OTL logfile created on: 7/4/2010 1:33:21 AM - Run 1
OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\Moms\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.00 Mb Total Physical Memory | 85.00 Mb Available Physical Memory | 17.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 47.86 Gb Total Space | 5.32 Gb Free Space | 11.12% Space Free | Partition Type: NTFS
Drive D: | 8.01 Gb Total Space | 0.96 Gb Free Space | 11.94% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-09DEDAFE33
Current User Name: Moms
NOT logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/07/04 01:23:07 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Moms\My Documents\Downloads\OTL.exe
PRC - [2010/02/25 17:21:50 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe
PRC - [2009/08/05 05:51:16 | 001,626,112 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/12/23 21:44:26 | 000,491,606 | ---- | M] () -- C:\Program Files\HPQ\Shared\HpqToaster.exe
PRC - [2005/11/10 22:03:52 | 000,036,975 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
PRC - [2005/09/24 09:42:32 | 000,475,136 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hp\Digital Imaging\bin\hpqimzone.exe
PRC - [2005/08/11 16:30:30 | 000,618,496 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
PRC - [2005/08/11 16:30:30 | 000,081,920 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [1997/08/19 00:00:00 | 000,051,984 | ---- | M] () -- C:\Program Files\Microsoft Office\Office\OSA.EXE
========== Modules (SafeList) ========== MOD - [2010/07/04 01:23:07 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Moms\My Documents\Downloads\OTL.exe
MOD - [2010/05/13 22:35:01 | 000,415,088 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\17.7.0.12\asoehook.dll
MOD - [2009/07/12 00:02:02 | 000,653,120 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Internet Security\Engine\17.7.0.12\microsoft.vc90.crt\msvcr90.dll
MOD - [2009/07/12 00:02:00 | 000,569,664 | R--- | M] (Microsoft Corporation) -- C:\Program Files\Norton Internet Security\Engine\17.7.0.12\microsoft.vc90.crt\msvcp90.dll
MOD - [2008/04/13 17:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== ========== Driver Services (SafeList) ========== ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=presario&pf=laptopIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
www.yahoo.com"FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\IPSFFPlgn\ [2010/06/26 10:32:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\coFFPlgn\ [2010/06/25 10:31:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/24 20:22:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/24 20:22:47 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Components: C:\Program Files\Netscape\Netscape Browser\Components [2010/05/21 15:00:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Plugins: C:\Program Files\Netscape\Netscape Browser\Plugins [2010/06/22 18:43:02 | 000,000,000 | ---D | M]
[2010/06/21 13:19:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Moms\Application Data\Mozilla\Extensions
[2010/06/21 13:19:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Moms\Application Data\Mozilla\Firefox\Profiles\npar0hin.default\extensions
[2010/07/02 11:06:13 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/19 17:58:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/03/24 20:21:00 | 002,889,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2004/08/04 14:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ipsbho.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\CHDAudPropShortcut.exe (Windows (R) Server 2003 DDK provider)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\CREATOR\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\StartUp\RSDUpdater.exe.lnk = C:\WINDOWS\explorer.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Moms\Start Menu\Programs\StartUp\Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll (Apple Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Digicode.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Digicode.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/07/04 01:23:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\My Documents\Downloads
[2010/07/02 12:20:47 | 000,000,000 | ---D | C] -- C:\word docs
[2010/06/26 17:32:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Malwarebytes
[2010/06/26 17:27:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Sun
[2010/06/25 18:55:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/06/25 14:16:17 | 000,361,904 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symtdi.sys
[2010/06/25 14:16:17 | 000,339,504 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symtdiv.sys
[2010/06/25 14:16:16 | 000,328,752 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symds.sys
[2010/06/25 14:16:16 | 000,173,104 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symefa.sys
[2010/06/25 14:16:15 | 000,043,696 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\srtspx.sys
[2010/06/25 14:16:14 | 000,325,680 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\srtsp.sys
[2010/06/25 14:16:13 | 000,116,784 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\ironx86.sys
[2010/06/25 14:16:12 | 000,501,888 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\cchpx86.sys
[2010/06/25 14:12:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NIS\1107000.00C
[2010/06/25 10:31:30 | 000,124,976 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/06/25 10:31:30 | 000,060,808 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/06/25 10:31:30 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2010/06/25 10:29:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NIS
[2010/06/25 10:29:40 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Internet Security
[2010/06/25 10:29:39 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar
[2010/06/25 10:15:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2010/06/25 10:15:13 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2010/06/25 10:15:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2010/06/25 10:02:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Norton
[2010/06/25 10:02:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2010/06/25 07:16:17 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/25 07:16:09 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/24 18:24:59 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Moms\PrivacIE
[2010/06/22 18:51:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/06/22 18:40:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/06/22 18:35:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2010/06/22 18:33:54 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/06/22 12:09:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/06/22 12:09:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/21 16:39:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Macromedia
[2010/06/21 16:39:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Adobe
[2010/06/21 14:38:54 | 000,405,504 | R--- | C] (Eastman Kodak Company) -- C:\WINDOWS\System32\EKIJ5000MON.dll
[2010/06/21 14:37:12 | 000,126,976 | R--- | C] (Eastman Kodak Company) -- C:\WINDOWS\System32\EKIJCOINST05.dll
[2010/06/21 13:59:05 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/06/21 13:59:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010/06/21 13:57:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kodak
[2010/06/21 13:47:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\kodak
[2010/06/21 13:46:58 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wiafbdrv.dll
[2010/06/21 13:19:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\Mozilla
[2010/06/21 13:19:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Mozilla
[2010/06/21 13:16:05 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Moms\IETldCache
[2010/06/21 13:15:57 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Moms\Application Data\Microsoft
[2010/06/21 13:15:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Moms\SendTo
[2010/06/21 13:15:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Moms\Recent
[2010/06/21 13:15:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Moms\Application Data
[2010/06/21 13:15:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Moms\Start Menu
[2010/06/21 13:15:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Moms\My Documents\My Videos
[2010/06/21 13:15:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Moms\My Documents\My Pictures
[2010/06/21 13:15:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Moms\My Documents\My Music
[2010/06/21 13:15:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Moms\My Documents
[2010/06/21 13:15:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Moms\Favorites
[2010/06/21 13:15:57 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Moms\Cookies
[2010/06/21 13:15:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Moms\Templates
[2010/06/21 13:15:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Moms\PrintHood
[2010/06/21 13:15:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Moms\NetHood
[2010/06/21 13:15:57 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Moms\Local Settings
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Symantec
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\Microsoft
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\IsolatedStorage
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Intuit
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Application Data\Identities
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\HP
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\Google
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Desktop
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\BVRP Software
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\ApplicationHistory
[2010/06/21 13:15:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Moms\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}
[2010/06/07 19:30:02 | 000,000,000 | ---D | C] -- C:\Program Files\MPC HomeCinema
[2010/06/07 19:29:33 | 000,000,000 | ---D | C] -- C:\Program Files\Citrix
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[17 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/07/04 01:30:57 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/07/04 01:30:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/07/04 01:30:51 | 526,503,936 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/03 14:19:34 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/02 14:53:02 | 001,310,720 | -H-- | M] () -- C:\Documents and Settings\Moms\NTUSER.DAT
[2010/07/02 14:53:02 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Moms\ntuser.ini
[2010/07/02 10:54:40 | 000,000,313 | ---- | M] () -- C:\hpqp.ini
[2010/07/02 10:54:27 | 000,000,039 | ---- | M] () -- C:\XP_TV.ini
[2010/07/01 08:47:58 | 000,005,133 | -H-- | M] () -- C:\ffastun.ffa
[2010/07/01 08:47:57 | 000,532,480 | -H-- | M] () -- C:\ffastun.ffo
[2010/07/01 08:47:44 | 004,493,312 | -H-- | M] () -- C:\ffastun0.ffx
[2010/07/01 08:47:44 | 002,007,040 | -H-- | M] () -- C:\ffastun.ffl
[2010/06/29 11:53:05 | 000,443,380 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/29 11:53:05 | 000,383,822 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/29 11:53:05 | 000,054,010 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/25 18:11:50 | 000,001,973 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2010/06/25 18:11:15 | 000,606,852 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\Cat.DB
[2010/06/25 10:31:30 | 000,124,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2010/06/25 10:31:30 | 000,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2010/06/25 10:31:30 | 000,007,443 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/06/25 10:31:30 | 000,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/06/24 18:11:42 | 000,103,056 | ---- | M] () -- C:\Documents and Settings\Moms\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/22 18:55:17 | 000,372,872 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/22 18:37:32 | 000,000,552 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/21 13:16:59 | 000,000,127 | ---- | M] () -- C:\Documents and Settings\Moms\Local Settings\Application Data\fusioncache.dat
[2010/06/21 13:16:17 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\Moms\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/06/21 13:16:12 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\Moms\Desktop\Windows Media Player.lnk
