Today I found that my computer would boot, but then stalled when loading the desktop. All the icons look fine but the cursor would not move and it had an hourglass next to it. According to my quick load icons, WinPatrol loaded, but nothing else. Ctrl-alt-del and Esc had no effect.
I can boot and load fine in safe mode with networking (this is how I'm writing this). Avast and Malware Bytes showed nothing wrong. I disabled all my startup programs, which had no effect. Firefox works in safe mode, but I can't get Avast to update and Google Chrome won't open. I don't know if this is normal or not, as this is the first time I've tried to go on the internet in safe mode.
ETA 12/17: I went and did the "last known good configuration" and now I can use my computer, but now I'm getting an error bubble that says "Windows System Error: There is an IP address conflict with another system on the network." I have never seen THAT before ever. 0.o
Here is my OTL log:
OTL logfile created on: 12/14/2011 10:35:08 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\patty\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 73.44% Memory free
5.85 Gb Paging File | 5.53 Gb Available in Paging File | 94.56% Paging File free
Paging file location(s): C:\pagefile.sys 4092 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.96 Gb Total Space | 81.82 Gb Free Space | 54.93% Space Free | Partition Type: NTFS
Drive D: | 232.82 Gb Total Space | 232.74 Gb Free Space | 99.96% Space Free | Partition Type: NTFS
Drive E: | 620.40 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: XENAA | User Name: patty | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/14 10:34:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\patty\Desktop\OTL.exe
PRC - [2011/11/10 19:35:54 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011/12/05 13:53:06 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCoreGecko8.dll
MOD - [2011/11/14 13:05:06 | 000,036,864 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\extensions\[email protected]\platform\echofonsign.dll
MOD - [2011/11/13 08:10:37 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/10 19:35:53 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2009/05/30 13:29:31 | 000,043,520 | ---- | M] () -- C:\WINDOWS\system32\CmdLineExt03.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (iPod Service)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/11/28 12:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/10/03 01:52:43 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Stopped] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2010/09/06 15:29:10 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2009/02/23 10:43:54 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Stopped] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
========== Driver Services (SafeList) ==========
DRV - [2011/11/28 11:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/28 11:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/28 11:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/28 11:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/28 11:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/28 11:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/28 11:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/05/23 10:37:17 | 001,211,480 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ha20x2k.sys -- (ha20x2k)
DRV - [2011/05/23 10:37:17 | 000,159,320 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV - [2011/05/23 10:37:17 | 000,095,832 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia)
DRV - [2011/05/23 10:37:16 | 001,399,384 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\CTEXFIFX.SYS -- (CTEXFIFX.SYS)
DRV - [2011/05/23 10:37:16 | 001,399,384 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV - [2011/05/23 10:37:16 | 000,537,048 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)
DRV - [2011/05/23 10:37:16 | 000,511,064 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k)
DRV - [2011/05/23 10:37:16 | 000,347,144 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k)
DRV - [2011/05/23 10:37:16 | 000,198,232 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\CT20XUT.SYS -- (CT20XUT.SYS)
DRV - [2011/05/23 10:37:16 | 000,198,232 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CT20XUT.sys -- (CT20XUT)
DRV - [2011/05/23 10:37:16 | 000,130,648 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv)
DRV - [2011/05/23 10:37:16 | 000,073,816 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\CTHWIUT.SYS -- (CTHWIUT.SYS)
DRV - [2011/05/23 10:37:16 | 000,073,816 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV - [2011/05/23 10:37:16 | 000,014,424 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV - [2008/08/01 17:36:26 | 000,022,016 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/08/01 17:36:20 | 000,054,784 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/04/13 12:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/01/22 07:37:02 | 000,070,144 | R--- | M] (Netgear Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\G311N6.sys -- (NetgearGA311)
DRV - [2006/10/30 20:06:52 | 000,067,456 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GA311ND5.SYS -- (RTL8023)
DRV - [2006/10/18 21:47:10 | 000,542,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\blackbox.dll -- (BlackBox)
DRV - [2006/04/03 08:46:43 | 000,010,344 | ---- | M] (Symantec Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd)
DRV - [2005/09/08 04:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/09/08 04:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/09/08 04:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/09/08 04:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/09/08 04:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/09/08 04:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/09/08 04:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/08/25 11:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/08/25 11:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/08/02 19:52:00 | 003,647,104 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/07/20 00:59:26 | 000,093,440 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvatabus.sys -- (nvatabus)
