OTL logfile created on: 8/10/2009 11:48:48 PM - Run 1
OTL by OldTimer - Version 3.0.10.5 Folder = C:\Documents and Settings\Administrator\Desktop
64bit-Windows Server 2003 Service Pack 2 (Version = 5.2.3790) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.01 Gb Available Physical Memory | 75.30% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.00 Gb Total Space | 20.34 Gb Free Space | 13.65% Space Free | Partition Type: NTFS
Drive D: | 4.14 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: THUNDERDOME
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2009/03/31 17:50:42 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jqs.exe
PRC - [2008/07/16 14:45:20 | 00,181,504 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PsCtrls.exe
PRC - [2008/07/10 12:02:00 | 00,169,216 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe
PRC - [2008/02/04 17:26:48 | 00,062,768 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
PRC - [2008/06/19 12:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimsvc.exe
PRC - [2008/06/25 16:43:08 | 00,028,928 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe
PRC - [2008/04/24 14:26:18 | 00,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2008/06/12 15:31:40 | 00,226,608 | —- | M] (Panda Software International) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Firewall\PSHOST.EXE
PRC - [2009/07/15 07:20:02 | 00,881,920 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\ApvxdWin.exe
PRC - [2008/07/04 14:28:34 | 00,290,048 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\pavsrvx86.exe
PRC - [2008/07/02 13:26:56 | 00,193,792 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\AVENGINE.EXE
PRC - [2008/04/24 14:25:22 | 00,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe
PRC - [2009/03/31 17:50:42 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jusched.exe
PRC - [2008/07/17 13:44:18 | 00,173,824 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe
PRC - [2008/05/14 18:21:02 | 00,107,824 | —- | M] (Panda Security, S.L.) – C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2009\WebProxy.exe
PRC - [2008/07/19 20:54:42 | 00,747,776 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Upgrader.exe
PRC - [2008/04/12 21:17:41 | 00,185,632 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/07/01 20:32:11 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/06/29 20:34:49 | 00,520,024 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/08/10 23:41:02 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2007/10/23 22:33:00 | 00,045,576 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/10/23 22:33:04 | 00,093,696 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2007/10/09 15:06:28 | 00,036,864 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/02 14:09:42 | 00,072,448 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Gwmsrv64.dll – (Gwmsrv [Auto | Running])
SRV - [2007/02/17 01:44:20 | 00,077,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/03/25 08:00:00 | 00,162,816 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWOW64\iasrecst.dll – (IASJet [On_Demand | Stopped])
SRV - [2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2007/10/10 22:08:40 | 00,921,600 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/03/31 17:50:42 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2009/07/01 20:32:11 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2007/02/18 12:05:42 | 00,430,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\netlogon.dll – (Netlogon [On_Demand | Stopped])
SRV - [2003/07/28 12:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/07/16 14:45:20 | 00,181,504 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PsCtrls.exe – (Panda Software Controller [Auto | Running])
SRV - [2008/07/10 12:02:00 | 00,169,216 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PavFnSvr.exe – (PAVFNSVR [Auto | Running])
SRV - [2008/02/04 17:26:48 | 00,062,768 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe – (PavPrSrv [Auto | Running])
SRV - [2008/07/04 14:28:34 | 00,290,048 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\pavsrvx86.exe – (PAVSRV [Auto | Running])
SRV - [2008/06/12 15:31:40 | 00,226,608 | —- | M] (Panda Software International) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Firewall\PSHOST.EXE – (PSHost [Auto | Running])
SRV - [2008/06/19 12:59:50 | 00,108,288 | —- | M] (Panda Security S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\psimsvc.exe – (PSIMSVC [Auto | Running])
SRV - [2008/06/25 16:43:08 | 00,028,928 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe – (PskSvcRetail [Auto | Running])
SRV - [2008/04/24 14:26:18 | 00,202,560 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtsvc.exe – (sprtsvc_ddoctorv2 [Auto | Running])
SRV - [2008/07/17 13:44:18 | 00,173,824 | —- | M] (Panda Security, S.L.) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\TPSrvWow.exe – (TPSrv [Auto | Running])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2009/02/23 19:05:39 | 00,000,000 | —D | M] – C:\WINDOWS\FltMgr – (FltMgr [Boot | Running])
DRV - [2005/03/25 08:00:00 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mnmdd.dll – (mnmdd [System | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yoog Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..keyword.URL: "http://www10.yoog.com/search.php?q="
FF - user.js..browser.search.selectedEngine: "Yoog Search"
FF - user.js..keyword.URL: "http://www10.yoog.com/search.php?q="
FF - user.js..keyword.enabled: true
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\ff [2009/03/31 17:50:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/08/06 23:22:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/08/05 08:14:36 | 00,000,000 | —D | M]
[2008/08/29 01:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2008/08/29 01:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/12 15:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\08p9vs40.default\extensions
[2009/08/09 14:21:12 | 00,001,687 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\08p9vs40.default\searchplugins\nutritiondata.xml
[2009/01/02 11:11:47 | 00,000,247 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Mozilla\FireFox\Profiles\08p9vs40.default\searchplugins\Yoog Search.xml
[2009/08/10 05:08:12 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions
[2009/08/05 08:14:36 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/31 17:50:54 | 00,000,000 | —D | M] – C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/08/05 08:14:31 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 08:14:31 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007/11/29 18:31:02 | 00,479,232 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\msvcm80.dll
[2007/11/29 18:31:02 | 00,548,864 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\msvcp80.dll
[2007/11/29 18:31:04 | 00,626,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\msvcr80.dll
[2007/04/10 18:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2009/01/16 20:17:04 | 00,114,688 | —- | M] (Adobe Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\np32dsw.dll
[2007/02/10 17:59:00 | 00,806,912 | —- | M] ( ) – C:\Program Files (x86)\mozilla firefox\plugins\npActiveGS.dll
[2009/03/31 17:50:43 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeploytk.dll
[2007/10/11 15:17:50 | 01,435,688 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/08/05 08:14:32 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2006/12/18 05:18:30 | 00,077,824 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2008/04/12 21:17:47 | 00,144,720 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2008/02/25 15:39:04 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2008/04/12 21:17:53 | 00,024,576 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll
[2008/04/12 21:17:44 | 00,081,920 | —- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll
[2007/04/16 13:07:12 | 00,180,293 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npViewpoint.dll
[2008/07/02 12:31:38 | 00,001,394 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2008/07/02 12:31:38 | 00,002,193 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2008/07/02 12:31:38 | 00,001,534 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/13 05:43:34 | 00,002,343 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2008/07/02 12:31:38 | 00,001,706 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2008/07/02 12:31:38 | 00,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2008/07/02 12:31:38 | 00,000,792 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files (x86)\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4:
64bit: - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4:
64bit: - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\SysNative\NvCpl.DLL File not found
O4:
64bit: - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\SysNative\NvMcTray.DLL File not found
O4:
64bit: - HKLM..\Run: [nwiz] File not found
O4:
64bit: - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.EXE (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files (x86)\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2009\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9:
64bit: - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9:
64bit: - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre6\bin\npjpi160_13.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15:
64bit: - ..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\SysNative\mshtml.dll File not found
O18:
64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\SysNative\wiascr.dll File not found
O18:
64bit: - Protocol\Filter: - application/octet-stream - File not found
O18:
64bit: - Protocol\Filter: - application/x-complus - File not found
O18:
64bit: - Protocol\Filter: - application/x-msdownload - File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - C:\WINDOWS\SysNative\logonui.exe File not found
O20:
64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\SysWow64\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (lsass.exe) - File not found
O20:
64bit: - Winlogon\Notify\avldr: DllName - Reg Error: Value error. - File not found
O20:
64bit: - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - File not found
O20:
64bit: - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - File not found
O20:
64bit: - Winlogon\Notify\cscdll: DllName - cscdll.dll - File not found
O20:
64bit: - Winlogon\Notify\dimsntfy: DllName - dimsntfy.dll - File not found
O20:
64bit: - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O20:
64bit: - Winlogon\Notify\Schedule: DllName - wlnotify.dll - File not found
O20:
64bit: - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - File not found
O20:
64bit: - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - File not found
O20:
64bit: - Winlogon\Notify\termsrv: DllName - Reg Error: Value error. - File not found
O20:
64bit: - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\avldr: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - File not found
O20 - Winlogon\Notify\termsrv: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - File not found
O21:
64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\SysNative\stobject.dll File not found
O21:
64bit: - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\SysNative\upnpui.dll File not found
O21:
64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\SysNative\WPDShServiceObj.dll File not found
O28:
64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/07 22:53:42 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2 C:\WINDOWS\SysWow64\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2099/01/01 12:00:00 | 00,000,000 | -HS- | C] () – C:\WINDOWS\SysWow64\zeraseba.dll
[2009/08/10 23:40:44 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/08/10 16:18:26 | 00,359,932 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/08/10 16:18:21 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/08/10 15:31:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\gmer(2)
[2009/08/10 15:31:05 | 00,279,461 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\gmer(2).zip
[2009/08/09 14:41:46 | 00,145,495 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\3795385154_c52a6e73ab.jpg
[2009/08/08 06:45:47 | 03,942,048 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/08/07 06:39:04 | 69,548,6782 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\StudentFriends—Episode-16.avi
[2009/08/07 01:30:46 | 00,278,846 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\gmer.zip
[2009/08/06 22:19:18 | 00,024,788 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\bustedtees.9577de9ebb920d053ef4f51d44843978.gif
[2009/08/05 16:05:57 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\goddesses
[2009/08/05 08:58:52 | 00,002,153 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Character Builder.lnk
[2009/08/05 08:58:50 | 00,000,000 | —D | C] – C:\Program Files (x86)\Wizards of the Coast
[2009/08/05 08:55:03 | 00,608,578 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB(2).exe
[2009/08/05 08:06:48 | 00,000,000 | —D | C] – C:\Program Files (x86)\MSBuild
[2009/08/05 08:06:44 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/08/05 08:06:37 | 00,000,000 | —D | C] – C:\WINDOWS\SysWow64\XPSViewer
[2009/08/05 08:06:29 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/05 08:06:29 | 00,000,000 | —D | C] – C:\Program Files (x86)\Reference Assemblies
[2009/08/05 08:04:44 | 00,391,730 | —- | C] () – C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2009/08/05 07:05:07 | 20,669,2864 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35.exe
[2009/08/05 06:56:57 | 00,122,992 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\clwireg-x64.exe
[2009/08/05 06:45:29 | 02,959,376 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35setup.exe
[2009/08/05 06:40:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\ddi
[2009/08/05 05:06:00 | 00,060,568 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rs005.jpg
[2009/08/05 04:59:44 | 00,136,802 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\rs001.jpg
[2009/08/01 17:53:21 | 00,034,473 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1380782321_30191200_414.jpg
[2009/07/29 18:11:04 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/07/29 18:10:23 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/07/29 17:58:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\WotC Games
[2009/07/29 17:58:14 | 00,608,578 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB.exe
[2009/07/28 12:43:03 | 25,368,146 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\c8932fa141d6.wmv
[2009/07/25 18:40:57 | 00,035,229 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\cooper1952.jpg
[2009/07/25 18:39:48 | 00,045,855 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1064207944_30131462_4640.jpg