[2010/06/10 17:22:55 | 000,000,761 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
[2010/06/10 17:19:51 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
[2010/06/07 19:30:06 | 000,000,648 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Media Player Classic - Home Cinema.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[17 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/06/28 23:28:03 | 526,503,936 | -HS- | C] () -- C:\hiberfil.sys
[2010/06/25 18:11:06 | 000,606,852 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\Cat.DB
[2010/06/25 14:16:17 | 000,007,787 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symnetv.cat
[2010/06/25 14:16:17 | 000,001,473 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symnetv.inf
[2010/06/25 14:16:17 | 000,001,445 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symnet.inf
[2010/06/25 14:16:16 | 000,007,873 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symefa.cat
[2010/06/25 14:16:16 | 000,007,425 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symds.cat
[2010/06/25 14:16:16 | 000,007,368 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symnet.cat
[2010/06/25 14:16:16 | 000,003,373 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symefa.inf
[2010/06/25 14:16:16 | 000,002,793 | R--- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\symds.inf
[2010/06/25 14:16:15 | 000,007,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\srtspx.cat
[2010/06/25 14:16:15 | 000,001,388 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\srtspx.inf
[2010/06/25 14:16:14 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\srtsp.cat
[2010/06/25 14:16:14 | 000,001,382 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\srtsp.inf
[2010/06/25 14:16:12 | 000,007,438 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\iron.cat
[2010/06/25 14:16:12 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\iron.inf
[2010/06/25 14:16:11 | 000,007,396 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\cchpx86.cat
[2010/06/25 14:16:11 | 000,001,754 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\cchpx86.inf
[2010/06/25 14:12:06 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NIS\1107000.00C\isolate.ini
[2010/06/25 10:31:30 | 000,007,443 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2010/06/25 10:31:30 | 000,000,805 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2010/06/25 10:31:18 | 000,001,973 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2010/06/21 13:16:12 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\Moms\Desktop\Windows Media Player.lnk
[2010/06/21 13:15:58 | 000,001,765 | ---- | C] () -- C:\Documents and Settings\Moms\Application Data\Microsoft\Internet Explorer\Quick Launch\Netscape Browser.lnk
[2010/06/21 13:15:58 | 000,001,632 | ---- | C] () -- C:\Documents and Settings\Moms\Desktop\3 Month Trial AOL Music Now.lnk
[2010/06/21 13:15:58 | 000,000,992 | ---- | C] () -- C:\Documents and Settings\Moms\Desktop\Help and Support.lnk
[2010/06/21 13:15:58 | 000,000,779 | ---- | C] () -- C:\Documents and Settings\Moms\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/06/21 13:15:58 | 000,000,663 | ---- | C] () -- C:\Documents and Settings\Moms\Application Data\Microsoft\Internet Explorer\Quick Launch\HP Rhapsody.lnk
[2010/06/21 13:15:58 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Moms\Local Settings\Application Data\fusioncache.dat
[2010/06/21 13:15:58 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Moms\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2010/06/21 13:15:58 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Moms\Local Settings\Application Data\DSwitch.txt
[2010/06/21 13:15:58 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Moms\Local Settings\Application Data\AtStart.txt
[2010/06/21 13:15:57 | 000,053,248 | -H-- | C] () -- C:\Documents and Settings\Moms\ntuser.dat.LOG
[2010/06/21 13:15:57 | 000,001,703 | ---- | C] () -- C:\Documents and Settings\Moms\Start Menu\Programs\StartUp\Vongo Tray.lnk
[2010/06/21 13:15:57 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Moms\ntuser.ini
[2010/06/21 13:15:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Moms\Local Settings\Application Data\QSwitch.txt
[2010/06/21 13:15:56 | 001,310,720 | -H-- | C] () -- C:\Documents and Settings\Moms\NTUSER.DAT
[2010/06/18 16:29:34 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/10 17:47:51 | 000,005,133 | -H-- | C] () -- C:\ffastun.ffa
[2010/06/10 17:47:47 | 000,532,480 | -H-- | C] () -- C:\ffastun.ffo
[2010/06/10 17:47:44 | 004,493,312 | -H-- | C] () -- C:\ffastun0.ffx
[2010/06/10 17:22:56 | 002,007,040 | -H-- | C] () -- C:\ffastun.ffl
[2010/06/10 17:19:51 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
[2010/06/10 17:19:40 | 000,000,761 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
[2010/06/07 19:30:06 | 000,000,648 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Media Player Classic - Home Cinema.lnk
[2009/01/09 09:42:08 | 000,001,043 | ---- | C] () -- C:\WINDOWS\_ISENV31.INI
[2009/01/09 08:53:04 | 000,000,419 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008/07/11 22:59:55 | 000,000,492 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/09/02 13:14:39 | 000,000,027 | ---- | C] () -- C:\WINDOWS\SmartAudio.INI
[2007/01/24 22:30:15 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2006/05/09 06:19:58 | 000,000,166 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2006/05/09 06:16:56 | 000,000,698 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/05/09 05:57:54 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/05/09 05:54:12 | 000,028,836 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/03/27 10:00:36 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/27 09:20:24 | 000,000,945 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/03/27 09:17:12 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2005/12/02 11:09:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/04 07:59:44 | 000,005,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\viaide.sys
[1997/08/19 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/08/19 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
========== Alternate Data Streams ========== @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >