Hi Gringo,
sorry for the late reply. I had to do another system restore because my workstation was acting up. Also noticed an additional user in safe mode labelled: Administrator
I didn't create that user. Could access the user without the correct password. All kinds of stuff was freaking out on me which is why I had to do a major system restore.
Here's the logs you requested:
OTL logfile created on: 5/18/2012 9:34:52 PM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Documents and Settings\RayRay\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.24 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 71.73% Memory free
5.08 Gb Paging File | 3.87 Gb Available in Paging File | 76.18% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.77 Gb Total Space | 181.25 Gb Free Space | 77.87% Space Free | Partition Type: NTFS
Computer Name: RAY | User Name: RayRay | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\RayRay\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\19.7.0.9\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Program Files\IDT\WDM\stacsv.exe (IDT, Inc.)
PRC - C:\WINDOWS\system32\AESTFltr.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe (Wave Systems Corp.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe ()
PRC - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Modules (No Company Name) ========== MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8dc4a28c456f81ee7399da21bd9d55aa\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\7861cd979ea5db3fb7d30ed94fb0edd2\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\92d58f840f549f9bd880783d43db7e3c\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\995fcf39ead2c2a53e084505c2c67d49\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\8ca00132a08c69697adf1cda32ebd835\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\6d8bef0d008389874e55c0308f0c18e5\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\Status Lib\1.6.460.18066__f25c74fcad379103\Status Lib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\StatusInterfaces\1.6.460.18065__4ca2a925deedf37d\StatusInterfaces.dll ()
MOD - C:\WINDOWS\system32\preflib.dll ()
MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\Program Files\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll ()
MOD - C:\WINDOWS\system32\Wavx_ESC_Logging.dll ()
MOD - C:\WINDOWS\system32\wxvault.dll ()
MOD - C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe ()
MOD - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe ()
MOD - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\TspPopup_ENU.dll ()
========== Win32 Services (SafeList) ========== SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe File not found
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NIS) -- C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\19.7.0.9\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (dcpsysmgrsvc) -- c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (STacSV) -- C:\Program Files\IDT\WDM\stacsv.exe (IDT, Inc.)
SRV - (TdmService) -- C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (Credential Vault Host Control Service) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Storage) -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (IAStorDataMgrSvc) Intel® -- C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (SecureStorageService) -- C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (InstallFilterService) -- C:\Program Files\STMicroelectronics\AccelerometerP11\InstallFilterService.exe ()
SRV - (NVIDIA Performance Driver Service) -- C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe ()
SRV - (tcsd_win32.exe) -- C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (PSI_SVC_2) -- C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ========== DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (MRENDIS5) -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (lbrtfdc) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\DOCUME~1\RayRay\LOCALS~1\Temp\catchme.sys File not found
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\VirusDefs\20120518.006\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilDrv11122) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11122.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\VirusDefs\20120518.006\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\BASHDefs\20120402.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\symtdi.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\SymEFA.sys (Symantec Corporation)
DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\SymDS.sys (Symantec Corporation)
DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\Ironx86.sys (Symantec Corporation)
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\IPSDefs\20120202.002\IDSXpx86.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\srtspx.sys (Symantec Corporation)
DRV - (ccSet_NIS) -- C:\WINDOWS\system32\drivers\NIS\1307000.009\ccSetx86.sys (Symantec Corporation)
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM43XX) -- C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (AESTAud) -- C:\WINDOWS\system32\drivers\AESTAud.sys (Andrea Electronics Corporation)
DRV - (MRESP50) -- C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) -- C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (e1kexpress) Intel® -- C:\WINDOWS\system32\drivers\e1k5132.sys (Intel Corporation)
DRV - (risdpcie) -- C:\WINDOWS\system32\drivers\risdpe86.sys (REDC)
DRV - (NAL) -- C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (NVHDA) -- C:\WINDOWS\system32\drivers\nvhda32.sys (NVIDIA Corporation)
DRV - (WavxDMgr) -- C:\WINDOWS\system32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (Acceler) -- C:\WINDOWS\system32\drivers\Accelern.sys (ST Microelectronics)
DRV - (stdflt) -- C:\WINDOWS\system32\drivers\stdfltn.sys (ST Microelectronics)
DRV - (BCMTPM) -- C:\WINDOWS\system32\drivers\btpmw32.sys (Broadcom Corp.)
DRV - (cvusbdrv) -- C:\WINDOWS\system32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (USBCCID) -- C:\WINDOWS\system32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (PBADRV) -- C:\WINDOWS\system32\drivers\PBADRV.sys (Dell Inc)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Help_Page =
http://support.dell.com/support/index.aspx?c=us&l=en&s=genIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}\InprocServer32 File not found
IE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRCIE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" =
http://www.ask.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=NIS&chn=retail&geo=US&ver=19IE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" =
http://search.yahoo.com/search?p={searchTerms}&fr=chr-attyIE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-9541066-2834051161-270261326-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\IPSFFPlgn\ [2012/05/18 18:15:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\coFFPlgn\ [2012/05/18 20:27:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/18 17:11:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/18 17:17:27 | 000,000,000 | ---D | M]
[2011/06/17 12:32:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Extensions
[2011/06/17 12:32:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Extensions\websecurify@gnucitizen.org
[2012/05/18 17:16:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions
[2012/05/18 17:18:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/07 19:34:23 | 000,000,000 | ---D | M] (att.net Toolbar) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/05/18 17:18:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2012/05/18 17:16:58 | 000,000,000 | ---D | M] (FT DeepDark) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}(2)
[2012/05/18 17:16:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}
[2012/05/18 17:16:58 | 000,000,000 | ---D | M] (FT SleekDark) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}(2)
[2011/04/11 17:10:34 | 000,000,000 | ---D | M] (Acunetix Web Scanner (Free Edition)) -- C:\Documents and Settings\RayRay\Application Data\Mozilla\Firefox\Profiles\s9fukuj6.default\extensions\acunetixwebscanner@attila.gerendi
[2012/02/10 11:40:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/02/10 11:40:32 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/12/08 17:07:15 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/18 10:49:48 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/29 14:33:46 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/29 14:33:46 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/05/18 11:00:00 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\19.7.0.9\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\19.7.0.9\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll File not found
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\19.7.0.9\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (att.net Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll File not found
O3 - HKU\S-1-5-21-9541066-2834051161-270261326-1005\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\19.7.0.9\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DellCleanup] c:\dell\winclean.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dell System Manager.lnk = C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TdmNotify.lnk = C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmNotify.exe (Wave Systems Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-9541066-2834051161-270261326-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-9541066-2834051161-270261326-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-9541066-2834051161-270261326-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-9541066-2834051161-270261326-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77}
http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab (DLM Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1295454096651 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644}
https://pattcw.att.motive.com/wizlet/DSLActivation/static/installer/ATTInternetInstaller.cab (WebBrowserType Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1830866F-6A4D-4D74-BBD8-91403669ADFA}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (waveGina.dll) - C:\WINDOWS\System32\waveGina.dll (Wave Systems Corp.)
O24 - Desktop WallPaper: C:\WINDOWS\dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\dell.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/05/18 21:33:11 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\RayRay\Desktop\OTL.exe
[2012/05/18 20:32:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/18 20:32:06 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/05/18 20:32:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/05/18 20:30:58 | 010,063,000 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\RayRay\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/18 18:18:47 | 002,126,424 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\RayRay\Desktop\tdsskiller.exe
[2012/05/18 18:15:17 | 000,141,944 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/05/18 18:15:17 | 000,060,872 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2012/05/18 18:15:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012/05/18 18:15:17 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/05/18 18:14:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Norton Internet Security
[2012/05/18 18:14:36 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2012/05/18 18:04:19 | 006,254,016 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\RayRay\Desktop\NRnR.exe
[2012/05/18 17:39:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2012/05/18 17:39:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2012/05/18 17:39:20 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2012/05/18 17:37:33 | 000,944,264 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\RayRay\Desktop\SkypeSetup.exe
[2012/05/18 17:18:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Start Menu\Programs\IETester
[2012/05/18 17:17:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\magent_firecheckout
[2012/05/18 17:17:31 | 000,000,000 | ---D | C] -- C:\Program Files\Aman Software
[2012/05/18 17:17:29 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2012/05/18 17:16:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\template
[2012/05/18 17:16:55 | 000,000,000 | ---D | C] -- C:\Program Files\WinSCP
[2012/05/18 17:16:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\Brush_Set_28___Birds_by_punksafetypin
[2012/05/18 17:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\Wood_Patterns
[2012/05/18 17:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\WinMTR-v092
[2012/05/18 17:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\WebCruiserPro
[2012/05/18 17:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\kldetector13
[2012/05/18 17:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\ICOFormat-1.6f9-win
[2012/05/18 17:16:35 | 000,000,000 | ---D | C] -- C:\Program Files\STMicroelectronics
[2012/05/18 17:16:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/05/18 17:16:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ATTYToolbar
[2012/05/18 17:16:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2012/05/18 17:16:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2012/05/18 17:16:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/05/18 17:16:14 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Application Data\Yahoo!
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Local Settings\Application Data\tific
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Application Data\Tific
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Application Data\LivePerson
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Application Data\AVG
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Local Settings\Application Data\ATTYToolbar
[2012/05/18 17:16:12 | 000,000,000 | ---D | C] -- C:\Program Files\Acunetix
[2012/05/18 17:14:11 | 000,000,000 | ---D | C] -- C:\cmdcons
[2012/05/18 17:14:10 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/05/18 17:14:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Test
[2012/05/18 17:14:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache
[2012/05/18 17:14:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/05/18 16:18:55 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2012/05/18 14:41:30 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2012/05/18 14:18:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sophos
[2012/05/18 13:15:38 | 000,000,000 | ---D | C] -- C:\RECYCLER(3)
[2012/05/18 10:51:53 | 000,000,000 | ---D | C] -- C:\cmdcons(2)
[2012/05/18 09:31:46 | 000,000,000 | ---D | C] -- C:\Program Files\Skype(3)
[2012/05/17 22:44:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8(2)
[2012/05/17 14:55:41 | 000,000,000 | ---D | C] -- C:\Program Files\Skype(2)
[2012/05/17 10:03:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes(2)
[2012/05/17 10:03:50 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware(2)
[2012/05/16 22:16:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Application Data\Wise Registry Cleaner
[2012/05/16 22:15:47 | 000,000,000 | ---D | C] -- C:\Program Files\Wise
[2012/05/16 21:57:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012/05/16 20:27:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Application Data\ElevatedDiagnostics
[2012/05/16 12:01:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/05/16 10:41:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2012/05/15 16:49:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\My Documents\Fiddler2
[2012/05/15 16:45:45 | 000,000,000 | ---D | C] -- C:\Program Files\Fiddler2
[2012/05/11 15:34:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\wendy-lp-std-medium
[2012/05/11 14:46:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2012/05/10 18:41:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\Desktop\New Folder
[2012/05/08 18:37:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\My Documents\retrobabyEmail-Finals
[2012/05/02 16:25:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\RayRay\My Documents\newdir
[2012/04/25 08:14:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/05/18 21:33:13 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\RayRay\Desktop\OTL.exe
[2012/05/18 20:32:07 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/18 20:30:58 | 010,063,000 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\RayRay\Desktop\mbam-setup-1.61.0.1400.exe
[2012/05/18 20:26:51 | 000,065,172 | ---- | M] () -- C:\WINDOWS\System32\NvwsApps.xml
[2012/05/18 20:26:48 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\RayRay\Local Settings\Application Data\WavXMapDrive.bat
[2012/05/18 20:26:47 | 000,048,734 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2012/05/18 20:26:37 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/05/18 20:26:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/05/18 20:25:51 | 3479,060,480 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/18 20:24:49 | 000,588,936 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1307000.009\Cat.DB
[2012/05/18 18:21:28 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\omc7qsvx.exe
[2012/05/18 18:18:47 | 002,126,424 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\RayRay\Desktop\tdsskiller.exe
[2012/05/18 18:15:17 | 000,141,944 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/05/18 18:15:17 | 000,060,872 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2012/05/18 18:15:17 | 000,007,468 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/05/18 18:15:17 | 000,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/05/18 18:15:14 | 000,002,237 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/05/18 18:04:27 | 006,254,016 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\RayRay\Desktop\NRnR.exe
[2012/05/18 17:54:35 | 000,522,888 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/05/18 17:51:40 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/05/18 17:48:58 | 000,598,286 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/05/18 17:48:58 | 000,138,594 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/05/18 17:39:22 | 000,001,878 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/05/18 17:37:35 | 000,944,264 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\RayRay\Desktop\SkypeSetup.exe
[2012/05/18 15:57:24 | 000,597,275 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1307010.005\Cat.DB
[2012/05/18 15:55:15 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/05/18 11:00:00 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/05/17 15:36:01 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\RayRay\defogger_reenable
[2012/05/16 18:26:55 | 000,048,734 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2012/05/16 15:12:09 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\RayRay\Application Data\winscp.rnd
[2012/05/15 09:13:06 | 000,000,973 | ---- | M] () -- C:\Documents and Settings\RayRay\My Documents\NSR_fairpricehosting.net_2012-05-15(1).csv
[2012/05/15 09:11:32 | 000,002,058 | ---- | M] () -- C:\Documents and Settings\RayRay\My Documents\NSR_fairpricehosting.com_2012-05-15(1).csv
[2012/05/14 12:15:34 | 000,898,048 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\Scrap.shs
[2012/05/11 15:33:50 | 000,050,006 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\wendy-lp-std-medium.zip
[2012/05/11 13:29:12 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\RayRay\My Documents\Default.rdp
[2012/05/11 10:23:09 | 000,029,131 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\SUB.csv
[2012/05/10 18:50:29 | 000,029,948 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\subscribers.csv
[2012/05/08 18:37:00 | 002,510,185 | ---- | M] () -- C:\Documents and Settings\RayRay\My Documents\retrobabyEmail-Finals.zip
[2012/05/01 22:10:58 | 008,106,249 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\localtit2.zip
[2012/05/01 22:07:36 | 008,110,211 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\localtit2.csv
[2012/05/01 22:05:47 | 008,108,864 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\localtit.csv.zip
[2012/04/27 21:12:23 | 005,358,862 | ---- | M] () -- C:\Documents and Settings\RayRay\Desktop\gnomes.eps
[2012/04/18 23:41:32 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NIS\1307000.009\isolate.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/05/18 20:32:07 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/18 18:21:25 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\omc7qsvx.exe
[2012/05/18 18:15:17 | 000,007,468 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/05/18 18:15:17 | 000,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/05/18 18:15:14 | 000,002,237 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012/05/18 17:39:22 | 000,001,878 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/05/18 17:19:04 | 3479,060,480 | -HS- | C] () -- C:\hiberfil.sys
