OTL
OTL logfile created on: 24/01/2010 12:54:22 PM - Run 1
OTL by OldTimer - Version 3.1.25.4 Folder = C:\Documents and Settings\knox\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
502.00 Mb Total Physical Memory | 227.00 Mb Available Physical Memory | 45.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.69 Gb Total Space | 13.66 Gb Free Space | 24.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-3962729A48
Current User Name: knox
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=\"#E56717\"]========== Processes (SafeList) ==========[/color]
PRC - [2010/01/22 14:17:56 | 00,547,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\knox\Desktop\OTL.exe
PRC - [2009/12/03 18:39:52 | 00,083,280 | ---- | M] () -- C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
PRC - [2009/10/21 11:50:12 | 00,995,528 | ---- | M] () -- C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
PRC - [2009/10/21 11:50:10 | 00,711,248 | ---- | M] () -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
PRC - [2009/10/15 19:00:30 | 00,275,792 | ---- | M] () -- C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
PRC - [2009/09/04 12:07:28 | 00,497,008 | ---- | M] () -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
PRC - [2009/09/04 11:51:40 | 00,677,128 | ---- | M] () -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/04/06 21:43:10 | 00,341,256 | ---- | M] () -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe
PRC - [2009/03/24 19:09:36 | 00,169,296 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
PRC - [2009/02/12 20:46:37 | 00,181,584 | ---- | M] () -- C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
PRC - [2009/02/12 17:52:44 | 00,161,104 | ---- | M] (Trend Micro Inc.) -- C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\platformdependent\ProToolbarComm.exe
PRC - [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/04/14 11:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/01/25 07:51:28 | 00,028,672 | ---- | M] (TOSHIBA) -- C:\WINDOWS\system32\TCtrlIOHook.exe
PRC - [2004/12/07 01:49:32 | 00,088,363 | ---- | M] (Agere Systems) -- C:\WINDOWS\agrsmmsg.exe
PRC - [2004/11/30 16:06:26 | 00,053,248 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
PRC - [2004/11/30 04:10:22 | 00,667,648 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
PRC - [2004/11/13 12:57:12 | 00,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
PRC - [2004/11/02 12:03:44 | 00,155,648 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxtray.exe
PRC - [2004/11/02 11:59:42 | 00,126,976 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
PRC - [2004/10/26 09:23:10 | 00,114,688 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
PRC - [2004/09/16 10:03:08 | 00,135,168 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
PRC - [2004/07/15 11:07:32 | 00,024,576 | ---- | M] (TOSHIBA) -- C:\WINDOWS\system32\ZoomingHook.exe
PRC - [2004/06/30 13:04:10 | 01,077,326 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
PRC - [2004/06/02 15:43:10 | 00,045,056 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSBattM.exe
PRC - [2004/03/24 01:40:42 | 00,196,608 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint2K\Apoint.exe
PRC - [2003/09/05 22:24:46 | 00,065,536 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
PRC - [2003/05/23 15:38:26 | 00,106,496 | ---- | M] (Matsu[censored]a Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\DVDRAMSV.exe
PRC - [2003/03/14 13:38:12 | 00,155,648 | ---- | M] (Matsu[censored]a Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\RAMASST.exe
PRC - [2003/02/26 14:08:42 | 00,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint2K\ApntEx.exe
[color=\"#E56717\"]========== Modules (SafeList) ==========[/color]
MOD - [2010/01/22 14:17:56 | 00,547,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\knox\Desktop\OTL.exe
[color=\"#E56717\"]========== Win32 Services (SafeList) ==========[/color]
SRV - [2009/10/21 11:50:10 | 00,711,248 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe -- (SfCtlCom)
SRV - [2009/09/21 16:36:02 | 00,545,568 | ---- | M] (Apple Inc.) [On_Demand | Stopped] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/09/04 12:07:28 | 00,497,008 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe -- (TmPfw)
SRV - [2009/09/04 11:51:40 | 00,677,128 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe -- (TmProxy)
SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/05/19 11:36:18 | 00,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/04/06 21:43:10 | 00,341,256 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe -- (TMBMServer)
SRV - [2009/02/12 20:46:37 | 00,181,584 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe -- (Security Activity Dashboard Service)
SRV - [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/04/14 11:11:55 | 00,028,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\irmon.dll -- (Irmon)
SRV - [2005/04/04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003/07/29 07:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2003/05/23 15:38:26 | 00,106,496 | ---- | M] (Matsu[censored]a Electric Industrial Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
