
[2012/03/22 09:38:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/03/22 09:38:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Quick Data Recovery Pro
[2012/03/22 09:38:08 | 000,000,000 | ---D | C] -- C:\Program Files\Quick Data Recovery Pro
[2012/03/21 21:42:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\{AC76BA86-7AD7-1033-7B44-AA1000000001}
[2012/03/21 21:42:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\Local Settings\Application Data\Solid State Networks
[2012/03/21 21:42:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\21782
[2012/03/21 21:08:41 | 000,000,000 | ---D | C] -- C:\Restoration
[2012/03/21 13:16:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\MagicCute Data Recovery
[2012/03/21 13:15:58 | 000,000,000 | ---D | C] -- C:\Program Files\MCsDataRecovery
[2012/03/21 09:26:54 | 000,000,000 | ---D | C] -- C:\Program Files\WhenUSearch
[2012/03/20 17:50:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\iolo
[2012/03/20 17:39:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\Local Settings\Application Data\Google
[2012/03/20 17:38:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Garry S. Glover\Google Toolbar
[2012/03/20 17:38:15 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/03/20 17:38:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2012/03/20 17:13:08 | 000,766,728 | ---- | C] (Solid State Networks) -- C:\Documents and Settings\Garry S. Glover\install_reader10_en_gtba_aih.exe
[47 C:\Documents and Settings\Garry S. Glover\*.tmp files -> C:\Documents and Settings\Garry S. Glover\*.tmp -> ]
[39 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/28 21:39:41 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Garry S. Glover\Desktop\OTL.exe
[2012/03/28 08:44:18 | 000,002,048 | ---- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2012/03/28 08:44:17 | 267,468,800 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/28 08:37:34 | 004,448,689 | R--- | M] (Swearware) -- C:\Documents and Settings\Garry S. Glover\Desktop\GSG.exe
[2012/03/28 08:36:22 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\Desktop\rkill.exe
[2012/03/27 21:03:58 | 009,601,504 | ---- | M] (OPSWAT, Inc.) -- C:\Documents and Settings\Garry S. Glover\Desktop\AppRemover.exe
[2012/03/27 09:12:16 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT81.xml
[2012/03/27 09:12:16 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT7F.xml
[2012/03/27 09:12:16 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT80.xml
[2012/03/27 09:11:35 | 002,232,826 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT68.xml
[2012/03/27 09:11:35 | 000,001,022 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT69.dtd
[2012/03/27 09:11:28 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT67.xml
[2012/03/27 09:11:28 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT65.xml
[2012/03/27 09:11:28 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT66.xml
[2012/03/27 09:11:14 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT5A.xml
[2012/03/27 09:11:13 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT58.xml
[2012/03/27 09:11:13 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT59.xml
[2012/03/27 09:10:22 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT4D.xml
[2012/03/27 09:10:22 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT4B.xml
[2012/03/27 09:10:22 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT4C.xml
[2012/03/27 09:09:40 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT33.xml
[2012/03/27 09:09:40 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT31.xml
[2012/03/27 09:09:40 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT32.xml
[2012/03/27 09:09:11 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT30.xml
[2012/03/27 09:09:11 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT2E.xml
[2012/03/27 09:09:11 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT2F.xml
[2012/03/27 09:08:34 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT23.xml
[2012/03/27 09:08:34 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT21.xml
[2012/03/27 09:08:34 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT22.xml
[2012/03/27 09:06:06 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2012/03/26 22:38:22 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Garry S. Glover\Desktop\aswMBR.exe
[2012/03/24 16:28:37 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMTC.xml
[2012/03/24 16:28:36 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMTA.xml
[2012/03/24 16:28:36 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMTB.xml
[2012/03/24 15:00:52 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/23 13:26:55 | 000,000,070 | ---- | M] () -- C:\WINDOWS\qdrp.INI
[2012/03/23 11:24:38 | 000,000,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MiniTool Power Data Recovery 6.6.lnk
[2012/03/22 09:38:11 | 000,000,763 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\Desktop\Quick Data Recovery Pro.lnk
[2012/03/22 07:26:22 | 000,000,211 | ---- | M] () -- C:\BOOT.INI
[2012/03/22 06:57:34 | 000,472,948 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2012/03/22 06:57:33 | 000,076,042 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2012/03/21 13:16:18 | 000,000,693 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\Application Data\Microsoft\Internet Explorer\Quick Launch\MagicCute Data Recovery.lnk
[2012/03/21 13:16:18 | 000,000,675 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MagicCute Data Recovery.lnk
[2012/03/21 13:08:20 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT24.xml
[2012/03/21 13:08:16 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT20.xml
[2012/03/21 13:08:15 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT1F.xml
[2012/03/21 13:07:18 | 000,707,340 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT1E.xml
[2012/03/21 13:07:18 | 000,001,994 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT1C.xml
[2012/03/21 13:07:18 | 000,000,426 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\IMT1D.xml
[2012/03/21 12:02:39 | 000,016,907 | ---- | M] () -- C:\WINDOWS\Garry S. Glover8.xlb
[2012/03/21 09:13:53 | 000,356,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/20 17:41:46 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cd06e23fae4ad8.job
[2012/03/20 17:13:22 | 000,766,728 | ---- | M] (Solid State Networks) -- C:\Documents and Settings\Garry S. Glover\install_reader10_en_gtba_aih.exe
[2012/03/19 22:33:15 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/03/19 20:46:43 | 000,002,393 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TurboTax 2011.lnk
[2012/03/10 21:24:51 | 000,024,748 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\SIntfNT.dll
[2012/03/10 21:24:51 | 000,020,020 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\SIntf32.dll
