I'm running on a Dell Latitude D600
It's got Windows XP Professional SP3
I had a couple of fake anti-virus programs last week. With the help of Google, this forum, Avast Anti-Virus, Malwarebytes' Anti-Malware, and Hijackthis, I believe I've removed the fake programs and fixed a Google redirect.
There still seems to be some leftover infection, though.
As Avast is running in the background every 10-20 minutes, it tells me that C:\WINDOWS\system32\svchost.exe throws a malicious url. Fortunately, it seems that Avast is doing a good job of blocking them.
Also, when I run a scan with Avast or Malwarebytes' it tells me that C:\WINDOWS\system32\svchost.exe and C:\WINDOWS\explorer.exe are infected. It won't repair the files, and if I removed them, it would mess up my OS pretty bad, right?
I'm hoping that someone here may be able to help me fix the last bits of the infection. So, here are my OTL logs.
Thank you all!!
OTL.Txt
OTL logfile created on: 11/18/2010 2:25:52 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Kendra\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 41.00 Mb Available Physical Memory | 8.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 60.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 18.96 Gb Free Space | 50.90% Space Free | Partition Type: NTFS
Computer Name: HAROLD | User Name: Kendra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/11/18 14:25:01 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kendra\Desktop\OTL.exe
PRC - [2010/09/07 10:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/07/23 04:59:14 | 002,388,264 | ---- | M] (Apple Inc.) -- C:\Program Files\Safari\Safari.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/02/12 11:02:08 | 000,240,992 | ---- | M] (Microsoft Corp.) -- C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe
PRC - [2009/08/07 17:15:06 | 000,242,048 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/04/14 05:42:40 | 000,507,904 | ---- | M] () -- C:\WINDOWS\system32\winlogon.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/11/18 14:25:01 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kendra\Desktop\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\spoolsv.exe -- (Spooler)
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\System32\6to4v32.dll -- (6to4)
SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 10:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/06/10 20:03:08 | 000,144,176 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/08/07 17:15:06 | 000,242,048 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\UIUSys.sys -- (UIUSys)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\s24trans.sys -- (s24trans)
DRV - [2010/09/07 09:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 09:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 09:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 09:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 09:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 09:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2006/05/10 15:00:16 | 000,156,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2005/11/10 22:49:24 | 001,406,464 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/05/03 15:09:28 | 001,033,728 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.SYS -- (HSF_DPV)
DRV - [2005/05/03 15:08:50 | 000,208,384 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/05/03 15:08:44 | 000,705,408 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/04/21 21:58:38 | 000,092,550 | ---- | M] (O2Micro) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ozscr.sys -- (OZSCR)
DRV - [2004/11/15 15:37:52 | 000,264,440 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\stac97.sys -- (STAC97) Audio Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 06 DC EC 19 56 87 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/11/12 15:49:20 | 000,000,000 | ---D | M]
[2010/10/29 06:32:06 | 000,002,077 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google_search.xml
O1 HOSTS File: ([2010/11/18 12:59:23 | 000,000,000 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe (Microsoft Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} http://download.micr...helpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1229440879408 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.31.0.9 172.31.0.7
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kendra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kendra\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/22 05:56:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/18 14:24:57 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kendra\Desktop\OTL.exe
[2010/11/18 12:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/11/15 17:54:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kendra\Application Data\Windows Search
[2010/11/15 17:49:54 | 003,024,056 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Kendra\My Documents\dfsetup200.exe
[2010/11/15 17:47:53 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kendra\Recent
[2010/11/15 17:42:49 | 002,811,584 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Kendra\My Documents\ccsetup300.exe
[2010/11/15 11:57:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
[2010/11/15 11:57:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2010/11/12 15:55:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/11/12 15:49:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/11/12 15:49:04 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar
[2010/11/12 15:46:14 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Toolbar Installer
[2010/11/12 15:08:26 | 000,000,000 | ---D | C] -- C:\ccleaner
[2010/11/10 15:51:29 | 000,000,000 | ---D | C] -- C:\65da8d16445ba9271017c21d797c
[2010/11/10 15:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kendra\Application Data\Windows Desktop Search
[2010/11/10 15:39:24 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2010/11/10 15:39:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2010/11/10 15:36:40 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2010/11/10 15:34:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF
[2010/11/10 15:34:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2010/11/10 15:31:08 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2010/11/10 15:31:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2010/11/10 15:31:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp
[2010/11/10 14:25:31 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/11/10 09:46:51 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2010/11/10 09:44:42 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/11/09 18:47:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/11/08 12:06:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kendra\Application Data\Malwarebytes
[2010/11/08 11:19:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010/11/08 09:53:53 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010/11/08 09:53:53 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/11/08 09:53:51 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/11/08 09:53:49 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/11/08 09:53:47 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/11/08 09:53:47 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010/11/08 09:53:46 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/11/08 09:53:35 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010/11/08 09:53:34 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010/11/08 09:53:27 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/11/08 09:53:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/04 17:14:58 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/04 17:14:57 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/04 17:14:57 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/04 17:14:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/04 16:48:26 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2010/11/04 15:21:24 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/11/04 15:21:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Update
[2010/11/04 15:21:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\cEaGe02001
[2010/11/02 02:03:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/11/02 02:03:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/11/02 01:36:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/11/02 01:36:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/11/02 01:25:23 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server
[1 C:\Documents and Settings\Kendra\My Documents\*.tmp files -> C:\Documents and Settings\Kendra\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/11/18 14:28:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/11/18 14:25:01 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kendra\Desktop\OTL.exe
[2010/11/18 14:21:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\Updater.job
[2010/11/18 13:59:27 | 000,002,449 | ---- | M] () -- C:\Documents and Settings\Kendra\Desktop\HiJackThis.lnk
[2010/11/18 13:38:00 | 000,000,286 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/18 13:38:00 | 000,000,248 | -H-- | M] () -- C:\WINDOWS\tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2010/11/18 13:34:00 | 000,000,286 | -H-- | M] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/11/18 13:33:14 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/18 13:32:15 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/18 12:59:23 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/11/15 20:32:25 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2010/11/15 20:32:25 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2010/11/15 19:26:13 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2010/11/15 19:26:13 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/11/15 19:26:13 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/11/15 17:53:00 | 000,001,580 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Defraggler.lnk
[2010/11/15 17:50:23 | 003,024,056 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Kendra\My Documents\dfsetup200.exe
[2010/11/15 17:48:22 | 000,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/11/15 17:45:28 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/15 17:43:16 | 002,811,584 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Kendra\My Documents\ccsetup300.exe
[2010/11/15 09:38:33 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/11/12 15:31:36 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/11/12 15:31:20 | 000,110,992 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/10 17:28:02 | 000,012,477 | ---- | M] () -- C:\WINDOWS\System32\234.js
[2010/11/10 15:54:38 | 000,429,418 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/11/10 15:54:38 | 000,071,880 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/11/10 15:39:39 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2010/11/10 15:37:09 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\Kendra\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/10 15:37:09 | 000,000,782 | ---- | M] () -- C:\Documents and Settings\Kendra\Desktop\Windows Media Player.lnk
[2010/11/10 15:37:06 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/11/10 15:37:06 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/11/10 15:34:20 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/11/10 14:40:41 | 000,002,205 | ---- | M] () -- C:\Documents and Settings\Kendra\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/11/10 10:28:05 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/11/09 18:47:42 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/11/09 17:13:25 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010/11/09 14:34:19 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2010/11/08 18:54:45 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/11/08 16:18:29 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Kendra\Application Data\completescan
[2010/11/08 09:53:48 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/11/04 15:39:51 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/11/04 15:31:54 | 000,000,006 | ---- | M] () -- C:\Documents and Settings\Kendra\Application Data\start
[2010/11/04 15:22:54 | 000,000,010 | ---- | M] () -- C:\Documents and Settings\Kendra\Application Data\install
[2010/11/04 15:22:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/11/04 15:21:58 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/11/04 15:21:52 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/11/04 15:21:52 | 000,000,416 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/11/04 15:21:36 | 000,000,201 | ---- | M] () -- C:\Documents and Settings\Kendra\Application Data\dkfjasdfshd.bat
[2010/11/04 12:34:09 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\sourcelistinternet.doc
[2010/11/04 02:24:46 | 009,367,681 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Ra-Ra-Riot-Boy-RAC-Mix.mp3
[2010/11/04 02:18:13 | 003,083,038 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\kag.mp3
[2010/11/04 02:16:28 | 005,003,339 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\When-I-Am-Gone.mp3
[2010/11/04 02:15:51 | 005,119,649 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\11 Beauty.mp3
[2010/11/04 02:15:07 | 007,662,372 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Ribbon Bow.mp3
[2010/11/04 02:14:52 | 009,882,570 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\08-Meet-the-Frownies.mp3
[2010/11/04 02:12:23 | 005,308,613 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\01-Mornin.mp3
[2010/11/04 02:12:20 | 004,317,767 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\lina.mp3
[2010/11/04 02:11:56 | 009,946,215 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\06-pure-affection.mp3
[2010/11/04 02:10:56 | 006,202,152 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Kissing-Clouds.mp3
[2010/11/04 02:10:38 | 005,550,079 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Watch-The-Glow.mp3
[2010/11/04 02:08:32 | 005,613,325 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\02-Tea-Lights.mp3
[2010/11/04 02:08:15 | 003,565,743 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\07-A-Bright-[bleep]-Light.mp3
[2010/11/04 01:51:36 | 004,921,936 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\backinyourheadrac.mp3
[2010/11/04 01:44:20 | 000,051,626 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\tegan-and-sara-home-recordings-1.html
[2010/11/04 01:41:54 | 000,051,626 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\tegan-and-sara-home-recordings.html
[2010/11/04 01:26:05 | 005,936,736 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\ohdarling.mp3
[2010/11/04 01:15:50 | 016,535,575 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Broken-Social-Scene-World-Sick.mp3
[2010/11/04 01:13:32 | 007,480,278 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Kate-Nash-I-Just-Love-You-More.mp3
[2010/11/03 15:44:11 | 003,937,841 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Kate-Nash-Do-Wah-Doo.mp3
[2010/11/03 15:44:03 | 004,913,327 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Kate-Nash-Paris.mp3
[2010/11/02 16:58:03 | 003,616,896 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Prince - Kiss.mp3
[2010/11/02 16:39:27 | 004,313,127 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\09-pumpkin-soup.mp3
[2010/11/02 16:31:10 | 007,000,923 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\01.the raveonettes - bang!.mp3
[2010/11/02 15:29:39 | 015,830,600 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Prince (Bassnectar Remix).mp3
[2010/11/02 11:20:01 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\journalresources.doc
[2010/11/01 17:32:14 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\litnotes.doc
[2010/11/01 15:32:32 | 000,022,528 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\journal4.doc
[2010/11/01 15:30:53 | 000,022,528 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\journal3-1.doc
[2010/11/01 14:48:00 | 000,265,104 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\Introduction_to_Literature.pdf
[2010/10/31 21:46:56 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\websummary6.doc
[2010/10/28 19:26:39 | 000,037,376 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\philofreligionnotes.doc
[2010/10/28 16:52:28 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\hhh8.doc
[2010/10/28 12:25:13 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\sourcelistbooks.doc
[2010/10/26 12:29:19 | 000,022,528 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\emmainterview.doc
[2010/10/26 12:24:53 | 000,024,576 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\apologeticreferences1.doc
[2010/10/26 10:34:34 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Kendra\My Documents\~$ologeticreferences.doc
[2010/10/25 14:34:59 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\introtoartsnotes.doc
[2010/10/25 12:19:24 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\websummary5.doc
[2010/10/25 00:01:04 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\journal3.doc
[2010/10/21 16:26:50 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\hhh7.doc
[2010/10/21 15:01:14 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Kendra\My Documents\hhh6.doc
[1 C:\Documents and Settings\Kendra\My Documents\*.tmp files -> C:\Documents and Settings\Kendra\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/02 16:57:34 | 003,616,896 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Prince - Kiss.mp3
[2010/12/02 15:26:52 | 015,830,600 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Prince (Bassnectar Remix).mp3
[2010/11/18 12:40:30 | 000,002,449 | ---- | C] () -- C:\Documents and Settings\Kendra\Desktop\HiJackThis.lnk
[2010/11/15 17:53:00 | 000,001,580 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Defraggler.lnk
[2010/11/15 17:45:28 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/11/10 15:39:39 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2010/11/10 15:36:55 | 000,000,782 | ---- | C] () -- C:\Documents and Settings\Kendra\Desktop\Windows Media Player.lnk
[2010/11/10 15:34:20 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf
[2010/11/10 10:28:04 | 000,012,477 | ---- | C] () -- C:\WINDOWS\System32\234.js
[2010/11/08 18:52:09 | 000,001,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2010/11/04 15:31:54 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Kendra\Application Data\start
[2010/11/04 15:26:59 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Kendra\Application Data\completescan
[2010/11/04 15:22:54 | 000,000,010 | ---- | C] () -- C:\Documents and Settings\Kendra\Application Data\install
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At24.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At23.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At22.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At21.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At20.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At19.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At18.job
