Post Continued:
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.concast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..network.proxy.autoconfig_url: "
http://overdrive.innernet.net/overdrive.pac"
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/07/21 08:15:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AG Toolbar\Firefox\0.1 [2009/05/01 08:00:29 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/05/21 12:41:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/22 02:31:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/21 06:10:36 | 000,000,000 | —D | M]
[2008/10/23 09:24:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Extensions
[2010/07/11 20:38:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\0zeyryfe.Default User\extensions
[2005/12/11 12:30:45 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\0zeyryfe.Default User\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/07/12 04:14:35 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\0zeyryfe.Default User\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/07/11 20:38:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\0zeyryfe.Default User\extensions\[removed]
[2010/07/22 21:40:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions
[2009/11/10 20:06:28 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/07/12 03:53:04 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/16 14:11:21 | 000,000,000 | —D | M] (Firefox Sync) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}
[2010/07/20 02:15:10 | 000,000,000 | —D | M] (WeatherBug) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{3EC9C995-8072-4fc0-953E-4F30620D17F3}
[2010/02/18 10:46:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/07/12 03:53:03 | 000,000,000 | —D | M] (iMacros for Firefox) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2010/02/18 10:46:54 | 000,000,000 | —D | M] (Firefox Showcase) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2010/07/07 05:25:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{D2A6A719-7CBC-4594-85FD-C36AD881424F}
[2010/07/05 17:51:24 | 000,000,000 | —D | M] (Yoono) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{d9284e50-81fc-11da-a72b-0800200c9a66}
[2010/07/17 10:58:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/07/05 17:51:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\feedly@devhd
[2010/07/05 17:51:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\[removed]
[2010/07/05 17:51:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\ejszbwp1.Default User\extensions\feedly@devhd\content\app\extension
[2010/07/12 04:02:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\hm7vtyjs.default\extensions
[2009/07/12 18:48:13 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\hm7vtyjs.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2005/02/06 11:17:53 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\hm7vtyjs.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2005/02/06 12:46:40 | 000,000,000 | —D | M] (BBCode) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\hm7vtyjs.default\extensions\{AE37D527-6604-461c-8102-975CF8053A2F}
[2010/07/12 04:14:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Dick\Application Data\Mozilla\Firefox\Profiles\hm7vtyjs.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/07/22 21:40:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/02/25 07:27:01 | 000,000,000 | —D | M] (SDI_Integrator) – C:\Program Files\Mozilla Firefox\extensions\{9d613b03-9b7c-4fa0-b2f8-32f7cc24873f}
[2002/09/27 08:59:00 | 000,090,112 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NpPopup.dll
[2005/04/27 16:10:49 | 000,102,400 | —- | M] (RealNetworks) – C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
[2005/06/13 01:12:00 | 000,098,304 | —- | M] (SkillJam Technologies) – C:\Program Files\Mozilla Firefox\plugins\npskilljamloader.dll
[2004/01/13 22:09:25 | 000,176,176 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2009/12/05 03:20:12 | 000,223,826 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 7882 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {11359F4A-B191-42D7-905A-594F8CF0387B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKCU..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe (Ulead Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://support.microsoft.com/dcode/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1125759480093 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://www.pandasoftware.com/activescan/as5/asinst.cab (Reg Error: Key error.)
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C}
http://ak.imgag.com/imgag/cp/install/Crusher.cab (Creative Toolbox Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: CabBuilder
http://ak.imgag.com/imgag/kiw/toolbar/down…llerControl.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: PackageCab
http://ak.imgag.com/imgag/cp/install/AxCtp2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\SYSTEM32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/10 14:24:32 | 000,000,488 | —- | M] () - C:\AUTOEXEC.BAK – [ NTFS ]
O32 - AutoRun File - [2010/02/18 10:36:48 | 000,000,590 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/01/03 17:49:52 | 000,000,375 | —- | M] () - C:\AUTOEXEC.LTN – [ NTFS ]
O32 - AutoRun File - [2009/02/12 00:08:51 | 000,000,045 | R— | M] () - D:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/07/22 02:23:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\My Documents\Dick's Finances
[2010/07/16 08:05:30 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/14 16:26:09 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/12 06:49:44 | 000,000,000 | —D | C] – C:\Avenger
[2010/07/12 04:21:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\Local Settings\Application Data\AskToolbar
[2010/07/12 04:09:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\Microsoft IntelliPoint
[2010/07/11 20:38:49 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2010/07/11 20:37:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\Local Settings\Application Data\The Weather Channel
[2010/07/10 06:28:58 | 000,000,000 | —D | C] – C:\Program Files\Search Toolbar
[2010/07/09 04:52:53 | 000,000,000 | —D | C] – C:\Amazon Orders
[2010/07/07 06:31:09 | 000,000,000 | —D | C] – C:\Post 606 Website
[2010/07/07 05:53:27 | 000,674,280 | —- | C] (ScreenTime Media) – C:\WINDOWS\System32\nature_3120380.scr
[2010/07/07 05:53:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Screentime
[2010/07/07 05:52:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\Local Settings\Application Data\Screentime
[2010/07/06 03:16:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\My Documents\Todd Ryder
[2010/07/05 04:11:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\Application Data\Process Hacker
[2010/07/05 04:10:50 | 000,000,000 | —D | C] – C:\Program Files\Process Hacker
[2010/07/04 19:20:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\My Documents\emmys Documents& Pics
[2010/07/02 05:56:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Dick\My Documents\Dell Dimension E510
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[1 C:\Documents and Settings\Dick\My Documents\*.tmp files -> C:\Documents and Settings\Dick\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\Dick\*.tmp files -> C:\Documents and Settings\Dick\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/07/23 03:01:01 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/07/23 02:32:10 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/07/23 02:31:04 | 000,000,436 | —- | M] () – C:\WINDOWS\tasks\RegCure Program Check.job
[2010/07/23 02:30:52 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/23 02:30:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/07/23 02:29:42 | 009,699,328 | —- | M] () – C:\Documents and Settings\Dick\ntuser.dat
[2010/07/23 02:29:36 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Dick\NTUSER.INI
[2010/07/23 02:10:40 | 000,000,000 | —- | M] () – C:\Documents and Settings\Dick\Local Settings\Application Data\prvlcl.dat
[2010/07/23 00:33:00 | 000,000,414 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2010/07/23 00:04:14 | 000,000,022 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/07/22 18:57:24 | 062,347,514 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/07/22 18:00:01 | 000,000,440 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration.job
[2010/07/22 04:42:38 | 000,002,515 | —- | M] () – C:\Documents and Settings\Dick\Desktop\Microsoft Word.lnk
[2010/07/22 04:13:00 | 000,000,370 | —- | M] () – C:\WINDOWS\tasks\RegCure.job
[2010/07/22 02:26:40 | 000,015,143 | —- | M] () – C:\Documents and Settings\Dick\My Documents\USAA Account.docx
[2010/07/21 05:56:57 | 000,000,226 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/07/19 11:47:15 | 000,226,258 | —- | M] () – C:\Documents and Settings\Dick\My Documents\EMBARQ_WiFi_Wireless.pdf
[2010/07/19 05:24:12 | 000,000,326 | —- | M] () – C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/07/17 15:45:55 | 001,431,981 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Mr Coffee JWX27_43_56431310.pdf
[2010/07/17 10:40:27 | 000,000,022 | —- | M] () – C:\Documents and Settings\Dick\Desktop\DelIndex.BAT
[2010/07/16 08:05:33 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/16 08:05:30 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/16 08:04:22 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/16 04:47:13 | 000,150,528 | —- | M] () – C:\Documents and Settings\Dick\My Documents\One of the Better Ones.doc
[2010/07/15 04:53:55 | 000,000,264 | —- | M] () – C:\WINDOWS\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/07/12 18:28:17 | 000,261,697 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Home Association CardsNEW Page 30.docx
[2010/07/12 18:24:02 | 000,002,473 | —- | M] () – C:\Documents and Settings\Dick\Desktop\Microsoft Excel.lnk
[2010/07/12 05:32:35 | 000,026,112 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Electronic Cigarete.doc
[2010/07/12 03:56:22 | 000,001,062 | —- | M] () – C:\Documents and Settings\Dick\My Documents\cc_20100712_035614.reg
[2010/07/11 09:08:23 | 000,009,410 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Todd Ryder.xlsx
[2010/07/11 06:58:07 | 000,014,852 | —- | M] () – C:\Documents and Settings\Dick\My Documents\USAA.docx
[2010/07/10 17:03:41 | 000,258,048 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Did I Read this Right.doc
[2010/07/09 21:48:55 | 000,015,058 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Your Names to be on the check.docx
[2010/07/09 06:39:27 | 000,263,862 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Home Association CardsNEW Page 29.docx
[2010/07/08 16:39:16 | 000,262,856 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Home Association CardsNEW Page 28.docx
[2010/07/08 06:07:31 | 000,001,854 | —- | M] () – C:\Documents and Settings\Dick\My Documents\cc_20100708_060723.reg
[2010/07/08 03:57:50 | 000,124,416 | —- | M] () – C:\Documents and Settings\Dick\My Documents\BETWEEN THE U.doc
[2010/07/07 17:24:52 | 000,014,909 | —- | M] () – C:\Documents and Settings\Dick\My Documents\HOME ASSOCIATION BOARD MINUTES.docx
[2010/07/07 08:28:29 | 000,026,338 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Resume.docx
[2010/07/07 08:26:05 | 000,062,976 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Resume.doc
[2010/07/07 05:53:27 | 000,674,280 | —- | M] (ScreenTime Media) – C:\WINDOWS\System32\nature_3120380.scr
[2010/07/07 04:39:42 | 000,000,288 | -H– | M] () – C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2010/07/06 03:48:52 | 000,042,496 | —- | M] () – C:\Documents and Settings\Dick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/05 08:06:50 | 000,015,087 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Richard G.docx
[2010/07/05 05:03:30 | 000,024,980 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Brad Slaybaugh.docx
[2010/07/05 04:58:24 | 000,024,936 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Dear Tim.docx
[2010/07/05 04:31:04 | 000,003,085 | —- | M] () – C:\Documents and Settings\Dick\Desktop\Penn State.jpg
[2010/07/05 04:28:30 | 000,009,145 | —- | M] () – C:\Documents and Settings\Dick\My Documents\July 2010 Budget.xlsx
[2010/07/05 04:10:51 | 000,001,677 | —- | M] () – C:\Documents and Settings\Dick\Desktop\Process Hacker.lnk
[2010/07/04 20:37:30 | 000,021,795 | —- | M] () – C:\Documents and Settings\Dick\My Documents\Mike Carrucoli.docx
[2010/07/03 04:25:46 | 000,496,264 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/07/03 04:25:46 | 000,091,642 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/07/03 04:25:45 | 000,599,752 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/01 06:28:48 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/06/30 06:34:32 | 000,003,838 | —- | M] () – C:\Documents and Settings\Dick\My Documents\cc_20100630_063418.reg
[2010/06/23 05:46:56 | 000,062,009 | —- | M] (Portrait Displays, Inc.) – C:\WINDOWS\System32\wpfb_ati2dvaa.dll
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[1 C:\Documents and Settings\Dick\My Documents\*.tmp files -> C:\Documents and Settings\Dick\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\Dick\*.tmp files -> C:\Documents and Settings\Dick\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/22 02:26:40 | 000,015,143 | —- | C] () – C:\Documents and Settings\Dick\My Documents\USAA Account.docx
[2010/07/19 11:47:15 | 000,226,258 | —- | C] () – C:\Documents and Settings\Dick\My Documents\EMBARQ_WiFi_Wireless.pdf
[2010/07/17 15:45:54 | 001,431,981 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Mr Coffee JWX27_43_56431310.pdf
[2010/07/16 04:47:12 | 000,150,528 | —- | C] () – C:\Documents and Settings\Dick\My Documents\One of the Better Ones.doc
[2010/07/15 04:53:55 | 000,000,264 | —- | C] () – C:\WINDOWS\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/07/15 04:52:02 | 000,000,326 | —- | C] () – C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/07/12 18:28:16 | 000,261,697 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Home Association CardsNEW Page 30.docx
[2010/07/12 05:32:34 | 000,026,112 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Electronic Cigarete.doc
[2010/07/12 03:56:16 | 000,001,062 | —- | C] () – C:\Documents and Settings\Dick\My Documents\cc_20100712_035614.reg
[2010/07/11 20:39:46 | 000,000,232 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/07/11 08:41:53 | 000,009,410 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Todd Ryder.xlsx
[2010/07/11 06:58:07 | 000,014,852 | —- | C] () – C:\Documents and Settings\Dick\My Documents\USAA.docx
[2010/07/10 17:03:40 | 000,258,048 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Did I Read this Right.doc
[2010/07/09 21:48:52 | 000,015,058 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Your Names to be on the check.docx
[2010/07/09 06:14:55 | 000,263,862 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Home Association CardsNEW Page 29.docx
[2010/07/08 06:53:15 | 000,262,856 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Home Association CardsNEW Page 28.docx
[2010/07/08 06:07:26 | 000,001,854 | —- | C] () – C:\Documents and Settings\Dick\My Documents\cc_20100708_060723.reg
[2010/07/08 03:57:49 | 000,124,416 | —- | C] () – C:\Documents and Settings\Dick\My Documents\BETWEEN THE U.doc
[2010/07/07 17:23:59 | 000,014,909 | —- | C] () – C:\Documents and Settings\Dick\My Documents\HOME ASSOCIATION BOARD MINUTES.docx
[2010/07/07 08:28:28 | 000,026,338 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Resume.docx
[2010/07/07 04:37:50 | 000,000,288 | -H– | C] () – C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2010/07/06 03:20:59 | 000,080,790 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Copy of schizo19.jpg
[2010/07/06 03:20:59 | 000,079,595 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Copy of schizo21.jpg
[2010/07/06 03:20:59 | 000,073,197 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Copy of schizo22.jpg
[2010/07/05 08:06:50 | 000,015,087 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Richard G.docx
[2010/07/05 05:03:08 | 000,024,980 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Brad Slaybaugh.docx
[2010/07/05 04:58:24 | 000,024,936 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Dear Tim.docx
[2010/07/05 04:31:03 | 000,003,085 | —- | C] () – C:\Documents and Settings\Dick\Desktop\Penn State.jpg
[2010/07/05 04:27:43 | 000,009,145 | —- | C] () – C:\Documents and Settings\Dick\My Documents\July 2010 Budget.xlsx
[2010/07/05 04:10:51 | 000,001,677 | —- | C] () – C:\Documents and Settings\Dick\Desktop\Process Hacker.lnk
[2010/07/04 20:37:30 | 000,021,795 | —- | C] () – C:\Documents and Settings\Dick\My Documents\Mike Carrucoli.docx
[2010/07/04 19:07:12 | 000,002,473 | —- | C] () – C:\Documents and Settings\Dick\Desktop\Microsoft Excel.lnk
[2010/06/30 06:34:21 | 000,003,838 | —- | C] () – C:\Documents and Settings\Dick\My Documents\cc_20100630_063418.reg
[2010/04/14 08:12:46 | 000,000,130 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2010/02/18 10:31:28 | 000,000,042 | —- | C] () – C:\WINDOWS\System32\RegistryPatrolUpdates.ini
[2010/02/06 14:10:04 | 000,000,616 | —- | C] () – C:\WINDOWS\RegGenie.ini
[2010/02/06 12:22:48 | 000,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2009/08/31 15:00:22 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\WBCustomizer.dll
[2009/08/31 15:00:21 | 000,185,344 | —- | C] () – C:\WINDOWS\System32\MemWarp.dll
[2009/04/20 14:30:40 | 000,565,248 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2009/01/08 18:16:53 | 000,000,086 | —- | C] () – C:\WINDOWS\KINGCORN.INI
[2009/01/01 12:18:06 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/22 10:28:25 | 000,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2007/08/22 10:28:25 | 000,032,714 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2007/08/08 20:26:08 | 000,000,340 | —- | C] () – C:\WINDOWS\QTW.INI
[2007/03/27 10:45:22 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
[2007/03/24 03:02:51 | 000,000,027 | —- | C] () – C:\WINDOWS\AtxTCBizControl03.ini
[2005/11/17 13:57:25 | 000,000,000 | —- | C] () – C:\WINDOWS\Versabook.INI
[2005/11/17 13:15:05 | 000,027,136 | —- | C] () – C:\WINDOWS\System32\VbMCHook.dll
[2005/03/02 08:34:06 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2004/12/31 11:11:49 | 000,000,032 | —- | C] () – C:\WINDOWS\thxcfg.ini
[2004/11/27 14:34:17 | 000,000,035 | —- | C] () – C:\WINDOWS\ulead32.ini
[2004/10/18 11:02:53 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2004/07/27 18:44:36 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2004/07/22 16:36:32 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/07/19 10:34:18 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS0W.DLL
[2004/04/28 20:47:20 | 000,000,226 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/04/17 09:40:54 | 000,000,679 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/04/17 09:40:53 | 000,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/04/17 09:23:08 | 000,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/01/01 08:41:53 | 000,000,105 | —- | C] () – C:\WINDOWS\AtxTCBizPref03.ini
[2003/11/15 04:35:29 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2003/11/13 23:34:40 | 000,000,297 | —- | C] () – C:\WINDOWS\ER3.ini
[2003/10/12 23:08:31 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2003/05/24 01:14:17 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/04/15 16:12:11 | 000,000,077 | —- | C] () – C:\WINDOWS\PrintWorkShop2003LE.ini
[2003/01/28 20:17:51 | 000,016,326 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2003/01/20 22:15:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/01/20 22:08:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/01/20 22:04:52 | 000,000,890 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/01/20 21:12:16 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/12/28 00:33:36 | 000,002,129 | —- | C] () – C:\WINDOWS\lexbar.ini
[2002/12/05 19:51:00 | 000,059,392 | R— | C] () – C:\WINDOWS\streamhlp.dll
[2002/04/11 14:47:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\msmscoin.dll
[2000/07/27 01:13:02 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[1999/07/23 14:46:48 | 000,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
========== LOP Check ==========
[2009/05/01 08:00:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AGI
[2009/06/22 23:27:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/09 10:54:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/03/11 13:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2003/01/20 22:06:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2003/01/29 07:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DelFin
[2009/04/12 19:40:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2009/03/17 11:00:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/04/12 18:14:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008/12/16 16:20:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/01/05 09:46:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\POP VIEW TRAY 16
[2010/02/03 18:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/07/07 05:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screentime
[2009/04/09 10:03:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/12/21 13:33:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/11/09 19:09:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TreeCardGames
[2004/11/26 16:30:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/03/20 07:45:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/06/02 01:54:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/05/01 13:23:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\agi
[2008/02/09 12:16:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Aim
[2009/03/06 15:10:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Amazon
[2010/06/15 02:55:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Azureus
[2009/02/18 14:21:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Canneverbe_Limited
[2009/07/29 01:21:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/04/09 10:39:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\ComcastToolbar
[2004/11/26 19:59:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Common Files
[2009/01/07 13:27:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\DeepBurner
[2010/06/30 05:01:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\DisplayTune
[2009/04/12 18:18:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\DriverCure
[2009/02/18 12:27:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\GetRightToGo
[2009/06/24 08:47:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Image Zone Express
[2005/04/05 23:46:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Kazaa Lite
[2009/04/17 07:19:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Kingston
[2003/04/14 15:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Leadertech
[2010/02/22 14:55:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\NumusDiskBuilder
[2009/11/18 12:31:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Nvu
[2009/08/06 11:02:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Passware
[2009/04/20 10:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Printer Info Cache
[2010/07/05 09:03:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Process Hacker
[2004/08/18 17:32:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Systweak