[2012/03/10 21:24:51 | 000,012,305 | ---- | M] () -- C:\Documents and Settings\Garry S. Glover\SIntf16.dll
[2012/03/10 21:24:49 | 000,043,520 | ---- | M] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[47 C:\Documents and Settings\Garry S. Glover\*.tmp files -> C:\Documents and Settings\Garry S. Glover\*.tmp -> ]
[39 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/28 08:44:17 | 267,468,800 | -HS- | C] () -- C:\hiberfil.sys
[2012/03/28 08:36:11 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\Desktop\rkill.exe
[2012/03/27 09:12:16 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT81.xml
[2012/03/27 09:12:16 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT7F.xml
[2012/03/27 09:12:16 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT80.xml
[2012/03/27 09:11:35 | 000,001,022 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT69.dtd
[2012/03/27 09:11:34 | 002,232,826 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT68.xml
[2012/03/27 09:11:28 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT67.xml
[2012/03/27 09:11:28 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT65.xml
[2012/03/27 09:11:28 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT66.xml
[2012/03/27 09:11:13 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT5A.xml
[2012/03/27 09:11:13 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT58.xml
[2012/03/27 09:11:13 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT59.xml
[2012/03/27 09:10:22 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT4D.xml
[2012/03/27 09:10:22 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT4B.xml
[2012/03/27 09:10:22 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT4C.xml
[2012/03/27 09:09:40 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT33.xml
[2012/03/27 09:09:40 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT31.xml
[2012/03/27 09:09:40 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT32.xml
[2012/03/27 09:09:11 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT30.xml
[2012/03/27 09:09:11 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT2E.xml
[2012/03/27 09:09:11 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT2F.xml
[2012/03/27 09:08:34 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT23.xml
[2012/03/27 09:08:34 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT21.xml
[2012/03/27 09:08:34 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT22.xml
[2012/03/24 16:28:36 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMTC.xml
[2012/03/24 16:28:36 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMTA.xml
[2012/03/24 16:28:36 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMTB.xml
[2012/03/24 15:00:52 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/23 11:24:38 | 000,000,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MiniTool Power Data Recovery 6.6.lnk
[2012/03/22 09:38:11 | 000,000,763 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\Desktop\Quick Data Recovery Pro.lnk
[2012/03/22 09:38:10 | 000,000,070 | ---- | C] () -- C:\WINDOWS\qdrp.INI
[2012/03/21 13:16:18 | 000,000,693 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\Application Data\Microsoft\Internet Explorer\Quick Launch\MagicCute Data Recovery.lnk
[2012/03/21 13:16:18 | 000,000,675 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MagicCute Data Recovery.lnk
[2012/03/21 13:08:20 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT24.xml
[2012/03/21 13:08:16 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT20.xml
[2012/03/21 13:08:15 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT1F.xml
[2012/03/21 13:07:18 | 000,707,340 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT1E.xml
[2012/03/21 13:07:18 | 000,001,994 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT1C.xml
[2012/03/21 13:07:18 | 000,000,426 | ---- | C] () -- C:\Documents and Settings\Garry S. Glover\IMT1D.xml
[2012/03/20 17:41:46 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cd06e23fae4ad8.job
[2012/02/21 10:36:20 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/01/19 18:48:40 | 001,565,222 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3766738458-558522827-3833581854-1006-0.dat
[2012/01/19 18:48:38 | 000,314,802 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/01/19 17:07:52 | 000,000,590 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2011/04/10 21:50:09 | 000,712,152 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/22 11:25:57 | 000,021,504 | ---- | C] () -- C:\WINDOWS\jestertb.dll
[2011/02/20 22:22:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\homeDVD-Music.INI
[2010/04/13 22:16:22 | 000,023,108 | ---- | C] () -- C:\WINDOWS\hpqins15.dat
========== LOP Check ==========
[2010/04/05 21:53:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATTToolbar
[2007/03/03 09:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg7
[2002/09/11 02:26:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2007/01/25 22:10:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2011/09/09 07:15:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2012/03/21 21:42:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2012/03/23 13:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/03/11 14:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TurboTax 2006
[2011/09/06 20:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2012/03/21 21:39:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\ATTToolbar
[2012/03/21 21:39:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\AVG7
[2012/02/14 14:22:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\ConsumerSoft
[2010/09/16 13:11:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\fhnetwork.com
[2012/03/20 19:46:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\FileOpen
[2012/02/16 10:15:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\InterTrust
[2012/03/21 21:40:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\IObit
[2006/01/22 13:55:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\Leadertech
[2003/12/03 22:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\Lycos
[2006/04/07 04:58:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\Magix
[2011/09/05 13:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\Uniblue
[2012/03/20 19:46:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\winlink
[2012/03/21 21:41:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\winshow
[2003/12/01 11:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Garry S. Glover\Application Data\{2CF0B992-5EEB-4143-99C0-5297EF71F444}
[2007/01/27 09:39:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\AVG7
[2011/09/09 07:09:41 | 000,000,290 | ---- | M] () -- C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
========== Purity Check ==========