O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1197145811562 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
https://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB}
http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280}
http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0}
http://download-games.pogo.com/online2/pogo/mahjong_escape_ancient_japan/SpinTopGamesLauncher.cab (SpinTop Games Launcher)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A}
http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605}
http://www.worldwinner.com/games/v68/clue/clue.cab (Clue Control)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644}
https://merlin.telus.net/wizlet/Merlin11/static/controls/MotiveClient.cab (WebBrowserType Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260}
http://download-games.pogo.com/online2/pogo/mahjong_escape_ancient/PTGameLauncher.cab (Playtime Games Launcher)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\daddy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\daddy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/12/08 14:44:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/11/24 18:40:28 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\daddy\Desktop\OTL.exe
[2010/11/24 10:04:53 | 001,912,872 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\daddy\Desktop\HousecallLauncher.exe
[2010/11/23 16:44:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Real
[2010/11/17 21:26:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\Local Settings\Application Data\Identities
[2010/11/13 15:02:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\Local Settings\Application Data\Conduit
[2010/11/13 14:32:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\Local Settings\Application Data\Temp
[2010/11/13 14:32:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2010/11/13 13:06:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\My Documents\Vuze Downloads
[2010/11/13 12:54:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\Application Data\Azureus
[2010/11/13 10:53:28 | 000,199,904 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/11/13 10:53:22 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2010/11/13 10:53:22 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/11/13 10:53:22 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/11/13 10:52:43 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2010/11/13 10:52:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Real
[2010/11/13 10:52:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\Application Data\Real
[2010/11/11 22:54:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/11/11 22:54:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/11/11 19:54:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/11/11 19:54:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/11/11 10:21:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\daddy\Application Data\Malwarebytes
[2010/11/11 10:20:59 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/11 10:20:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/11 10:20:57 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/11 10:20:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/11/24 18:45:17 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/24 18:44:27 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/24 18:44:27 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515967899-1993962763-839522115-1006.job
[2010/11/24 18:44:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/24 18:43:03 | 000,007,500 | ---- | M] () -- C:\WINDOWS\System32\123.js
[2010/11/24 18:43:03 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2010/11/24 18:41:11 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-1993962763-839522115-1006.job
[2010/11/24 18:40:48 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\daddy\Desktop\OTL.exe
[2010/11/24 18:10:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/24 17:57:45 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/11/24 17:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/11/24 16:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/11/24 15:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/11/24 15:18:19 | 000,000,422 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5710E62F-4F38-4158-9F61-7E5EEBF6864D}.job
[2010/11/24 14:50:35 | 000,010,666 | ---- | M] () -- C:\Documents and Settings\daddy\My Documents\christmas list.docx
[2010/11/24 14:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/11/24 13:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/11/24 12:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/11/24 11:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/11/24 10:43:13 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2010/11/24 10:05:02 | 001,912,872 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\daddy\Desktop\HousecallLauncher.exe
[2010/11/24 09:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/11/24 08:43:05 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2010/11/24 08:40:38 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/11/23 23:43:06 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2010/11/23 22:43:09 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2010/11/23 21:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2010/11/23 20:43:03 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2010/11/23 19:43:02 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2010/11/18 08:24:23 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/11/17 22:54:13 | 000,013,158 | ---- | M] () -- C:\Documents and Settings\daddy\My Documents\Resume.docx
[2010/11/13 14:25:26 | 000,001,943 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/11/13 14:20:39 | 002,018,222 | ---- | M] () -- C:\WINDOWS\iis6.BAK
[2010/11/13 14:20:35 | 000,446,298 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/13 14:20:35 | 000,073,444 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/13 13:58:58 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\daddy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/13 10:53:41 | 000,000,934 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2010/11/13 10:53:28 | 000,199,904 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/11/13 10:53:22 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2010/11/13 10:53:22 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/11/13 10:53:22 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/11/11 23:43:02 | 000,012,477 | ---- | M] () -- C:\WINDOWS\System32\234.js
[2010/11/11 10:21:02 | 000,000,701 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/07 10:48:40 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\daddy\Application Data\completescan
[2010/11/05 19:59:14 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\daddy\Application Data\start
[2010/11/05 19:47:47 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\daddy\Application Data\install
[2010/11/05 19:41:51 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/11/05 19:41:51 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/11/05 19:41:51 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2010/11/05 19:41:51 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2010/11/05 19:41:51 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2010/11/05 19:41:51 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/11/05 14:21:58 | 000,010,377 | ---- | M] () -- C:\Documents and Settings\daddy\My Documents\Your VIA Préférence number is.docx
[2010/11/03 14:34:51 | 000,126,856 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2010/10/27 16:44:24 | 000,011,096 | ---- | M] () -- C:\Documents and Settings\daddy\My Documents\We have been through a lot in our first 2 years of marriage.docx
[2010/10/25 21:28:54 | 000,010,486 | ---- | M] () -- C:\Documents and Settings\daddy\My Documents\JF1983.docx
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/11/24 14:49:54 | 000,010,666 | ---- | C] () -- C:\Documents and Settings\daddy\My Documents\christmas list.docx
[2010/11/23 19:43:02 | 000,007,500 | ---- | C] () -- C:\WINDOWS\System32\123.js
[2010/11/17 22:54:13 | 000,013,158 | ---- | C] () -- C:\Documents and Settings\daddy\My Documents\Resume.docx
[2010/11/13 10:53:56 | 000,000,286 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-515967899-1993962763-839522115-1006.job
[2010/11/13 10:53:56 | 000,000,278 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-515967899-1993962763-839522115-1006.job
[2010/11/13 10:53:41 | 000,000,934 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2010/11/11 20:38:01 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/11/11 19:43:02 | 000,012,477 | ---- | C] () -- C:\WINDOWS\System32\234.js
[2010/11/11 10:21:02 | 000,000,701 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/05 19:59:14 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\daddy\Application Data\start
[2010/11/05 19:58:42 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\daddy\Application Data\completescan
[2010/11/05 19:47:47 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\daddy\Application Data\install
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At24.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At23.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At22.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At21.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At20.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At19.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At18.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At17.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At16.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At15.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At14.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At13.job
[2010/11/05 19:41:50 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At12.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At9.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At8.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At7.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At6.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At5.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At4.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At3.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At11.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At10.job
[2010/11/05 19:41:49 | 000,000,422 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2010/11/05 14:21:58 | 000,010,377 | ---- | C] () -- C:\Documents and Settings\daddy\My Documents\Your VIA Préférence number is.docx
[2010/10/27 16:44:24 | 000,011,096 | ---- | C] () -- C:\Documents and Settings\daddy\My Documents\We have been through a lot in our first 2 years of marriage.docx
[2010/08/31 01:18:57 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\daddy\Local Settings\Application Data\fusioncache.dat
[2010/02/08 04:59:29 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/08/18 13:44:48 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\daddy\Local Settings\Application Data\housecall.guid.cache
[2009/05/27 14:02:03 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\daddy\Application Data\Smiley.ico
[2009/01/02 18:11:08 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2008/07/16 16:06:40 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/07/16 16:06:40 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/07/02 12:26:20 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\daddy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/13 00:26:38 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/05/13 00:26:38 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/05/13 00:26:38 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/05/03 20:36:22 | 000,001,040 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/05/03 20:36:09 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2007/12/11 03:13:40 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/12/08 06:51:48 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2001/07/07 04:00:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
< End of report >