[2012/05/17 15:36:01 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\RayRay\defogger_reenable
[2012/05/15 09:13:06 | 000,000,973 | ---- | C] () -- C:\Documents and Settings\RayRay\My Documents\NSR_fairpricehosting.net_2012-05-15(1).csv
[2012/05/15 09:11:24 | 000,002,058 | ---- | C] () -- C:\Documents and Settings\RayRay\My Documents\NSR_fairpricehosting.com_2012-05-15(1).csv
[2012/05/11 16:04:54 | 001,383,576 | ---- | C] () -- C:\Documents and Settings\RayRay\My Documents\_MG_7775.jpg
[2012/05/11 16:00:33 | 001,219,343 | ---- | C] () -- C:\Documents and Settings\RayRay\My Documents\_MG_7766.jpg
[2012/05/11 15:33:49 | 000,050,006 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\wendy-lp-std-medium.zip
[2012/05/11 13:29:12 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\RayRay\My Documents\Default.rdp
[2012/05/11 10:23:09 | 000,029,131 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\SUB.csv
[2012/05/10 12:14:28 | 000,029,948 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\subscribers.csv
[2012/05/08 18:37:43 | 002,510,185 | ---- | C] () -- C:\Documents and Settings\RayRay\My Documents\retrobabyEmail-Finals.zip
[2012/05/07 08:59:00 | 000,002,315 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/05/01 22:10:57 | 008,106,249 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\localtit2.zip
[2012/05/01 22:07:36 | 008,110,211 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\localtit2.csv
[2012/05/01 22:05:47 | 008,108,864 | ---- | C] () -- C:\Documents and Settings\RayRay\Desktop\localtit.csv.zip
[2012/02/17 12:51:32 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/02/15 11:25:22 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/11/14 21:12:15 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/11/14 21:12:15 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/11/14 21:12:15 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/11/14 21:12:15 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/11/14 21:12:15 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/11/14 20:21:28 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/09/29 11:02:01 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\RayRay\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/23 18:17:07 | 000,053,524 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/06/14 09:54:58 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011/05/09 20:31:44 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011/04/21 13:51:23 | 000,000,952 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2011/04/21 13:51:23 | 000,000,008 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\90AED82D59.sys
[2011/04/11 17:09:33 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\ptlx55.dat.{5728B11F-B697-47AA-9C1B-8ECB545B5193}
[2011/02/24 16:30:58 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\RayRay\Application Data\winscp.rnd
[2011/02/09 12:06:39 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\RayRay\Local Settings\Application Data\fusioncache.dat
[2011/02/09 11:56:40 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2011/02/09 11:56:07 | 000,000,167 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2011/02/09 11:55:05 | 000,000,694 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2011/01/31 17:17:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/01/19 21:34:46 | 000,108,336 | ---- | C] () -- C:\Program Files\Photoshop CS4 — Lisez-moi.pdf
[2011/01/19 21:34:46 | 000,103,148 | ---- | C] () -- C:\Program Files\Léame de Photoshop CS4.pdf
[2011/01/19 21:34:46 | 000,065,686 | ---- | C] () -- C:\Program Files\Photoshop CS4 Read Me.pdf
[2011/01/19 18:03:10 | 000,196,140 | ---- | C] () -- C:\Program Files\Dreamweaver CS4 — Lisez-moi.pdf
[2011/01/19 18:03:10 | 000,186,678 | ---- | C] () -- C:\Program Files\Léame de Dreamweaver CS4.pdf
[2011/01/19 18:03:10 | 000,084,227 | ---- | C] () -- C:\Program Files\Dreamweaver CS4 Read Me.pdf
[2011/01/19 13:14:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\RayRay\Local Settings\Application Data\WavXMapDrive.bat
[2011/01/19 13:09:17 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2011/01/19 13:00:24 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2011/01/19 13:00:23 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2011/01/19 13:00:23 | 000,025,088 | ---- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE
[2011/01/19 12:56:46 | 000,308,624 | ---- | C] () -- C:\WINDOWS\System32\brcmbsp.dll
[2011/01/19 12:56:46 | 000,206,216 | ---- | C] () -- C:\WINDOWS\System32\bipbsp.dll
[2011/01/19 12:56:36 | 000,080,368 | ---- | C] () -- C:\WINDOWS\System32\pbadrvdll.dll
[2011/01/19 12:43:17 | 000,048,734 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2011/01/14 20:43:04 | 000,077,824 | ---- | C] () -- C:\WINDOWS\setpwr32.exe
[2011/01/14 20:42:58 | 001,589,414 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2011/01/14 20:38:34 | 000,001,157 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
========== Files - Unicode (All) ==========[2011/08/02 19:57:55 | 000,000,017 | ---- | M] ()(C:\WINDOWS\System32\?ý) -- C:\WINDOWS\System32\燈ý
[2011/08/02 19:57:55 | 000,000,017 | ---- | C] ()(C:\WINDOWS\System32\?ý) -- C:\WINDOWS\System32\燈ý
< End of report >