OTL logfile created on: 15/11/2012 1:46:52 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Sheila\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 109.21 Gb Total Space | 14.24 Gb Free Space | 13.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 228.13 Gb Total Space | 145.12 Gb Free Space | 63.61% Space Free | Partition Type: NTFS
Drive S: | 931.51 Gb Total Space | 783.09 Gb Free Space | 84.07% Space Free | Partition Type: NTFS
Computer Name: JETHROE
Current User Name: Sheila
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2012/11/15 13:45:27 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sheila\Desktop\OTL.exe
PRC - [2012/11/08 15:14:16 | 000,122,032 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
PRC - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
PRC - [2012/11/08 15:01:30 | 001,516,680 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe
PRC - [2012/02/26 23:15:42 | 000,055,144 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2011/11/25 10:21:32 | 001,175,384 | ---- | M] (Intuit Canada ULC.) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
PRC - [2011/11/25 10:19:24 | 001,178,968 | ---- | M] (Intuit Canada ULC.) -- C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE
PRC - [2011/11/25 10:19:22 | 000,062,808 | ---- | M] (Intuit, Inc.) -- C:\Program Files\Intuit\QuickBooks 2012\QBHelp.exe
PRC - [2011/11/25 08:44:50 | 000,045,056 | ---- | M] (Intuit) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2011/08/09 20:39:22 | 000,974,944 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2011/08/09 20:39:16 | 003,076,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2011/05/26 14:14:52 | 000,477,080 | ---- | M] () -- C:\Documents and Settings\Sheila\Application Data\HP SimpleSave Application\StartHelper.exe
PRC - [2011/04/13 11:04:04 | 000,679,936 | ---- | M] (Intuit, Inc.) -- C:\Program Files\Intuit\QuickBooks 2012\QBDBMgrN.exe
PRC - [2010/11/24 13:39:00 | 000,129,872 | ---- | M] () -- C:\Program Files\Rogers Connection Manager\AutoDect.exe
PRC - [2010/09/06 01:19:58 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2010/07/01 10:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) -- C:\Documents and Settings\Sheila\Application Data\HP SimpleSave Application\uUACTokenSvc.exe
PRC - [2010/06/10 12:42:44 | 002,621,440 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Browny02\Brother\BrStMonW.exe
PRC - [2010/01/25 07:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Browny02\BrYNSvc.exe
PRC - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2009/05/21 09:55:32 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/01 16:39:28 | 000,189,736 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2007/06/06 16:28:18 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2007/05/14 15:23:32 | 001,191,936 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2006/11/03 19:02:14 | 000,050,688 | ---- | M] (Avanquest Software ) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/11/02 15:05:50 | 000,282,624 | ---- | M] (Knowles Acoustics) -- C:\WINDOWS\system32\KADxMain.exe
PRC - [2004/07/27 17:50:18 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2002/06/03 10:38:12 | 000,049,152 | ---- | M] (ScanSoft, Inc) -- C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2012/11/15 13:45:27 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sheila\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/04/13 19:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2002/06/03 10:37:50 | 000,167,936 | ---- | M] (ScanSoft, Inc) -- C:\Program Files\ScanSoft\OmniPageSE\ophook32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe -- (Seagate Dashboard Services)
SRV - [2012/11/07 12:50:47 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/26 23:15:42 | 000,055,144 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2011/11/25 08:44:50 | 000,045,056 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2011/08/09 20:39:22 | 000,974,944 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/04/13 11:04:04 | 000,679,936 | ---- | M] (Intuit, Inc.) [On_Demand | Running] -- C:\Program Files\Intuit\QuickBooks 2012\QBDBMgrN.exe -- (QuickBooksDB22)
SRV - [2010/09/06 01:19:58 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2010/07/01 10:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Documents and Settings\Sheila\Application Data\HP SimpleSave Application\uUACTokenSvc.exe -- (BackupService)
SRV - [2010/03/29 07:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus(R)
SRV - [2010/03/18 16:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010/03/18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010/01/25 07:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2009/07/27 21:57:50 | 000,131,072 | ---- | M] (Intuit, Inc.) [Disabled | Stopped] -- C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe -- (QuickBooksDB20)
SRV - [2009/07/27 21:57:50 | 000,131,072 | ---- | M] (Intuit, Inc.) [Auto | Stopped] -- C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe -- (QuickBooksDB18)
SRV - [2009/07/23 22:10:38 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2008/08/13 17:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2011/08/09 12:57:10 | 000,154,136 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2011/08/04 08:20:38 | 000,103,112 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2011/08/04 08:20:36 | 000,118,104 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2011/03/26 09:37:12 | 000,126,976 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnet.sys -- (ZTEusbnet)
DRV - [2011/03/26 09:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2011/03/26 09:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2011/03/26 09:37:12 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2011/03/26 09:37:12 | 000,009,216 | ---- | M] (MBB Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2008/04/13 13:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 13:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 13:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 11:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/12/11 15:58:10 | 001,123,328 | ---- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2007/12/02 19:26:22 | 000,989,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2007/12/02 19:26:20 | 000,731,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2007/12/02 19:26:20 | 000,211,200 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2007/06/06 16:30:32 | 005,707,744 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007/06/06 16:28:16 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007/06/03 15:20:58 | 000,202,912 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2007/05/08 22:49:02 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2007/05/08 22:46:12 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/05/08 22:46:08 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/05/08 22:46:06 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/05/08 21:22:58 | 000,277,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor)
DRV - [2006/11/02 13:31:38 | 000,103,168 | ---- | M] (Knowles Acoustics) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dxec02.sys -- (DXEC02)
DRV - [2005/08/12 18:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004/08/03 23:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2001/08/17 15:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = »
partnerpage.google.com/smallbiz.···=0080304IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = »
www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = »
partnerpage.google.com/smallbiz.···=0080304IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = »
partnerpage.google.com/smallbiz.···=0080304IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = »
www.google.com/hws/sb/dell-row/e···l=ca-smbIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »
www.google.ca/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=#E56717]========== FireFox ==========[/color]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/08/31 10:11:22 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/06 17:10:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012/06/06 09:13:37 | 000,000,000 | ---D | M]
[2010/03/19 16:12:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Mozilla\Extensions
[2010/03/19 16:12:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\idm85d8m.default\extensions
[2010/03/19 16:12:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\idm85d8m.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/19 16:12:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\idm85d8m.default\extensions\staged-xpis
[2011/11/19 16:33:16 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/06/15 10:26:53 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/06/16 08:24:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/19 16:33:17 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Alexa Toolbar) - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files\Alexa Toolbar\AlexaToolbar.10.0.dll (Alexa.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [autodetect] C:\Program Files\Rogers Connection Manager\AutoDect.exe ()
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DBAgent] C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe (Seagate Technology LLC)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\dell\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe (Knowles Acoustics)
O4 - HKLM..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [QuickBooksDB20] C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe (Intuit, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Hardware Helper] C:\Program Files\Hardware Helper\HHLauncher.exe (PC Help Soft)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Uploader] C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Seagate Technology LLC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Canada ULC.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Canada ULC.)
O4 - Startup: C:\Documents and Settings\Sheila\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk = C:\Documents and Settings\Sheila\Application Data\HP SimpleSave Application\StartHelper.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Web 2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} »
www.update.microsoft.com/microso···34809031 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} »
java.sun.com/update/1.5.0/jinsta···i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} »
platformdl.adobe.com/NOS/getPlus···6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Sheila\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sheila\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/11/15 13:45:20 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sheila\Desktop\OTL.exe
[2012/11/14 14:23:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sheila\Application Data\Nero
[2012/11/14 14:23:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sheila\Application Data\Seagate
[2012/11/14 11:56:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2012/11/14 11:56:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero
[2012/11/14 11:55:56 | 000,000,000 | ---D | C] -- C:\Program Files\Seagate
[2012/11/14 11:51:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2012/11/09 11:37:06 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sheila\Desktop\TFC.exe
[2012/11/07 12:04:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\MATS
[2012/11/07 12:04:09 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fix it Center
[2012/11/07 11:07:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/11/15 13:45:27 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sheila\Desktop\OTL.exe
[2012/11/15 13:37:25 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/15 13:30:23 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2012/11/15 13:30:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/11/15 13:30:18 | 3210,780,672 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/15 13:29:49 | 006,553,600 | ---- | M] () -- C:\Documents and Settings\Sheila\NTUSER.DAT
[2012/11/15 13:29:25 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Sheila\ntuser.ini
[2012/11/15 13:21:20 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sheila\Desktop\TFC.exe
[2012/11/15 13:19:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/11/15 13:09:00 | 000,001,022 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1146484910-959827588-941327896-1008UA.job
[2012/11/15 13:05:40 | 000,000,574 | ---- | M] () -- C:\WINDOWS\tasks\Sheila1.job
[2012/11/15 12:53:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/15 12:37:16 | 000,000,572 | ---- | M] () -- C:\WINDOWS\tasks\Sheila.job
[2012/11/14 16:30:44 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\Sheila DBAgent 2 0.job
[2012/11/14 15:30:27 | 000,000,586 | ---- | M] () -- C:\WINDOWS\tasks\Sheila1 Merge.job
[2012/11/14 15:09:00 | 000,000,970 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1146484910-959827588-941327896-1008Core.job
[2012/11/14 14:31:17 | 000,000,584 | ---- | M] () -- C:\WINDOWS\tasks\Sheila Merge.job
[2012/11/14 14:26:51 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0E201E48-B373-4E02-8A61-919982036CA5}.job
[2012/11/14 14:01:55 | 000,000,634 | ---- | M] () -- C:\WINDOWS\tasks\G8 Accommodation1.job
[2012/11/14 13:53:50 | 000,000,632 | ---- | M] () -- C:\WINDOWS\tasks\G8 Accommodation.job
[2012/11/14 13:31:44 | 000,000,646 | ---- | M] () -- C:\WINDOWS\tasks\G8 Accommodation1 Merge.job
[2012/11/14 13:22:22 | 000,000,396 | ---- | M] () -- C:\WINDOWS\tasks\G8 Accommodation DBAgent 2 0.job
[2012/11/14 13:20:28 | 000,000,644 | ---- | M] () -- C:\WINDOWS\tasks\G8 Accommodation Merge.job
[2012/11/14 12:59:46 | 000,000,400 | ---- | M] () -- C:\WINDOWS\tasks\New COW Expression DBAgent 2 0.job
[2012/11/14 12:56:24 | 000,000,656 | ---- | M] () -- C:\WINDOWS\tasks\New COW Expression Merge.job
[2012/11/14 12:56:19 | 000,000,644 | ---- | M] () -- C:\WINDOWS\tasks\New COW Expression.job
[2012/11/14 12:45:20 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\Temp for email smgiv DBAgent 2 0.job
[2012/11/14 12:44:51 | 000,000,656 | ---- | M] () -- C:\WINDOWS\tasks\Temp for email smgiv.job
[2012/11/14 12:44:39 | 000,000,372 | ---- | M] () -- C:\WINDOWS\tasks\User DBAgent 2 0.job
[2012/11/14 12:42:15 | 000,000,400 | ---- | M] () -- C:\WINDOWS\tasks\Port Carling Boats DBAgent 2 0.job
[2012/11/14 12:40:46 | 000,000,656 | ---- | M] () -- C:\WINDOWS\tasks\Port Carling Boats Merge.job
[2012/11/14 12:40:41 | 000,000,644 | ---- | M] () -- C:\WINDOWS\tasks\Port Carling Boats.job
[2012/11/14 12:29:18 | 000,000,572 | ---- | M] () -- C:\WINDOWS\tasks\User Merge.job
[2012/11/14 12:29:13 | 000,000,560 | ---- | M] () -- C:\WINDOWS\tasks\User.job
[2012/11/14 12:14:33 | 000,000,668 | ---- | M] () -- C:\WINDOWS\tasks\Temp for email smgiv Merge.job
[2012/11/14 11:56:55 | 000,001,932 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Seagate Dashboard 2.0.lnk
[2012/11/13 12:13:20 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/11/08 10:32:41 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\Sheila\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/08 10:30:33 | 000,609,250 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2012/11/08 10:30:33 | 000,507,512 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/11/08 10:30:33 | 000,089,782 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/11/07 15:55:05 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/11/07 12:50:45 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/11/07 12:50:44 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/11/07 12:04:14 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/10/31 15:22:09 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Sheila\Desktop\Microsoft Word.lnk
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/11/14 16:31:11 | 000,475,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1146484910-959827588-941327896-1008-0.dat
[2012/11/14 16:31:11 | 000,153,754 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1146484910-959827588-941327896-1013-0.dat
[2012/11/14 16:31:11 | 000,153,754 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1146484910-959827588-941327896-1010-0.dat
[2012/11/14 16:31:11 | 000,153,754 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1146484910-959827588-941327896-1007-0.dat
[2012/11/14 16:31:06 | 000,153,754 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1146484910-959827588-941327896-1012-0.dat
[2012/11/14 14:32:24 | 000,000,586 | ---- | C] () -- C:\WINDOWS\tasks\Sheila1 Merge.job
[2012/11/14 14:32:22 | 000,000,574 | ---- | C] () -- C:\WINDOWS\tasks\Sheila1.job
[2012/11/14 14:31:16 | 000,000,584 | ---- | C] () -- C:\WINDOWS\tasks\Sheila Merge.job
[2012/11/14 14:31:14 | 000,000,572 | ---- | C] () -- C:\WINDOWS\tasks\Sheila.job
[2012/11/14 14:23:22 | 000,000,376 | ---- | C] () -- C:\WINDOWS\tasks\Sheila DBAgent 2 0.job
[2012/11/14 13:24:39 | 000,000,646 | ---- | C] () -- C:\WINDOWS\tasks\G8 Accommodation1 Merge.job
[2012/11/14 13:24:37 | 000,000,634 | ---- | C] () -- C:\WINDOWS\tasks\G8 Accommodation1.job
[2012/11/14 13:10:39 | 000,000,644 | ---- | C] () -- C:\WINDOWS\tasks\G8 Accommodation Merge.job
[2012/11/14 13:10:37 | 000,000,632 | ---- | C] () -- C:\WINDOWS\tasks\G8 Accommodation.job
[2012/11/14 13:08:41 | 000,000,396 | ---- | C] () -- C:\WINDOWS\tasks\G8 Accommodation DBAgent 2 0.job
[2012/11/14 12:47:57 | 000,000,656 | ---- | C] () -- C:\WINDOWS\tasks\New COW Expression Merge.job
[2012/11/14 12:47:54 | 000,000,644 | ---- | C] () -- C:\WINDOWS\tasks\New COW Expression.job
[2012/11/14 12:47:13 | 000,000,400 | ---- | C] () -- C:\WINDOWS\tasks\New COW Expression DBAgent 2 0.job
[2012/11/14 12:32:33 | 000,000,656 | ---- | C] () -- C:\WINDOWS\tasks\Port Carling Boats Merge.job
[2012/11/14 12:32:31 | 000,000,644 | ---- | C] () -- C:\WINDOWS\tasks\Port Carling Boats.job
[2012/11/14 12:31:22 | 000,000,400 | ---- | C] () -- C:\WINDOWS\tasks\Port Carling Boats DBAgent 2 0.job
[2012/11/14 12:20:48 | 000,000,572 | ---- | C] () -- C:\WINDOWS\tasks\User Merge.job
[2012/11/14 12:20:46 | 000,000,560 | ---- | C] () -- C:\WINDOWS\tasks\User.job
[2012/11/14 12:19:54 | 000,000,372 | ---- | C] () -- C:\WINDOWS\tasks\User DBAgent 2 0.job
[2012/11/14 12:05:57 | 000,000,668 | ---- | C] () -- C:\WINDOWS\tasks\Temp for email smgiv Merge.job
[2012/11/14 12:05:55 | 000,000,656 | ---- | C] () -- C:\WINDOWS\tasks\Temp for email smgiv.job
[2012/11/14 11:58:02 | 000,000,404 | ---- | C] () -- C:\WINDOWS\tasks\Temp for email smgiv DBAgent 2 0.job
[2012/11/14 11:56:55 | 000,001,932 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Seagate Dashboard 2.0.lnk
[2012/11/14 11:33:04 | 3210,780,672 | -HS- | C] () -- C:\hiberfil.sys
[2012/11/08 10:32:41 | 000,001,791 | ---- | C] () -- C:\Documents and Settings\Sheila\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/07 12:52:50 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/11/07 12:04:14 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/08/06 17:34:50 | 000,000,525 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2012/05/17 09:34:08 | 000,000,653 | ---- | C] () -- C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2012/03/19 16:41:25 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2012/03/19 16:41:21 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BRTCPCON.DLL
[2012/02/16 12:30:22 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/01/17 13:39:17 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/07/23 16:46:35 | 000,000,026 | ---- | C] () -- C:\WINDOWS\starter.INI
[2010/07/23 13:21:05 | 000,000,117 | ---- | C] () -- C:\WINDOWS\restore.INI
[2009/12/23 14:11:40 | 000,000,090 | ---- | C] () -- C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/03/24 17:40:03 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/03/04 13:47:16 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/03/04 13:43:33 | 000,198,144 | ---- | C] () -- C:\WINDOWS\System32\_psisdecd.dll
[2008/03/04 13:39:52 | 000,000,120 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/03/04 13:35:12 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2008/03/04 13:35:10 | 000,753,664 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2008/03/04 13:12:38 | 000,910,304 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2008/03/04 13:12:38 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4831.dll
[2008/03/04 13:12:36 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2008/03/04 13:11:04 | 000,001,219 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 05:25:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/02/09 13:46:30 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\VSHP1020.DLL
[2004/08/10 14:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[1999/01/22 21:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[color=#E56717]========== LOP Check ==========[/color]
[2011/09/17 09:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Caspedia
[2008/04/16 17:25:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2012/06/06 09:13:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/11/02 11:52:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\espionServerData
[2012/01/16 15:33:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2010/11/02 12:25:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012/11/14 11:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2010/11/02 11:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2010/01/18 12:47:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2012/01/16 15:39:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2012/08/06 17:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2012/08/06 17:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2008/03/04 13:43:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/08/08 14:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/29 16:38:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2012/06/06 17:03:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/08/10 17:08:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Canon
[2011/09/17 09:44:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Caspedia
[2010/11/02 11:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/07/26 13:41:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Dropbox
[2012/08/09 14:40:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Hardware Helper
[2012/08/06 17:10:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\InterTrust
[2011/01/25 18:43:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\KeePass
[2012/08/06 17:34:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\ScanSoft
[2012/11/14 14:23:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\Seagate
[2011/06/07 15:10:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\UDC Profiles
[2011/02/01 20:43:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sheila\Application Data\VirtualStore
[2012/11/14 13:22:22 | 000,000,396 | ---- | M] () -- C:\WINDOWS\Tasks\G8 Accommodation DBAgent 2 0.job
[2012/11/14 13:20:28 | 000,000,644 | ---- | M] () -- C:\WINDOWS\Tasks\G8 Accommodation Merge.job
[2012/11/14 13:53:50 | 000,000,632 | ---- | M] () -- C:\WINDOWS\Tasks\G8 Accommodation.job
[2012/11/14 13:31:44 | 000,000,646 | ---- | M] () -- C:\WINDOWS\Tasks\G8 Accommodation1 Merge.job
[2012/11/14 14:01:55 | 000,000,634 | ---- | M] () -- C:\WINDOWS\Tasks\G8 Accommodation1.job
[2012/11/14 12:59:46 | 000,000,400 | ---- | M] () -- C:\WINDOWS\Tasks\New COW Expression DBAgent 2 0.job
[2012/11/14 12:56:24 | 000,000,656 | ---- | M] () -- C:\WINDOWS\Tasks\New COW Expression Merge.job
[2012/11/14 12:56:19 | 000,000,644 | ---- | M] () -- C:\WINDOWS\Tasks\New COW Expression.job
[2012/11/14 12:42:15 | 000,000,400 | ---- | M] () -- C:\WINDOWS\Tasks\Port Carling Boats DBAgent 2 0.job
[2012/11/14 12:40:46 | 000,000,656 | ---- | M] () -- C:\WINDOWS\Tasks\Port Carling Boats Merge.job
[2012/11/14 12:40:41 | 000,000,644 | ---- | M] () -- C:\WINDOWS\Tasks\Port Carling Boats.job
[2012/11/14 16:30:44 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\Sheila DBAgent 2 0.job
[2012/11/14 14:31:17 | 000,000,584 | ---- | M] () -- C:\WINDOWS\Tasks\Sheila Merge.job
[2012/11/15 12:37:16 | 000,000,572 | ---- | M] () -- C:\WINDOWS\Tasks\Sheila.job
[2012/11/14 15:30:27 | 000,000,586 | ---- | M] () -- C:\WINDOWS\Tasks\Sheila1 Merge.job
[2012/11/15 13:05:40 | 000,000,574 | ---- | M] () -- C:\WINDOWS\Tasks\Sheila1.job
[2012/11/14 12:45:20 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\Temp for email smgiv DBAgent 2 0.job
[2012/11/14 12:14:33 | 000,000,668 | ---- | M] () -- C:\WINDOWS\Tasks\Temp for email smgiv Merge.job
[2012/11/14 12:44:51 | 000,000,656 | ---- | M] () -- C:\WINDOWS\Tasks\Temp for email smgiv.job
[2012/11/14 12:44:39 | 000,000,372 | ---- | M] () -- C:\WINDOWS\Tasks\User DBAgent 2 0.job
[2012/11/14 12:29:18 | 000,000,572 | ---- | M] () -- C:\WINDOWS\Tasks\User Merge.job
[2012/11/14 12:29:13 | 000,000,560 | ---- | M] () -- C:\WINDOWS\Tasks\User.job
[2012/11/14 14:26:51 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{0E201E48-B373-4E02-8A61-919982036CA5}.job
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~