This one is the OTL.txt:
OTL logfile created on: 27/03/2010 11:57:42 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Hannah\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 81.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.98 Gb Total Space | 202.59 Gb Free Space | 70.84% Space Free | Partition Type: NTFS
Drive D: | 12.11 Gb Total Space | 1.94 Gb Free Space | 16.01% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HANNAH-PC
Current User Name: Hannah
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/03/27 10:34:15 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\explorer.exe
PRC - [2010/02/18 16:22:26 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
========== Modules (SafeList) ========== MOD - [2010/03/27 10:34:15 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\explorer.exe
MOD - [2008/01/20 19:50:03 | 000,450,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008/01/20 19:48:06 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2008/01/20 19:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2007/10/17 16:37:22 | 000,412,672 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2009/12/09 15:23:34 | 000,365,280 | ---- | M] (PC Tools) [Auto | Stopped] -- C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/11/27 08:24:34 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2009/10/01 16:03:14 | 001,858,144 | ---- | M] (Emsi Software GmbH) [Auto | Stopped] -- C:\Program Files (x86)\a-squared Free\a2service.exe -- (a2free)
SRV - [2009/08/25 17:09:09 | 000,117,640 | R--- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe -- (Norton Internet Security)
SRV - [2008/10/25 11:44:08 | 000,065,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/10/06 09:54:52 | 000,365,952 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/07/27 11:01:49 | 000,093,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2006/11/02 06:34:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
SRV - [2006/11/01 23:35:15 | 000,060,994 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2006/11/01 23:35:15 | 000,055,846 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vss.mof -- (VSS)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnbIE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnbIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnbIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://search13.net/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://search13.net/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://search13.net/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=ZCxdm491VBCA&ptb=vX6EbNFAAlQIwlyHMMq9fAIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://search13.net/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search13.net/IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaulturl: "http://flvdirect.iamwired.net/websearch.php?src=tops&search="
FF - prefs.js..browser.search.selectedEngine: "MyWebSearch"
FF - prefs.js..browser.startup.homepage: "http://flvdirect.iamwired.net/"
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.2.1
FF - prefs.js..extensions.enabledItems: {624e6297-2280-db9d-b6b5-c65c71caca47}:4.6.6.6
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA80}:1.0.22
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA82}:1.0.2
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA96}:1.0.3
FF - prefs.js..extensions.enabledItems: {6236BA26-C117-4007-928C-DE0716C7FA99}:1.0.1
FF - prefs.js..extensions.enabledItems: {7645f4b1-1f19-13dd-2d6b-0200600c2a56}:1.0
FF - prefs.js..extensions.enabledItems: m3ffxtbr@mywebsearch.com:1.1
FF - prefs.js..keyword.URL: "http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm491VBCA&fl=0&ptb=vX6EbNFAAlQIwlyHMMq9fA&url=http://search.mywebsearch.com/mywebsearch/GGmain.jhtml&st=kwd&n=77c07070&searchfor="
FF - HKLM\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2010/03/27 10:30:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files (x86)\MyWebSearch\bar\2.bin [2010/03/25 15:16:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/02/18 16:22:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/03/25 15:16:35 | 000,000,000 | ---D | M]
[2009/11/05 16:50:51 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Mozilla\Extensions
[2010/03/27 10:31:18 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions
[2009/11/05 17:05:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/12 13:39:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA80}
[2010/03/12 13:39:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA82}
[2010/03/19 15:17:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}
[2010/03/12 13:39:44 | 000,000,000 | ---D | M] (FBFan) -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
[2010/03/19 20:13:35 | 000,000,000 | ---D | M] (U Flv) -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\extensions\{7645f4b1-1f19-13dd-2d6b-0200600c2a56}
[2010/03/25 16:36:21 | 000,009,985 | ---- | M] () -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\searchplugins\mywebsearch.xml
[2010/03/19 20:12:53 | 000,000,266 | ---- | M] () -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\searchplugins\Search.xml
[2010/03/19 15:27:06 | 000,001,586 | ---- | M] () -- C:\Users\Hannah\AppData\Roaming\Mozilla\Firefox\Profiles\dyryftfg.default\searchplugins\web-search.xml
[2010/03/27 11:53:06 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/03/19 20:13:02 | 000,000,000 | ---D | M] (LoudMo Contextual Ad Assistant) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{624e6297-2280-db9d-b6b5-c65c71caca47}
[2009/11/05 16:50:20 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\personas@christopher.beard
O1 HOSTS File: ([2006/09/18 14:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (flvdome) - {56357f9a-1f34-f456-27ef-aa5f3a8ced9b} - C:\Windows\SysWOW64\-W6H-_-.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (TomBHO Class) - {8AA217B9-D729-4ee0-AED7-E93D695E94A2} - C:\Program Files (x86)\Stylish Profile\tom4ie.dll (ChameleonTom)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (GdfrDUEn Class) - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files (x86)\Stylish Profile\enlbrdr.dll (TODO: )
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe ()
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files (x86)\MyWebSearch\bar\2.bin\M3SRCHMN.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files (x86)\MyWebSearch\bar\2.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort11reminder] C:\Program Files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [apllwspq] C:\Users\Hannah\AppData\Local\tfoier\qitesftav.exe ()
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files (x86)\Stylish Profile\ct.htm ()
O9 - Extra 'Tools' menuitem : StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files (x86)\Stylish Profile\ct.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInitialSetup1.0.1.1.cab (Reg Error: Key error.)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} https://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\CoIEPlg.dll (Symantec Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (OldTimer Tools)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (OldTimer Tools)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll ()
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img35.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img35.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0f595a91-aa3b-11de-8b99-001f16db6631}\Shell\AutoRun - "" = Autorun
O33 - MountPoints2\{0f595a99-aa3b-11de-8b99-001f16db6631}\Shell\AutoRun - "" = Autorun
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 14 Days ==========
[2010/03/27 11:13:37 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Desktop\IceSword122en
[2010/03/27 10:33:59 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Users\Hannah\Desktop\explorer.exe
[2010/03/26 23:14:47 | 000,000,000 | ---D | C] -- C:\Users\Hannah\Documents\a-squared Free
[2010/03/26 23:14:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\a-squared Free
[2010/03/26 22:27:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spyware Doctor
[2010/03/26 22:27:26 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Roaming\PC Tools
[2010/03/26 22:27:26 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/03/26 22:27:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2010/03/26 15:55:42 | 000,000,000 | ---D | C] -- C:\Users\Hannah\AppData\Local\tfoier
[2010/03/19 20:12:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FLV Direct Player
[2010/03/13 20:47:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64
[2010/03/13 20:47:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Security Scan
[2010/03/13 20:47:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NSSx64\0207030.022
[2010/03/13 17:47:32 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
========== Files - Modified Within 14 Days ==========
[2010/03/27 11:54:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/27 11:53:26 | 000,000,290 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2010/03/27 11:53:14 | 002,621,440 | -HS- | M] () -- C:\Users\Hannah\NTUSER.DAT
[2010/03/27 11:53:05 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/27 11:53:05 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/27 11:52:58 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/27 11:52:05 | 000,524,288 | -HS- | M] () -- C:\Users\Hannah\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/03/27 11:52:05 | 000,065,536 | -HS- | M] () -- C:\Users\Hannah\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/03/27 11:52:02 | 002,974,288 | -H-- | M] () -- C:\Users\Hannah\AppData\Local\IconCache.db
[2010/03/27 11:33:53 | 000,744,960 | ---- | M] () -- C:\Users\Hannah\Desktop\IceSword.exe
[2010/03/27 11:13:14 | 002,205,157 | ---- | M] () -- C:\Users\Hannah\Desktop\IceSword122en.zip
[2010/03/27 10:34:15 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Users\Hannah\Desktop\explorer.exe
[2010/03/26 22:27:35 | 000,001,813 | ---- | M] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/03/26 18:48:01 | 000,031,744 | ---- | M] () -- C:\Users\Hannah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/24 22:34:45 | 000,032,768 | ---- | M] (FunWebProducts.com) -- C:\Windows\SysWow64\f3PSSavr.scr