[2010/11/04 15:21:58 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At17.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At9.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At8.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At16.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At15.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At14.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At13.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At12.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At11.job
[2010/11/04 15:21:54 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At10.job
[2010/11/04 15:21:53 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At7.job
[2010/11/04 15:21:53 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At6.job
[2010/11/04 15:21:53 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At5.job
[2010/11/04 15:21:53 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At4.job
[2010/11/04 15:21:49 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At3.job
[2010/11/04 15:21:49 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2010/11/04 15:21:49 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2010/11/04 15:21:46 | 000,000,416 | ---- | C] () -- C:\WINDOWS\tasks\Updater.job
[2010/11/04 15:21:36 | 000,000,201 | ---- | C] () -- C:\Documents and Settings\Kendra\Application Data\dkfjasdfshd.bat
[2010/11/04 12:34:09 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\sourcelistinternet.doc
[2010/11/04 02:23:52 | 009,367,681 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Ra-Ra-Riot-Boy-RAC-Mix.mp3
[2010/11/04 02:18:04 | 003,083,038 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\kag.mp3
[2010/11/04 02:16:16 | 005,003,339 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\When-I-Am-Gone.mp3
[2010/11/04 02:15:27 | 005,119,649 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\11 Beauty.mp3
[2010/11/04 02:14:25 | 007,662,372 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Ribbon Bow.mp3
[2010/11/04 02:14:22 | 009,882,570 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\08-Meet-the-Frownies.mp3
[2010/11/04 02:12:08 | 005,308,613 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\01-Mornin.mp3
[2010/11/04 02:11:54 | 004,317,767 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\lina.mp3
[2010/11/04 02:11:36 | 009,946,215 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\06-pure-affection.mp3
[2010/11/04 02:10:44 | 006,202,152 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Kissing-Clouds.mp3
[2010/11/04 02:10:23 | 005,550,079 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Watch-The-Glow.mp3
[2010/11/04 02:08:18 | 005,613,325 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\02-Tea-Lights.mp3
[2010/11/04 02:08:08 | 003,565,743 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\07-A-Bright-[bleep]-Light.mp3
[2010/11/04 01:50:49 | 004,921,936 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\backinyourheadrac.mp3
[2010/11/04 01:44:18 | 000,051,626 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\tegan-and-sara-home-recordings-1.html
[2010/11/04 01:41:50 | 000,051,626 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\tegan-and-sara-home-recordings.html
[2010/11/04 01:25:43 | 005,936,736 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\ohdarling.mp3
[2010/11/04 01:13:50 | 016,535,575 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Broken-Social-Scene-World-Sick.mp3
[2010/11/04 01:12:39 | 007,480,278 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Kate-Nash-I-Just-Love-You-More.mp3
[2010/11/03 15:43:20 | 003,937,841 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Kate-Nash-Do-Wah-Doo.mp3
[2010/11/03 15:43:16 | 004,913,327 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Kate-Nash-Paris.mp3
[2010/11/02 16:38:52 | 004,313,127 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\09-pumpkin-soup.mp3
[2010/11/02 16:29:51 | 007,000,923 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\01.the raveonettes - bang!.mp3
[2010/11/02 10:20:41 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\journalresources.doc
[2010/11/02 01:26:12 | 000,000,286 | -H-- | C] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/02 01:26:11 | 000,000,286 | -H-- | C] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/11/02 01:26:11 | 000,000,248 | -H-- | C] () -- C:\WINDOWS\tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2010/11/01 15:32:22 | 000,022,528 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\journal4.doc
[2010/11/01 15:30:53 | 000,022,528 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\journal3-1.doc
[2010/11/01 14:48:00 | 000,265,104 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\Introduction_to_Literature.pdf
[2010/10/31 21:28:55 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\websummary6.doc
[2010/10/28 16:52:25 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\hhh8.doc
[2010/10/28 12:25:12 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\sourcelistbooks.doc
[2010/10/26 11:23:09 | 000,024,576 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\apologeticreferences1.doc
[2010/10/26 10:34:34 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Kendra\My Documents\~$ologeticreferences.doc
[2010/10/25 16:22:50 | 000,022,528 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\emmainterview.doc
[2010/10/25 14:34:59 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\introtoartsnotes.doc
[2010/10/25 00:59:18 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\websummary5.doc
[2010/10/25 00:01:03 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\journal3.doc
[2010/10/21 16:26:50 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Kendra\My Documents\hhh7.doc
[2010/01/11 00:24:07 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/12/17 10:52:14 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2004/09/19 16:16:28 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
========== LOP Check ==========
[2004/09/22 05:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Absolutist
[2010/11/08 09:53:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/11/04 18:18:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010/11/08 18:49:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\cEaGe02001
