OTL logfile created on: 12/1/2010 12:41:20 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
766.00 Mb Total Physical Memory | 475.00 Mb Available Physical Memory | 62.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.65 Gb Total Space | 1.76 Gb Free Space | 9.42% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 248.83 Gb Free Space | 83.48% Space Free | Partition Type: NTFS
Computer Name: COMP1 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2010/12/01 00:40:36 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/11/16 10:26:34 | 000,061,720 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QueryExplorer\queryexplorer119.exe
PRC - [2010/11/16 10:26:34 | 000,061,720 | ---- | M] () -- C:\Program Files\QueryExplorer\queryexplorer.exe
PRC - [2010/04/05 23:01:06 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/05/19 10:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/03/15 12:49:54 | 000,060,928 | RHS- | M] () -- C:\Documents and Settings\Owner\Application Data\ShieldManager.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2001/11/29 18:10:28 | 000,045,056 | ---- | M] ( ) -- C:\WINDOWS\system32\slserv.exe
========== Modules (SafeList) ========== MOD - [2010/12/01 00:40:36 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
MOD - [2010/11/16 10:27:16 | 000,577,536 | ---- | M] () -- C:\Program Files\QueryExplorer\queryexplorer.dll
MOD - [2006/08/25 08:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/11/16 10:26:34 | 000,061,720 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\QueryExplorer\queryexplorer119.exe -- (QueryExplorer Service)
SRV - [2010/02/11 20:24:40 | 001,181,328 | ---- | M] (Lavasoft) [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/01/25 10:00:54 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2009/05/19 10:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2008/12/08 18:01:58 | 000,533,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2005/11/14 02:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2001/11/29 18:10:28 | 000,045,056 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\slserv.exe -- (SLService)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\RTL8187B.sys -- (RTL8187B)
DRV - [2009/04/30 22:56:32 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2008/12/08 18:01:56 | 000,055,136 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2005/05/11 00:33:12 | 000,032,256 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdrbsdrv.sys -- (cdrbsdrv)
DRV - [2005/04/22 21:14:42 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PieAutoUpdater\pgfilter.sys -- (pgfilter)
DRV - [2002/10/02 08:57:12 | 000,013,532 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SjyPkt.sys -- (SjyPkt)
DRV - [2002/03/11 10:26:56 | 000,089,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1000nt5.sys -- (E1000) Intel(R)
DRV - [2001/12/05 16:48:12 | 000,322,948 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\slntamr.sys -- (Slntamr)
DRV - [2001/11/29 18:10:32 | 001,432,836 | ---- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\v90drv.sys -- (V90drv)
DRV - [2001/11/29 18:10:28 | 000,033,028 | ---- | M] (Vireo Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\slwdmsup.sys -- (SlWdmSup)
DRV - [2001/11/29 18:10:26 | 000,175,160 | ---- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\slnthal.sys -- (SlNtHal)
DRV - [2001/11/29 18:10:20 | 000,607,732 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ntmtlfax.sys -- (NtMtlFax)
DRV - [2001/11/29 18:10:18 | 002,383,460 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mtlstrm.sys -- (Mtlstrm)
DRV - [2001/11/29 18:10:14 | 000,172,708 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mtlmnt5.sys -- (Mtlmnt5)
DRV - [2001/08/17 05:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr9/*http://www.yahoo.com/ext/search/search.html IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.comIE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz2.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/06 13:52:41 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/30 12:10:38 | 000,000,000 | ---D | M]
[2010/04/06 13:53:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/10/24 16:01:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/11/30 12:19:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xp8te9cp.default\extensions
[2010/09/27 21:37:39 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xp8te9cp.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/04/17 13:57:50 | 000,000,000 | ---D | M] (Vuze Remote Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xp8te9cp.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/06/17 09:56:56 | 000,002,254 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xp8te9cp.default\searchplugins\askcom.xml
[2010/10/24 14:01:09 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/10/24 14:01:09 | 000,000,000 | ---D | M] (QueryExplorer) -- C:\Program Files\Mozilla Firefox\extensions\{27E679CC-6AAB-4B2A-BB87-096FE4178464}
O1 HOSTS File: ([2010/04/05 10:38:17 | 000,000,822 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz2.dll (Conduit Ltd.)
O2 - BHO: (no name) - {D5792AA9-D373-4039-8670-2CDAB6A71F15} - No CLSID value found.
O2 - BHO: (no name) - {DE50B320-D8D5-46C3-92CC-FC3CC17619F9} - No CLSID value found.
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Microsoft Shield Manager] C:\Documents and Settings\Owner\Application Data\ShieldManager.exe ()
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: google.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: jpcycles.com ([www] http in Trusted sites)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab (Reg Error: Key error.)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127151680796 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet32: DllName - cryptnet32.dll - C:\WINDOWS\System32\cryptnet32.dll ()
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/19 10:00:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{407dccd5-0331-11dd-bde9-00087431f1d6}\Shell\AutoRun\command - "" = E:\.Autorun\835694854683549385398626893468946\Autorun.exe -- File not found
O33 - MountPoints2\{407dccd5-0331-11dd-bde9-00087431f1d6}\Shell\open\command - "" = E:\.Autorun\835694854683549385398626893468946\Autorun.exe -- File not found
O33 - MountPoints2\{74fc03d1-f724-11de-81f6-00087431f1d6}\Shell\AutoRun\command - "" = H:\.Autorun\835694854683549385398626893468946\Autorun.exe -- File not found
O33 - MountPoints2\{74fc03d1-f724-11de-81f6-00087431f1d6}\Shell\open\command - "" = H:\.Autorun\835694854683549385398626893468946\Autorun.exe -- File not found
O33 - MountPoints2\{c9a7047f-292f-11da-8424-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{c9a7047f-292f-11da-8424-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c9a7047f-292f-11da-8424-806d6172696f}\Shell\AutoRun\command - "" = D:\AutoRunPro.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ========== [2010/12/01 00:40:36 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/30 12:05:46 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010/11/23 13:35:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\LMI1B.tmp
[2010/11/23 13:35:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\LMI1A.tmp
[2010/11/22 12:56:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/11/21 13:41:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\downloads from azureus
[2010/11/21 11:00:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\ConduitEngine
[2010/11/21 11:00:18 | 000,000,000 | ---D | C] -- C:\Program Files\ConduitEngine
[2010/11/02 20:00:44 | 000,000,000 | ---D | C] -- C:\Program Files\Incomplete
[2010/11/02 19:59:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\FrostWire
[2010/11/02 19:59:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\FrostWire
[2010/11/02 19:59:11 | 000,000,000 | ---D | C] -- C:\Program Files\FrostWire
[2009/01/10 20:36:10 | 001,144,136 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wlsetup-custom.exe
[2008/12/12 21:39:26 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Owner\Application Data\pcouffin.sys
[2008/12/12 21:29:54 | 016,944,264 | ---- | C] (VSO-Software ) -- C:\Program Files\vsoConvertXtoDVD3_setup-avangate_689.exe
[2008/04/25 05:30:38 | 016,500,592 | ---- | C] (DivX, Inc.) -- C:\Program Files\DivXInstaller.exe
[2008/04/06 09:14:04 | 007,980,040 | ---- | C] (Azureus, Inc.) -- C:\Program Files\Azureus_3.0.5.0_windows.exe
[2008/02/01 16:02:59 | 007,792,648 | ---- | C] (Azureus, Inc.) -- C:\Program Files\Azureus_3.0.4.2_windows.exe
[2008/01/28 09:42:33 | 058,619,176 | ---- | C] (Apple Inc.) -- C:\Program Files\iTunesSetup.exe
[2008/01/28 09:37:38 | 025,755,448 | ---- | C] (Microsoft Corporation) -- C:\Program Files\wmp11-windowsxp-x86-enu.exe
[2008/01/07 12:49:50 | 000,382,352 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\jre-6u3-windows-i586-p-iftw.exe
[2001/11/29 18:10:32 | 001,432,836 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\v90drv.sys
[2001/11/29 18:10:26 | 000,175,160 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\slnthal.sys
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/12/01 00:40:36 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/12/01 00:21:33 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/01 00:21:23 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/01 00:21:16 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/01 00:12:44 | 000,000,012 | ---- | M] () -- C:\WINDOWS\System32\crt.dat
[2010/12/01 00:12:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/30 14:24:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/11/30 12:21:32 | 000,010,832 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/11/30 12:10:38 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/30 12:00:15 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{4326F475-2E73-49F2-80AA-FE247CF805F4}.job
[2010/11/30 11:58:10 | 000,297,053 | ---- | M] () -- C:\WINDOWS\System32\shimg.dll
[2010/11/23 14:26:40 | 000,000,246 | ---- | M] () -- C:\WINDOWS\LEXSTAT.INI
[2010/11/22 18:21:00 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/22 12:34:53 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/21 21:00:31 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/11/21 21:00:31 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/11/21 21:00:31 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/11/21 17:20:38 | 000,046,592 | ---- | M] () -- C:\WINDOWS\System32\cryptnet32.dll
[2010/11/09 19:22:27 | 000,000,118 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2010/11/07 17:04:31 | 000,000,874 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.1.lnk