DRV - [2002/11/18 14:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.co...-inc&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.co...-inc&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.thehungersite.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Swag Bucks Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=374563"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.thehunger...faces?siteId=1"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.9.7.3
FF - prefs.js..extensions.enabledItems: [email protected]:7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: [email protected]:2.11
FF - prefs.js..extensions.enabledItems: [email protected]:2.2.42
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}:1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {69D30031-F4A8-452a-A5B3-5D6787C3C5CF}:3.6
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - prefs.js..keyword.url: "http://www.startsearcher.com/?q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\patty\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@sun.com/npsopluginmi;version=1.0: C:\Program Files\OpenOffice.org 2.4\program [2008/12/24 21:55:07 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.0: C:\Documents and Settings\patty\Application Data\Facebook\npfbplugin_1_0_0.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\patty\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\patty\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\patty\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\patty\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\patty\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/23 08:39:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/02 09:09:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/10 19:35:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/15 11:02:06 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/23 08:39:25 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\patty\Application Data\Move Networks [2011/11/05 20:36:51 | 000,000,000 | ---D | M]
[2008/07/16 19:05:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\patty\Application Data\Mozilla\Extensions
[2011/12/10 13:55:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\extensions
[2011/12/10 13:55:46 | 000,000,000 | ---D | M] (Swag Bucks Community Toolbar) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
[2011/10/07 16:47:51 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2011/11/16 21:24:46 | 000,000,000 | ---D | M] (Echofon) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\extensions\[email protected]
[2010/05/18 13:44:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions
[2010/04/28 06:08:00 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/18 13:47:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/18 21:33:07 | 000,000,000 | ---D | M] (OldFactory Black) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\{69D30031-F4A8-452a-A5B3-5D6787C3C5CF}
[2010/04/08 20:26:33 | 000,000,000 | ---D | M] ("BetterPrivacy") -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2010/01/22 12:06:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\{de5809e0-2b07-11dd-bd0b-0800200c9a66}
[2010/03/20 17:16:22 | 000,000,000 | ---D | M] (Diccionario español Mexico) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\[email protected]
[2008/08/25 18:57:42 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\[email protected]
[2010/05/11 11:01:34 | 000,000,000 | ---D | M] (Echofon) -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\kst7dvut.default\extensions\[email protected]
[2010/05/13 10:14:13 | 000,001,754 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\etsy.xml
[2007/02/07 14:52:35 | 000,005,357 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\everystockphotocom.xml
[2011/11/18 11:25:18 | 000,001,820 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\flickr-search-suggestions.xml
[2009/07/05 08:51:44 | 000,001,157 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\freedict.xml
[2008/06/24 14:13:03 | 000,000,908 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\IMDB.xml
[2010/07/18 14:18:07 | 000,000,990 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\netflixcom.xml
[2010/05/22 20:41:10 | 000,002,423 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\paperbackswap.xml
[2010/02/22 11:14:38 | 000,001,180 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\urban-dictionary.xml
[2008/06/18 11:01:47 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\wikipedia.xml
[2009/10/05 12:44:59 | 000,004,153 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Mozilla\Firefox\Profiles\7lhtdebw.default\searchplugins\youtube.xml
[2011/11/10 19:36:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/30 12:15:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA}
() (No name found) -- C:\DOCUMENTS AND SETTINGS\PATTY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7LHTDEBW.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\PATTY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7LHTDEBW.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\PATTY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7LHTDEBW.DEFAULT\EXTENSIONS\[email protected]
[2011/12/02 09:09:19 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011/11/10 19:35:54 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 01:53:41 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 18:26:50 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/10 19:35:54 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\patty\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\patty\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\patty\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\patty\Application Data\Facebook\npfbplugin_1_0_0.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\patty\Application Data\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\patty\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Documents and Settings\patty\Application Data\Move Networks\plugins\npqmp071701000002.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\patty\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 7 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Alexa Traffic Rank = C:\Documents and Settings\patty\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel\1.1.0_0\
CHR - Extension: Celestial Night Theme = C:\Documents and Settings\patty\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mdodgcbfdjeeoknaiglbpihbfgmmlnog\1.0_0\
O1 HOSTS File: ([2011/08/22 10:07:22 | 000,000,021 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe (ICQ, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C53A2113-29B6-41C9-8AF7-64EF1E4974D5}: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\patty\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\patty\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1998/12/13 01:43:32 | 000,000,040 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/14 10:34:35 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\patty\Desktop\OTL.exe
[2011/12/14 09:20:18 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2011/12/02 09:09:31 | 000,435,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/12/02 09:09:31 | 000,314,456 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/12/02 09:09:31 | 000,052,952 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/12/02 09:09:31 | 000,034,392 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/12/02 09:09:31 | 000,020,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/12/02 09:09:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/12/02 09:09:30 | 000,111,320 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/12/02 09:09:30 | 000,105,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/12/02 09:09:30 | 000,030,808 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/12/02 09:09:17 | 000,199,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/12/02 09:09:17 | 000,041,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/12/02 09:09:03 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/12/02 09:09:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/12/02 08:57:57 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011/12/01 11:50:10 | 000,000,000 | ---D | C] -- C:\My Web Sites
[2006/04/03 08:22:22 | 000,012,800 | ---- | C] ( ) -- C:\WINDOWS\System32\killapps.exe
========== Files - Modified Within 30 Days ==========
[2011/12/14 10:34:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\patty\Desktop\OTL.exe
[2011/12/14 10:29:24 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/14 10:28:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/14 10:25:27 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3599948769-1508766627-293611528-1005.job
[2011/12/14 10:16:38 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/14 09:28:23 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2011/12/14 08:05:10 | 000,001,100 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/12/13 21:27:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3599948769-1508766627-293611528-1005UA.job
[2011/12/13 12:27:00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3599948769-1508766627-293611528-1005Core.job
[2011/12/13 09:21:04 | 000,016,406 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\site audit spreadsheet.ods
[2011/12/12 09:46:10 | 000,002,519 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\Jasc Paint Shop Pro 8.lnk
[2011/12/08 13:14:00 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3599948769-1508766627-293611528-1005.job
[2011/12/06 12:24:32 | 001,634,572 | ---- | M] () -- C:\Documents and Settings\patty\My Documents\December2011Newsletter.pdf
[2011/12/06 11:55:58 | 016,215,880 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\EngagementFromScratchFull.pdf
[2011/12/06 08:18:22 | 000,013,843 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\balance sheet.ods
[2011/12/04 13:11:33 | 000,017,436 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\2011 goals.odt
[2011/12/04 12:09:30 | 000,364,160 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\10-really-big-and-really-simple-success-on-switches.pdf
[2011/12/04 10:55:52 | 000,010,643 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\480x380-rock_life_value.png
[2011/12/03 21:06:55 | 000,188,881 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\NetWorthTrackingBookBonus.pdf
[2011/12/03 21:06:37 | 000,071,222 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\SOMMDeclarations.pdf
[2011/12/02 11:39:03 | 000,549,276 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/12/02 11:39:03 | 000,100,554 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/12/02 09:09:31 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/12/02 08:28:42 | 006,291,456 | ---- | M] () -- C:\Documents and Settings\patty\ntuser.bak
[2011/12/02 07:29:21 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/01 13:14:00 | 000,000,000 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2011/12/01 12:48:43 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\patty\lpg1
[2011/12/01 12:11:19 | 000,000,403 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\Shortcut to My Web Sites (ELD backup).lnk
[2011/11/29 08:26:39 | 000,086,979 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\Enjoy it.jpg
[2011/11/28 12:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/11/28 12:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/11/28 11:53:53 | 000,435,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/11/28 11:53:35 | 000,314,456 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/11/28 11:52:19 | 000,034,392 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/11/28 11:52:16 | 000,052,952 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/11/28 11:52:02 | 000,111,320 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/11/28 11:51:59 | 000,105,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/11/28 11:51:50 | 000,020,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/11/28 11:48:49 | 000,030,808 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/11/28 11:16:14 | 000,136,526 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\one man show.png
[2011/11/27 08:14:58 | 000,066,312 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\success.jpg
[2011/11/26 10:53:54 | 000,000,807 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Second Life Viewer 2.lnk
[2011/11/25 12:42:32 | 000,002,471 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\Microsoft Calculator Plus.lnk
[2011/11/19 16:56:50 | 000,660,760 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\10.LongTail.pdf
[2011/11/17 16:28:17 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\patty\Desktop\Google Chrome.lnk
[2011/11/17 16:28:17 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\patty\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
========== Files Created - No Company Name ==========
[2011/12/06 12:24:31 | 001,634,572 | ---- | C] () -- C:\Documents and Settings\patty\My Documents\December2011Newsletter.pdf
[2011/12/06 11:55:49 | 016,215,880 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\EngagementFromScratchFull.pdf
[2011/12/04 12:09:29 | 000,364,160 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\10-really-big-and-really-simple-success-on-switches.pdf
[2011/12/04 10:55:51 | 000,010,643 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\480x380-rock_life_value.png
[2011/12/03 21:06:55 | 000,188,881 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\NetWorthTrackingBookBonus.pdf
[2011/12/03 21:06:36 | 000,071,222 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\SOMMDeclarations.pdf
[2011/12/02 09:09:31 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/12/01 12:48:42 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\patty\lpg1
[2011/12/01 12:11:19 | 000,000,403 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\Shortcut to My Web Sites (ELD backup).lnk
[2011/11/29 08:26:39 | 000,086,979 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\Enjoy it.jpg
[2011/11/28 11:16:12 | 000,136,526 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\one man show.png
[2011/11/27 08:14:57 | 000,066,312 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\success.jpg
[2011/11/19 16:56:50 | 000,660,760 | ---- | C] () -- C:\Documents and Settings\patty\Desktop\10.LongTail.pdf
[2011/09/19 18:16:22 | 000,000,459 | ---- | C] () -- C:\WINDOWS\Tcd_BF94FC15.ini
[2011/09/19 17:12:08 | 000,000,122 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2011/08/19 06:16:40 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2011/08/18 06:54:34 | 000,001,480 | R--- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfg
[2011/08/18 06:54:16 | 000,002,423 | R--- | C] () -- C:\WINDOWS\cmudax3.ini
[2011/06/26 11:53:45 | 000,180,624 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2011/05/23 10:04:51 | 000,313,207 | R--- | C] () -- C:\WINDOWS\System32\ctstatic.dat
[2011/05/23 10:04:51 | 000,053,932 | R--- | C] () -- C:\WINDOWS\System32\ctdaught.dat
[2011/02/09 22:03:48 | 000,000,314 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2011/01/14 10:11:49 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\BFADFBFFA6.dll
[2011/01/01 18:20:14 | 000,000,072 | ---- | C] () -- C:\WINDOWS\sbwin.ini
[2010/11/19 21:34:54 | 000,072,192 | ---- | C] () -- C:\WINDOWS\unlite3.exe
[2010/09/06 14:30:51 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/06 14:30:49 | 000,232,968 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/06 14:30:49 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/09/06 14:30:07 | 002,195,030 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2010/05/22 11:59:05 | 000,000,481 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2010/03/16 07:34:09 | 000,004,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2010/02/23 08:38:36 | 000,023,110 | ---- | C] () -- C:\WINDOWS\hpqins15.dat
[2010/02/23 08:34:18 | 000,077,349 | ---- | C] () -- C:\WINDOWS\hpqins05.dat
[2010/01/26 07:26:10 | 000,341,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/10 14:22:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\patty\Local Settings\Application Data\prvlcl.dat
[2009/09/07 21:22:29 | 000,116,840 | ---- | C] () -- C:\WINDOWS\hpqins00.dat
[2009/08/28 11:09:03 | 000,010,563 | R--- | C] () -- C:\WINDOWS\hpwscr19.dat
[2009/08/28 11:07:22 | 000,176,414 | ---- | C] () -- C:\WINDOWS\hpwins19.dat
[2009/08/28 11:07:21 | 000,000,997 | R--- | C] () -- C:\WINDOWS\hpwmdl19.dat
[2009/07/23 04:26:18 | 000,023,384 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2009/07/23 03:12:12 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\enlocstr.exe
[2009/06/03 23:55:20 | 000,002,560 | ---- | C] () -- C:\WINDOWS\System32\CtxfiRes.dll
[2009/06/03 23:55:20 | 000,002,560 | ---- | C] () -- C:\WINDOWS\CTXFIRES.DLL
[2009/01/15 20:08:58 | 000,061,440 | ---- | C] () -- C:\WINDOWS\wnUninstall.exe
[2008/07/05 08:32:39 | 000,035,190 | ---- | C] () -- C:\WINDOWS\scunin.dat
[2008/02/18 05:40:13 | 000,001,100 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2007/09/07 09:43:33 | 000,000,124 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/05/12 20:26:33 | 000,001,362 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/12 10:39:02 | 000,056,509 | ---- | C] () -- C:\WINDOWS\System32\ctdnlstr.dat
[2006/09/23 17:55:29 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2006/09/23 17:24:57 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2006/09/23 17:24:57 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2006/09/23 17:24:57 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2006/09/23 17:23:55 | 000,038,688 | ---- | C] () -- C:\WINDOWS\DIIUnin.dat
[2006/08/27 14:20:14 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\patty\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/08 12:51:13 | 000,038,114 | ---- | C] () -- C:\Documents and Settings\patty\Application Data\wklnhst.dat
[2006/04/08 12:22:06 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/04/08 12:22:01 | 000,107,134 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2006/04/08 12:21:54 | 000,006,540 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/04/08 09:21:53 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\patty\Local Settings\Application Data\fusioncache.dat
[2006/04/03 08:51:55 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/04/03 08:44:53 | 000,000,172 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/04/03 08:43:40 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/04/03 08:22:22 | 000,366,255 | ---- | C] () -- C:\WINDOWS\System32\ctdlang.dat
[2006/04/03 08:22:22 | 000,265,066 | ---- | C] () -- C:\WINDOWS\System32\CTSBAS2W.DAT
[2006/04/03 08:22:22 | 000,231,821 | ---- | C] () -- C:\WINDOWS\System32\CTSBASW.DAT
[2006/04/03 08:22:22 | 000,140,643 | ---- | C] () -- C:\WINDOWS\System32\CTBAS2W.DAT
[2006/04/03 08:22:22 | 000,113,221 | ---- | C] () -- C:\WINDOWS\System32\CTBASICW.DAT
[2006/04/03 08:22:22 | 000,050,432 | ---- | C] () -- C:\WINDOWS\System32\claptn.ini
[2006/04/03 08:22:22 | 000,038,400 | ---- | C] () -- C:\WINDOWS\System32\CTBURST.DLL
[2006/04/03 08:22:22 | 000,034,304 | ---- | C] () -- C:\WINDOWS\PSCONV.EXE
[2006/04/03 08:22:22 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\regplib.exe
[2006/04/03 08:22:22 | 000,000,321 | ---- | C] () -- C:\WINDOWS\System32\kill.ini
[2006/04/03 08:22:22 | 000,000,054 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2006/04/03 08:21:54 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2006/04/03 08:21:38 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/04/03 08:21:18 | 000,000,384 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/16 03:48:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/08/16 03:38:45 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 03:33:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:18:35 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/08/16 03:18:33 | 000,549,276 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/08/16 03:18:33 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2005/08/16 03:18:33 | 000,100,554 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/08/16 03:18:33 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2005/08/16 03:18:32 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2005/08/16 03:18:30 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/08/16 03:18:28 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2005/08/16 03:18:23 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2005/08/16 03:18:23 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2005/08/16 03:18:15 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2005/08/16 03:18:08 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2002/11/19 14:46:20 | 000,039,104 | ---- | C] () -- C:\WINDOWS\cmijack.dat
[2002/11/19 14:43:38 | 000,022,178 | ---- | C] () -- C:\WINDOWS\cmaudio.dat
========== LOP Check ==========
[2009/01/15 20:13:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\4 Warn Alert
[2011/12/02 09:09:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/05/12 19:02:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2009/11/11 18:17:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/08/09 11:05:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2009/11/30 12:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RootsMagic
[2011/12/13 18:57:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/02/08 12:45:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Generations Network
[2011/05/28 18:57:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\W3i
[2009/02/27 07:32:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2010/06/03 20:47:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{B7A015B7-4802-4678-8CEC-700380BA9AFD}
[2010/09/16 13:24:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\.anki
[2008/04/01 07:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\aignes
[2010/06/21 17:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/20 06:20:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\DeviceDoctorSoftware
[2010/02/08 12:46:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\EAST Technologies
[2010/03/30 10:34:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\Facebook
[2008/03/28 19:33:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\ICQ
[2008/04/15 12:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\ICQ Toolbar
[2009/01/19 10:42:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\Jasc
[2008/09/23 08:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\KeyingTool
[2009/02/23 10:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\Leadertech
[2006/12/20 10:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\MSNInstaller
[2010/09/06 16:01:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\My Games
[2008/12/24 21:58:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\OpenOffice.org
[2011/09/14 11:52:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\PrimoPDF
[2009/11/30 13:01:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\RootsMagic
[2010/05/27 10:45:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\Sammsoft
[2010/08/04 21:25:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\SecondLife
[2006/10/13 09:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\SmartDraw
[2008/09/21 18:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\SPORE
[2008/09/14 09:11:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\SPORE Creature Creator
[2006/06/27 11:26:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\Template
[2010/06/21 07:27:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\Uniblue
[2010/03/04 11:20:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\WeatherBug
[2011/08/09 11:05:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\patty\Application Data\WinPatrol
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\patty\My Documents\rabbitry.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\patty\My Documents\jdk-6u19-windows-i586.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\patty\Desktop\7z912 (unzipper).exe:SummaryInformation
@Alternate Data Stream - 199 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B1FBBD09
< End of report >
Thanks in advance, you guys have always been awesome
Edited by Pat Williams, 17 December 2011 - 03:25 PM.