OLT.Txt - 1st of 2
This is the first time since we started that I've been able to use normal mode to access the internet. Lookin good so far.
*****************************************************
OTL logfile created on: 3/20/2011 4:54:44 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\PAP\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,015.00 Mb Total Physical Memory | 569.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.25 Gb Total Space | 67.52 Gb Free Space | 48.49% Space Free | Partition Type: NTFS
Drive D: | 9.78 Gb Total Space | 6.29 Gb Free Space | 64.27% Space Free | Partition Type: NTFS
Computer Name: YOUR-235B2CE4A2 | User Name: PAP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/03/20 16:50:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PAP\Desktop\OTL.exe
PRC - [2011/02/28 07:00:46 | 006,707,464 | RH-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\servicescache.exe
PRC - [2011/02/28 06:58:28 | 000,203,016 | -HS- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\CNGKeyLock.exe
PRC - [2010/12/21 08:04:30 | 000,987,704 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psia.exe
PRC - [2010/12/21 08:04:30 | 000,399,416 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\sua.exe
PRC - [2010/12/21 08:04:30 | 000,291,896 | ---- | M] (Secunia) -- C:\Program Files\Secunia\PSI\psi_tray.exe
PRC - [2010/06/16 18:13:38 | 001,070,296 | ---- | M] (Mischel Internet Security) -- C:\Program Files\TrojanHunter 5.3\THGuard.exe
PRC - [2010/03/18 10:57:48 | 000,020,480 | ---- | M] (AG Interactive) -- C:\Program Files\AGI\core\4.2.0.10753\AGCoreService.exe
PRC - [2010/03/17 16:55:42 | 001,565,696 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Verizon\McciTrayApp.exe
PRC - [2009/12/08 13:38:16 | 003,474,848 | ---- | M] (Webshots.com) -- C:\Program Files\Webshots\3.1.5.7617\Webshots.scr
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002/06/20 15:06:12 | 000,339,968 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\hphmon04.exe
PRC - [2002/05/24 08:46:16 | 000,188,416 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
PRC - [2002/05/24 08:46:13 | 000,077,824 | ---- | M] (HP) -- C:\WINDOWS\system32\hphipm11.exe
PRC - [2002/04/17 10:49:16 | 000,077,824 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
PRC - [2002/04/17 10:42:56 | 000,069,632 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
========== Modules (SafeList) ==========
MOD - [2011/03/20 16:50:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PAP\Desktop\OTL.exe
MOD - [2010/08/23 12:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010/03/17 16:53:28 | 000,198,656 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - File not found [On_Demand | Stopped] -- -- (ACDaemon)
SRV - [2011/02/28 07:00:46 | 006,707,464 | RH-- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\System32\servicescache.exe -- (systemCheck)
SRV - [2011/02/28 06:58:28 | 000,203,016 | -HS- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\CNGKeyLock.exe -- (CNGKeyLock)
SRV - [2011/02/28 06:58:26 | 006,859,016 | RHS- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\sysDriverHardWare.exe -- (MicrosoftHardwareDriver)
SRV - [2011/02/28 06:58:23 | 006,863,112 | RHS- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\sysSecurityCheck.exe -- (SysCacheDriver)
SRV - [2010/12/21 08:04:30 | 000,987,704 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\PSIA.exe -- (Secunia PSI Agent)
SRV - [2010/12/21 08:04:30 | 000,399,416 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2010/03/18 10:57:48 | 000,020,480 | ---- | M] (AG Interactive) [Auto | Running] -- C:\Program Files\AGI\core\4.2.0.10753\AGCoreService.exe -- (AGCoreService)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2002/05/24 08:46:13 | 000,077,824 | ---- | M] (HP) [On_Demand | Running] -- C:\WINDOWS\system32\hphipm11.exe -- (Pml Driver HPH11)
========== Driver Services (SafeList) ==========
DRV - [2011/02/28 07:00:53 | 000,014,600 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\Drivers\pcrasys32.sys -- (pcrasys)
DRV - [2011/02/28 07:00:53 | 000,014,088 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\Drivers\akerneldrv32.sys -- (akerneldrv)
DRV - [2010/12/03 05:05:34 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/09/01 04:30:58 | 000,015,544 | ---- | M] (Secunia) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psi_mf.sys -- (PSI)
DRV - [2010/03/17 16:53:38 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2010/03/08 10:41:48 | 000,220,112 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/02/11 13:40:40 | 005,028,352 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/09/10 00:10:00 | 000,207,872 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS3.sys -- (HSFHWBS3)
