*Noticed this program trying to access my system 2 days ago and then it crashed--> CLMP3enc.acm
--internet stated it was for DVDpowertogo program, but who knows.
Thank you in advance for your help
Ran OTL program in safe mode. Unable to run it normally, because it appeared to be stuck in a loop and would never generate a report.
Ran it for several hours 2 times and it never stopped running.
OTL logfile created on: 3/11/2013 5:17:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.43 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 69.03% Memory free
3.12 Gb Paging File | 2.81 Gb Available in Paging File | 90.17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 65.26 Gb Total Space | 19.65 Gb Free Space | 30.12% Space Free | Partition Type: NTFS
Drive D: | 9.27 Gb Total Space | 3.61 Gb Free Space | 38.98% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/10 21:47:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2009/04/10 23:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2013/03/07 18:42:07 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/02/26 14:39:37 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/18 07:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/04/06 13:01:06 | 004,326,472 | ---- | M] (Emsi Software GmbH) [Auto | Stopped] -- C:\Program Files\Online Armor\oasrv.exe -- (SvcOnlineArmor)
SRV - [2011/04/06 13:01:04 | 000,381,512 | ---- | M] (Emsi Software GmbH) [Auto | Stopped] -- C:\Program Files\Online Armor\oacat.exe -- (OAcat)
SRV - [2011/02/02 12:00:32 | 000,052,288 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper)
SRV - [2010/11/02 22:06:06 | 000,365,336 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe -- (AVP)
SRV - [2008/01/19 00:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/06/05 13:20:32 | 000,177,704 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2007/05/28 23:06:44 | 000,598,960 | ---- | M] ( ) [Auto | Stopped] -- C:\Windows\System32\lxdfcoms.exe -- (lxdf_device)
SRV - [2007/05/28 23:06:20 | 000,099,248 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdfserv.exe -- (lxdfCATSCustConnectService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2011/09/24 14:55:19 | 000,488,536 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2011/04/06 13:02:26 | 000,039,048 | ---- | M] () [Kernel | System | Stopped] -- C:\Windows\System32\drivers\oahlp32.sys -- (oahlpXX)
DRV - [2011/04/06 13:01:32 | 000,029,312 | ---- | M] (Emsisoft) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\OAnet.sys -- (OAnet)
DRV - [2011/04/06 13:01:30 | 000,205,864 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\System32\drivers\OADriver.sys -- (OADevice)
DRV - [2011/04/06 13:01:30 | 000,025,192 | ---- | M] (Emsisoft) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\OAmon.sys -- (OAmon)
DRV - [2010/06/09 16:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2010/06/09 16:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (KL1)
DRV - [2010/04/22 18:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2009/11/02 19:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2007/04/11 15:33:06 | 000,079,376 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007/04/11 15:32:58 | 000,036,112 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/04/11 15:32:52 | 000,034,832 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/04/11 15:32:38 | 000,063,248 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007/04/11 15:32:30 | 000,020,496 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/01/25 21:19:46 | 002,387,456 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/11/02 00:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/02 00:30:56 | 000,311,808 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL85n86.sys -- (RTL85n86)
DRV - [2006/10/06 15:59:06 | 000,044,224 | R--- | M] (BVRP Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledAddons: weatherwatcherlive%40singerscreations.com:1.0.17
FF - prefs.js..extensions.enabledAddons: %7B77b819fa-95ad-4f2c-ac7c-486b356188a9%7D:2.0.20120203
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7B241aae70-0022-11de-87af-0800200c9a66%7D:15.0.21.08.12
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[email protected] [2011/09/24 15:35:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[email protected] [2011/09/24 15:35:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/07 18:42:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/04/05 19:03:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2013/02/23 05:03:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions
[2012/08/22 13:47:37 | 000,000,000 | ---D | M] (Blue Fox) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions\{241aae70-0022-11de-87af-0800200c9a66}
[2012/10/24 10:29:38 | 000,000,000 | ---D | M] (Bloody Red) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions\{2458abc0-f443-11dd-87af-0800200c9a66}
[2012/04/11 22:45:01 | 000,000,000 | ---D | M] (IE Tab) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2013/02/23 05:03:24 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/04/23 13:12:12 | 002,203,212 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions\[email protected]
[2012/05/04 00:10:59 | 000,758,641 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\09g8tyeb.default\extensions\[email protected]
[2013/03/07 18:41:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/03/07 18:42:08 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/29 02:40:31 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/19 22:22:44 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2013/03/05 04:46:20 | 000,445,223 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 15317 more lines...
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O4 - HKLM..\Run: [@OnlineArmor GUI] C:\Program Files\Online Armor\oaui.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Lexmark 6500 Series Fax Server] C:\Program Files\Lexmark 6500 Series\fm3032.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Owner\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.186.46.5 208.186.47.5 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6FBD5B69-E619-4515-84DD-5ACB9E1CE4DC}: DhcpNameServer = 208.186.46.5 208.186.47.5 8.8.8.8
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img17.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img17.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - C:\Program Files\Online Armor\oaevent.dll (Emsi Software GmbH)
O28 - HKCU ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = ComFile] -- Reg Error: Key error. File not found
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/10 21:47:03 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2013/03/07 18:41:49 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/03/05 05:03:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013/02/09 19:27:07 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\TO print
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/11 05:14:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/03/11 04:56:18 | 000,003,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/11 04:56:18 | 000,003,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/11 04:38:08 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/11 04:20:25 | 000,604,502 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/03/11 04:20:25 | 000,104,170 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/03/11 04:08:12 | 000,001,446 | ---- | M] () -- C:\Users\Owner\Documents\errors.rtf
[2013/03/10 21:47:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2013/03/10 21:44:47 | 000,044,088 | ---- | M] () -- C:\Users\Owner\Documents\lights.rtf
[2013/03/10 05:06:46 | 000,005,177 | ---- | M] () -- C:\Users\Owner\Documents\marcusjobs.rtf
[2013/03/08 10:29:17 | 000,003,754 | ---- | M] () -- C:\Users\Owner\Documents\MH Resume.rtf
[2013/03/08 01:49:51 | 000,028,188 | ---- | M] () -- C:\Users\Owner\Documents\bladder.rtf
[2013/03/07 11:29:34 | 000,003,379 | ---- | M] () -- C:\Users\Owner\Documents\unemployment hearing.rtf
[2013/03/07 00:47:14 | 000,001,271 | ---- | M] () -- C:\Users\Owner\Documents\unemployment.rtf
[2013/03/06 14:36:09 | 000,003,374 | ---- | M] () -- C:\Users\Owner\Documents\marcus job questions.rtf
[2013/03/05 18:47:19 | 000,000,180 | ---- | M] () -- C:\Users\Owner\Documents\Library.rtf
[2013/03/05 18:33:43 | 000,001,803 | ---- | M] () -- C:\Users\Owner\Documents\Marcus work history dates.rtf
[2013/03/05 18:03:32 | 000,003,781 | ---- | M] () -- C:\Users\Owner\Documents\Marcus resume2.rtf
[2013/03/05 05:02:19 | 000,000,876 | ---- | M] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2013/03/05 04:46:20 | 000,445,223 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/03/05 01:08:05 | 000,004,740 | ---- | M] () -- C:\Users\Owner\Documents\Marcus Resume3.rtf
[2013/03/04 21:42:28 | 000,004,645 | ---- | M] () -- C:\Users\Owner\Documents\resumetmpF51F.rtf
[2013/03/04 08:44:17 | 000,004,202 | ---- | M] () -- C:\Users\Owner\Documents\domain.rtf
[2013/03/03 01:18:00 | 000,000,860 | ---- | M] () -- C:\Users\Owner\Documents\answers1.rtf
[2013/02/27 16:41:15 | 000,000,289 | ---- | M] () -- C:\Users\Owner\Documents\UNIDEN PHONE MANUAL.rtf
[2013/02/26 14:31:45 | 000,001,770 | ---- | M] () -- C:\Users\Owner\Documents\friends phone numbers.rtf
[2013/02/24 23:31:00 | 000,000,300 | ---- | M] () -- C:\Users\Owner\Documents\computerpics 2.rtf
[2013/02/23 19:21:26 | 000,001,976 | ---- | M] () -- C:\Users\Owner\Documents\DVD Recorder and RF modulator.rtf
[2013/02/22 17:24:56 | 000,005,540 | ---- | M] () -- C:\Users\Owner\Documents\Resume writing.rtf
[2013/02/22 17:19:48 | 000,000,596 | ---- | M] () -- C:\Users\Owner\Documents\Marcus Resume.rtf
[2013/02/21 14:28:29 | 000,028,535 | ---- | M] () -- C:\Users\Owner\Documents\recipes.rtf
[2013/02/21 05:55:58 | 000,023,852 | ---- | M] () -- C:\Users\Owner\Documents\menopause.rtf
[2013/02/17 18:13:57 | 000,050,952 | ---- | M] () -- C:\Users\Owner\Documents\quotes.rtf
[2013/02/16 01:34:01 | 000,008,857 | ---- | M] () -- C:\Users\Owner\Documents\BLADDER best information.rtf