[2009/05/01 08:00:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Temp
[2009/01/08 12:20:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Template
[2009/11/09 19:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\TreeCardGames
[2004/11/26 16:30:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Ulead Systems
[2010/03/07 11:33:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Uniblue
[2009/01/08 17:00:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Windows Desktop Search
[2009/01/08 17:11:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Dick\Application Data\Windows Search
[2010/07/22 18:00:01 | 000,000,440 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2010/07/23 00:33:00 | 000,000,414 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Update Version2.job
[2010/07/23 02:31:04 | 000,000,436 | —- | M] () – C:\WINDOWS\Tasks\RegCure Program Check.job
[2010/07/22 04:13:00 | 000,000,370 | —- | M] () – C:\WINDOWS\Tasks\RegCure.job
[2010/07/23 03:01:01 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2005/02/11 01:09:27 | 000,412,585 | —- | M] () – C:\ccsetup117.exe
[2008/12/16 00:50:30 | 003,889,824 | —- | M] (Comcast Cable Communications, LLC ) – C:\downloadable_install_wizard(4).exe
[2005/03/19 19:34:00 | 004,826,536 | —- | M] (Mozilla) – C:\Firefox Setup 1.0.2.exe
[2004/11/13 16:36:42 | 000,258,560 | —- | M] () – C:\ie-spyad.exe
[2005/01/15 08:43:33 | 006,537,888 | —- | M] (Microsoft Corporation ) – C:\MicrosoftAntiSpywareInstall.exe
[2005/03/12 09:11:34 | 002,513,056 | —- | M] (Javacool Software LLC ) – C:\spywareblastersetup33.exe
[2005/05/29 11:22:12 | 002,560,240 | —- | M] (Javacool Software LLC ) – C:\spywareblastersetup34.exe
[2003/04/07 01:28:28 | 000,058,368 | —- | M] (Soeperman Enterprises Ltd.) – C:\StartupList.exe
[2004/10/01 18:03:35 | 000,883,719 | —- | M] (McAfee Inc.) – C:\stinger.exe
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2009/04/07 09:43:14 | 000,496,368 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB892050-v3-x86-ENU.exe
[2009/04/07 09:43:14 | 000,051,440 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB892050-v3-x86-Symbols-ENU.exe
[2004/10/06 16:37:10 | 005,827,728 | —- | M] () – C:\zlsSetup_51_033_000.exe
[2005/02/28 09:43:52 | 006,670,952 | —- | M] () – C:\zlsSetup_55_062_011.exe
[2006/06/22 13:00:01 | 013,707,688 | —- | M] () – C:\zlsSetup_65_722_000_en.exe
< MD5 for: AGP440.SYS >
[2004/09/15 21:27:23 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2008/08/31 09:41:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2004/09/15 21:27:23 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/08/31 09:41:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DLLCACHE\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\AGP440.SYS
[2008/04/13 15:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\ReinstallBackups\0020\DriverFiles\i386\AGP440.SYS
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\ReinstallBackups\0058\DriverFiles\i386\AGP440.SYS
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 15:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2002/08/29 07:00:00 | 010,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002/08/29 07:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2004/09/15 21:27:23 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2008/08/31 09:41:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2004/09/15 21:27:23 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/08/31 09:41:48 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2002/10/16 19:31:10 | 000,087,040 | —- | M] (Microsoft Corporation) MD5=3DF589B9A15FF9EF4AA499F98C1C16D5 – C:\I386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\ReinstallBackups\0063\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\ReinstallBackups\0064\DriverFiles\i386\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002/08/29 07:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL
< MD5 for: IDECHNDR.SYS >
[2002/10/15 00:00:00 | 000,101,431 | —- | M] (Intel Corporation) MD5=7D2B8BE9E89628663C1FB571F7C34062 – C:\Program Files\intel\Intel Application Accelerator\Driver\IdeChnDr.sys
[2002/10/15 00:00:00 | 000,101,431 | —- | M] (Intel Corporation) MD5=7D2B8BE9E89628663C1FB571F7C34062 – C:\WINDOWS\SYSTEM32\DRIVERS\IdeChnDr.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2002/08/29 07:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2004/08/04 03:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002/08/29 07:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2002/09/03 10:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 10:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 10:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Dick\My Documents\spider.sav:SummaryInformation
< End of report >