Thanks Again
OTL LOG
OTL logfile created on: 8/11/2012 6:50:31 PM - Run 3
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Documents and Settings\Andrew Conkling\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.24 Gb Total Physical Memory | 0.54 Gb Available Physical Memory | 43.17% Memory free
2.34 Gb Paging File | 1.31 Gb Available in Paging File | 55.96% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 25.05 Gb Total Space | 2.31 Gb Free Space | 9.22% Space Free | Partition Type: NTFS
Drive D: | 3.34 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: NOTEBOOK | User Name: Andrew Conkling | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/11 18:48:47 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Andrew Conkling\Desktop\OTL.exe
PRC - [2012/08/07 01:43:41 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/05/04 19:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
PRC - [2011/08/02 13:21:52 | 001,506,536 | ---- | M] (Defender Pro) -- C:\Program Files\Defender Pro\Defender Pro\vsserv.exe
PRC - [2011/08/02 13:21:48 | 000,050,128 | ---- | M] (Defender Pro) -- C:\Program Files\Defender Pro\Defender Pro\updatesrv.exe
PRC - [2011/08/02 13:21:06 | 000,066,608 | ---- | M] (Defender Pro) -- C:\Program Files\Defender Pro\Defender Pro Safebox\safeboxservice.exe
PRC - [2011/08/02 13:21:04 | 000,065,560 | ---- | M] (Defender Pro) -- C:\Program Files\Defender Pro\Defender Pro\pchooklaunch32.exe
PRC - [2011/08/02 13:19:56 | 001,053,336 | ---- | M] (Defender Pro) -- C:\Program Files\Defender Pro\Defender Pro\bdagent.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/11/10 12:54:48 | 000,598,016 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2004/09/15 02:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2004/05/13 11:23:56 | 000,098,304 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
========== Modules (No Company Name) ==========
MOD - [2012/08/07 01:43:40 | 000,442,392 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\ppgooglenaclpluginchrome.dll
MOD - [2012/08/07 01:43:39 | 012,235,800 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
MOD - [2012/08/07 01:43:37 | 003,997,720 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\pdf.dll
MOD - [2012/08/07 01:42:09 | 000,144,424 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\avutil-51.dll
MOD - [2012/08/07 01:42:08 | 000,266,792 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\avformat-54.dll
MOD - [2012/08/07 01:42:07 | 002,480,680 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\avcodec-54.dll
MOD - [2012/07/08 00:35:45 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\494e536022ee1a0d2fe124c3d2500f74\System.Xml.ni.dll
MOD - [2012/07/08 00:22:52 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\2448ec34d1e318a77a0d32704961c646\System.ni.dll
MOD - [2012/07/08 00:21:39 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012/07/07 18:17:42 | 000,139,480 | ---- | M] () -- \\?\C:\Program Files\Defender Pro\Defender Pro\bdnc.dll
MOD - [2011/08/02 12:47:52 | 000,186,880 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\UI\popup.ui
MOD - [2011/08/02 12:47:50 | 000,009,216 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\UI\imsecurityal.ui
MOD - [2011/08/02 12:47:48 | 000,007,680 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\UI\accessl.ui
MOD - [2011/07/22 20:20:05 | 000,337,992 | ---- | M] () -- \\?\C:\Program Files\Common Files\Defender Pro\Defender Pro Threat Scanner\trufos.dll
MOD - [2011/07/22 17:53:36 | 000,126,360 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\popup.dll
MOD - [2011/07/22 17:51:24 | 000,060,416 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\excludemgr.dll
MOD - [2011/07/22 17:51:22 | 000,109,856 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\accessl.dll
MOD - [2011/07/22 14:00:30 | 000,239,136 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\avc3al.dll
MOD - [2011/07/22 12:53:14 | 000,035,208 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\procinfo.dll
MOD - [2011/07/22 12:39:24 | 000,109,856 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\connector.dll
MOD - [2011/07/22 12:38:50 | 000,151,592 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\framework.dll
MOD - [2011/07/22 12:37:56 | 000,202,032 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\txmlutil.dll
MOD - [2011/07/22 12:37:48 | 000,059,392 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\bdmltusrsrv.dll
MOD - [2011/07/22 12:37:44 | 000,035,720 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\strdecoder.dll
MOD - [2011/07/22 12:22:34 | 002,035,712 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\ashttpf.mdl
MOD - [2011/07/22 12:22:34 | 001,975,296 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\ashttpph.mdl
MOD - [2011/07/22 12:22:34 | 001,903,104 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\ashttpfr.mdl
MOD - [2011/07/22 12:22:34 | 001,850,368 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\asimf.mdl
MOD - [2011/07/22 12:22:34 | 001,090,048 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\ashttprbl.mdl
MOD - [2011/07/22 12:22:34 | 000,855,040 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\ashttpdsp.mdl
MOD - [2011/07/22 12:22:34 | 000,793,600 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\asimdsp.mdl
MOD - [2011/07/22 12:22:34 | 000,770,560 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\ashttpbr.mdl
MOD - [2011/07/22 12:22:34 | 000,739,840 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\as2core\asimbr.mdl
MOD - [2011/07/13 13:10:30 | 000,130,456 | ---- | M] () -- C:\Program Files\Common Files\Defender Pro\Defender Pro Threat Scanner\bdsmartdb.dll
MOD - [2011/05/19 19:34:22 | 000,056,224 | ---- | M] () -- \\?\C:\Program Files\Common Files\Defender Pro\Defender Pro Threat Scanner\Antivirus_09840_170\avxdisk.dll
MOD - [2011/05/04 21:45:12 | 001,235,152 | ---- | M] () -- \\?\C:\Program Files\Defender Pro\Defender Pro\wslib.dll
MOD - [2011/03/01 17:46:16 | 000,132,176 | ---- | M] () -- C:\Program Files\Defender Pro\Defender Pro\bdfwcore.dll
MOD - [2008/04/13 19:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 19:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2004/11/10 12:54:48 | 000,598,016 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
MOD - [2004/09/15 02:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
MOD - [2003/06/17 11:50:08 | 000,073,728 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/05/04 19:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011/08/02 13:21:52 | 001,506,536 | ---- | M] (Defender Pro) [Auto | Running] -- C:\Program Files\Defender Pro\Defender Pro\vsserv.exe -- (VSSERV)
SRV - [2011/08/02 13:21:48 | 000,050,128 | ---- | M] (Defender Pro) [Auto | Running] -- C:\Program Files\Defender Pro\Defender Pro\updatesrv.exe -- (UPDATESRV)
SRV - [2011/08/02 13:21:06 | 000,066,608 | ---- | M] (Defender Pro) [Auto | Running] -- C:\Program Files\Defender Pro\Defender Pro Safebox\safeboxservice.exe -- (SafeBox)
SRV - [2011/08/02 13:19:54 | 000,307,544 | ---- | M] (Defender Pro) [On_Demand | Stopped] -- C:\Program Files\Common Files\Defender Pro\Defender Pro Arrakis Server\bin\arrakis3.exe -- (Update Server)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\wanatw4.sys -- (wanatw)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SBREdrv.sys -- (SBRE)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\SPCA561.SYS -- (CA561)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (bvrp_pci)
DRV - [2011/07/22 20:20:05 | 000,311,248 | ---- | M] (BitDefender S.R.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\trufos.sys -- (trufos)
DRV - [2011/07/19 16:20:36 | 000,127,056 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Program Files\Defender Pro\Defender Pro\bdselfpr.sys -- (bdselfpr)
DRV - [2011/07/15 16:11:48 | 000,451,864 | ---- | M] (BitDefender) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avckf.sys -- (avckf)
DRV - [2011/07/15 16:11:46 | 000,596,600 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avc3.sys -- (avc3)
DRV - [2011/07/15 16:11:46 | 000,240,184 | ---- | M] (BitDefender) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avchv.sys -- (avchv)
DRV - [2011/06/17 19:54:44 | 000,063,568 | ---- | M] (Windows ® Win 7 DDK provider) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bdsandbox.sys -- (bdsandbox)
DRV - [2011/03/24 15:36:18 | 000,353,096 | ---- | M] (BitDefender) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bdfsfltr.sys -- (bdfsfltr)
DRV - [2011/03/01 17:45:34 | 000,113,232 | ---- | M] (BitDefender LLC) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Defender Pro\Defender Pro Firewall\bdfndisf.sys -- (Bdfndisf)
DRV - [2011/03/01 17:45:32 | 000,130,640 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Program Files\Common Files\Defender Pro\Defender Pro Firewall\bdftdif.sys -- (bdftdif)
DRV - [2010/02/11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2010/01/19 19:32:40 | 000,085,128 | ---- | M] (BitDefender) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\bdvedisk.sys -- (BDVEDISK)
DRV - [2005/03/10 15:56:06 | 000,273,168 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
DRV - [2004/12/11 21:28:20 | 000,371,584 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcmwl5.sys -- (BCM43XX)
DRV - [2004/08/18 15:53:54 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\APPDRV.SYS -- (APPDRV)
DRV - [2004/06/17 21:57:02 | 000,200,064 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/06/17 21:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/17 21:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2004/02/13 17:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {4561B2A9-163D-4076-981E-5E1B4CC84EC6}
IE - HKCU\..\SearchScopes\{4561B2A9-163D-4076-981E-5E1B4CC84EC6}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {4DC70064-89E2-4a55-8FC6-E8CDEAE3612C}:0.6.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.3.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Andrew Conkling\Application Data\Facebook\npfbplugin_1_0_1.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\Defender Pro\Defender Pro\bdtbext\ [2012/07/07 17:10:31 | 000,000,000 | ---D | M]
[2010/06/07 11:06:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Andrew Conkling\Application Data\Mozilla\Extensions
[2010/06/07 11:06:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Andrew Conkling\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/03 18:35:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Andrew Conkling\Application Data\Mozilla\Firefox\Profiles\x6qo5si3.default\extensions
[2011/12/02 18:03:28 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Documents and Settings\Andrew Conkling\Application Data\Mozilla\Firefox\Profiles\x6qo5si3.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2012/07/03 18:35:27 | 000,743,290 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\ANDREW CONKLING\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X6QO5SI3.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/27 08:57:13 | 000,021,360 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\ANDREW CONKLING\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\X6QO5SI3.DEFAULT\EXTENSIONS\[email protected]
========== Chrome ==========
CHR - homepage: http://www.yahoo.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.yahoo.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Word Search Puzzle = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\alcobafdkcddhiabfgnongafffchimnl\1.2_0\
CHR - Extension: YouTube = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Apple Shooter = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ingecjekeggadjbbklelffkgeppklgnm\4.0.0_0\
CHR - Extension: Earth = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jieopfhnlbjmbpckpdhfdedccdmngdac\1.5_0\
CHR - Extension: Gmail = C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2010/03/31 08:33:26 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BDAgent] C:\Program Files\Defender Pro\Defender Pro\bdagent.exe (Defender Pro)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe File not found
O4 - HKLM..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://oas.support....veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1249795892625 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B02CE3E5-0662-4868-9015-75384E835392}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/11 18:48:51 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Andrew Conkling\Desktop\OTL.exe
[2012/08/06 18:44:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrew Conkling\Desktop\Slave Leia
[2012/07/31 19:35:24 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Andrew Conkling\Recent
[2012/07/23 10:32:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrew Conkling\Desktop\Resume Information
[2012/07/16 07:37:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\bluebrick.lswproject.com
[2012/07/15 07:07:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andrew Conkling\My Documents\Downloads
[1 C:\Documents and Settings\LocalService\Local Settings\Application Data\*.tmp files -> C:\Documents and Settings\LocalService\Local Settings\Application Data\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/11 19:02:06 | 000,000,904 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/11 19:00:39 | 000,000,305 | ---- | M] () -- C:\WINDOWS\System32\checkdnsid.xml
[2012/08/11 18:57:11 | 000,001,018 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-27987841-921125120-4191668413-1006UA.job
[2012/08/11 18:48:47 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Andrew Conkling\Desktop\OTL.exe
[2012/08/11 17:42:40 | 000,000,442 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9428CBF6-0627-40EE-826A-E289221FE899}.job
[2012/08/11 14:57:02 | 000,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-27987841-921125120-4191668413-1006Core.job
[2012/08/11 12:02:14 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/08 17:13:46 | 000,002,358 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Desktop\Google Chrome.lnk
[2012/08/08 17:13:46 | 000,002,336 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/06 18:31:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/08/01 10:20:26 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2012/08/01 09:35:44 | 000,003,120 | ---- | M] () -- C:\WINDOWS\FDK47J7J.ocx
[2012/08/01 09:35:43 | 000,003,120 | ---- | M] () -- C:\WINDOWS\System32\FEHXUQ9Q.ocx
[2012/07/30 19:44:38 | 000,346,015 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Desktop\012.jpg
[2012/07/29 07:03:24 | 000,269,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/28 15:33:46 | 000,117,367 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Desktop\KateUptonruffles.jpg
[2012/07/25 00:05:31 | 000,572,756 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Desktop\KateUptonhandbra.jpg
[2012/07/25 00:04:27 | 000,367,596 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Desktop\KateUptonbowtie.jpg
[2012/07/22 06:35:27 | 000,000,385 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Application Datauser_gensett.xml
[2012/07/21 10:06:58 | 000,000,376 | ---- | M] () -- C:\Documents and Settings\Andrew Conkling\Application Dataprivacy.xml
========== Files Created - No Company Name ==========
[2012/08/11 04:32:33 | 000,053,671 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Desktop\Bathroom before.jpg
[2012/08/01 09:35:44 | 000,003,120 | ---- | C] () -- C:\WINDOWS\FDK47J7J.ocx
[2012/08/01 09:35:43 | 000,003,120 | ---- | C] () -- C:\WINDOWS\System32\FEHXUQ9Q.ocx
[2012/07/30 19:44:41 | 000,346,015 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Desktop\012.jpg
[2012/07/25 00:05:43 | 000,572,756 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Desktop\KateUptonhandbra.jpg
[2012/07/25 00:05:22 | 000,117,367 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Desktop\KateUptonruffles.jpg
[2012/07/25 00:04:58 | 000,367,596 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Desktop\KateUptonbowtie.jpg
[2012/07/22 06:35:27 | 000,000,385 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Application Datauser_gensett.xml
[2012/07/21 10:06:58 | 000,000,376 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Application Dataprivacy.xml
[2012/07/18 11:22:36 | 000,000,305 | ---- | C] () -- C:\WINDOWS\System32\checkdnsid.xml
[2012/07/07 17:18:36 | 000,177,320 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\1341698476.bdinstall.bin
[2010/04/07 19:37:48 | 000,038,480 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Application Data\Comma Separated Values (Windows).ADR
[2009/12/11 17:06:42 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Application Data\PnkBstrK.sys
[2009/09/27 10:28:58 | 000,000,138 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\fusioncache.dat
[2009/03/16 09:05:20 | 000,010,240 | ---- | C] () -- C:\Documents and Settings\Andrew Conkling\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/03 17:10:40 | 010,747,904 | -H-- | C] () -- C:\Documents and Settings\Andrew Conkling\NTUSER.bak
[2009/03/03 17:10:40 | 004,718,592 | -H-- | C] () -- C:\Documents and Settings\Andrew Conkling\NTUSER.BK1
[2005/01/28 18:57:50 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
========== LOP Check ==========
[2012/07/07 17:17:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bitdefender
[2012/07/07 17:09:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Defender Pro
[2011/09/05 12:38:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\f-secure
[2010/04/13 15:45:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fssg
[2010/01/16 06:19:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2010/01/16 22:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/01/18 17:49:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2005/01/28 19:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/08/08 21:34:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\Avanquest
[2012/07/07 17:27:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\BitDefender
[2012/07/07 17:10:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\Defender Pro
[2010/06/29 18:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\ElevatedDiagnostics
[2010/04/15 15:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\f-secure
[2009/08/13 15:08:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\FoxPlayerAIR.01F2E49DE175CC541F416F2DF78BDD5E63AD0096.1
[2010/06/22 17:11:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\GARMIN
[2010/06/01 14:17:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\HorizonWimba
[2010/05/08 17:30:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\Image Zone Express
[2010/03/04 21:07:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\My Games
[2012/07/05 16:24:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\Oracle
[2012/07/07 17:06:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\QuickScan
[2010/06/07 11:06:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\Thunderbird
[2009/08/02 13:51:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andrew Conkling\Application Data\Windows Search
[2012/08/11 17:42:40 | 000,000,442 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{9428CBF6-0627-40EE-826A-E289221FE899}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >