OTL Text
OTL logfile created on: 9/28/2011 8:26:07 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 1.16 Gb Available Physical Memory | 77.32% Memory free
2.85 Gb Paging File | 2.72 Gb Available in Paging File | 95.31% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 147.51 Gb Total Space | 125.55 Gb Free Space | 85.11% Space Free | Partition Type: NTFS
Drive D: | 5.14 Gb Total Space | 0.95 Gb Free Space | 18.44% Space Free | Partition Type: FAT32
Drive H: | 7.53 Gb Total Space | 7.52 Gb Free Space | 99.81% Space Free | Partition Type: FAT32
Computer Name: BILLSR | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\Share\PIHook.dll ()
========== Win32 Services (SafeList) ==========
SRV - (SDhelper) -- File not found
SRV - (NVSvc) -- File not found
SRV - (JavaQuickStarterService) -- File not found
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) -- File not found
SRV - (AppMgmt) -- File not found
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
========== Driver Services (SafeList) ==========
DRV - (PSI) -- C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (symlcbrd) -- C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (Ps2) -- C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (Afc) -- C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (S3Psddr) -- C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (MxlW2k) -- C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (AFS2K) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (snapman) -- C:\WINDOWS\System32\DRIVERS\snapman.sys (Acronis)
DRV - (MAPMEM) -- C:\Program Files\CheckIt\Diagnostics\MAPMEM.SYS ()
DRV - (BCMNTIO) -- C:\Program Files\CheckIt\Diagnostics\BCMNTIO.SYS ()
DRV - (nvnforce) Service for NVIDIA(R) nForce(TM) -- C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA(R) nForce(TM) -- C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (nv_agp) -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (nvcap) nVidia WDM Video Capture (universal) -- C:\WINDOWS\system32\drivers\nvcap.sys ()
DRV - (NVXBAR) -- C:\WINDOWS\system32\drivers\nvxbar.sys (NVIDIA Corporation)
DRV - (viaagp1) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (fasttx2k) -- C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (SiS315) -- C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (NVENET) -- C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (SiSkp) -- C:\WINDOWS\system32\drivers\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP) -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (rtl8139) -- C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://srch-qus10.hpwis.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://qus10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-qus10.hpwis.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/?s=https&r0=1276167334
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.1879: C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1939: C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.872: C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2011/09/26 01:35:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [PopUpStopperFreeEdition] C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.60.2 192.168.60.3 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60578A1D-F672-4C15-B767-65A2E2E0CF00}: DhcpNameServer = 192.168.60.2 192.168.60.3 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\My Documents\My Pictures\smile.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\My Documents\My Pictures\smile.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/11 06:16:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/28 20:24:41 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/09/28 20:18:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Owner\Recent
[2011/09/28 20:18:47 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/09/27 16:21:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/09/25 01:02:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\second logs
[2011/09/25 01:01:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\first logs
[2011/09/22 21:09:04 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/22 21:09:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/09/18 03:34:37 | 000,000,000 | ---D | C] -- C:\Program Files\CafeScribe Offline
[2011/09/18 02:52:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Ethics
[2011/09/18 02:51:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Biology
[2011/09/18 02:49:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Mangerial Accounting
[2011/09/18 02:48:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Business Calc
[2006/11/21 19:52:08 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/28 20:24:45 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/09/28 19:09:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/09/28 19:09:05 | 1609,945,088 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/27 16:11:10 | 000,000,617 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to ComboFix.exe.lnk
[2011/09/26 23:37:41 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2003.lnk
[2011/09/26 01:35:02 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/09/23 23:25:36 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\MBR.dat
[2011/09/22 21:09:08 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/22 15:33:31 | 010,223,616 | ---- | M] () -- C:\Documents and Settings\Owner\ntuser.bak
[2011/09/21 03:50:39 | 000,001,538 | ---- | M] () -- C:\WINDOWS\System32\CountBlockedByFirewall.XML
[2011/09/18 03:34:37 | 000,000,738 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CafeScribe Offline.lnk
[2011/09/18 03:34:29 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\com.Follett.CafeScribe.Offline_state.xml
[2011/09/17 21:26:18 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110922-175058.backup
[2011/09/17 21:14:17 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner\defogger_reenable
[2011/09/14 09:45:19 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/27 16:11:10 | 000,000,617 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to ComboFix.exe.lnk
[2011/09/23 23:25:36 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\MBR.dat
[2011/09/23 00:34:34 | 1609,945,088 | -HS- | C] () -- C:\hiberfil.sys
[2011/09/22 22:58:45 | 000,454,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\mrxsmb.svs
[2011/09/22 21:09:08 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/18 03:34:29 | 000,000,377 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\com.Follett.CafeScribe.Offline_state.xml
[2011/09/17 21:14:17 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\defogger_reenable
[2011/07/27 22:14:01 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/07/27 22:14:01 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/07/27 22:14:01 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/07/27 22:14:01 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/07/27 22:14:01 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/07/27 21:52:50 | 000,012,084 | -HS- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\306m286c3ht12fbhr40333q55j27e0i1ue06
[2011/07/27 21:52:50 | 000,012,084 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\306m286c3ht12fbhr40333q55j27e0i1ue06
[2011/07/13 03:00:59 | 000,013,004 | -HS- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\d8cuhn4b277pj1vnbjoj5h37u7j
[2011/07/13 03:00:59 | 000,013,004 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\d8cuhn4b277pj1vnbjoj5h37u7j
[2011/06/14 19:16:43 | 000,013,764 | -HS- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\o65qw5qxmp45w71w2010773
[2011/06/14 19:16:43 | 000,013,764 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\o65qw5qxmp45w71w2010773
[2011/06/05 17:16:40 | 000,012,054 | -HS- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\8f2gvu11wnj076224dw377dm
[2011/06/05 17:16:40 | 000,012,054 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\8f2gvu11wnj076224dw377dm
[2011/05/17 23:34:21 | 000,000,208 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\m2647CgIbCbK8588
[2011/02/15 19:44:56 | 000,000,064 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Statdisk.prefs
[2010/05/14 01:32:39 | 000,000,035 | ---- | C] () -- C:\WINDOWS\worldbuilder.INI
[2010/05/07 10:29:01 | 000,000,107 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\netstat.bat
[2010/04/20 23:03:36 | 000,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2009/09/11 10:57:10 | 000,001,152 | ---- | C] () -- C:\WINDOWS\System32\windrv.sys
[2009/09/10 03:07:16 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/17 22:38:18 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2008/06/17 22:38:18 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2008/06/17 22:36:27 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPCX8400.ini
[2008/02/28 15:30:08 | 000,008,784 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/03/05 13:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/01/15 00:01:25 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/04/13 00:57:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006/04/11 19:36:11 | 000,000,206 | ---- | C] () -- C:\WINDOWS\HPGdiPlus.ini
[2006/03/09 19:58:24 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\rrsec.dll
[2006/03/09 19:58:24 | 000,090,151 | ---- | C] () -- C:\WINDOWS\System32\rrsec2k.exe
[2006/03/08 23:46:46 | 000,015,872 | ---- | C] () -- C:\WINDOWS\System32\drivers\AdFirewall.SYS
[2006/02/13 22:38:41 | 000,007,512 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/02/13 22:38:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2005/06/06 15:01:41 | 000,004,156 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2005/06/02 19:32:41 | 000,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2005/06/02 19:32:25 | 000,205,312 | R--- | C] () -- C:\WINDOWS\pw32a.dll
[2005/06/02 11:50:42 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2005/06/02 11:50:42 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2005/06/02 11:50:42 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2005/06/02 11:50:42 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2005/06/02 11:50:42 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2005/06/02 11:50:42 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2005/06/02 11:50:42 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2005/06/02 11:50:42 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2005/06/02 11:50:42 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2005/06/02 11:50:42 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2005/05/09 20:16:57 | 000,071,749 | ---- | C] () -- C:\WINDOWS\hcextoutput.dll
[2005/05/09 20:16:57 | 000,000,823 | ---- | C] () -- C:\WINDOWS\tsc.ini
[2005/05/09 20:15:50 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/03/23 22:58:46 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2005/01/02 19:44:42 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI_setup.ini
[2005/01/02 19:44:29 | 000,073,220 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2005/01/02 19:44:29 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2005/01/02 19:44:29 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2005/01/02 19:44:28 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2005/01/02 19:37:44 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPCX4600.ini
[2005/01/02 00:32:24 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2004/11/29 19:58:20 | 000,000,051 | ---- | C] () -- C:\WINDOWS\iTouch.ini
[2004/09/27 09:16:55 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/07/21 21:50:11 | 000,000,027 | ---- | C] () -- C:\WINDOWS\FTSL.INI
[2004/07/06 10:23:45 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/06/19 14:38:22 | 000,000,395 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2004/06/19 13:52:43 | 000,000,744 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2004/06/16 17:59:28 | 000,142,336 | ---- | C] () -- C:\WINDOWS\System32\faboot.exe
[2004/05/10 20:55:25 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A6W.INI
[2004/05/10 20:55:19 | 000,002,140 | ---- | C] () -- C:\WINDOWS\AWSHKWV.INI
[2004/04/02 22:49:59 | 000,001,402 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2004/04/02 22:23:52 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.Owner.ini
[2004/04/02 16:55:09 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2004/04/02 16:52:22 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\setupnt.dll
[2004/04/02 15:13:34 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\nvuaudio.exe
[2004/04/02 15:09:09 | 000,001,181 | ---- | C] () -- C:\WINDOWS\System32\imbrmute.ini
[2004/03/22 11:42:36 | 000,811,008 | ---- | C] () -- C:\WINDOWS\System32\MYCALC.DLL
[2003/11/15 04:23:36 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/11/15 04:23:33 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/11/15 04:23:16 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/11/15 04:23:16 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/11/15 04:22:31 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/11/15 04:22:28 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/11/15 03:57:41 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/11/15 03:57:41 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/11/15 03:57:39 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/11/08 01:34:36 | 000,009,216 | ---- | C] () -- C:\WINDOWS\System32\PURGEDRM.dll
[2003/10/14 09:52:37 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/10/14 09:35:01 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
[2003/10/11 08:51:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/10/11 08:50:32 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/10/11 08:50:32 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2003/10/11 08:47:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2003/10/11 08:45:41 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/10/11 08:42:56 | 000,090,112 | R--- | C] () -- C:\WINDOWS\bwUnin-6.2.3.66L.exe
[2003/10/11 08:40:57 | 000,029,222 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2003/10/11 08:40:38 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2003/10/11 08:40:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2003/10/11 08:29:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/10/11 08:16:42 | 000,000,907 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/10/11 07:34:34 | 000,006,848 | ---- | C] () -- C:\WINDOWS\System32\hphmon05.dat
[2003/10/11 07:34:21 | 000,018,403 | ---- | C] () -- C:\WINDOWS\HPHins01.dat
[2003/10/11 07:34:21 | 000,004,308 | ---- | C] () -- C:\WINDOWS\hphmdl01.dat
[2003/10/11 07:25:05 | 000,034,468 | ---- | C] () -- C:\WINDOWS\hpomdl03.dat
[2003/10/11 07:25:05 | 000,028,885 | ---- | C] () -- C:\WINDOWS\hpoins03.dat
[2003/10/11 07:08:49 | 000,001,040 | ---- | C] () -- C:\WINDOWS\System32\drivers\alcxinit.dat
[2003/10/11 07:07:05 | 000,126,348 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvcap.sys
[2003/10/11 07:05:13 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis740.bin
[2003/10/11 07:05:13 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis650.bin
[2003/10/11 06:47:37 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/10/11 06:39:21 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2003/10/11 06:39:21 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2003/10/11 06:39:04 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2003/10/11 06:19:00 | 000,000,905 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/10/11 06:17:38 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2003/10/11 06:14:08 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2003/10/11 06:06:45 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/10/11 06:06:18 | 000,463,448 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/10/11 06:06:18 | 000,078,024 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/10/11 03:10:46 | 000,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
[2003/10/11 03:10:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
[2003/10/11 02:45:39 | 000,001,648 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2003/10/10 23:10:25 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/10/10 23:09:39 | 000,177,856 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/09/23 04:19:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/01/08 01:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/19 17:30:00 | 000,216,576 | ---- | C] () -- C:\WINDOWS\System32\PowerCalc.exe
[2000/01/28 01:00:00 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\wrkgadm.exe
[2000/01/28 01:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1999/07/23 14:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
========== LOP Check ==========
[2006/02/13 22:42:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund
[2008/06/17 22:45:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/10/11 21:08:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2010/02/10 16:55:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2004/07/07 13:22:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FullAudio
[2006/08/02 20:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Individual Software
[2009/12/26 02:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2008/12/11 12:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2008/12/11 13:01:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/09/24 16:44:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/21 00:37:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrojanHunter
[2007/03/29 22:08:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2004/04/02 16:54:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Acronis
[2011/08/22 18:17:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Blackboard
[2011/01/05 18:39:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Centra
[2011/08/22 18:10:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Collaborate
[2011/08/23 11:59:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\com.Follett.CafeScribe.Offline
[2008/10/12 10:27:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\EPSON
[2009/09/11 10:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2011/05/16 05:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\HorizonWimba
[2006/02/13 22:37:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Individual Software
[2003/10/14 09:35:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\interMute
[2004/04/23 12:10:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\InterVideo
[2005/06/03 04:03:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\IsolatedStorage
[2004/04/23 12:06:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Leadertech
[2011/01/06 20:04:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\MyScribe
[2003/10/11 09:03:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SampleView
[2005/01/17 22:14:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
[2010/04/21 00:10:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\TrojanHunter
[2007/03/29 22:08:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Viewpoint
[2010/05/07 00:19:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\WinPatrol
[2011/09/28 07:30:09 | 000,030,600 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF54F1CA
@Alternate Data Stream - 155 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP

FC5A2B2
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EA029835
< End of report >