DRV - [2008/09/10 00:09:54 | 000,731,264 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2008/09/10 00:09:52 | 000,985,728 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/10/07 21:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2002/05/24 08:46:13 | 000,050,896 | R--- | M] (HP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hphid411.sys -- (Dot4 HPH11)
DRV - [2002/05/24 08:46:13 | 000,050,276 | R--- | M] (Hewlett-Packard) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hphs2k11.sys -- (Dot4Storage HPH11) Storage Class Driver for IEEE-1284.4 (HPH11)
DRV - [2002/05/24 08:46:13 | 000,018,928 | R--- | M] (HP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hphius11.sys -- (Dot4Usb HPH11)
DRV - [2002/05/24 08:46:13 | 000,016,112 | R--- | M] (HP) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hphipr11.sys -- (Dot4Print HPH11)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_IN&c=64&bd=PRESARIO&pf=desktop
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_IN&c=64&bd=PRESARIO&pf=desktop
IE - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig?hl=en
IE - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/30 12:17:23 | 000,000,000 | ---D | M]
[2010/10/13 11:09:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\PAP\Application Data\Mozilla\Extensions
[2009/11/28 19:11:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\PAP\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/10/13 11:09:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\PAP\Application Data\Mozilla\Extensions\uploadr@flickr.com
O1 HOSTS File: ([2011/03/20 13:48:33 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {C17590D2-ECB4-4B15-8820-F58798DCC118} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {C17590D2-ECB4-4B15-8820-F58798DCC118} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe (HP)
O4 - HKLM..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD04] C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe (Hewlett-Packard)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [THGuard] C:\Program Files\TrojanHunter 5.3\THGuard.exe (Mischel Internet Security)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKU\S-1-5-21-2694351943-356035358-1331127216-1014..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe ()
O4 - Startup: C:\Documents and Settings\Aaron\Start Menu\Programs\Startup\ZooskMessenger.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O4 - Startup: C:\Documents and Settings\Kieran\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\PAP\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\3.1.5.7617\Launcher.exe (Webshots.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2694351943-356035358-1331127216-1014\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5}
http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB (Tpwin Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468}
http://www.gamehouse.com/games/abxgh.cab (Abx(gh) Control)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B}
http://www.gamehouse.com/games/gamehouse/ghplayer.cab (GameHouse Games Player)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A}
http://www.gamehouse.com/realarcade-webgames/luxor/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A}
http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}
http://www.gamehouse.com/realarcade-webgames/zylom/zylomplayer.cab (Zylom Games Player)
O16 - DPF: {C2AD5B59-154E-4090-91F5-19FC1410E8EE}
http://www.koreatimes.co.kr/www/TTS/App/Downloader.cab (Downloader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
http://bestbuy.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://www.shockwave.com/content/peggle/sis/popcaploader_v10_en.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\PAP\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\PAP\Application Data\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/26 18:25:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 30 Days ==========
[2011/03/20 16:50:15 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\PAP\Desktop\OTL.exe
[2011/03/20 14:01:41 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/03/20 13:55:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/03/20 13:21:29 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/03/20 13:21:29 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/03/20 13:21:29 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/03/20 13:21:29 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/03/20 13:05:26 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/03/10 16:57:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\AIM
[2011/03/10 16:57:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
