OTL logfile created on: 3/14/2010 8:06:56 PM - Run 1
OTL by OldTimer - Version 3.1.37.1 Folder = C:\Documents and Settings\Donnie Thibodeaux\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 59.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 766 766 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 19.07 Gb Total Space | 4.10 Gb Free Space | 21.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 149.05 Gb Total Space | 128.25 Gb Free Space | 86.05% Space Free | Partition Type: NTFS
Computer Name: THIBODEAUX
Current User Name: Donnie Thibodeaux
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/03/14 20:04:11 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\OTL.exe
PRC - [2007/06/13 05:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINNT\explorer.exe
PRC - [2006/03/03 21:03:10 | 000,069,632 | ---- | M] (HP) -- C:\WINNT\system32\HPZipm12.exe
PRC - [2006/02/10 07:56:12 | 000,479,232 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
PRC - [2005/06/23 20:27:36 | 000,085,696 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\VPTray.exe
PRC - [2005/06/23 20:27:28 | 001,715,904 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2005/06/23 20:27:18 | 000,019,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe
PRC - [2005/06/02 10:21:46 | 000,161,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2005/06/02 10:21:40 | 000,185,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2005/06/02 10:21:38 | 000,048,752 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2004/08/04 01:56:52 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\inetsrv\inetinfo.exe
PRC - [2001/08/23 07:00:00 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\tcpsvcs.exe
========== Modules (SafeList) ========== MOD - [2010/03/14 20:04:11 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\OTL.exe
MOD - [2006/08/25 10:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINNT\winsxs\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2006/11/20 03:42:45 | 000,033,280 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\snmp.exe -- (SNMP)
SRV - [2006/03/03 21:03:10 | 000,069,632 | ---- | M] (HP) [Unknown | Running] -- C:\WINNT\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2005/10/06 19:12:30 | 000,855,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS)
SRV - [2005/06/23 20:27:30 | 000,124,608 | ---- | M] (symantec) [On_Demand | Stopped] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2005/06/23 20:27:28 | 001,715,904 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2005/06/23 20:27:18 | 000,019,648 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2005/06/02 10:21:46 | 000,161,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2005/06/02 10:21:46 | 000,083,568 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc)
SRV - [2005/06/02 10:21:40 | 000,185,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2005/04/22 13:03:28 | 000,206,552 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2005/03/30 22:48:22 | 000,992,864 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)
SRV - [2004/08/04 01:56:58 | 000,050,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\utilman.exe -- (UtilMan)
SRV - [2004/08/04 01:56:52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2004/08/04 01:56:52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\inetsrv\inetinfo.exe -- (SMTPSVC) Simple Mail Transfer Protocol (SMTP)
SRV - [2004/08/04 01:56:52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2004/08/04 01:56:46 | 000,086,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2004/08/04 01:56:44 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\iprip.dll -- (Iprip)
SRV - [2001/08/23 07:00:00 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\tcpsvcs.exe -- (SimpTcp)
SRV - [2001/08/23 07:00:00 | 000,019,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\tcpsvcs.exe -- (LPDSVC)
========== Driver Services (SafeList) ========== DRV - [2010/02/16 04:00:00 | 001,324,720 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100313.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2010/02/16 04:00:00 | 000,084,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100313.002\NAVENG.SYS -- (NAVENG)
DRV - [2009/08/27 03:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2009/06/22 06:48:44 | 000,091,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\mqac.sys -- (MQAC)
DRV - [2008/06/20 04:52:06 | 000,225,920 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINNT\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008/05/08 07:28:49 | 000,202,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2006/10/17 20:22:26 | 000,009,216 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINNT\system32\DRIVERS\videX32.sys -- (videX32)
DRV - [2006/02/21 22:46:25 | 001,505,792 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/01/20 16:47:43 | 000,058,000 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINNT\system32\drivers\cdr4_2K.sys -- (Cdr4_2K)
DRV - [2005/09/05 09:39:22 | 000,040,576 | ---- | M] () [Kernel | System | Running] -- C:\WINNT\system32\drivers\sdcplh.sys -- (sdcplh)
DRV - [2005/08/19 03:00:00 | 000,002,560 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINNT\system32\drivers\cdralw2k.sys -- (Cdralw2k)
DRV - [2005/05/13 20:50:10 | 000,123,488 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
DRV - [2005/04/22 13:03:02 | 000,267,192 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINNT\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2005/04/22 13:03:00 | 000,017,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2005/03/30 22:48:20 | 000,372,832 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2005/02/04 21:14:32 | 000,053,896 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2005/02/04 21:14:30 | 000,324,232 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV - [2004/10/05 17:54:00 | 000,009,038 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINNT\System32\Drivers\viausb.sys -- (viafilter)
DRV - [2004/08/04 00:10:14 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\mpe.sys -- (MPE)
DRV - [2003/09/19 14:47:24 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\pfc.sys -- (pfc)
DRV - [2003/06/19 14:05:04 | 000,024,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\openhci.sys -- (openhci)
DRV - [2003/06/16 11:05:40 | 000,369,920 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\viaudios.sys -- (VIAudio) VIA AC'97 Audio Controller (WDM)
DRV - [2003/05/27 16:45:06 | 000,003,351 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\vsp.sys -- (Vsp)
DRV - [2003/01/09 21:32:30 | 000,069,472 | R--- | M] (VIA Technologies, INC.) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\usbhub20.sys -- (usbhub20)
DRV - [2001/10/18 13:00:00 | 000,006,234 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Stopped] -- C:\WINNT\System32\DRIVERS\viaide.sys -- (viaide)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
[2009/07/08 16:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\Mozilla\Extensions
[2009/07/08 16:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\Mozilla\Extensions\mozswing@mozswing.org
O1 HOSTS File: ([2010/03/13 16:05:09 | 000,000,734 | ---- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (ST) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (Microsoft Corporation)
O2 - BHO: (MSNToolBandBHO) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe File not found
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe File not found
O4 - HKLM..\Run: [MsmqIntCert] C:\WINNT\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe File not found
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [VTTimer] File not found
O4 - HKCU..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: com.tw ([asia.msi] http in Trusted sites)
O15 - HKCU\..Trusted Domains: com.tw ([global.msi] http in Trusted sites)
O15 - HKCU\..Trusted Domains: com.tw ([www.msi] http in Trusted sites)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - File not found
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINNT\system32\NavLogon.dll - C:\WINNT\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\wzcnotif: DllName - wzcdlg.dll - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Donnie Thibodeaux\My Documents\Unzipped\south park theme\Southpark\wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/20 11:58:39 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/03/14 20:04:09 | 000,555,008 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\OTL.exe
[2010/03/13 16:15:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\Malwarebytes
[2010/03/13 16:15:22 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbamswissarmy.sys
[2010/03/13 16:15:20 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbam.sys
[2010/03/13 16:15:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/13 16:15:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/13 16:05:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\backups