[2010/11/07 17:04:29 | 000,000,856 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\FrostWire 4.21.1.lnk
[2010/11/07 08:41:08 | 000,337,248 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/07 08:41:08 | 000,051,608 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/11/30 12:08:43 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/11/30 11:58:22 | 000,010,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010/11/21 17:23:10 | 000,000,012 | ---- | C] () -- C:\WINDOWS\System32\crt.dat
[2010/11/21 17:20:38 | 000,297,053 | ---- | C] () -- C:\WINDOWS\System32\shimg.dll
[2010/11/21 17:20:38 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\cryptnet32.dll
[2010/11/18 20:04:50 | 733,855,744 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Next (Sci-fi-Action) Nicholas Cage, Julianne Moore, Jessica Biel.avi
[2010/11/15 20:21:18 | 000,060,928 | RHS- | C] () -- C:\Documents and Settings\Owner\Application Data\ShieldManager.exe
[2010/11/07 17:04:31 | 000,000,874 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.1.lnk
[2010/11/07 17:04:29 | 000,000,856 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\FrostWire 4.21.1.lnk
[2009/12/30 13:53:01 | 001,606,064 | ---- | C] () -- C:\Program Files\googletalk-setup.exe
[2009/12/22 13:25:34 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/06 10:11:24 | 000,221,696 | ---- | C] () -- C:\Program Files\McAfeeActiveProtection.msi
[2009/04/30 22:39:36 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/04/16 22:01:37 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/03/21 19:32:23 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/12/12 21:40:21 | 000,000,671 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\vso_ts_preview.xml
[2008/12/12 21:39:49 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\pcouffin.log
[2008/12/12 21:39:26 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\inst.exe
[2008/12/12 21:39:26 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\pcouffin.cat
[2008/12/12 21:39:26 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\pcouffin.inf
[2008/04/05 15:50:48 | 035,960,792 | ---- | C] () -- C:\Program Files\avg75free_519a1276.exe
[2008/04/01 19:18:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\bteasy.ini
[2008/03/02 14:58:24 | 000,007,207 | R--- | C] () -- C:\WINDOWS\Disktool.INI
[2008/03/02 14:58:24 | 000,006,399 | R--- | C] () -- C:\WINDOWS\fwupgrade.ini
[2008/03/02 14:58:24 | 000,003,677 | R--- | C] () -- C:\WINDOWS\PlaySnd.INI
[2008/02/02 22:17:00 | 000,024,468 | ---- | C] () -- C:\Program Files\Man_on_fire.3321480.TPB.torrent
[2008/02/01 20:37:49 | 002,278,771 | ---- | C] () -- C:\Program Files\BitTorrent-3.4.2.exe
[2008/02/01 16:41:42 | 000,029,518 | ---- | C] () -- C:\Program Files\Man_on_Fire__2004__DvDrip_ENG_.torrent
[2008/02/01 16:36:13 | 000,219,952 | ---- | C] () -- C:\Program Files\utorrent.exe
[2008/02/01 16:34:01 | 000,029,859 | ---- | C] () -- C:\Program Files\[isoHunt]_download.torrent
[2008/02/01 16:16:28 | 000,028,298 | ---- | C] () -- C:\Program Files\O_s_historie..3263434.TPB.torrent
[2008/02/01 16:06:12 | 000,089,463 | ---- | C] () -- C:\Program Files\Man_on_Fire.3314824.TPB.torrent
[2008/02/01 14:27:36 | 000,015,854 | ---- | C] () -- C:\Program Files\Documentary_The.Story.of.O.1975.DVDRip.DivX.FR.-.BG.SUB[
www.btmon.com].torrent[2008/01/30 23:28:33 | 003,519,966 | ---- | C] () -- C:\Program Files\TorrentStorm-1.3.exe
[2008/01/07 22:06:43 | 000,062,982 | ---- | C] () -- C:\Program Files\Man.on.Fire.2004.DVDRip.XviD.iNT-PFa.3727267.TPB.torrent
[2008/01/07 19:08:41 | 000,014,780 | ---- | C] () -- C:\Program Files\The.Story.of.O.1975.DVDRip.DivX.FR.-.BG.SUB_-_[TeSTER].torrent
[2008/01/07 01:30:18 | 000,022,447 | ---- | C] () -- C:\Program Files\Man.On.Fire.PAL.NODRiC.DVDR_-_Pitbull.3928947.TPB.torrent
[2008/01/07 00:55:46 | 025,235,178 | ---- | C] () -- C:\Program Files\BitZip-Powered_By_Miro.exe
[2008/01/07 00:50:36 | 000,150,537 | ---- | C] () -- C:\Program Files\CREASY_man_on_fire_special_edition_CBB_DVD_[
www.Fulldls.com].torrent[2008/01/07 00:23:51 | 000,002,858 | ---- | C] () -- C:\Program Files\BitTornado-0.3.17-w32install.exe.torrent
[2008/01/03 23:11:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\setup32.INI
[2007/07/11 18:23:27 | 000,000,246 | ---- | C] () -- C:\WINDOWS\LEXSTAT.INI
[2005/09/19 11:04:32 | 000,012,288 | R--- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2005/09/19 10:04:22 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/09/19 09:47:52 | 000,000,330 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/09/19 02:52:28 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/09/16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS
[2001/12/05 16:48:12 | 000,322,948 | ---- | C] () -- C:\WINDOWS\System32\drivers\slntamr.sys
[2001/11/29 18:10:36 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\slextspk.dll
[2001/11/29 18:10:36 | 000,151,552 | ---- | C] () -- C:\WINDOWS\System32\amr_cpl.dll
[2001/11/29 18:10:20 | 000,607,732 | ---- | C] () -- C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2001/11/29 18:10:18 | 002,383,460 | ---- | C] () -- C:\WINDOWS\System32\drivers\mtlstrm.sys
[2001/11/29 18:10:14 | 000,172,708 | ---- | C] () -- C:\WINDOWS\System32\drivers\mtlmnt5.sys
< End of report >