[color=\"#E56717\"]========== Driver Services (SafeList) ==========[/color]
DRV - [2009/05/22 19:02:26 | 00,225,296 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmxpflt.sys -- (tmxpflt)
DRV - [2009/05/22 19:00:40 | 00,036,368 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmpreflt.sys -- (tmpreflt)
DRV - [2009/05/22 18:45:58 | 01,220,120 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\vsapint.sys -- (vsapint)
DRV - [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/04/06 21:43:46 | 00,335,376 | ---- | M] (Trend Micro Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\TM_CFW.sys -- (tmcfw)
DRV - [2009/04/06 21:43:45 | 00,080,400 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tmtdi.sys -- (tmtdi)
DRV - [2009/04/03 10:08:54 | 00,050,192 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmactmon.sys -- (tmactmon)
DRV - [2009/04/03 10:08:52 | 00,050,192 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV - [2009/04/03 10:08:48 | 00,153,104 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2009/03/26 16:23:46 | 00,036,864 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaapl.sys -- (USBAAPL)
DRV - [2008/04/14 04:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007/11/13 21:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2007/09/29 03:07:50 | 00,043,528 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2007/07/18 19:37:51 | 00,223,128 | ---- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\dtscsi.sys -- (dtscsi)
DRV - [2007/07/18 19:33:29 | 00,642,560 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2004/12/15 17:22:08 | 00,010,240 | ---- | M] (Dritek System Inc.) [Kernel | Auto | Running] -- C:\DRIVERS\FN-ESSE\DPortIO.sys -- (DritekPortIO)
DRV - [2004/12/14 21:29:28 | 00,016,128 | ---- | M] (TOSHIBA ) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TPwSav.sys -- (TPwSav)
DRV - [2004/12/12 09:12:00 | 00,006,144 | ---- | M] (TOSHIBA ) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\Windows Utilities\spDispatch.sys -- (SPCtl)
DRV - [2004/12/12 09:12:00 | 00,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Applet\HWS_IoDispatch.sys -- (HWSCtrl)
DRV - [2004/12/11 20:52:14 | 00,006,144 | ---- | M] (TOSHIBA ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\TCtrlIO.sys -- (TCtrlIO)
DRV - [2004/12/11 09:00:44 | 00,006,144 | ---- | M] (TOSHIBA) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys -- (StickyMesger)
DRV - [2004/12/11 08:49:18 | 00,006,144 | ---- | M] (TOAHIBA, ) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\TouchPad\TPECioCtl.sys -- (TPECioCtl)
DRV - [2004/12/11 03:29:50 | 00,006,144 | ---- | M] (TOAHIBA, ) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\E-KEY\EKECioCtl.sys -- (EKECioCtl)
DRV - [2004/12/07 01:50:14 | 01,270,572 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004/11/27 08:04:38 | 00,029,056 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tvs.sys -- (Tvs)
DRV - [2004/11/26 10:29:00 | 00,224,000 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2004/11/17 13:30:00 | 00,147,840 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004/11/15 19:22:08 | 00,101,874 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/11/02 12:27:20 | 00,773,565 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm)
DRV - [2004/10/30 13:48:10 | 03,222,784 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2004/10/27 16:57:38 | 02,284,864 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/04 23:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2004/07/31 09:05:04 | 00,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EPIOMngr.sys -- (SerTVOutCtlr)
DRV - [2004/07/30 18:05:08 | 00,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\E-KEY\SSIOMngr.sys -- (SrvcSSIOMngr)
DRV - [2004/07/30 18:05:04 | 00,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\E-KEY\EKIOMngr.sys -- (SrvcEKIOMngr)
DRV - [2004/06/17 06:19:58 | 00,046,080 | ---- | M] (SMSC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
DRV - [2004/01/30 12:32:32 | 00,090,480 | ---- | M] (Matsu[censored]a Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2003/09/19 20:47:00 | 00,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc)
DRV - [2003/09/11 18:36:54 | 00,021,060 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iviaspi.sys -- (Iviaspi)
[color=\"#E56717\"]========== Standard Registry (SafeList) ==========[/color]
[color=\"#E56717\"]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.live.com/results.aspx?q={sea...ferrer:source?}IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=\"#E56717\"]========== FireFox ==========[/color]
FF - prefs.js..extensions.enabledItems:
[email protected]:1.2.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {f8454bbe-519f-4004-85c1-12d1b31988fc}:1.24
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.10
FF - prefs.js..extensions.enabledItems:
[email protected]:0.7.9
FF - prefs.js..extensions.enabledItems: {71328583-3CA7-4809-B4BA-570A85818FBB}:0.6.2
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.0
