OTL logfile created on: 4/13/2011 5:52:03 PM - Run
OTLPE by OldTimer - Version 3.1.46.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.21 Gb Total Space | 13.74 Gb Free Space | 36.93% Space Free | Partition Type: NTFS
Drive X: | 284.12 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet004
========== Win32 Services (SafeList) ========== SRV - File not found [Auto] -- -- (sdCoreService)
SRV - File not found [Auto] -- -- (sdAuxService)
SRV - [2009/11/17 00:44:31 | 000,016,792 | ---- | M] () [Auto] -- C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe -- (atnthost)
SRV - [2009/09/16 19:22:08 | 000,020,480 | ---- | M] (Intuit) [Auto] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2008/03/17 15:02:24 | 000,438,272 | ---- | M] (RealVNC Ltd.) [Auto] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
SRV - [2008/01/29 00:04:24 | 000,840,008 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe -- (BackupExecAgentAccelerator)
SRV - [2008/01/09 15:43:56 | 000,472,440 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec\Backup Exec\DLO\DLOChangeLogSvcu.exe -- (DLOChangeJournalSvc)
SRV - [2007/11/28 20:51:41 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/10/07 23:48:36 | 000,116,664 | ---- | M] (symantec) [Auto] -- C:\Program Files\Symantec AntiVirus\SavRoam.exe -- (SavRoam)
SRV - [2007/10/07 23:48:32 | 001,822,648 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2007/10/07 23:48:24 | 000,031,160 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Symantec AntiVirus\DefWatch.exe -- (DefWatch)
SRV - [2007/09/12 21:27:24 | 002,999,664 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
SRV - [2007/08/27 20:14:00 | 000,214,408 | ---- | M] (Symantec Corporation) [On_Demand] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2007/07/26 22:25:20 | 001,181,016 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)
SRV - [2007/05/29 19:33:36 | 000,169,576 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr)
SRV - [2007/05/29 19:33:26 | 000,192,104 | ---- | M] (Symantec Corporation) [Auto] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr)
SRV - [2007/05/24 10:08:44 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2007/01/04 17:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/09/13 13:32:12 | 000,128,536 | ---- | M] (iAnywhere Solutions, Inc.) [Disabled] -- C:\Program Files\Intuit\QuickBooks Enterprise Solutions 8.0\QBDBMgrN.exe -- (QuickBooksDB18)
SRV - [2004/04/01 19:05:48 | 000,077,824 | ---- | M] (Broadcom Corp.) [Auto] -- C:\WINDOWS\SYSTEM32\BAsfIpM.exe -- (BAsfIpM)
SRV - [2004/02/13 11:47:02 | 000,155,648 | ---- | M] (Dell Inc) [Auto] -- C:\Program Files\Dell\OpenManage\Client\Iap.exe -- (Iap)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand] -- -- (WDICA)
DRV - File not found [Kernel | Boot] -- -- (tonkqgc)
DRV - File not found [Kernel | On_Demand] -- -- (TMPassthruMP)
DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP)
DRV - File not found [Kernel | System] -- -- (PCIDump)
DRV - File not found [Kernel | System] -- -- (lbrtfdc)
DRV - File not found [File_System | System] -- -- (IKFileFlt)
DRV - File not found [Kernel | On_Demand] -- -- (EraserUtilDrv10822)
DRV - File not found [Kernel | On_Demand] -- -- (EraserUtilDrv10821)
DRV - File not found [Kernel | On_Demand] -- -- (EraserUtilDrv10820)
DRV - File not found [Kernel | System] -- -- (Changer)
DRV - File not found [Kernel | On_Demand] -- -- (catchme)
DRV - [2011/04/07 17:45:36 | 001,393,144 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110407.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/04/07 17:45:36 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110407.002\NAVENG.SYS -- (NAVENG)
DRV - [2010/12/02 18:57:35 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/12/02 18:57:35 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/05/10 14:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 14:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2008/08/06 15:59:46 | 000,110,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS -- (SymEvent)
DRV - [2007/09/25 17:52:30 | 000,054,192 | ---- | M] (Symantec Corporation) [Kernel | Boot] -- C:\WINDOWS\SYSTEM32\DRIVERS\VSP.sys -- (VSP)
DRV - [2007/08/27 20:13:36 | 000,189,320 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2007/07/26 22:25:18 | 000,400,216 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2007/05/23 19:58:50 | 000,083,024 | ---- | M] (PCTools Research Pty Ltd.) [Kernel | System] -- C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys -- (IKSysSec)
DRV - [2007/05/23 19:58:46 | 000,057,424 | ---- | M] (PCTools Research Pty Ltd.) [Kernel | System] -- C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys -- (IkSysFlt)
DRV - [2007/05/23 19:58:42 | 000,053,840 | ---- | M] (PCTools Research Pty Ltd.) [Kernel | System] -- C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys -- (IKFileSec)
DRV - [2006/09/06 17:41:20 | 000,337,592 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Symantec AntiVirus\savrt.sys -- (SAVRT)
DRV - [2006/09/06 17:41:20 | 000,054,968 | ---- | M] (Symantec Corporation) [Kernel | System] -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys -- (SAVRTPEL)
DRV - [2004/05/29 18:41:54 | 000,186,112 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys -- (b57w2k)
DRV - [2004/02/13 11:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2003/04/24 17:21:50 | 000,006,025 | ---- | M] (Broadcom Corporation) [Kernel | Auto] -- C:\WINDOWS\SYSTEM32\DRIVERS\BASFND.sys -- (BASFND)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\administrator.DESSERT_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\administrator.DESSERT_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\administrator.DESSERT_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\administrator.DESSERT_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKU\administrator.DESSERT_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\Administrator_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\Administrator_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\DODUser_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\DODUser_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\DODUser_ON_C\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\DODUser_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKU\DODUser_ON_C\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key error. File not found
IE - HKU\DODUser_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\jfaris_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\jfaris_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\jfaris_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\jfaris_ON_C\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKU\jfaris_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\k-admin_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\k-admin_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\k-admin_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\k-admin_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepage IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comIE - HKU\QBDataServiceUser18_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\ssanders_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\ssanders_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\WaltB_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comIE - HKU\WaltB_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepageIE - HKU\WaltB_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2008/04/13 20:12:08 | 000,004,921 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 82.165.237.14
O1 - Hosts: 127.0.0.1 82.165.250.33
O1 - Hosts: 127.0.0.1 akamai.avg.com
O1 - Hosts: 127.0.0.1 antivir.es
O1 - Hosts: 127.0.0.1 anti-virus.by
O1 - Hosts: 127.0.0.1 avast.com
O1 - Hosts: 127.0.0.1 avg.com
O1 - Hosts: 127.0.0.1 avp.com
O1 - Hosts: 127.0.0.1 avp.ru
O1 - Hosts: 127.0.0.1 avp.ru/download/
O1 - Hosts: 127.0.0.1 avpg.crsi.symantec.com
O1 - Hosts: 127.0.0.1 backup.avg.cz
O1 - Hosts: 127.0.0.1 bancoguayaquil.com
O1 - Hosts: 127.0.0.1 bcpzonasegura.viabcp.com
O1 - Hosts: 127.0.0.1 bitdefender.com
O1 - Hosts: 127.0.0.1 clamav.net
O1 - Hosts: 127.0.0.1 comodo.com
O1 - Hosts: 127.0.0.1 customer.symantec.com
O1 - Hosts: 127.0.0.1 dispatch.mcafee.com
O1 - Hosts: 127.0.0.1 download.mcafee.com
O1 - Hosts: 127.0.0.1 download.microsoft.com
O1 - Hosts: 127.0.0.1 downloads.microsoft.com
O1 - Hosts: 127.0.0.1 downloads1.kaspersky-labs.com
O1 - Hosts: 127.0.0.1 downloads1.kaspersky-labs.com/products/
O1 - Hosts: 140 more lines...
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Viewpoint Toolbar) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll (Viewpoint Corporation)
O3 - HKU\administrator.DESSERT_ON_C\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKU\administrator.DESSERT_ON_C\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKU\DODUser_ON_C\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKU\DODUser_ON_C\..\Toolbar\WebBrowser: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKU\DODUser_ON_C\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKU\jfaris_ON_C\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKU\jfaris_ON_C\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No CLSID value found.
O3 - HKU\ssanders_ON_C\..\Toolbar\WebBrowser: (&Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKU\WaltB_ON_C\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ADP Scheduler] File not found
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1143156683\ee\aolsoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickBooksDB18] C:\Program Files\Intuit\QuickBooks Enterprise Solutions 8.0\QBDBMgrN.exe (iAnywhere Solutions, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKU\ssanders_ON_C..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe (Sammsoft)
O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\System32\restore\rstrui.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk = C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Remote Access.LNK = C:\WINDOWS\DOWNLO~1\MyWebEx\319\raagtx.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Web Connector.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBWebConnector\QBWebConnector.exe (Intuit)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Backup Exec Desktop Agent.lnk = C:\Program Files\Symantec\Backup Exec\DLO\DLOClientu.exe (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\DODUser\Start Menu\Programs\Startup\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\DODUser\Start Menu\Programs\Startup\Shortcut to MapDrives.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\administrator.DESSERT_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\administrator.DESSERT_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Administrator_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\DODUser_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\DODUser_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\jfaris_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\jfaris_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\jfaris_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\k-admin_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\k-admin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\QBDataServiceUser18_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\QBDataServiceUser18_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\ssanders_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\ssanders_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\ssanders_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKU\ssanders_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\ssanders_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\WaltB_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\WaltB_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Quick AllToPDF - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\All_To_PDF\IEAddon.exe (QuickPDFtoWord)
O9 - Extra 'Tools' menuitem : Quick AllToPDF - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\All_To_PDF\IEAddon.exe (QuickPDFtoWord)
O15 - HKU\DODUser_ON_C\..Trusted Domains: fedex.com ([www] http in Trusted sites)
O15 - HKU\DODUser_ON_C\..Trusted Domains: hsn.net ([view] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0B195D55-0AB4-48C7-828F-34BE10BA4266}
http://www.worldwinner.com/games/v53/dealornodeal/dealornodeal.cab (DealOrNoDeal Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
https://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {10DE6CF7-3E36-445B-985D-07603082B36B}
https://forms.orefonline.com/OLF/Runtime/FormLoader_RMLS.CAB (FormLoader.Loader)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E}
http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1257361301243 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB}
http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280}
http://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab (WorldWinner ActiveX Launcher Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03}
http://www.worldwinner.com/games/v51/bejeweledtwist/bejeweledtwist.cab (BejeweledTwist Control)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.102.5
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dessert.local
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks Enterprise Solutions 8.0\HelpAsyncPluggableProtocol.dll (TODO:
)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\SYSTEM32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (PFDNNT C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/04/12 14:37:27 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/04/12 14:37:26 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/04/12 14:37:26 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/04/11 22:24:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ssanders\Local Settings\Application Data\Identities
[2011/04/11 18:33:26 | 000,997,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msgina.dll
[2011/04/11 18:33:26 | 000,507,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winlogon.exe
[2011/04/11 18:33:25 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licdll.dll
[2011/04/11 18:32:51 | 001,396,264 | ---- | C] (Microsoft Corporation) -- C:\WindowsXP-KB948277-x86-ENU.exe
[2011/04/11 06:16:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\tmp
[2011/03/20 15:01:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ssanders\Application Data\Nikon
[2009/12/29 19:38:45 | 007,044,048 | ---- | C] (Citrix Online, a division of Citrix Systems, Inc.) -- C:\Documents and Settings\ssanders\gosetup.exe
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/13 19:44:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2011/04/13 19:12:44 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2011/04/13 19:11:47 | 000,000,318 | -HS- | M] () -- C:\WINDOWS\tasks\vlhpianc.job
[2011/04/13 12:40:02 | 000,058,652 | ---- | M] () -- C:\Documents and Settings\ssanders\Desktop\juniper041311.TIF
[2011/04/13 12:25:36 | 000,181,088 | ---- | M] () -- C:\Documents and Settings\ssanders\Desktop\041811.TIF
[2011/04/12 15:13:30 | 000,159,877 | ---- | M] () -- C:\Documents and Settings\ssanders\Desktop\JavaRa[1].zip
[2011/04/12 15:13:03 | 000,159,877 | ---- | M] () -- C:\Documents and Settings\ssanders\Desktop\JavaRa.zip
[2011/04/12 14:37:08 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2011/04/12 14:37:08 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2011/04/12 14:37:08 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2011/04/12 14:37:08 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2011/04/12 14:37:08 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2011/04/11 22:47:25 | 000,000,474 | ---- | M] () -- C:\Documents and Settings\ssanders\Desktop\Peachtree Classic 13.0.lnk
[2011/04/11 18:19:24 | 000,000,327 | RHS- | M] () -- C:\BOOT.INI
[2011/04/11 18:19:06 | 000,000,000 | R--D | M] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/04/11 18:08:42 | 000,014,434 | -HS- | M] () -- C:\Documents and Settings\ssanders\Local Settings\Application Data\0nnj6s0q485lxgr78w4q2u5y4n81ki06
[2011/04/11 18:08:42 | 000,014,434 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\0nnj6s0q485lxgr78w4q2u5y4n81ki06
[2011/04/11 15:03:55 | 000,280,536 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/11 13:31:55 | 000,405,618 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2011/04/11 13:31:55 | 000,063,976 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2011/03/27 00:56:28 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2011/03/25 16:59:20 | 000,002,435 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Publisher.lnk
[2011/03/20 15:04:23 | 000,006,144 | ---- | M] () -- C:\Documents and Settings\ssanders\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/13 12:40:02 | 000,058,652 | ---- | C] () -- C:\Documents and Settings\ssanders\Desktop\juniper041311.TIF
[2011/04/13 12:24:28 | 000,181,088 | ---- | C] () -- C:\Documents and Settings\ssanders\Desktop\041811.TIF
[2011/04/12 15:13:42 | 000,159,877 | ---- | C] () -- C:\Documents and Settings\ssanders\Desktop\JavaRa[1].zip
[2011/04/12 14:42:02 | 000,159,877 | ---- | C] () -- C:\Documents and Settings\ssanders\Desktop\JavaRa.zip
[2011/04/11 22:47:25 | 000,000,474 | ---- | C] () -- C:\Documents and Settings\ssanders\Desktop\Peachtree Classic 13.0.lnk
[2011/04/11 18:19:06 | 000,002,109 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2011/04/11 18:19:06 | 000,001,848 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Backup Exec Desktop Agent.lnk
[2011/04/11 18:19:06 | 000,001,824 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
[2011/04/11 18:19:06 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2011/04/11 18:19:06 | 000,001,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/04/11 18:19:06 | 000,001,481 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Remote Access.LNK
[2011/04/11 18:19:06 | 000,001,078 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
[2011/04/11 18:19:06 | 000,001,017 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Web Connector.lnk
[2011/04/11 18:19:06 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk
[2011/04/11 17:05:26 | 000,014,434 | -HS- | C] () -- C:\Documents and Settings\ssanders\Local Settings\Application Data\0nnj6s0q485lxgr78w4q2u5y4n81ki06
[2011/04/11 17:05:26 | 000,014,434 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\0nnj6s0q485lxgr78w4q2u5y4n81ki06
[2011/04/02 13:41:13 | 000,000,318 | -HS- | C] () -- C:\WINDOWS\tasks\vlhpianc.job
[2011/01/12 12:26:38 | 002,309,120 | ---- | C] () -- C:\WINDOWS\System32\pdftk.exe
[2011/01/12 12:26:29 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\gswin32c.exe
[2011/01/12 12:26:28 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\utility3.dll
[2011/01/12 12:26:28 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\unredmon.exe
[2011/01/12 12:26:27 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\Execute.dll
[2010/12/14 21:49:53 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/14 21:49:53 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/14 21:49:53 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/14 21:49:53 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/14 21:49:53 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/05/17 14:35:00 | 000,006,144 | ---- | C] () -- C:\Documents and Settings\ssanders\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/10 20:57:26 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\ssanders\Local Settings\Application Data\housecall.guid.cache
[2010/03/10 01:23:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2010/03/09 22:40:27 | 000,008,498 | ---- | C] () -- C:\WINDOWS\fs1235.dat1
[2010/01/30 14:25:29 | 000,000,490 | ---- | C] () -- C:\WINDOWS\paycal.INI
[2009/11/17 00:44:35 | 000,050,652 | ---- | C] () -- C:\WINDOWS\System32\drivers\atntwink.sys
[2009/06/29 20:14:30 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/08 14:39:57 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2008/03/19 11:55:53 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\.googlewebacchosts
[2007/11/28 14:03:03 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\People
[2007/11/28 14:03:03 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\DODUser\Application Data\PDEs
[2007/11/28 14:03:03 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2007/11/06 14:31:17 | 000,000,026 | ---- | C] () -- C:\WINDOWS\FPKPMSV.INI
[2007/09/18 22:34:27 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\DODUser\Local Settings\Application Data\fusioncache.dat
[2007/08/27 14:34:47 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2007/06/13 06:03:40 | 000,000,197 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/03/05 16:34:28 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2006/12/01 15:32:11 | 000,037,027 | ---- | C] () -- C:\WINDOWS\atmoUn.exe
[2006/10/23 11:56:11 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\DODUser\Application Data\.googlewebacchosts
[2006/09/18 17:37:50 | 000,000,530 | ---- | C] () -- C:\WINDOWS\System32\tx12_ic.ini
[2006/09/18 17:37:48 | 000,667,280 | ---- | C] () -- C:\WINDOWS\System32\tx12.dll
[2006/03/03 20:06:29 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\DODUser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/02/09 21:42:04 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/02/09 21:39:04 | 000,000,028 | ---- | C] () -- C:\WINDOWS\atid.ini
[2005/06/23 14:33:51 | 000,096,733 | ---- | C] () -- C:\WINDOWS\System32\Crp9516e.dll
[2005/06/23 14:33:51 | 000,053,258 | ---- | C] () -- C:\WINDOWS\System32\Cryp95e.dll
[2005/05/17 19:44:18 | 000,000,067 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2005/05/02 07:13:27 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/05/02 07:11:38 | 000,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/05/02 07:10:56 | 000,000,549 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/05/02 06:56:08 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2005/05/02 06:55:26 | 000,405,618 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2005/05/02 06:55:26 | 000,063,976 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2005/05/02 06:44:52 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 18:25:56 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/11 18:20:10 | 000,280,536 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 18:14:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 18:12:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 11:31:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/11 11:31:24 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 06:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 06:00:00 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\k.dll
[2004/08/04 06:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 17:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/06/28 16:20:54 | 000,005,025 | ---- | C] () -- C:\WINDOWS\System32\patterns.dat
[2000/10/13 20:52:56 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\wh2robo.dll
========== LOP Check ==========
[2007/09/18 22:33:01 | 000,000,000 | ---D | M] -- C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Kinko's
[2008/08/06 15:50:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\administrator.DESSERT\Application Data\JAM Software
[2005/07/19 19:37:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech
[2007/10/06 11:55:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Aim
[2007/12/14 23:18:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Downloaded Installations
[2007/11/06 14:31:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Kinko's
[2007/09/15 14:37:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Leadertech
[2007/11/28 14:09:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Nikon
[2007/12/13 13:47:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Snapfish
[2007/05/22 14:06:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\DODUser\Application Data\Viewpoint
[2007/09/18 22:32:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Kinko's
[2009/10/06 14:24:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/03/20 15:01:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\Nikon
[2010/03/10 22:52:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\Sammsoft
[2011/02/26 13:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\TeamViewer
[2010/08/05 13:14:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\Uniblue
[2008/11/21 13:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\Viewpoint
[2009/11/18 01:11:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ssanders\Application Data\Z-Firm LLC
[2008/07/29 15:54:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/12/29 19:39:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CitrixLogs
[2009/06/26 12:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2007/11/28 14:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dance Kit
[2007/11/28 14:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2007/11/28 21:18:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/12/30 20:43:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2007/11/28 14:04:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2007/10/02 18:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagull
[2008/03/22 17:39:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/11/28 14:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2008/08/10 21:50:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/08/29 16:09:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WorldWinner
[2011/04/13 19:11:47 | 000,000,318 | -HS- | M] () -- C:\WINDOWS\Tasks\vlhpianc.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CAAA7DD7
< End of report >