[2013/02/14 04:42:25 | 000,288,760 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/14 01:41:27 | 000,001,172 | ---- | M] () -- C:\Users\Owner\Documents\jobsinfo.rtf
[2013/02/13 15:13:57 | 000,444,966 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20130305-034620.backup
[2013/02/13 04:34:12 | 000,004,709 | ---- | M] () -- C:\Users\Owner\Documents\marcus.rtf
[2013/02/13 01:22:45 | 000,001,305 | ---- | M] () -- C:\Users\Owner\Documents\job agency.rtf
[2013/02/13 01:00:45 | 000,000,278 | ---- | M] () -- C:\Users\Owner\Documents\cell phone plans cheap.rtf
[2013/02/11 09:44:17 | 000,022,468 | ---- | M] () -- C:\Users\Owner\Documents\WISH LIST.rtf
[2013/02/09 10:54:58 | 000,000,693 | ---- | M] () -- C:\Users\Owner\Documents\copyright disclaimer youtube.rtf
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/10 05:01:01 | 000,001,446 | ---- | C] () -- C:\Users\Owner\Documents\errors.rtf
[2013/03/07 04:45:50 | 000,003,379 | ---- | C] () -- C:\Users\Owner\Documents\unemployment hearing.rtf
[2013/03/07 00:27:44 | 000,001,271 | ---- | C] () -- C:\Users\Owner\Documents\unemployment.rtf
[2013/03/06 10:55:39 | 000,003,374 | ---- | C] () -- C:\Users\Owner\Documents\marcus job questions.rtf
[2013/03/05 18:46:31 | 000,000,180 | ---- | C] () -- C:\Users\Owner\Documents\Library.rtf
[2013/03/05 18:10:28 | 000,003,754 | ---- | C] () -- C:\Users\Owner\Documents\MH Resume.rtf
[2013/03/05 05:02:19 | 000,000,876 | ---- | C] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2013/03/05 01:15:33 | 000,001,803 | ---- | C] () -- C:\Users\Owner\Documents\Marcus work history dates.rtf
[2013/03/05 01:08:05 | 000,004,740 | ---- | C] () -- C:\Users\Owner\Documents\Marcus Resume3.rtf
[2013/03/04 22:02:20 | 000,003,781 | ---- | C] () -- C:\Users\Owner\Documents\Marcus resume2.rtf
[2013/03/04 21:42:28 | 000,004,645 | ---- | C] () -- C:\Users\Owner\Documents\resumetmpF51F.rtf
[2013/02/27 16:41:14 | 000,000,289 | ---- | C] () -- C:\Users\Owner\Documents\UNIDEN PHONE MANUAL.rtf
[2013/02/24 22:28:12 | 000,000,860 | ---- | C] () -- C:\Users\Owner\Documents\answers1.rtf
[2013/02/23 19:20:49 | 000,001,976 | ---- | C] () -- C:\Users\Owner\Documents\DVD Recorder and RF modulator.rtf
[2013/02/22 17:06:35 | 000,000,596 | ---- | C] () -- C:\Users\Owner\Documents\Marcus Resume.rtf
[2013/02/13 19:18:43 | 000,005,177 | ---- | C] () -- C:\Users\Owner\Documents\marcusjobs.rtf
[2013/02/13 01:00:44 | 000,000,278 | ---- | C] () -- C:\Users\Owner\Documents\cell phone plans cheap.rtf
[2013/02/12 23:55:31 | 000,001,305 | ---- | C] () -- C:\Users\Owner\Documents\job agency.rtf
[2013/01/19 02:52:09 | 000,000,022 | -H-- | C] () -- C:\Users\Owner\AppData\Local\xftredahs.dat
[2011/09/24 16:24:37 | 000,205,864 | ---- | C] () -- C:\Windows\System32\drivers\OADriver.sys
[2011/09/24 16:24:37 | 000,039,048 | ---- | C] () -- C:\Windows\System32\drivers\oahlp32.sys
[2011/09/24 15:02:04 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2011/09/24 15:02:04 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2011/08/20 22:57:13 | 000,017,408 | ---- | C] () -- C:\Users\Owner\AppData\Local\WebpageIcons.db
[2010/01/26 14:22:21 | 000,000,680 | ---- | C] () -- C:\Users\Owner\AppData\Local\d3d9caps.dat
[2008/12/13 14:59:46 | 000,000,560 | ---- | C] () -- C:\ProgramData\lxdf
[2007/10/14 19:26:28 | 000,005,632 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/11 02:04:24 | 000,000,682 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\wklnhst.dat
========== ZeroAccess Check ==========
[2006/11/02 05:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 10:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 23:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 23:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2008/12/14 00:30:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\6500 Series
[2010/01/29 22:12:13 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Auslogics
[2008/12/13 14:55:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Lexmark Productivity Studio
[2011/09/24 16:28:02 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\OnlineArmor
[2012/07/28 17:31:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SanDisk
[2007/10/11 02:04:27 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Template
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 347878 bytes -> C:\Users\Owner\AppData\Roaming\desktop.ini:init
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >