OTL Log new scan
OTL logfile created on: 4/11/2013 2:48:51 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Authorized User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.75 Mb Total Physical Memory | 390.17 Mb Available Physical Memory | 38.49% Memory free
3.82 Gb Paging File | 3.34 Gb Available in Paging File | 87.39% Paging File free
Paging file location(s): C:\pagefile.sys 3000 3000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 190.33 Gb Free Space | 81.73% Space Free | Partition Type: NTFS
Computer Name: AUTHORIZ-28629F | User Name: Authorized User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Authorized User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
PRC - C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
PRC - C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe (IObit)
PRC - C:\Program Files\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - c:\Program Files\IDT\IntelXPV_v83\WDM\stacsv.exe (IDT, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Mozilla Firefox\extensions\{99a0337c-6303-4879-b72e-500fd9aaca8c}\components\TextAloud3Adapter.dll ()
MOD - C:\Program Files\program\libxml2.dll ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\madexcept_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\maddisAsm_.bpl ()
MOD - C:\Program Files\IObit\Advanced SystemCare 6\madbasic_.bpl ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\IObit\Smart Defrag 2\NtfsData.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\Primomonnt.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (AdvancedSystemCareService6) -- C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (nvUpdatusService) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (spupdsvc) -- C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (STacSV) -- c:\Program Files\IDT\IntelXPV_v83\WDM\stacsv.exe (IDT, Inc.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (SetupNTGLM7X) -- D:\NTGLM7X.sys File not found
DRV - (NTACCESS) -- D:\NTACCESS.sys File not found
DRV - (MSICPL) -- D:\install4\MSICPL.sys File not found
DRV - (Lbd) -- system32\DRIVERS\Lbd.sys File not found
DRV - (GMSIPCI) -- D:\INSTALL\GMSIPCI.SYS File not found
DRV - (bezmrzjs) -- System32\Drivers\bezmrzjs.sys File not found
DRV - (MpKsl8e2a9956) -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C52A8FCB-5ACD-4DA8-93D6-C35AB52FAE38}\MpKsl8e2a9956.sys (Microsoft Corporation)
DRV - (SmartDefragDriver) -- C:\WINDOWS\system32\drivers\SmartDefragDriver.sys ()
DRV - (PsSdkLBF) -- C:\WINDOWS\system32\drivers\pssdklbf.drv (microOLAP Technologies LTD)
DRV - (PsSdk31) -- C:\WINDOWS\system32\drivers\pssdk31.drv (microOLAP Technologies LTD)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (sfng32) -- C:\WINDOWS\system32\drivers\sfng32.sys (Sonic Focus, Inc)
DRV - (HECI) -- C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.bing.com/?pc=AVBR
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKU\S-1-5-21-57989841-1897051121-725345543-1006\..\SearchScopes,DefaultScope =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=902615"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B9D7B21FA-0991-472C-8F8E-2CD6CC1CB7BC%7D:2.01
FF - prefs.js..extensions.enabledAddons: %7B99a0337c-6303-4879-b72e-500fd9aaca8c%7D:3.0.37
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=902615&p="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2897: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2955: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1675: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: File not found
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/06 18:05:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/06 18:04:45 | 000,000,000 | ---D | M]
[2008/08/27 02:55:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Extensions
[2013/03/19 20:12:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions
[2010/08/27 15:15:33 | 000,000,000 | ---D | M] (Bible Fox Blue) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}
[2010/12/17 21:56:03 | 000,000,000 | ---D | M] (Bible Fox) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{646f1212-bb24-11db-8314-0800200c9a66}
[2007/08/10 12:08:00 | 000,000,000 | ---D | M] (Bible Fox) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{646f1212-bb24-11db-8314-0800200c9a66}(2)
[2008/01/12 04:18:03 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2008/06/24 11:08:02 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(3)
[2008/07/06 23:22:43 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(4)
[2010/08/27 15:15:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}\chrome\mac\mozapps\extensions
[2010/08/27 15:15:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2010/12/17 21:56:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{646f1212-bb24-11db-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2011/05/10 18:15:15 | 000,056,087 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{9D7B21FA-0991-472C-8F8E-2CD6CC1CB7BC}.xpi
[2010/06/25 23:08:40 | 000,001,182 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}\chrome\mac\mozapps\xpinstall\xpinstallConfirm.css
[2010/06/25 23:08:40 | 000,001,937 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}\chrome\mac\mozapps\xpinstall\xpinstallItemGeneric.png
[2010/04/01 08:10:00 | 000,001,502 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}\chrome\win\mozapps\xpinstall\xpinstallConfirm.css
[2010/04/01 07:51:04 | 000,001,362 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{0c2508e6-de4c-11db-8314-0800200c9a66}\chrome\win\mozapps\xpinstall\xpinstallItemGeneric.png
[2010/04/01 09:10:00 | 000,001,502 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{646f1212-bb24-11db-8314-0800200c9a66}\chrome\win\mozapps\xpinstall\xpinstallConfirm.css
[2010/04/01 08:51:04 | 000,001,362 | ---- | M] () (No name found) -- C:\Documents and Settings\Authorized User\Application Data\Mozilla\Firefox\Profiles\mxj2tocu.default\extensions\{646f1212-bb24-11db-8314-0800200c9a66}\chrome\win\mozapps\xpinstall\xpinstallItemGeneric.png
[2013/04/06 18:04:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/04/06 18:04:44 | 000,000,000 | ---D | M] (TextAloud 3 Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{99a0337c-6303-4879-b72e-500fd9aaca8c}
[2013/04/06 18:04:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}(2)
[2013/04/06 18:04:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\browserhighlighter@ebay.com
[2013/04/06 18:05:19 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/03/19 22:10:37 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/03/19 22:10:37 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2013/04/11 02:36:56 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (TextAloud Toolbar) - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files\TextAloud\TAForIE.dll (NextUp.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-57989841-1897051121-725345543-1003..\Run: [Advanced SystemCare 6] C:\Program Files\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-57989841-1897051121-725345543-1006..\Run: [ooVoo] C\ooVoo.exe /minimized File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Authorized User\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 55924053
O7 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-57989841-1897051121-725345543-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D1E1F7ED622A0E5D.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..Trusted Domains: google.com ([b.mail] https in Trusted sites)
O15 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKU\S-1-5-21-57989841-1897051121-725345543-1003\..Trusted Domains: google.com ([www] https in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.123.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{839C5D34-0789-4D47-A5F4-D14E41364C1F}: DhcpNameServer = 192.168.123.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 () -
O24 - Desktop WallPaper: C:\Documents and Settings\Authorized User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Authorized User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/07/31 09:29:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/04/11 02:36:53 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/04/10 21:40:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013/04/10 21:40:22 | 000,000,000 | ---D | C] -- C:\JRT
[2013/04/06 18:12:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/04/06 18:12:43 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2013/04/06 18:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/03/31 22:37:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Authorized User\Recent
[2013/03/30 22:30:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Authorized User\My Documents\Q-Sciences
[2013/03/22 19:32:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2013/03/19 20:24:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Authorized User\Desktop\Registration_sheets_for_November
[2013/03/19 20:23:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\PC_Drivers_Headquarters
[2013/03/19 20:12:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IncrediMail
[2013/03/19 20:12:23 | 000,000,000 | ---D | C] -- C:\Program Files\Photo Notifier and Animation Creator
[2013/03/19 17:56:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Authorized User\Application Data\Reason
[2013/03/19 17:56:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Authorized User\Start Menu\Programs\Boost
[2013/03/19 14:48:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2013/03/19 14:48:02 | 000,000,000 | ---D | C] -- C:\Program Files\PCPitstop
[2013/03/16 00:04:25 | 000,000,000 | ---D | C] -- C:\ReimageUndo
[2013/03/15 23:53:01 | 000,000,000 | ---D | C] -- C:\rei
[2013/03/15 23:52:53 | 000,000,000 | ---D | C] -- C:\Program Files\Reimage
[2013/03/15 23:05:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\join.me
[2007/09/01 10:49:23 | 000,411,248 | ---- | C] (Applian Technologies Inc.) -- C:\Program Files\FLV PlayerRCSetup.exe
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/04/11 02:52:00 | 000,000,412 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{CF3510EA-7E82-4CDD-95EE-2B0EFB946C87}.job
[2013/04/11 02:51:44 | 000,000,442 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{AD28DB5B-3C98-4A5B-BDEB-170A25E647C8}.job
[2013/04/11 02:48:55 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/04/11 02:39:05 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/04/11 02:38:54 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefragUpdate.job
[2013/04/11 02:38:52 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/11 02:38:52 | 000,000,300 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2013/04/11 02:38:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/04/11 02:36:56 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2013/04/11 02:34:13 | 000,000,773 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\Shortcut to OTL.exe.lnk
[2013/04/11 02:16:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/04/10 21:03:34 | 000,001,116 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\aswMBR.zip
[2013/04/10 20:50:59 | 000,004,702 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\DDS 04-6-2013 attach.zip
[2013/04/10 20:40:32 | 000,004,674 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\attach.zip
[2013/04/10 18:00:07 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2013/04/10 06:23:30 | 000,263,024 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/04/10 06:06:21 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/04/08 23:53:00 | 000,000,436 | ---- | M] () -- C:\WINDOWS\tasks\Reimage ScanAgent.job
[2013/04/06 18:12:45 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\NTREGOPT.lnk
[2013/04/06 18:12:45 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\ERUNT.lnk
[2013/04/06 16:14:46 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\MBR.dat
[2013/04/02 03:33:22 | 000,237,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2013/03/31 00:25:52 | 000,312,572 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/03/31 00:25:52 | 000,040,516 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/03/29 15:50:19 | 000,208,997 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\Doreen PGE.pdf
[2013/03/22 19:32:19 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2013/03/22 09:29:33 | 000,142,199 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\IMG_9573.jpg
[2013/03/20 14:27:30 | 000,001,177 | ---- | M] () -- C:\Documents and Settings\Authorized User\Desktop\join.me.lnk
[2013/03/19 22:16:25 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/03/19 22:16:25 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/03/18 23:53:29 | 000,000,836 | ---- | M] () -- C:\WINDOWS\System32\ScanResults.xml
[2013/03/18 23:53:03 | 000,000,976 | ---- | M] () -- C:\WINDOWS\System32\SettingsFile
[2013/03/17 13:54:54 | 030,508,911 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Support_Info.zip
[2013/03/16 00:25:35 | 000,002,470 | ---- | M] () -- C:\WINDOWS\System32\reimage.nat
[2013/03/16 00:19:56 | 000,726,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jscript(2).dll
[2013/03/16 00:19:56 | 000,232,448 | ---- | M] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\l3codecp.acm
[2013/03/16 00:19:50 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[1 C:\WINDOWS\System32\drivers\etc\*.tmp files -> C:\WINDOWS\System32\drivers\etc\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/04/11 02:34:13 | 000,000,773 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\Shortcut to OTL.exe.lnk
[2013/04/10 21:02:40 | 000,001,116 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\aswMBR.zip
[2013/04/10 20:42:54 | 000,004,702 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\DDS 04-6-2013 attach.zip
[2013/04/10 20:40:32 | 000,004,674 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\attach.zip
[2013/04/10 06:01:51 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2013/04/06 18:12:45 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\NTREGOPT.lnk
[2013/04/06 18:12:45 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\ERUNT.lnk
[2013/04/06 16:14:46 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\MBR.dat
[2013/03/30 20:58:22 | 000,263,024 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/03/29 15:50:19 | 000,208,997 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\Doreen PGE.pdf
[2013/03/22 19:32:19 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2013/03/22 09:29:30 | 000,142,199 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\IMG_9573.jpg
[2013/03/20 14:27:30 | 000,001,177 | ---- | C] () -- C:\Documents and Settings\Authorized User\Start Menu\Programs\join.me.lnk
[2013/03/20 14:27:29 | 000,001,177 | ---- | C] () -- C:\Documents and Settings\Authorized User\Desktop\join.me.lnk
[2013/03/18 23:53:29 | 000,000,836 | ---- | C] () -- C:\WINDOWS\System32\ScanResults.xml
[2013/03/18 23:53:03 | 000,000,976 | ---- | C] () -- C:\WINDOWS\System32\SettingsFile
[2013/03/17 13:54:52 | 030,508,911 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Support_Info.zip
[2013/03/16 01:26:35 | 000,000,412 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{CF3510EA-7E82-4CDD-95EE-2B0EFB946C87}.job
[2013/03/16 00:21:30 | 000,002,470 | ---- | C] () -- C:\WINDOWS\System32\reimage.nat
[2013/03/16 00:18:08 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2013/03/16 00:18:08 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2013/03/16 00:18:06 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2013/03/16 00:18:06 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2013/03/16 00:18:06 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2013/03/16 00:17:30 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2013/03/16 00:17:30 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2013/03/16 00:17:30 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2013/03/16 00:17:30 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2013/03/16 00:17:30 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2013/03/16 00:17:29 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2013/03/15 23:53:09 | 000,000,436 | ---- | C] () -- C:\WINDOWS\tasks\Reimage ScanAgent.job
[2012/12/18 17:32:36 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2012/08/13 11:57:00 | 000,012,927 | ---- | C] () -- C:\Program Files\readme.html
[2012/05/08 15:15:36 | 000,000,005 | ---- | C] () -- C:\Program Files\basis-link
[2012/03/31 23:10:36 | 002,784,050 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2012/03/15 20:57:42 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2012/02/14 15:17:27 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/11/03 13:52:46 | 000,127,589 | ---- | C] () -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\census.cache
[2011/11/03 13:52:22 | 000,207,176 | ---- | C] () -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\ars.cache
[2011/11/03 12:14:13 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\housecall.guid.cache
[2011/05/10 17:19:36 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\redmonnt.dll
[2010/08/23 16:01:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\prvlcl.dat
[2009/12/09 01:33:52 | 000,000,408 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2009/11/30 16:52:42 | 000,072,080 | ---- | C] () -- C:\Documents and Settings\Authorized User\g2mdlhlpx.exe
[2008/05/08 14:28:55 | 000,095,744 | ---- | C] () -- C:\Documents and Settings\Authorized User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/21 04:07:41 | 000,005,663 | ---- | C] () -- C:\Documents and Settings\Authorized User\Application Data\PrimoPDFSet.xml
[2008/03/21 04:06:46 | 000,000,399 | ---- | C] () -- C:\Documents and Settings\Authorized User\Application Data\APUSet.xml
[2007/12/12 13:20:00 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/09/01 11:05:24 | 002,293,712 | ---- | C] () -- C:\Program Files\FLV PlayerFCSetup.exe
[2007/09/01 11:01:00 | 003,655,488 | ---- | C] () -- C:\Program Files\FLV PlayerRCATSetup.exe
========== ZeroAccess Check ==========
[2007/08/03 13:50:19 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 17:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 17:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/03 08:54:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/08/25 11:50:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/10/02 00:36:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/25 10:08:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/01/10 12:28:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\clp
[2010/10/25 10:25:42 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/07/03 08:56:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2012/03/31 12:43:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2012/08/25 10:16:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HardwareHelper
[2012/12/22 00:30:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[2008/05/19 13:25:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IM
[2008/05/19 10:19:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail
[2013/03/07 19:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/10/02 00:39:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/12 09:57:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008/11/07 10:05:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2013/03/19 15:48:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2011/02/27 19:35:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Photo Notifier and Animation Creator
[2009/11/21 10:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2007/08/10 12:13:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/01/12 04:14:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/07/30 00:44:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2008/07/26 02:24:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WORDsearch
[2008/07/26 02:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wsc
[2011/04/18 20:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/27 20:43:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/07/26 02:13:22 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CDF61231-6AD7-4969-B4DD-9E6C0F51DD5E}
[2012/04/03 14:24:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Acapela Group
[2008/11/05 11:00:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Audacity
[2010/01/07 14:14:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\AVG9
[2012/06/16 10:17:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\blekkotb_019
[2007/11/28 10:15:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Canon
[2008/10/29 01:17:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Crossword Compiler 8
[2008/06/21 17:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\DMCache
[2009/02/04 17:02:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\eBookPro6
[2008/06/17 15:23:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\EBookSys
[2007/09/27 11:30:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\eFax Messenger
[2012/03/06 18:57:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\EPSON
[2012/12/09 22:46:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\EurekaLog
[2013/01/23 01:46:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\GlarySoft
[2007/08/05 10:42:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\InterVideo
[2007/12/05 13:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\INVISUS
[2012/11/25 12:01:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\IObit
[2010/04/10 12:42:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\MsgCnf
[2012/03/24 17:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\MSNInstaller
[2010/05/21 00:29:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\MxBoost
[2010/04/13 20:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\MyShoppingGenie
[2010/06/30 19:37:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\ooVoo Details
[2009/12/11 17:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\OpenOffice.org
[2008/06/28 23:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Opera
[2011/03/12 09:58:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\ParetoLogic
[2009/11/23 01:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\ReaSoft
[2013/03/19 17:56:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Reason
[2010/02/26 10:34:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\TeamViewer
[2007/12/05 13:16:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\TuneUp Software
[2012/08/25 12:25:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Uniblue
[2012/01/26 01:37:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\uTorrent
[2011/09/23 15:06:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Windows Desktop Search
[2011/09/23 15:12:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Authorized User\Application Data\Windows Search
[2012/10/24 08:39:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\IObit
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

1B5B4F1
< End of report >