[2010/03/24 20:00:30 | 000,000,500 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Hannah.job
[2010/03/24 15:27:06 | 001,470,810 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/03/24 15:27:06 | 000,672,380 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2010/03/24 15:27:06 | 000,600,378 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/03/24 15:27:06 | 000,127,578 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2010/03/24 15:27:06 | 000,105,852 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/03/22 15:13:45 | 000,000,034 | ---- | M] () -- C:\Windows\SysWow64\BD7030.DAT
[2010/03/19 20:13:02 | 000,111,467 | ---- | M] () -- C:\Windows\SysWow64\7vwYElm-N-A_.exe
[2010/03/19 20:12:42 | 000,000,914 | ---- | M] () -- C:\Users\Public\Desktop\FLV Direct Player.lnk
[2010/03/19 06:14:12 | 001,126,400 | ---- | M] () -- C:\Windows\SysWow64\-W6H-_-.dll
[2010/03/18 15:26:32 | 000,108,784 | ---- | M] () -- C:\Users\Hannah\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/18 15:26:25 | 000,400,288 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/03/13 22:21:55 | 012,213,755 | ---- | M] () -- C:\Users\Hannah\Desktop\Place1.rbxl
[2010/03/13 20:47:27 | 000,001,179 | ---- | M] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2010/03/13 20:47:23 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini
========== Files Created - No Company Name ==========
[2010/03/27 11:13:02 | 002,205,157 | ---- | C] () -- C:\Users\Hannah\Desktop\IceSword122en.zip
[2010/03/26 22:27:38 | 000,306,648 | ---- | C] () -- C:\Windows\SysNative\drivers\pctgntdi64.sys
[2010/03/26 22:27:38 | 000,133,072 | ---- | C] () -- C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2010/03/26 22:27:38 | 000,007,357 | ---- | C] () -- C:\Windows\SysNative\drivers\pctgntdi64.cat
[2010/03/26 22:27:36 | 000,218,056 | ---- | C] () -- C:\Windows\SysNative\drivers\PCTCore64.sys
[2010/03/26 22:27:36 | 000,007,353 | ---- | C] () -- C:\Windows\SysNative\drivers\pctcore64.cat
[2010/03/26 22:27:35 | 000,001,813 | ---- | C] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/03/26 22:27:32 | 000,092,896 | ---- | C] () -- C:\Windows\SysNative\drivers\pctplsg64.sys
[2010/03/26 22:27:32 | 000,007,353 | ---- | C] () -- C:\Windows\SysNative\drivers\pctplsg64.cat
[2010/03/19 20:13:02 | 000,111,467 | ---- | C] () -- C:\Windows\SysWow64\7vwYElm-N-A_.exe
[2010/03/19 20:12:42 | 000,000,914 | ---- | C] () -- C:\Users\Public\Desktop\FLV Direct Player.lnk
[2010/03/19 06:14:12 | 001,126,400 | ---- | C] () -- C:\Windows\SysWow64\-W6H-_-.dll
[2010/03/13 20:47:27 | 000,001,179 | ---- | C] () -- C:\Users\Public\Desktop\Norton Security Scan.lnk
[2010/03/13 20:47:27 | 000,000,500 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Hannah.job
[2010/03/13 20:47:23 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NSSx64\0207030.022\isolate.ini
[2009/10/27 20:16:47 | 000,000,410 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2009/10/27 20:12:56 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\BRLMW03A.INI
[2009/10/27 20:10:00 | 000,031,567 | ---- | C] () -- C:\Windows\maxlink.ini
[2009/10/15 15:09:37 | 000,000,680 | ---- | C] () -- C:\Users\Hannah\AppData\Local\d3d9caps.dat
[2009/09/25 22:23:12 | 000,031,744 | ---- | C] () -- C:\Users\Hannah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/25 12:19:23 | 000,000,000 | ---- | C] () -- C:\Users\Hannah\AppData\Local\QSwitch.txt
[2009/09/25 12:19:23 | 000,000,000 | ---- | C] () -- C:\Users\Hannah\AppData\Local\DSwitch.txt
[2009/09/25 12:19:23 | 000,000,000 | ---- | C] () -- C:\Users\Hannah\AppData\Local\AtStart.txt
[2009/07/06 06:11:49 | 000,000,105 | ---- | C] () -- C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/07/06 06:11:41 | 000,000,032 | ---- | C] () -- C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/07/06 06:11:17 | 000,000,032 | ---- | C] () -- C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/07/06 06:10:46 | 000,000,032 | ---- | C] () -- C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/07/06 06:08:41 | 000,000,032 | ---- | C] () -- C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/07/06 06:08:13 | 000,000,290 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2009/04/20 17:59:22 | 000,000,109 | ---- | C] () -- C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2009/04/20 17:52:22 | 000,000,110 | ---- | C] () -- C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2009/04/20 17:50:14 | 000,000,105 | ---- | C] () -- C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2009/04/20 17:48:37 | 000,000,107 | ---- | C] () -- C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2008/01/20 19:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 19:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
========== LOP Check ==========
[2009/12/21 18:41:58 | 000,000,000 | ---D | M] -- C:\Users\Hannah\AppData\Roaming\TeamViewer
[2010/03/27 11:52:07 | 000,032,630 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========