[2011/03/04 09:27:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/03/04 09:26:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/03/04 09:25:59 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/03/04 09:19:31 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2008/12/30 04:09:30 | 008,007,680 | ---- | C] ( ) -- C:\WINDOWS\System32\Microsoft.mshtml.dll
[2008/12/30 02:43:22 | 000,126,976 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.SHDocVw.dll
========== Files - Modified Within 30 Days ==========
[2011/03/20 16:57:00 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2694351943-356035358-1331127216-1011UA.job
[2011/03/20 16:50:19 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\PAP\Desktop\OTL.exe
[2011/03/20 16:47:49 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/03/20 16:46:53 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/20 16:46:52 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2694351943-356035358-1331127216-1010.job
[2011/03/20 16:46:52 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2694351943-356035358-1331127216-1012.job
[2011/03/20 16:46:52 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2694351943-356035358-1331127216-1011.job
[2011/03/20 16:46:52 | 000,000,274 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2694351943-356035358-1331127216-1014.job
[2011/03/20 16:45:48 | 000,009,570 | -H-- | M] () -- C:\WINDOWS\System32\masteraclini.enu
[2011/03/20 16:45:48 | 000,000,136 | RH-- | M] () -- C:\WINDOWS\System32\masteraclbini.enu
[2011/03/20 16:44:27 | 000,003,322 | -H-- | M] () -- C:\WINDOWS\System32\{master}(1)avg.enu
[2011/03/20 16:44:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/20 15:41:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2694351943-356035358-1331127216-1013UA.job
[2011/03/20 13:48:33 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/03/20 13:18:41 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/03/20 12:00:52 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/20 11:26:17 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/20 10:56:13 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/03/19 21:21:42 | 000,301,568 | ---- | M] () -- C:\Documents and Settings\PAP\Desktop\fptjo31v.exe
[2011/03/19 20:05:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2694351943-356035358-1331127216-1009UA.job
[2011/03/18 08:04:07 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/18 07:10:06 | 001,691,399 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\2567annotated2aa2.png
[2011/03/18 05:29:55 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2694351943-356035358-1331127216-1010.job
[2011/03/18 03:57:02 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2694351943-356035358-1331127216-1011Core.job
[2011/03/18 01:29:09 | 001,085,368 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\2567annotated1.jpg
[2011/03/18 01:26:24 | 001,677,019 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\2567annotated2aa.png
[2011/03/18 01:19:31 | 001,678,108 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\2567annotated2a.png
[2011/03/18 00:25:06 | 001,080,515 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\2567annotated.jpg
[2011/03/17 22:51:19 | 000,054,710 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\ProgramFront.JPG
[2011/03/17 22:43:55 | 000,313,375 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\OCSPrgm.pdf
[2011/03/17 22:26:18 | 002,703,469 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\ClassPhoto.jpg
[2011/03/17 21:41:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2694351943-356035358-1331127216-1013Core.job
[2011/03/17 21:38:41 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2694351943-356035358-1331127216-1014.job
[2011/03/17 21:05:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2694351943-356035358-1331127216-1009Core.job
[2011/03/17 16:07:00 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2694351943-356035358-1331127216-1012.job
[2011/03/17 12:27:14 | 000,064,801 | ---- | M] () -- C:\Documents and Settings\PAP\Desktop\Mahare.jpg
[2011/03/17 12:26:55 | 000,042,595 | ---- | M] () -- C:\Documents and Settings\PAP\Desktop\MahareGarrell.jpg
[2011/03/16 23:23:05 | 001,004,855 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\ArirangOriginal_64kb_mp3.zip
[2011/03/16 07:36:52 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/03/16 07:17:17 | 000,104,280 | ---- | M] () -- C:\Documents and Settings\PAP\My Documents\SPCSVCNW0311.pdf
[2011/03/13 10:13:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2694351943-356035358-1331127216-1011.job
[2011/03/13 04:46:09 | 000,432,664 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/03/13 04:46:09 | 000,067,428 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/03/10 16:57:55 | 000,001,401 | -H-- | M] () -- C:\IPH.PH
[2011/02/28 22:21:45 | 000,000,783 | ---- | M] () -- C:\Documents and Settings\PAP\Start Menu\Programs\Startup\Webshots.lnk