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0.3
FF - prefs.js..extensions.enabledItems: {06997db0-c027-4d5f-bd37-b0d9230226ea}:0.52
FF - prefs.js..extensions.enabledItems: {cd617375-6743-4ee8-bac4-fbf10f35729e}:2.5
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.3.20091214_AMO
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems:
[email protected]:1.1.3
FF - prefs.js..extensions.enabledItems: {22181a4d-af90-4ca3-a569-faed9118d6bc}:1.2.0.1073
FF - prefs.js..extensions.enabledItems: unplug@compunach:2.024
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.2.14
FF - HKLM\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension [2010/01/23 16:15:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/07 19:40:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/08 15:23:39 | 00,000,000 | ---D | M]
[2009/11/12 23:58:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Extensions
[2008/07/10 02:19:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Extensions\
[email protected][2009/02/23 17:52:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Extensions\
[email protected][2010/01/23 17:28:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions
[2009/11/14 02:21:39 | 00,000,000 | ---D | M] (Remove Cookie(s) for Site) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{06997db0-c027-4d5f-bd37-b0d9230226ea}
[2010/01/12 10:36:14 | 00,000,000 | ---D | M] (CacheViewer) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}
[2009/12/31 15:31:01 | 00,000,000 | ---D | M] (Zynga Toolbar) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2009/11/14 11:33:34 | 00,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010/01/21 15:29:43 | 00,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/11/14 02:21:45 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}
[2010/01/21 15:29:41 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/01/12 10:36:12 | 00,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/11/14 02:21:57 | 00,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/11/14 11:34:38 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/01/12 10:36:20 | 00,000,000 | ---D | M] (DownThemAll!) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/11/14 11:02:49 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\{f8454bbe-519f-4004-85c1-12d1b31988fc}
[2009/11/14 11:02:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\
[email protected][2009/12/05 12:36:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\
[email protected][2009/12/16 15:37:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\SkipScreen@SkipScreen
[2010/01/16 13:14:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\
[email protected][2009/11/20 02:05:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\unplug@compunach
[2010/01/16 13:14:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\knox\Application Data\Mozilla\Firefox\Profiles\owxnpul6.default\extensions\
[email protected][2009/10/27 07:34:34 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/07/17 19:40:12 | 00,704,512 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
O1 HOSTS File: ([2004/08/04 23:00:00 | 00,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {1f6e533e-905c-484b-b5c0-c42f2b5c7c8b} - Reg Error: Value error. File not found
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll (BitComet)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\agrsmmsg.exe (Agere Systems)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NWEReboot] File not found
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\System32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\System32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe File not found
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\knox\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsu[censored]a Electric Industrial Co., Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 177
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: {79DDFA20-063B-1033-0413-05080220003d} = "C:\Program Files\Common Files\{79DDFA20-063B-1033-0413-05080220003d}\Update.exe" mc-110-12-0001411 File not found
O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O9 - Extra 'Tools' menuitem : IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - File not found
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll (BitComet)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Marcia\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741}
http://www.slide.com/uploader/SlideImageUploader.cab (Slide Image Uploader Control)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0}
http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC}
http://upload.facebook.com/controls/Facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
http://messenger.zone.msn.com/binary/Messe...nt.cab50997.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/shock...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\knox\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\knox\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/12/28 11:33:53 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{7e53f466-c806-11dc-a019-0012f051e6ae}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
[color=\"#E56717\"]========== Files/Folders - Created Within 30 Days ==========[/color]
[2010/01/22 14:17:20 | 00,547,840 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\knox\Desktop\OTL.exe
[2010/01/20 17:59:00 | 00,000,000 | ---D | C] -- C:\Config.Msi
[2010/01/20 14:08:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\knox\Local Settings\Application Data\Ahead
[2010/01/20 13:52:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\knox\Application Data\Ahead
[2010/01/20 13:48:27 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Ahead
[2010/01/18 10:41:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\knox\Desktop\New Folder (2)
[2010/01/13 13:35:25 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll
[2009/04/06 22:19:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Trend Micro
[2008/06/10 09:49:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/12/04 22:53:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/01/16 20:23:57 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/11/01 08:23:13 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/11/15 17:28:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Symantec
[2004/12/28 11:37:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[color=\"#E56717\"]========== Files - Modified Within 30 Days ==========[/color]
[2010/01/24 12:53:33 | 00,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F17FA9A5-94A2-4393-8283-B524550BF09B}.job
[2010/01/24 12:46:06 | 00,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2370085308-4065420486-4255011411-1006UA.job
[2010/01/24 12:04:22 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/01/24 12:01:37 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/01/24 12:01:33 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/01/24 12:01:32 | 52,689,7152 | -HS- | M] () -- C:\hiberfil.sys
[2010/01/23 19:21:59 | 06,172,672 | ---- | M] () -- C:\Documents and Settings\knox\ntuser.dat
[2010/01/23 19:21:59 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\knox\ntuser.ini
[2010/01/23 19:21:06 | 05,411,756 | -H-- | M] () -- C:\Documents and Settings\knox\Local Settings\Application Data\IconCache.db
[2010/01/22 14:17:56 | 00,547,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\knox\Desktop\OTL.exe
[2010/01/21 15:22:48 | 00,082,944 | ---- | M] () -- C:\Documents and Settings\knox\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/20 22:46:01 | 00,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2370085308-4065420486-4255011411-1006Core.job
[2010/01/20 19:40:29 | 00,000,937 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Media Player Classic.lnk
[2010/01/20 15:13:37 | 00,000,042 | ---- | M] () -- C:\Documents and Settings\knox\default.pls
[2010/01/16 14:18:15 | 17,535,561 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\the-cougar-club-trailer-scene5-2.mp4
[2010/01/14 16:03:14 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/01/13 19:57:10 | 00,012,088 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\bzv_carmella_bing.wmv.torrent
[2010/01/13 19:56:57 | 00,020,273 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\btis_angelina_carmella.wmv.torrent
[2010/01/13 19:10:33 | 00,030,644 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\Bonny Bon-lesbian anal fist.mpg.torrent
[2010/01/13 18:56:45 | 00,012,936 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\adventures in squirtland.mp4.torrent
[2010/01/12 20:08:59 | 00,759,677 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\FarmvilleGuide.pdf
[2010/01/09 19:33:21 | 00,014,763 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\gianna_michaels-donger_brothers.wmv.torrent
[2010/01/08 22:28:47 | 00,010,729 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\btiu_carmella_bing.wmv.torrent
[2010/01/04 11:53:12 | 00,163,846 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\supergirl megan.jpeg
[2010/01/03 03:26:52 | 00,016,859 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\Blacks On Blondes - Gianna Michaels.torrent
[2010/01/03 03:17:01 | 00,036,780 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\MyFirstSexTeacher.com - Julia Ann - HDV 720p + Picture - Set(2).torrent
[2009/12/30 19:58:40 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/12/29 16:42:47 | 00,068,589 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\Angelica Sin.torrent
[2009/12/26 00:04:07 | 00,027,822 | ---- | M] () -- C:\Documents and Settings\knox\Desktop\Pregnant [censored]ing in public places 3 p.torrent
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[color=\"#E56717\"]========== Files Created - No Company Name ==========[/color]
[2010/01/20 15:13:37 | 00,000,042 | ---- | C] () -- C:\Documents and Settings\knox\default.pls
[2010/01/19 19:23:19 | 06,172,672 | ---- | C] () -- C:\Documents and Settings\knox\ntuser.dat
[2010/01/16 14:11:48 | 17,535,561 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\the-cougar-club-trailer-scene5-2.mp4
[2010/01/13 19:57:05 | 00,012,088 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\bzv_carmella_bing.wmv.torrent
[2010/01/13 19:56:56 | 00,020,273 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\btis_angelina_carmella.wmv.torrent
[2010/01/13 19:10:11 | 00,030,644 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\Bonny Bon-lesbian anal fist.mpg.torrent
[2010/01/13 18:56:44 | 00,012,936 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\adventures in squirtland.mp4.torrent
[2010/01/12 20:08:53 | 00,759,677 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\FarmvilleGuide.pdf
[2010/01/09 19:33:20 | 00,014,763 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\gianna_michaels-donger_brothers.wmv.torrent
[2010/01/08 22:28:46 | 00,010,729 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\btiu_carmella_bing.wmv.torrent
[2010/01/04 11:53:11 | 00,163,846 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\supergirl megan.jpeg
[2010/01/03 03:26:52 | 00,016,859 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\Blacks On Blondes - Gianna Michaels.torrent
[2010/01/03 03:17:00 | 00,036,780 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\MyFirstSexTeacher.com - Julia Ann - HDV 720p + Picture - Set(2).torrent
[2009/12/30 19:58:40 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/12/29 16:42:46 | 00,068,589 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\Angelica Sin.torrent
[2009/12/26 00:04:07 | 00,027,822 | ---- | C] () -- C:\Documents and Settings\knox\Desktop\Pregnant [censored]ing in public places 3 p.torrent
[2009/11/14 03:30:35 | 00,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/11/14 03:30:34 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009/11/14 03:30:31 | 00,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/11/14 03:30:31 | 00,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/11/14 03:30:29 | 00,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/11/14 03:30:29 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/12/31 17:04:42 | 00,691,560 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2008/11/07 03:37:32 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/07 03:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/05 08:38:30 | 00,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2008/09/04 21:45:06 | 00,000,025 | ---- | C] () -- C:\WINDOWS\CDE CX5500Asia.ini
[2007/12/05 00:16:23 | 00,000,000 | ---- | C] () -- C:\WINDOWS\CeEKey.INI
[2007/07/18 19:33:29 | 00,642,560 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/07/18 19:33:29 | 00,096,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd4781.sys
[2007/06/14 01:44:05 | 00,000,216 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/01/03 20:06:52 | 00,001,739 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/08/20 18:09:50 | 00,000,026 | ---- | C] () -- C:\WINDOWS\dvdSanta.INI
[2006/08/07 01:04:12 | 00,001,891 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI
[2006/05/13 10:43:35 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\impborl.dll
[2005/10/11 22:51:29 | 00,000,056 | ---- | C] () -- C:\WINDOWS\RALLYC.INI
[2005/09/15 18:31:40 | 00,082,944 | ---- | C] () -- C:\Documents and Settings\knox\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/08/28 10:00:54 | 00,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2005/08/28 10:00:54 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2005/08/28 10:00:54 | 00,010,167 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2005/08/28 10:00:54 | 00,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2005/08/11 09:00:12 | 00,647,168 | ---- | C] () -- C:\WINDOWS\System32\pqdvdb.dll
[2004/12/28 22:22:37 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/12/28 12:27:22 | 00,000,000 | ---- | C] () -- C:\WINDOWS\TPTray.INI
[2004/12/28 12:21:50 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/12/28 12:17:50 | 00,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2004/12/28 12:16:10 | 00,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2004/12/28 12:16:10 | 00,028,032 | ---- | C] () -- C:\WINDOWS\System32\drivers\WOWXT_kern_i386.sys
[2004/12/28 12:15:35 | 00,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/12/28 12:14:41 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2004/12/28 12:14:41 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2004/12/28 12:14:41 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2004/12/28 12:14:41 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2004/12/28 12:14:41 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2004/12/28 12:14:41 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2004/12/28 12:03:21 | 00,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2004/12/28 11:38:39 | 00,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/12/28 10:14:48 | 00,002,388 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/12/15 02:40:16 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\EKECioCtl.dll
[2004/01/13 21:46:00 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\tifmicon.dll
[1999/01/23 13:46:58 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[color=\"#E56717\"]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CAAA7DD7
< End of report >