[2009/07/25 18:01:28 | 00,064,417 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\6093_1184953216984_1022854898_30587081_5179701_n.jpg
[2009/07/25 06:30:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\ybookself
[2009/07/21 20:55:48 | 00,001,666 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PoxNora.lnk
[2009/07/21 20:55:38 | 00,000,000 | —D | C] – C:\Program Files (x86)\PoxNora
[2009/07/21 20:54:06 | 15,087,616 | —- | C] (Octopi, Inc) – C:\Documents and Settings\Administrator\Desktop\PoxNora.exe
[2009/07/21 06:17:24 | 00,047,443 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146852_337.jpg
[2009/07/21 06:16:57 | 00,044,009 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146846_8302.jpg
[2009/07/21 06:16:29 | 00,046,932 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146813_7295.jpg
[2009/07/21 06:13:37 | 00,038,316 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30253702_5922.jpg
[2009/07/21 06:07:38 | 00,034,882 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30406666_8089571.jpg
[2009/07/20 00:11:48 | 03,597,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mshtml.dll
[2009/07/20 00:11:48 | 01,159,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\urlmon.dll
[2009/07/20 00:11:48 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\wininet.dll
[2009/07/20 00:11:48 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iertutil.dll
[2009/07/20 00:11:48 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\url.dll
[2009/07/20 00:11:48 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\SysWow64\jsproxy.dll
[2009/07/19 06:02:17 | 00,269,311 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\152p0l.png
[2009/07/19 05:44:20 | 00,046,825 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\ryanhead.jpg
[2009/07/19 05:41:51 | 00,050,368 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\kseniahead.jpg
[2009/07/17 03:01:23 | 00,020,516 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\null.pdf
[2009/07/12 16:26:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\rob wedding
[2009/03/30 15:43:02 | 00,000,425 | —- | C] () – C:\WINDOWS\AvDetected.ini
[2009/01/14 19:59:31 | 00,000,615 | —- | C] () – C:\WINDOWS\tlknw4.ini
[2009/01/05 23:09:54 | 00,000,002 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/11/29 18:20:56 | 00,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/10/07 14:33:00 | 01,486,848 | —- | C] () – C:\WINDOWS\SysWow64\nview.dll
[2008/10/07 14:33:00 | 01,019,904 | —- | C] () – C:\WINDOWS\SysWow64\nvwimg.dll
[2008/07/09 22:10:24 | 00,034,308 | —- | C] () – C:\WINDOWS\SysWow64\bassmod.dll
[2007/11/07 23:45:58 | 00,002,467 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2007/11/07 23:45:38 | 00,010,288 | —- | C] () – C:\WINDOWS\SysWow64\drivers\ASUSHWIO.SYS
[2007/11/07 22:52:15 | 00,000,570 | —- | C] () – C:\WINDOWS\win.ini
[2007/11/07 17:33:35 | 00,000,150 | —- | C] () – C:\WINDOWS\system.ini
[2006/01/12 17:09:14 | 00,090,112 | —- | C] () – C:\WINDOWS\SysWow64\DXFLib.dll
[2006/01/12 17:08:06 | 00,143,360 | —- | C] () – C:\WINDOWS\SysWow64\opcode.dll
[2005/03/25 08:00:00 | 01,277,952 | —- | C] () – C:\WINDOWS\SysWow64\quartz.dll
[2005/03/25 08:00:00 | 00,733,696 | —- | C] () – C:\WINDOWS\SysWow64\qedwipes.dll
[2005/03/25 08:00:00 | 00,512,512 | —- | C] () – C:\WINDOWS\SysWow64\qedit.dll
[2005/03/25 08:00:00 | 00,498,742 | —- | C] () – C:\WINDOWS\SysWow64\dxmasf.dll
[2005/03/25 08:00:00 | 00,396,288 | —- | C] () – C:\WINDOWS\SysWow64\encdec.dll
[2005/03/25 08:00:00 | 00,385,536 | —- | C] () – C:\WINDOWS\SysWow64\qdvd.dll
[2005/03/25 08:00:00 | 00,355,112 | —- | C] () – C:\WINDOWS\SysWow64\msjetoledb40.dll
[2005/03/25 08:00:00 | 00,279,040 | —- | C] () – C:\WINDOWS\SysWow64\qdv.dll
[2005/03/25 08:00:00 | 00,276,992 | —- | C] () – C:\WINDOWS\SysWow64\sbe.dll
[2005/03/25 08:00:00 | 00,199,168 | —- | C] () – C:\WINDOWS\SysWow64\ir32_32.dll
[2005/03/25 08:00:00 | 00,192,512 | —- | C] () – C:\WINDOWS\SysWow64\qcap.dll
[2005/03/25 08:00:00 | 00,114,688 | —- | C] () – C:\WINDOWS\SysWow64\msencode.dll
[2005/03/25 08:00:00 | 00,072,704 | —- | C] () – C:\WINDOWS\SysWow64\amstream.dll
[2005/03/25 08:00:00 | 00,062,464 | —- | C] () – C:\WINDOWS\SysWow64\mciqtz32.dll
[2005/03/25 08:00:00 | 00,061,440 | —- | C] () – C:\WINDOWS\SysWow64\devenum.dll
[2005/03/25 08:00:00 | 00,016,896 | —- | C] () – C:\WINDOWS\SysWow64\tsd32.dll
[2005/03/25 08:00:00 | 00,014,336 | —- | C] () – C:\WINDOWS\SysWow64\msdmo.dll
[2005/03/25 08:00:00 | 00,004,126 | —- | C] () – C:\WINDOWS\SysWow64\msdxmlc.dll
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\SysWow64\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2099/01/01 12:00:00 | 00,000,000 | -HS- | M] () – C:\WINDOWS\SysWow64\zeraseba.dll
[2009/08/10 23:41:02 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2009/08/10 20:32:14 | 00,000,496 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/10 16:18:27 | 00,359,932 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2009/08/10 15:31:06 | 00,279,461 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\gmer(2).zip
[2009/08/09 14:41:48 | 00,145,495 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\3795385154_c52a6e73ab.jpg
[2009/08/08 20:35:33 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/08 07:00:14 | 00,000,326 | —- | M] () – C:\WINDOWS\tasks\bmpnzxfh.job
[2009/08/08 06:55:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/08 06:55:42 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/08 06:46:22 | 00,000,726 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/08 06:45:48 | 03,942,048 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/08/08 05:02:06 | 00,012,720 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/07 01:30:47 | 00,278,846 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\gmer.zip
[2009/08/06 22:19:20 | 00,024,788 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\bustedtees.9577de9ebb920d053ef4f51d44843978.gif
[2009/08/06 15:33:01 | 00,000,296 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/06 11:49:10 | 00,008,627 | —- | M] () – C:\WINDOWS\SysWow64\PAV_FOG.OPC
[2009/08/05 08:58:52 | 00,002,153 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Character Builder.lnk
[2009/08/05 08:55:06 | 00,608,578 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB(2).exe
[2009/08/05 08:04:51 | 00,391,730 | —- | M] () – C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2009/08/05 07:39:21 | 20,669,2864 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35.exe
[2009/08/05 06:56:57 | 00,122,992 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\clwireg-x64.exe
[2009/08/05 06:45:31 | 02,959,376 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Administrator\Desktop\dotnetfx35setup.exe
[2009/08/05 05:06:00 | 00,060,568 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rs005.jpg
[2009/08/05 04:59:45 | 00,136,802 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\rs001.jpg
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SysWow64\drivers\mbamswissarmy.sys
[2009/08/01 17:53:22 | 00,034,473 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1380782321_30191200_414.jpg
[2009/07/29 17:58:26 | 00,608,578 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\700_DDI_CB.exe
[2009/07/29 03:01:04 | 00,000,970 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/29 00:49:09 | 00,111,104 | —- | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/28 12:44:30 | 25,368,146 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\c8932fa141d6.wmv
[2009/07/25 18:40:57 | 00,035,229 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\cooper1952.jpg
[2009/07/25 18:39:50 | 00,045,855 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1064207944_30131462_4640.jpg
[2009/07/25 18:01:30 | 00,064,417 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\6093_1184953216984_1022854898_30587081_5179701_n.jpg
[2009/07/21 20:55:48 | 00,001,666 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PoxNora.lnk
[2009/07/21 20:54:40 | 15,087,616 | —- | M] (Octopi, Inc) – C:\Documents and Settings\Administrator\Desktop\PoxNora.exe
[2009/07/21 06:17:24 | 00,047,443 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146852_337.jpg
[2009/07/21 06:16:58 | 00,044,009 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146846_8302.jpg
[2009/07/21 06:16:29 | 00,046,932 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30146813_7295.jpg
[2009/07/21 06:13:37 | 00,038,316 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30253702_5922.jpg
[2009/07/21 06:07:39 | 00,034,882 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\n1022854898_30406666_8089571.jpg
[2009/07/20 00:11:48 | 06,067,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieframe.dll
[2009/07/20 00:11:48 | 03,597,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mshtml.dll
[2009/07/20 00:11:48 | 02,452,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieapfltr.dat
[2009/07/20 00:11:48 | 01,830,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\inetcpl.cpl
[2009/07/20 00:11:48 | 01,159,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\urlmon.dll
[2009/07/20 00:11:48 | 00,991,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieframe.dll.mui
[2009/07/20 00:11:48 | 00,827,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\wininet.dll
[2009/07/20 00:11:48 | 00,671,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mstime.dll
[2009/07/20 00:11:48 | 00,477,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\mshtmled.dll
[2009/07/20 00:11:48 | 00,459,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\msfeeds.dll
[2009/07/20 00:11:48 | 00,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\html.iec
[2009/07/20 00:11:48 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iedkcs32.dll
[2009/07/20 00:11:48 | 00,380,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieapfltr.dll
[2009/07/20 00:11:48 | 00,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\dxtmsft.dll
[2009/07/20 00:11:48 | 00,268,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iertutil.dll
[2009/07/20 00:11:48 | 00,233,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\webcheck.dll
[2009/07/20 00:11:48 | 00,230,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieaksie.dll
[2009/07/20 00:11:48 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\dxtrans.dll
[2009/07/20 00:11:48 | 00,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\msrating.dll
[2009/07/20 00:11:48 | 00,161,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieakui.dll
[2009/07/20 00:11:48 | 00,153,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieakeng.dll
[2009/07/20 00:11:48 | 00,133,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\extmgr.dll
[2009/07/20 00:11:48 | 00,124,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\advpack.dll
[2009/07/20 00:11:48 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\url.dll
[2009/07/20 00:11:48 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\occache.dll
[2009/07/20 00:11:48 | 00,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieencode.dll
[2009/07/20 00:11:48 | 00,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ie4uinit.exe
[2009/07/20 00:11:48 | 00,063,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\icardie.dll
[2009/07/20 00:11:48 | 00,052,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\msfeedsbs.dll
[2009/07/20 00:11:48 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\pngfilt.dll
[2009/07/20 00:11:48 | 00,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\iernonce.dll
[2009/07/20 00:11:48 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\jsproxy.dll
[2009/07/20 00:11:48 | 00,017,408 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\corpol.dll
[2009/07/20 00:11:48 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SysWow64\ieudinit.exe
[2009/07/19 06:02:17 | 00,269,311 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\152p0l.png
[2009/07/19 05:44:21 | 00,046,825 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\ryanhead.jpg
[2009/07/19 05:41:52 | 00,050,368 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\kseniahead.jpg
[2009/07/17 03:01:24 | 00,020,516 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\null.pdf
========== LOP Check ==========
[2009/04/16 16:26:29 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data
[2008/03/04 23:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\acccore
[2009/08/08 05:02:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Azureus
[2008/11/10 20:29:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\DAEMON Tools
[2008/07/10 02:35:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\dvdcss
[2009/07/12 15:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Move Networks
[2007/11/12 01:34:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\My Games
[2009/03/30 15:48:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Panda Security
[2007/11/14 00:18:13 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Administrator\Application Data\SecuROM
[2008/02/12 22:51:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\teamspeak2
[2009/04/16 16:26:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\The Creative Assembly
[2008/10/24 21:36:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Ventrilo
[2009/03/29 22:57:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Vso
[2009/02/10 16:28:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wal-Mart Digital Photo Viewer
[2009/06/10 20:29:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/06/10 20:29:39 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2007/12/02 20:51:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/02/11 07:11:42 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/01/07 18:53:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2008/05/13 10:19:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2009/02/23 17:41:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Norton
[2009/02/23 18:21:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/03/30 15:48:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2009/05/07 06:30:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/11/10 20:11:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Redirected
[2009/06/18 09:01:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/01/03 12:32:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/03/04 23:30:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/07/09 21:41:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/08/10 20:32:14 | 00,000,496 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/08/06 15:33:01 | 00,000,296 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/08/08 07:00:14 | 00,000,326 | —- | M] () – C:\WINDOWS\Tasks\bmpnzxfh.job
[2005/03/25 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/08/08 06:55:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/08/08 06:54:48 | 00,032,286 | —- | M] () – C:\WINDOWS\Tasks\SchedLgU.Txt
========== Purity Check ==========
< End of report >