[2010/03/23 11:56:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/11/04 15:21:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Update
[2010/08/16 16:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2004/09/22 05:47:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/11/10 15:40:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kendra\Application Data\Windows Desktop Search
[2010/11/15 17:54:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kendra\Application Data\Windows Search
[2010/11/04 15:21:52 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2010/11/04 15:21:58 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2010/11/09 14:34:19 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2010/11/12 15:31:36 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2010/11/18 14:28:00 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2010/11/10 10:28:05 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2010/11/08 18:54:45 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2010/11/15 19:26:13 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2010/11/15 19:26:13 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2010/11/15 20:32:25 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2010/11/15 09:38:33 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2010/11/15 20:32:25 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2010/11/15 19:26:13 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2010/11/04 15:22:50 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2010/11/04 15:21:52 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2010/11/04 15:21:59 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
[2010/11/18 14:21:01 | 000,000,416 | ---- | M] () -- C:\WINDOWS\Tasks\Updater.job
[2010/11/18 13:38:00 | 000,000,286 | -H-- | M] () -- C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/11/18 13:38:00 | 000,000,248 | -H-- | M] () -- C:\WINDOWS\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job
[2010/11/18 13:34:00 | 000,000,286 | -H-- | M] () -- C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
========== Purity Check ==========
< End of report >
Extras.Txt
OTL Extras logfile created on: 11/18/2010 2:25:52 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Kendra\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 41.00 Mb Available Physical Memory | 8.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 60.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 18.96 Gb Free Space | 50.90% Space Free | Partition Type: NTFS
Computer Name: HAROLD | User Name: Kendra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = SafariHTML] -- C:\Program Files\Safari\Safari.exe (Apple Inc.)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java 6 Update 22
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{66468F4D-BC4E-470C-9093-B3B6A1BB378C}" = MSN Toolbar Platform
"{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom Gigabit Integrated Controller
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C5BED10B-42A9-4142-B4C2-008C0FDE27D5}" = O2Micro Smartcard Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EAFEF30E-3789-49C7-A6D9-77C12E005BAC}" = Safari
"{F8A3C1B6-D2E0-4CE1-80A2-555D6F71C639}" = Microsoft Search Enhancement Pack
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"avast5" = avast! Free Antivirus
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1" = Conexant D480 MDC V.92 Modem
"Defraggler" = Defraggler
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{C5BED10B-42A9-4142-B4C2-008C0FDE27D5}" = O2Micro Smartcard Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Plants vs. Zombies" = Plants vs. Zombies
"VLC media player" = VLC media player 0.9.2
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/15/2010 7:31:02 PM | Computer Name = HAROLD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 11/15/2010 9:20:45 PM | Computer Name = HAROLD | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.
Error - 11/15/2010 10:28:23 PM | Computer Name = HAROLD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 11/15/2010 10:28:24 PM | Computer Name = HAROLD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 11/18/2010 2:36:59 PM | Computer Name = HAROLD | Source = Windows Search Service | ID = 3013
Description = The entry <C:\DOCUMENTS AND SETTINGS\KENDRA\RECENT\DESKTOP.INI> in
the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)
Error - 11/18/2010 2:37:21 PM | Computer Name = HAROLD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 11/18/2010 2:37:21 PM | Computer Name = HAROLD | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 11/18/2010 2:47:48 PM | Computer Name = HAROLD | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.
Error - 11/18/2010 3:46:59 PM | Computer Name = HAROLD | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.
Error - 11/18/2010 4:29:09 PM | Computer Name = HAROLD | Source = Windows Search Service | ID = 3024
Description = The update cannot be started because the content sources cannot be
accessed. Fix the errors and try the update again. Context: Application, SystemIndex
Catalog
[ System Events ]
Error - 11/18/2010 2:34:53 PM | Computer Name = HAROLD | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126
Error - 11/18/2010 2:37:29 PM | Computer Name = HAROLD | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 11/18/2010 3:28:32 PM | Computer Name = HAROLD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 11/18/2010 3:28:40 PM | Computer Name = HAROLD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 11/18/2010 3:30:00 PM | Computer Name = HAROLD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MSIServer with
arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
Error - 11/18/2010 3:30:00 PM | Computer Name = HAROLD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service MSIServer with
arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
Error - 11/18/2010 3:30:32 PM | Computer Name = HAROLD | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.
Error - 11/18/2010 3:30:35 PM | Computer Name = HAROLD | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 11/18/2010 3:33:05 PM | Computer Name = HAROLD | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2
Error - 11/18/2010 3:33:05 PM | Computer Name = HAROLD | Source = Service Control Manager | ID = 7023
Description = The Network Security service terminated with the following error:
%%126
< End of report >