He directed me to come here and follow the directions given. I downloaded OTL and did the scan described in step 2. I am now at step three with this post. OTL generated 2 docs in Notepad which I have saved and those will follow this post.
What prompted this journey was the fact that my manager had completely filled his HD. I've taken it upon myself to get things back up and running. I started here: http://www.geekstogo...pair-in-xp-pro/ This was after the defrag steps taken in the thread mentioned at the top of this post - (end date 01/08/12).
This got me to a place where XP is running well with most of the original issues resolved. I started the first mentioned thread (top of post) as I could not defrag the HD in a manner I was used to seeing. It is still highly fragmented. I then went to the second step - thread mentioned in above paragraph - as I figured I needed to try a repair of XP or perhaps a clean install. Ztruker took me through the process and resolved many issues.
I was contacted again by you folks to see if my "OS size" question thread had been resolved. I started in on that. The Mod took me through some steps which resulted in the discovery of Zango. This presented a "red flag" for him and now I'm here.
A note: the scans show a "networked" drive - "U" drive. I believe this to be the exact same drive as the C drive. I draw that conclusion due to the identical nature of the "stats" for the drive. I do not know that a "physical" U drive exists at this point. This PC was originally on an in office network which is no longer the case. It is being used as a stand alone PC - or at least it is intended to be stand alone. Originally there were 3 PCs networked. That network does not formally exist to my knowledge as 2 of the PCs are no longer working nor connected in any manner. We do have a "production" PC that was not connected to the network to my knowledge. I use this PC daily and am not able to interact with my manager's PC in any manner. It has it's own unique software and is only connected to our NexGen automation system.
Thank you in advance for any help you can offer. I really appreciate your time and efforts. OTL scan results follow.
OTL logfile created on: 1/25/2012 1:29:49 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = \\Kfff2k3\user\crohloff\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 507.32 Mb Available Physical Memory | 49.57% Memory free
2.41 Gb Paging File | 2.08 Gb Available in Paging File | 86.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.49 Gb Total Space | 11.25 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive E: | 74.49 Gb Total Space | 73.08 Gb Free Space | 98.11% Space Free | Partition Type: NTFS
Drive U: | 74.49 Gb Total Space | 11.25 Gb Free Space | 15.10% Space Free | Partition Type: *NT5CSC
Computer Name: RECEPT-WS | User Name: crohloff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/25 13:29:00 | 000,584,192 | ---- | M] (OldTimer Tools) -- \\Kfff2k3\user\crohloff\My Documents\Downloads\OTL.exe
PRC - [2012/01/05 03:48:46 | 001,047,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/01/17 17:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 17:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/22 04:25:21 | 000,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
PRC - [2006/11/03 19:20:12 | 000,866,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2004/11/15 04:20:20 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
========== Modules (No Company Name) ==========
MOD - [2012/01/05 03:48:44 | 000,411,120 | ---- | M] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppgooglenaclpluginchrome.dll
MOD - [2012/01/05 03:48:43 | 003,767,792 | ---- | M] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
MOD - [2012/01/05 03:47:19 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\avutil-51.dll
MOD - [2012/01/05 03:47:18 | 000,222,208 | ---- | M] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\avformat-53.dll
MOD - [2012/01/05 03:47:17 | 001,746,432 | ---- | M] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\avcodec-53.dll
MOD - [2012/01/05 01:06:01 | 008,593,056 | ---- | M] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
MOD - [2011/07/07 08:50:14 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2009/11/05 07:39:40 | 000,087,552 | ---- | M] () -- C:\WINDOWS\system32\cpwmon2k.dll
========== Win32 Services (SafeList) ==========
SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2010/09/27 14:50:44 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2010/05/31 11:31:10 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/04/13 12:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2004/11/17 05:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 22:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/07/16 00:19:52 | 000,070,400 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2001/08/17 12:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\crohloff\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Zango) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll File not found
O3 - HKLM\..\Toolbar: (Zango) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll File not found
O4 - HKLM..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24 File not found
O4 - HKLM..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe File not found
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" File not found
O4 - HKLM..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" File not found
O4 - HKLM..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" File not found
O4 - HKLM..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime File not found
O4 - HKLM..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.431.0\OEAddOn.exe File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = File not found
O4 - Startup: C:\Documents and Settings\crohloff\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 1 = net use Q: /delete (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 2 = net use Q: \\kfff2k3\Accounting (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL File not found
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.c...loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} http://www.gis.co.po...s/ACGM/Acgm.cab (ActiveCGM Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.70.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = KFFF.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A0B208A5-E87B-4FC9-B458-4ABAB8A60DCE}: DhcpNameServer = 192.168.70.1
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL File not found
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\crohloff\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\crohloff\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/27 15:54:20 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{f0801829-32e0-11e0-a3bd-000fea28c351}\Shell - "" = AutoRun
O33 - MountPoints2\{f0801829-32e0-11e0-a3bd-000fea28c351}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f0801829-32e0-11e0-a3bd-000fea28c351}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2099/01/01 12:00:00 | 000,000,000 | R--D | C] -- \\Kfff2k3\user\crohloff\My Documents\My Videos
[2099/01/01 12:00:00 | 000,000,000 | R--D | C] -- \\Kfff2k3\user\crohloff\My Documents\My Pictures
[2099/01/01 12:00:00 | 000,000,000 | R--D | C] -- \\Kfff2k3\user\crohloff\My Documents\My Music
[2099/01/01 12:00:00 | 000,000,000 | -HSD | C] -- \\Kfff2k3\user\crohloff\My Documents\RECYCLER
[2099/01/01 12:00:00 | 000,000,000 | ---D | C] -- \\Kfff2k3\user\crohloff\My Documents\Downloads
[2012/01/25 13:26:34 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\crohloff\Desktop\OTL.exe
[2012/01/25 03:00:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/01/24 16:44:17 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012/01/18 10:09:26 | 000,000,000 | ---D | C] -- C:\Temp
[2012/01/16 12:57:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2012/01/16 12:56:59 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee Security Scan
[2012/01/16 12:56:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2012/01/16 12:55:18 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012/01/16 12:54:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012/01/16 11:48:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012/01/14 03:14:18 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2012/01/14 03:13:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012/01/14 03:13:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2012/01/14 03:13:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/01/13 13:09:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2012/01/13 13:02:02 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2012/01/10 11:27:56 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2012/01/10 11:27:56 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2012/01/10 11:26:13 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2012/01/10 11:14:20 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2012/01/10 11:13:38 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2012/01/10 10:36:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2012/01/10 04:15:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2012/01/09 16:44:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/01/09 16:36:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\crohloff\Application Data\Auslogics
[2012/01/09 16:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2012/01/09 16:36:06 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2012/01/05 17:03:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\crohloff\Start Menu\Programs\Google Chrome
[2012/01/05 15:21:08 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/01/02 08:59:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2012/01/02 08:59:57 | 000,000,000 | ---D | C] -- C:\Program Files\ORKTOOLS
[2011/12/29 17:06:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\crohloff\Local Settings\Application Data\WMTools Downloaded Files
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 \\Kfff2k3\user\crohloff\My Documents\*.tmp files -> \\Kfff2k3\user\crohloff\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/25 13:32:02 | 000,000,392 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D67791F9-59A1-4712-8289-0376237523BE}.job
[2012/01/25 13:26:31 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\crohloff\Desktop\OTL.exe
[2012/01/25 13:26:00 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/25 13:05:00 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-308248587-1703384483-2866846594-1152UA.job
[2012/01/25 03:02:25 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/25 01:46:04 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/01/24 17:05:00 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-308248587-1703384483-2866846594-1152Core.job
[2012/01/24 16:52:30 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\crohloff\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/24 16:52:28 | 000,013,868 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/24 16:52:27 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/24 16:51:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/24 16:51:38 | 1073,270,784 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/20 14:28:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/18 12:10:53 | 000,863,665 | ---- | M] () -- C:\Documents and Settings\crohloff\Desktop\InsuranceInGoodHandsWithRadio.pdf
[2012/01/18 12:07:36 | 000,805,845 | ---- | M] () -- C:\Documents and Settings\crohloff\Desktop\IMAG0600.jpg
[2012/01/17 03:46:12 | 000,446,042 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/17 03:46:12 | 000,073,248 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/17 03:41:45 | 000,251,088 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/16 12:56:02 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/16 11:48:43 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012/01/16 11:31:51 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/01/14 08:24:57 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/01/14 08:24:57 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/01/13 13:12:45 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2012/01/13 13:06:50 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2012/01/10 11:44:16 | 000,013,846 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2012/01/10 11:29:21 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/01/10 11:24:29 | 000,025,065 | ---- | M] () -- C:\WINDOWS\System32\wmpscheme.xml
[2012/01/10 11:24:24 | 000,299,552 | ---- | M] () -- C:\WINDOWS\WMSysPrx.prx
[2012/01/10 11:20:40 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2012/01/10 11:14:18 | 000,023,348 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/01/10 11:13:53 | 000,000,535 | ---- | M] () -- C:\WINDOWS\System32\mapisvc.inf
[2012/01/06 23:06:21 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\crohloff\Desktop\Google Chrome.lnk
[2012/01/06 23:06:21 | 000,002,287 | ---- | M] () -- C:\Documents and Settings\crohloff\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 17:13:01 | 000,000,169 | ---- | M] () -- C:\WINDOWS\RtlRack.ini
[2011/12/29 17:02:09 | 000,000,011 | ---- | M] () -- C:\WINDOWS\P_ACS6
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 \\Kfff2k3\user\crohloff\My Documents\*.tmp files -> \\Kfff2k3\user\crohloff\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 010,352,516 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\SYATP 10 - RADIO EDITS (MP3s).zip
[2099/01/01 12:00:00 | 009,574,988 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\sarahyoung-jesuscalling.zip
[2099/01/01 12:00:00 | 009,159,224 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Wordsower International-Jason Nightingale draft.mp3
[2099/01/01 12:00:00 | 003,674,952 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\USBankLobbyCeiling#1.JPG
[2099/01/01 12:00:00 | 003,376,954 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\USBankLobbyCeiling#2(floor).JPG
[2099/01/01 12:00:00 | 003,036,390 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\WTRU_LB_Liners_2.mp3
[2099/01/01 12:00:00 | 002,613,207 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\WTRU_LB_ID.mp3
[2099/01/01 12:00:00 | 002,565,141 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\WTRU_PB_ID.mp3
[2099/01/01 12:00:00 | 001,658,225 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Print Ads_Full Page.jpg
[2099/01/01 12:00:00 | 001,465,602 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\qrtpageAdWOF.pdf
[2099/01/01 12:00:00 | 000,668,202 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Stu Promo for 2011.wav
[2099/01/01 12:00:00 | 000,572,872 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Salemtalkclock.pdf
[2099/01/01 12:00:00 | 000,408,627 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\sunrise_aspen_colorado.jpg
[2099/01/01 12:00:00 | 000,279,894 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Rohloff Photo.bmp
[2099/01/01 12:00:00 | 000,259,720 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\StationManager-NeedDocumentation.pdf
[2099/01/01 12:00:00 | 000,233,060 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Rohloff Flight to NRB and Back.MDI
[2099/01/01 12:00:00 | 000,162,672 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Rohloff Flight plan to NRB.pdf
[2099/01/01 12:00:00 | 000,122,461 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Putting_Off_Procrastination.pdf
[2099/01/01 12:00:00 | 000,094,908 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\ProLifeTownhallFlyerOctober2010.pdf
[2099/01/01 12:00:00 | 000,052,610 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Program Guide inside Oct 2010.pdf
[2099/01/01 12:00:00 | 000,038,570 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\The Goal of God's Love -John Piper.pdf
[2099/01/01 12:00:00 | 000,036,339 | ---- | C] () -- \\Kfff2k3\user\crohloff\My Documents\Rohloff Business Card.JPG
[2012/01/18 12:10:50 | 000,863,665 | ---- | C] () -- C:\Documents and Settings\crohloff\Desktop\InsuranceInGoodHandsWithRadio.pdf
[2012/01/18 12:03:10 | 000,805,845 | ---- | C] () -- C:\Documents and Settings\crohloff\Desktop\IMAG0600.jpg
[2012/01/16 12:56:02 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/16 12:56:02 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/10 11:44:16 | 000,013,846 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2012/01/10 11:27:45 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2012/01/10 11:27:09 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2012/01/10 11:26:57 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2012/01/10 11:26:56 | 000,196,665 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2012/01/10 11:26:53 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2012/01/10 11:26:44 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2012/01/10 11:26:38 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2012/01/10 11:26:16 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2012/01/10 11:24:27 | 000,025,065 | ---- | C] () -- C:\WINDOWS\System32\wmpscheme.xml
[2012/01/10 11:24:24 | 000,299,552 | ---- | C] () -- C:\WINDOWS\WMSysPrx.prx
[2012/01/10 11:13:56 | 000,001,844 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN Explorer.lnk
[2012/01/10 11:13:56 | 000,000,769 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/01/10 10:24:16 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2012/01/10 10:24:16 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012/01/10 10:24:16 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012/01/10 10:24:16 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012/01/10 10:24:15 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012/01/10 10:24:15 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012/01/05 17:03:19 | 000,002,309 | ---- | C] () -- C:\Documents and Settings\crohloff\Desktop\Google Chrome.lnk
[2012/01/05 17:00:42 | 000,000,990 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-308248587-1703384483-2866846594-1152UA.job
[2012/01/05 17:00:42 | 000,000,938 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-308248587-1703384483-2866846594-1152Core.job
[2012/01/05 15:22:52 | 000,002,287 | ---- | C] () -- C:\Documents and Settings\crohloff\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/05 15:21:15 | 000,000,890 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/05 15:21:14 | 000,000,886 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/03 09:33:20 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\crohloff\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/02 13:15:39 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2008/09/11 08:38:31 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2008/03/04 15:05:32 | 000,000,765 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2007/07/18 14:31:26 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2007/07/18 14:29:53 | 000,000,058 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/06/01 09:19:00 | 000,001,778 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/05/11 09:19:43 | 000,000,037 | ---- | C] () -- C:\WINDOWS\ipixActivex.ini
[2006/04/07 10:39:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2006/02/09 13:29:56 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\ZSHP1020.EXE
[2006/02/09 13:29:54 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\VSHP1020.DLL
[2005/11/23 10:26:21 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2005/10/06 13:35:10 | 000,000,172 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2005/09/29 07:11:02 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/09/28 08:14:36 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2005/09/28 07:12:59 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2005/09/28 07:12:55 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2005/09/28 07:12:55 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2005/09/27 15:56:43 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/09/27 15:51:20 | 000,023,348 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/09/26 23:32:16 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/09/26 23:31:03 | 000,251,088 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/04 06:00:00 | 000,446,042 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 06:00:00 | 000,073,248 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 06:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 06:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/06/02 20:31:38 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2003/06/02 20:30:20 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.exe
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 06:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 06:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 06:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 06:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 06:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 06:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 06:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 06:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001/08/10 17:37:54 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
========== LOP Check ==========
[2009/12/11 14:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2009/12/15 10:30:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nexon
[2009/08/13 10:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS
[2005/12/15 12:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2009/01/08 10:51:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SeekmoSA
[2012/01/25 08:55:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2007/07/18 14:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/01/22 16:29:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/11/22 15:18:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\crohloff\Application Data\Amazon
[2012/01/09 17:12:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\crohloff\Application Data\Auslogics
[2011/11/22 15:54:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\crohloff\Application Data\Dropbox
[2011/09/28 14:03:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\crohloff\Application Data\FileZilla
[2011/11/22 13:48:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\crohloff\Application Data\MSNInstaller
[2011/07/07 09:27:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\crohloff\Application Data\OpenOffice.org
[2012/01/25 01:46:04 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/01/25 13:32:02 | 000,000,392 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{D67791F9-59A1-4712-8289-0376237523BE}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BF512B
< End of report >
OTL Extras logfile created on: 1/25/2012 1:29:49 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = \\Kfff2k3\user\crohloff\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 507.32 Mb Available Physical Memory | 49.57% Memory free
2.41 Gb Paging File | 2.08 Gb Available in Paging File | 86.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.49 Gb Total Space | 11.25 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive E: | 74.49 Gb Total Space | 73.08 Gb Free Space | 98.11% Space Free | Partition Type: NTFS
Drive U: | 74.49 Gb Total Space | 11.25 Gb Free Space | 15.10% Space Free | Partition Type: *NT5CSC
Computer Name: RECEPT-WS | User Name: crohloff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1"
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1"
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1"
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"Enabled" = 1
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"Enabled" = 1
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"135:TCP:*:Enabled:Offer Remote Assistance - Port" = 135:TCP:*:Enabled:Offer Remote Assistance - Port
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = LocalSubnet
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = *
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\crohloff\Local Settings\Temp\7zS4.tmp\SymNRT.exe" = C:\Documents and Settings\crohloff\Local Settings\Temp\7zS4.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool
"C:\Documents and Settings\crohloff\Local Settings\Temp\7zS1C.tmp\SymNRT.exe" = C:\Documents and Settings\crohloff\Local Settings\Temp\7zS1C.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1D5355BA-562B-4C29-83C0-1D0ED41B2D87}" = TinyZIP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23E5032B-56CA-4C19-A72E-B50161DB82CA}" = Shadow Copy Client
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java 6 Update 29
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}" = Google Earth
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{90240409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Resource Kit
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}" = WinZip 14.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Display Driver" = ATI Display Driver
"Backyard Football" = Backyard Football
"CutePDF Writer Installation" = CutePDF Writer 2.8
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Telos ProFiler Client" = Telos ProFiler Client
"ViewpointMediaPlayer" = Viewpoint Media Player
"WGA" = Windows Genuine Advantage Validation Tool
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/24/2012 6:56:51 PM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/25/2012 2:51:54 AM | Computer Name = RECEPT-WS | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 1/25/2012 10:21:41 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1002
Description = Hanging application helpctr.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/25/2012 10:21:44 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1001
Description = Fault bucket 724433971.
Error - 1/25/2012 10:51:54 AM | Computer Name = RECEPT-WS | Source = AutoEnrollment | ID = 15
Description = Automatic certificate enrollment for local system failed to contact
the active directory (0x8007054b). The specified domain either does not exist
or could not be contacted. Enrollment will not be performed.
Error - 1/25/2012 10:56:22 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/25/2012 10:56:23 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/25/2012 10:56:24 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/25/2012 10:56:26 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.
Error - 1/25/2012 10:56:33 AM | Computer Name = RECEPT-WS | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.
[ System Events ]
Error - 1/24/2012 7:36:57 PM | Computer Name = RECEPT-WS | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 60 minutes. NtpClient has no source of accurate
time.
Error - 1/24/2012 8:36:57 PM | Computer Name = RECEPT-WS | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 120 minutes. NtpClient has no source of accurate
time.
Error - 1/24/2012 10:36:58 PM | Computer Name = RECEPT-WS | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 240 minutes. NtpClient has no source of accurate
time.
Error - 1/24/2012 10:51:59 PM | Computer Name = RECEPT-WS | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain KFFF due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 1/25/2012 2:36:58 AM | Computer Name = RECEPT-WS | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 480 minutes. NtpClient has no source of accurate
time.
Error - 1/25/2012 2:57:00 AM | Computer Name = RECEPT-WS | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain KFFF due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 1/25/2012 6:57:03 AM | Computer Name = RECEPT-WS | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain KFFF due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 1/25/2012 10:36:59 AM | Computer Name = RECEPT-WS | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 960 minutes. NtpClient has no source of accurate
time.
Error - 1/25/2012 11:02:02 AM | Computer Name = RECEPT-WS | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain KFFF due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
Error - 1/25/2012 3:06:56 PM | Computer Name = RECEPT-WS | Source = NETLOGON | ID = 5719
Description = No Domain Controller is available for domain KFFF due to the following:
%%1311. Make sure that the computer is connected to the network and try again. If
the problem persists, please contact your domain administrator.
< End of report >