[2011/02/28 16:29:54 | 000,001,784 | RHS- | M] () -- C:\WINDOWS\System32\masterlock.enu
[2011/02/28 07:01:59 | 008,007,680 | ---- | M] ( ) -- C:\WINDOWS\System32\Microsoft.mshtml.dll
[2011/02/28 07:01:57 | 000,726,016 | RH-- | M] (Igor Pavlov) -- C:\WINDOWS\System32\7z.dll
[2011/02/28 07:01:57 | 000,256,000 | RH-- | M] (Markovtsev Vadim) -- C:\WINDOWS\System32\SevenZipSharp.dll
[2011/02/28 07:01:57 | 000,126,976 | ---- | M] ( ) -- C:\WINDOWS\System32\Interop.SHDocVw.dll
[2011/02/28 07:01:56 | 000,200,704 | ---- | M] (ICSharpCode.net) -- C:\WINDOWS\System32\ICSharpCode.SharpZipLib.dll
[2011/02/28 07:00:52 | 000,003,573 | RH-- | M] () -- C:\WINDOWS\System32\{master}(99)misc.enu
[2011/02/28 07:00:52 | 000,003,400 | RH-- | M] () -- C:\WINDOWS\System32\{master}(9)com.enu
[2011/02/28 07:00:52 | 000,003,382 | RH-- | M] () -- C:\WINDOWS\System32\{master}(8)pro.enu
[2011/02/28 07:00:52 | 000,003,353 | RH-- | M] () -- C:\WINDOWS\System32\{master}(zz)Template.enu
[2011/02/28 07:00:51 | 000,003,394 | RH-- | M] () -- C:\WINDOWS\System32\{master}(2)cas.enu
[2011/02/28 07:00:51 | 000,003,348 | RH-- | M] () -- C:\WINDOWS\System32\{master}(3)pan.enu
[2011/02/28 07:00:50 | 000,004,652 | RH-- | M] () -- C:\WINDOWS\System32\{master}(0)nrt.enu
========== Files Created - No Company Name ==========
[2011/03/20 13:21:29 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/03/20 13:21:29 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/03/20 13:21:29 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/03/20 13:21:29 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/03/20 13:21:29 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/03/19 21:21:39 | 000,301,568 | ---- | C] () -- C:\Documents and Settings\PAP\Desktop\fptjo31v.exe
[2011/03/18 07:10:06 | 001,691,399 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\2567annotated2aa2.png
[2011/03/18 05:29:55 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2694351943-356035358-1331127216-1010.job
[2011/03/18 01:29:08 | 001,085,368 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\2567annotated1.jpg
[2011/03/18 01:26:23 | 001,677,019 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\2567annotated2aa.png
[2011/03/18 01:19:30 | 001,678,108 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\2567annotated2a.png
[2011/03/18 00:25:03 | 001,080,515 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\2567annotated.jpg
[2011/03/17 22:48:00 | 000,054,710 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\ProgramFront.JPG
[2011/03/17 22:43:54 | 000,313,375 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\OCSPrgm.pdf
[2011/03/17 22:26:10 | 002,703,469 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\ClassPhoto.jpg
[2011/03/17 12:12:43 | 000,064,801 | ---- | C] () -- C:\Documents and Settings\PAP\Desktop\Mahare.jpg
[2011/03/17 12:10:06 | 000,042,595 | ---- | C] () -- C:\Documents and Settings\PAP\Desktop\MahareGarrell.jpg
[2011/03/16 23:23:02 | 001,004,855 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\ArirangOriginal_64kb_mp3.zip
[2011/03/16 07:17:13 | 000,104,280 | ---- | C] () -- C:\Documents and Settings\PAP\My Documents\SPCSVCNW0311.pdf
[2011/02/20 11:13:18 | 000,000,276 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2694351943-356035358-1331127216-1011.job
[2011/02/20 11:13:17 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2694351943-356035358-1331127216-1011.job
[2010/12/30 01:09:04 | 000,000,644 | -HS- | C] () -- C:\WINDOWS\System32\settings.ini
[2010/11/12 15:49:37 | 000,000,040 | ---- | C] () -- C:\WINDOWS\RSoftInfo.dat
[2010/11/02 23:08:41 | 000,163,128 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/01 11:14:34 | 000,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2010/01/19 23:24:44 | 000,000,223 | ---- | C] () -- C:\WINDOWS\HP PrecisionScan Pro.INI
[2010/01/19 14:29:46 | 000,765,688 | ---- | C] () -- C:\WINDOWS\System32\KMDownloader.exe
[2009/10/09 23:29:47 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/09/22 19:48:26 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/09/13 14:36:40 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/29 05:21:56 | 000,143,360 | ---- | C] () -- C:\Documents and Settings\PAP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/10 16:52:49 | 000,000,017 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2009/05/12 23:11:05 | 000,062,068 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/11 12:15:50 | 000,000,034 | ---- | C] () -- C:\WINDOWS\hpfsched.ini
[2009/05/11 12:13:58 | 000,004,760 | ---- | C] () -- C:\WINDOWS\hphmdl11.dat
[2009/05/11 11:35:37 | 000,335,872 | ---- | C] () -- C:\WINDOWS\System32\ldf252.dll
[2009/05/07 14:24:11 | 000,000,175 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/04/07 10:52:52 | 000,364,032 | RHS- | C] () -- C:\WINDOWS\System32\vshadowamd64.exe
[2009/04/07 10:52:46 | 000,352,256 | RHS- | C] () -- C:\WINDOWS\System32\vshadowXP.exe
[2009/04/07 10:52:45 | 000,405,504 | RHS- | C] () -- C:\WINDOWS\System32\vshadow.exe
[2008/11/26 19:38:39 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/11/26 18:40:20 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2008/11/26 18:27:54 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008/11/26 18:23:33 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008/11/26 17:11:00 | 000,080,416 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2008/11/26 17:10:50 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/11/26 17:10:49 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/11/26 17:10:49 | 000,432,664 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2008/11/26 17:10:49 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/11/26 17:10:49 | 000,067,428 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2008/11/26 17:10:49 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/11/26 17:10:49 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/11/26 17:10:48 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/11/26 17:10:46 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/11/26 17:10:46 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/11/26 17:10:44 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/11/26 17:10:42 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2008/11/26 10:17:56 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008/11/26 10:17:10 | 000,272,576 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2002/06/20 15:09:10 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\hpodinet.dll
[2002/05/24 08:46:08 | 000,036,864 | ---- | C] () -- C:\WINDOWS\hpfsched.exe
[2001/08/07 18:59:54 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HPNVRRes.dll
[2001/01/24 09:31:18 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\prntfix.exe
[2000/04/14 16:50:02 | 000,343,040 | ---- | C] () -- C:\WINDOWS\System32\Lffpx7.dll
[1998/06/11 14:08:06 | 000,095,232 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
========== LOP Check ==========
[2009/05/02 09:53:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\acccore
[2010/10/19 13:38:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\AVG10
[2010/07/07 08:25:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2009/09/29 20:37:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\ieSpell
[2009/06/07 07:37:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\OpenOffice.org
[2009/06/28 10:10:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Skinux
[2009/05/19 08:40:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Viewpoint
[2011/01/02 15:55:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aaron\Application Data\Windows Desktop Search
[2011/03/18 20:05:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TrojanHunter
[2009/05/02 08:54:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2010/03/06 11:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\agi
[2009/11/23 22:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2011/01/15 11:16:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/03/20 12:36:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2009/12/02 02:46:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/19 06:38:17 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/06 06:23:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/05/19 07:34:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/07/17 22:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Merscom
[2011/01/15 11:01:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/01/15 11:22:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData2
[2009/05/22 21:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/05/18 13:55:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008/11/26 18:49:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2009/05/07 19:13:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2009/06/10 16:52:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/06/15 04:14:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2010/08/01 11:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrojanHunter
[2011/01/15 10:44:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/05/15 22:58:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
[2011/03/20 12:42:47 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2010/08/27 08:29:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/02 11:17:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/07 08:19:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/05/22 18:35:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\acccore
[2010/10/19 16:44:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\AVG10
[2010/11/06 15:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\BabylonToolbar
[2011/01/23 07:43:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\Foxit Software
[2009/05/02 15:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\OpenOffice.org
[2009/08/19 19:34:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\PopCapv1005
[2009/06/28 03:36:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\Skinux
[2010/12/13 16:28:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\TrojanHunter
[2011/01/01 08:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gram\Application Data\Windows Desktop Search
[2009/05/04 15:46:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\acccore
[2010/11/25 15:03:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\ACD Systems
[2010/10/19 18:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\AVG10
[2011/02/07 18:09:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\Foxit Software
[2010/12/26 22:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\FrostWire
[2009/06/20 11:31:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\ieSpell
[2010/12/26 21:27:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\LimeWire
[2009/09/22 19:32:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\OpenOffice.org
[2009/06/27 18:48:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\Skinux
[2009/05/04 15:47:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kieran\Application Data\Viewpoint
[2010/06/10 14:34:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\acccore
[2010/12/08 11:08:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\ACD Systems
[2010/03/06 11:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\AGI
[2010/11/07 13:08:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\AnvSoft
[2010/12/30 13:21:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\AVG10
[2009/08/02 00:05:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\Easy Thumbnails
[2010/10/13 11:09:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\Flickr
[2010/12/31 01:35:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\Foxit Software
[2010/11/24 11:13:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\FrostWire
[2009/06/27 12:13:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\ieSpell
[2010/09/10 00:03:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\LimeWire
[2010/04/18 21:47:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\MSNInstaller
[2009/07/02 12:46:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\OpenOffice.org
[2010/05/12 22:53:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\PopCapv1002
[2009/08/18 23:32:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\PopCapv1005
[2010/08/01 11:20:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\TrojanHunter
[2009/06/22 22:59:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\PAP\Application Data\Webshots
[2009/07/07 16:28:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\acccore
[2011/01/27 16:23:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\ACD Systems
[2010/10/20 20:48:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\AVG10
[2010/11/06 14:11:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\Babylon
[2010/11/06 13:51:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\BabylonToolbar
[2009/06/22 21:38:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\ieSpell
[2010/12/27 11:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\LimeWire
[2010/06/07 19:16:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\OpenOffice.org
[2009/06/28 21:24:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\Skinux
[2009/08/07 15:22:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\Viewpoint
[2011/01/02 11:34:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rachel\Application Data\Windows Desktop Search
[2009/05/05 22:20:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\acccore
[2010/11/07 16:53:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\AnvSoft
[2010/10/21 01:50:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\AVG10
[2010/11/06 15:06:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\Babylon
[2010/11/06 14:12:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\BabylonToolbar
[2010/11/06 12:40:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\Flickr
[2011/03/05 18:31:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\Foxit Software
[2010/12/27 11:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\FrostWire
[2009/06/13 17:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\LimeWire
[2011/01/25 21:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\OpenOffice.org
[2009/06/28 11:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\Skinux
[2009/05/19 11:45:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Travis\Application Data\Viewpoint
========== Purity Check ==========