[2010/03/12 22:06:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/10 19:11:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Local Settings\Application Data\mvwmdg
[2010/03/04 17:54:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/28 16:52:21 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Software
[2010/02/28 16:51:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/02/28 16:51:17 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Swift Sound
[2010/02/28 16:51:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\NCH Swift Sound
[2010/02/28 16:50:13 | 000,338,624 | ---- | C] (NCH Software) -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\switchsetup.exe
[2010/02/28 16:34:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\Xilisoft Corporation
[2010/02/28 16:34:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\Xilisoft Corporation
[2010/02/27 18:47:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\Downloads
[2010/02/27 18:47:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Application Data\GetRightToGo
[2010/02/16 18:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\maps- dui
[2010/02/13 15:51:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\Temp videos
[2010/01/18 14:12:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/04/15 08:11:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2006/12/06 17:02:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2006/11/18 22:44:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2006/03/20 09:39:51 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/03/15 18:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2006/03/15 03:04:18 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/02/19 03:28:56 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) -- C:\WINNT\Fonts\RandFont.dll
[6 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[5 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/03/14 20:04:11 | 000,555,008 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\OTL.exe
[2010/03/14 19:02:51 | 000,002,133 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/03/13 19:53:19 | 000,000,006 | -H-- | M] () -- C:\WINNT\tasks\SA.DAT
[2010/03/13 19:52:58 | 000,002,048 | --S- | M] () -- C:\WINNT\bootstat.dat
[2010/03/13 19:51:38 | 004,456,448 | -H-- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\NTUSER.DAT
[2010/03/13 19:51:12 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\ntuser.ini
[2010/03/13 18:24:30 | 003,788,308 | -H-- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\Local Settings\Application Data\IconCache.db
[2010/03/13 16:15:24 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/13 16:05:09 | 000,000,734 | ---- | M] () -- C:\WINNT\System32\drivers\etc\hosts
[2010/03/12 15:19:21 | 000,002,206 | ---- | M] () -- C:\WINNT\System32\wpa.dbl
[2010/03/08 14:12:02 | 000,000,284 | ---- | M] () -- C:\WINNT\tasks\AppleSoftwareUpdate.job
[2010/03/07 06:16:12 | 000,000,116 | ---- | M] () -- C:\WINNT\NeroDigital.ini
[2010/03/07 06:09:34 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/06 17:32:23 | 000,038,367 | ---- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\metallica burn.nr3
[2010/03/06 16:49:45 | 000,012,146 | ---- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\metallica play list-burn.nri
[2010/03/05 16:02:37 | 000,001,725 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/03/04 22:43:16 | 577,794,772 | ---- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\PICT0006.AVI
[2010/03/04 18:59:54 | 000,639,091 | ---- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\Police Officer sulfer.pdf
[2010/03/03 19:59:07 | 000,325,632 | ---- | M] () -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\Harris County Child Support.doc
[2010/02/28 16:51:30 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Switch Sound File Converter.lnk
[2010/02/28 16:50:14 | 000,338,624 | ---- | M] (NCH Software) -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\switchsetup.exe
[2010/02/24 19:22:07 | 000,001,374 | ---- | M] () -- C:\WINNT\imsins.BAK
[2010/02/18 11:16:42 | 000,079,760 | -H-- | M] () -- C:\WINNT\System32\mlfcache.dat
[2010/02/17 21:21:51 | 000,230,808 | RH-- | M] (Coupons, Inc.) -- C:\WINNT\System32\cpnprt2.cid
[6 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[5 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/13 16:15:24 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/12 17:55:53 | 000,263,168 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\rkill.com
[2010/03/09 23:12:33 | 000,040,576 | ---- | C] () -- C:\WINNT\System32\drivers\sdcplh.sys
[2010/03/07 06:09:40 | 577,794,772 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\PICT0006.AVI
[2010/03/06 17:32:23 | 000,038,367 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\metallica burn.nr3
[2010/03/05 17:07:44 | 000,012,146 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\Desktop\metallica play list-burn.nri
[2010/03/04 18:59:54 | 000,639,091 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\Police Officer sulfer.pdf
[2010/03/03 19:59:07 | 000,325,632 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\My Documents\Harris County Child Support.doc
[2010/02/28 16:51:30 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Switch Sound File Converter.lnk
[2010/02/18 11:16:42 | 000,079,760 | -H-- | C] () -- C:\WINNT\System32\mlfcache.dat
[2010/02/17 19:16:29 | 000,001,725 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2008/06/25 22:07:31 | 000,003,351 | ---- | C] () -- C:\WINNT\System32\drivers\vsp.sys
[2008/06/18 19:18:23 | 000,000,140 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\Local Settings\Application Data\fusioncache.dat
[2008/06/18 19:00:26 | 000,077,824 | R--- | C] () -- C:\WINNT\System32\HPZIDS01.dll
[2008/06/18 18:59:57 | 000,000,161 | ---- | C] () -- C:\WINNT\System32\AddPort.ini
[2008/06/18 18:58:40 | 000,000,737 | ---- | C] () -- C:\WINNT\hpntwksetup.ini
[2008/06/18 18:49:33 | 000,001,086 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/06/11 16:07:52 | 000,003,654 | ---- | C] () -- C:\WINNT\System32\drivers\Sonyhcp.dll
[2007/11/26 14:13:19 | 000,000,031 | -H-- | C] () -- C:\WINNT\uccspecc.sys
[2006/12/08 23:31:59 | 000,021,840 | ---- | C] () -- C:\WINNT\System32\SIntfNT.dll
[2006/12/08 23:31:59 | 000,017,212 | ---- | C] () -- C:\WINNT\System32\SIntf32.dll
[2006/12/08 23:31:59 | 000,012,067 | ---- | C] () -- C:\WINNT\System32\SIntf16.dll
[2006/12/08 23:14:58 | 000,000,025 | ---- | C] () -- C:\WINNT\SIERRA.INI
[2006/11/18 21:01:31 | 000,021,791 | ---- | C] () -- C:\WINNT\System32\smtpctrs.ini
[2006/11/18 21:01:30 | 000,001,037 | ---- | C] () -- C:\WINNT\System32\ntfsdrct.ini
[2006/11/18 21:00:53 | 000,038,576 | ---- | C] () -- C:\WINNT\System32\w3ctrs.ini
[2006/11/18 21:00:53 | 000,010,225 | ---- | C] () -- C:\WINNT\System32\axperf.ini
[2006/11/18 21:00:52 | 000,011,435 | ---- | C] () -- C:\WINNT\System32\infoctrs.ini
[2006/11/10 17:35:49 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/09/04 16:02:40 | 000,314,880 | ---- | C] () -- C:\WINNT\System32\Tx32.dll
[2006/08/20 05:16:34 | 000,196,608 | ---- | C] () -- C:\WINNT\System32\avisynth.dll
[2006/08/11 03:14:23 | 000,000,000 | ---- | C] () -- C:\WINNT\iPlayer.INI
[2006/05/05 16:22:02 | 000,000,116 | ---- | C] () -- C:\WINNT\NeroDigital.ini
[2006/04/28 12:43:55 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Donnie Thibodeaux\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/25 20:07:36 | 000,000,552 | ---- | C] () -- C:\WINNT\WM7.INI
[2006/03/15 18:26:45 | 000,000,000 | ---- | C] () -- C:\WINNT\vpc32.INI
[2006/03/15 07:15:59 | 000,028,672 | R--- | C] () -- C:\WINNT\System32\cmirmdrv.dll
[2006/03/15 02:21:53 | 000,032,768 | ---- | C] () -- C:\WINNT\System32\UnAudioNT.dll
[2006/03/11 13:31:06 | 000,000,020 | ---- | C] () -- C:\WINNT\Hposcv07.INI
[2006/01/20 13:47:35 | 000,382,159 | ---- | C] () -- C:\WINNT\System32\BOCOLE.DLL
[2006/01/20 13:47:35 | 000,319,696 | ---- | C] () -- C:\WINNT\System32\BOCOF.DLL
[2006/01/20 13:38:13 | 000,000,626 | ---- | C] () -- C:\WINNT\ODBC.INI
[2006/01/20 11:57:54 | 000,021,952 | -H-- | C] () -- C:\Program Files\folder.htt
[2004/09/17 18:37:42 | 000,069,632 | ---- | C] () -- C:\WINNT\System32\vuins32.dll
[2001/08/17 17:36:28 | 000,363,520 | ---- | C] () -- C:\WINNT\System32\psisdecd.dll
[2001/07/07 03:00:00 | 000,003,399 | ---- | C] () -- C:\WINNT\System32\hptcpmon.ini
[1999/12/07 07:00:00 | 000,176,400 | ---- | C] () -- C:\WINNT\System32\qcut.dll
[1999/09/25 05:36:24 | 000,088,816 | ---- | C] () -- C:\WINNT\System32\drivers\lvcam.sys
[1999/09/25 05:36:22 | 000,017,424 | ---- | C] () -- C:\WINNT\System32\drivers\lvsound.sys
[1998/08/16 06:00:00 | 000,004,096 | ---- | C] () -- C:\WINNT\System32\sysres.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >