Random info - the computer runs fine after rkill, but after restart, the virus always comes back up.
OTL.Txt:
OTL logfile created on: 8/16/2010 8:40:22 AM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\James Angehr\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 55.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 187.74 Gb Total Space | 36.13 Gb Free Space | 19.25% Space Free | Partition Type: NTFS
Drive D: | 30.38 Gb Total Space | 28.53 Gb Free Space | 93.91% Space Free | Partition Type: NTFS
Drive E: | 7.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JAMESANGEHR-PC
Current User Name: James Angehr
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\James Angehr\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\ID Vault\IDVaultSvc.exe (White Sky, Inc.)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\CE\nmSvc.exe ()
PRC - C:\Program Files (x86)\CE\nmFlt.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe ()
PRC - C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe ()
PRC - C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
PRC - C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
PRC - C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarDriverAdapter_550vista.exe (Lenovo)
PRC - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe (Lenovo)
PRC - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe ()
PRC - C:\Windows\SysWOW64\IgrsSvcs.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\James Angehr\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV:
64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV:
64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV:
64bit: - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV:
64bit: - (lxeb_device) – C:\Windows\SysNative\lxebcoms.exe ( )
SRV:
64bit: - (System_Repair_UpdateMonitor) – C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe (Lenovo Group Limited)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (IDVaultSvc) – C:\Program Files (x86)\ID Vault\IDVaultSvc.exe (White Sky, Inc.)
SRV - (DDNIService) – C:\Program Files (x86)\DDNI\DIBS\DDNIService.exe (Digital Delivery Networks, Inc.)
SRV - (DDNIMSGService) – C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGService.exe (Digital Delivery Networks, Inc.)
SRV - (lxeb_device) – C:\Windows\SysWow64\lxebcoms.exe ( )
SRV - (IGRS) – C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe (Lenovo Group Limited)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (FHPService) – C:\Program Files (x86)\Lenovo\OneKey App\OneKey Recovery\FHPService.exe ()
SRV - (GameConsoleService) – C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe (WildTangent, Inc.)
SRV - (IncSvc) – C:\Windows\SysWow64\IgrsSvcs.exe (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (NwlnkFwd) – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys File not found
DRV:
64bit: - (NwlnkFlt) – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys File not found
DRV:
64bit: - (IpInIp) – C:\Windows\SysNative\DRIVERS\ipinip.sys File not found
DRV:
64bit: - (aswFsBlk) – C:\Windows\SysNative\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV:
64bit: - (aswMonFlt) – C:\Windows\SysNative\DRIVERS\aswMonFlt.sys (ALWIL Software)
DRV:
64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (ACPIVPC) – C:\Windows\SysNative\DRIVERS\AcpiVpc.sys (Lenovo Corporation)
DRV:
64bit: - (tvtumon) – C:\Windows\SysNative\DRIVERS\tvtumon.sys (Lenovo)
DRV:
64bit: - (WSVD) – C:\Windows\SysNative\drivers\WSVD.sys (CyberLink)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:
64bit: - (usbsmi) – C:\Windows\SysNative\DRIVERS\SMIksdrv.sys (SMI)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (enecir) – C:\Windows\SysNative\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV:
64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:
64bit: - (RTSTOR) – C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:
64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:
64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\DRIVERS\k57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (enecirhid) – C:\Windows\SysNative\DRIVERS\enecirhid.sys (ENE TECHNOLOGY INC.)
DRV:
64bit: - (enecirhidma) – C:\Windows\SysNative\DRIVERS\enecirhidma.sys (ENE TECHNOLOGY INC.)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\DRIVERS\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:
64bit: - (WimFltr) – C:\Windows\SysNative\DRIVERS\wimfltr.sys (Microsoft Corporation)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/07/24 19:35:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/07/24 19:35:19 | 000,000,000 | —D | M]
[2009/10/23 17:46:45 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Mozilla\Extensions
[2010/08/15 12:51:37 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions
[2010/04/26 22:20:08 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/23 19:32:52 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\James Angehr\AppData\Roaming\Mozilla\Firefox\Profiles\9wse360s.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/20 08:10:10 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark Pro200-S500 Series\ezprint.exe ()
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [lxebmon.exe] C:\Program Files (x86)\Lexmark Pro200-S500 Series\lxebmon.exe ()
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [Unattend0000000001{2F0CCE2D-26B0-45A0-90A2-BEE09B5FC562}] C:\Windows\test.bat File not found
O4:
64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4 - HKLM..\Run: [IdeaNotesUser] C:\Program Files (x86)\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe (Digital Delivery Networks, Inc.)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Lenovo SlideNav] C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe (Lenovo)
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Lenovo\MediaShow\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NMSVC] C:\Program Files (x86)\CE\nmSvc.exe ()
O4 - HKLM..\Run: [OnekeyDM] C:\Program Files (x86)\Lenovo\OnekeyDM\OnekeyDM.exe ()
O4 - HKLM..\Run: [Readycomm] C:\Program Files (x86)\Lenovo\ReadyComm\ReadyComm.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [WordPerfect Office 1215] C:\Program Files (x86)\WordPerfect Office 12\Programs\Registration.exe (Corel Corporation)
O4 - HKCU..\Run: [aqormobi] C:\Users\James Angehr\AppData\Local\mnlpsrxej\punhcdmshdw.exe ()
O4 - HKCU..\Run: [ISUSPM Startup] C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - Startup: C:\Users\James Angehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk = C:\Users\James Angehr\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:
64bit: - Extra context menu item: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: &Windows Live Search - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - File not found
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img27.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/13 18:11:22 | 000,000,073 | R— | M] () - E:\AUTORUN.INF – [ UDF ]
O33 - MountPoints2\{94a99a26-ad74-11de-9c73-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{94a99a26-ad74-11de-9c73-806e6f6e6963}\Shell\AutoRun\command - "" = E:\install.EXE id= ver=1.0.0.0 – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:
64bit: aux - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: midimapper - midimap.dll (Microsoft Corporation)
Drivers32:
64bit: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32:
64bit: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32:
64bit: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32:
64bit: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32:
64bit: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32:
64bit: wave - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32:
64bit: wavemapper - msacm32.drv (Microsoft Corporation)
Drivers32: aux - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\Windows\SysWow64\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.clmp3enc - C:\Program Files (x86)\Lenovo\Power2Go\CLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.imaadpcm - C:\Windows\SysWow64\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\Windows\SysWow64\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\Windows\SysWow64\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\Windows\SysWow64\msgsm32.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - C:\Windows\SysWow64\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - C:\Windows\SysWow64\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\Windows\SysWow64\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.uyvy - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - C:\Windows\SysWow64\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\Windows\SysWow64\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\Windows\SysWow64\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\Windows\SysWow64\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/08/13 18:33:23 | 000,000,000 | —D | C] – C:\Users\James Angehr\AppData\Roaming\Malwarebytes
[2010/08/13 18:33:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/13 18:33:10 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/13 18:33:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/13 18:33:10 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/13 11:02:43 | 000,000,000 | —D | C] – C:\Users\James Angehr\AppData\Local\mnlpsrxej
[2010/08/11 09:37:35 | 000,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/08/11 09:37:35 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/08/11 09:36:57 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/08/11 09:36:55 | 004,697,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/08/11 09:36:41 | 002,335,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iertutil.dll
[2010/08/11 09:36:39 | 000,706,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2010/08/11 09:36:39 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2010/08/11 09:36:38 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2010/08/11 09:36:36 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2010/08/11 09:36:36 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2010/08/11 09:36:36 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/08/11 09:36:36 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/08/11 09:36:36 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2010/08/11 09:36:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2010/08/11 09:36:36 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2010/08/11 09:36:36 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2010/08/11 09:36:36 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2010/08/11 09:36:36 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/08/11 09:36:35 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2010/08/11 09:36:35 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/08/11 09:36:35 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/08/11 09:36:35 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2010/08/11 09:36:35 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2010/08/11 09:36:35 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2010/08/11 09:36:35 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2010/08/11 09:36:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2010/08/11 09:36:35 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/07/18 07:52:48 | 000,000,000 | —D | C] – C:\ProgramData\Ezprint
[2010/07/17 15:14:52 | 000,796,160 | —- | C] ( ) – C:\Windows\SysNative\lxebcoin.dll
[2010/07/17 15:14:51 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lxk_g.dll
[2010/07/17 15:14:45 | 000,983,121 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lxk_gf.dll
[2010/07/17 15:14:04 | 000,510,464 | —- | C] (Lexmark International, Inc.) – C:\Windows\SysNative\LXEBwupd.dll
[2010/07/17 15:14:04 | 000,295,592 | —- | C] (Lexmark International, Inc.) – C:\Windows\SysNative\LXEBwupd.exe
[2010/07/17 15:13:30 | 000,000,000 | —D | C] – C:\Program Files\Lexmark
[2010/07/17 15:13:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lexmark Toolbar
[2010/07/17 15:13:10 | 000,000,000 | —D | C] – C:\Program Files\Lexmark Printable Web
[2010/07/17 15:13:01 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\lxebinpa.dll
[2010/07/17 15:13:01 | 000,344,064 | —- | C] ( ) – C:\Windows\SysWow64\lxebiesc.dll
[2010/07/17 15:13:01 | 000,126,976 | —- | C] (Lexmark International Inc.) – C:\Windows\SysWow64\lxeblnks.dll
[2010/07/17 15:13:00 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\lxebusb1.dll
[2010/07/17 15:13:00 | 000,651,264 | —- | C] ( ) – C:\Windows\SysWow64\lxebpmui.dll
[2010/07/17 15:12:59 | 001,056,768 | —- | C] ( ) – C:\Windows\SysWow64\lxebserv.dll
[2010/07/17 15:12:59 | 000,688,128 | —- | C] ( ) – C:\Windows\SysWow64\lxebhbn3.dll
[2010/07/17 15:12:59 | 000,602,792 | —- | C] ( ) – C:\Windows\SysWow64\lxebcoms.exe
[2010/07/17 15:12:59 | 000,581,632 | —- | C] ( ) – C:\Windows\SysWow64\lxeblmpm.dll
[2010/07/17 15:12:59 | 000,328,360 | —- | C] ( ) – C:\Windows\SysWow64\lxebih.exe
[2010/07/17 15:12:58 | 000,802,816 | —- | C] ( ) – C:\Windows\SysWow64\lxebcomc.dll
[2010/07/17 15:12:58 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\lxebcomm.dll
[2010/07/17 15:12:58 | 000,369,320 | —- | C] ( ) – C:\Windows\SysWow64\lxebcfg.exe
[2010/07/17 15:12:58 | 000,086,121 | —- | C] (Lexmark International) – C:\Windows\SysWow64\LXEBcfg.dll
[2010/07/17 15:12:45 | 001,335,808 | —- | C] ( ) – C:\Windows\SysNative\lxebusb1.dll
[2010/07/17 15:12:45 | 000,683,008 | —- | C] ( ) – C:\Windows\SysNative\LXEBhcp.dll
[2010/07/17 15:12:45 | 000,558,592 | —- | C] ( ) – C:\Windows\SysNative\lxebinpa.dll
[2010/07/17 15:12:45 | 000,515,072 | —- | C] ( ) – C:\Windows\SysNative\lxebiesc.dll
[2010/07/17 15:12:44 | 001,648,128 | —- | C] ( ) – C:\Windows\SysNative\lxebserv.dll
[2010/07/17 15:12:44 | 000,989,696 | —- | C] ( ) – C:\Windows\SysNative\lxebpmui.dll
[2010/07/17 15:12:44 | 000,899,072 | —- | C] ( ) – C:\Windows\SysNative\lxeblmpm.dll
[2010/07/17 15:12:43 | 001,107,456 | —- | C] ( ) – C:\Windows\SysNative\lxebhbn3.dll
[2010/07/17 15:12:43 | 000,527,016 | —- | C] ( ) – C:\Windows\SysNative\lxebih.exe
[2010/07/17 15:12:42 | 001,366,528 | —- | C] ( ) – C:\Windows\SysNative\lxebcomc.dll
[2010/07/17 15:12:42 | 001,054,888 | —- | C] ( ) – C:\Windows\SysNative\lxebcoms.exe
[2010/07/17 15:12:42 | 000,581,632 | —- | C] ( ) – C:\Windows\SysNative\lxebcomm.dll
[2010/07/17 15:12:41 | 000,616,104 | —- | C] ( ) – C:\Windows\SysNative\lxebcfg.exe
[2010/07/17 15:12:41 | 000,075,264 | —- | C] (Lexmark International) – C:\Windows\SysNative\LXEBcfg.dll
[2010/07/17 15:12:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lexmark Pro200-S500 Series
[2010/07/17 15:09:03 | 000,000,000 | —D | C] – C:\Program Files\Lexmark Pro200-S500 Series
[2009/07/24 09:24:50 | 001,526,576 | —- | C] (Adobe Systems Incorporated) – C:\ProgramData\flashax9f.exe
========== Files - Modified Within 30 Days ==========
[2010/08/16 08:44:01 | 003,670,016 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT
[2010/08/16 08:41:59 | 000,000,470 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{F63E9C45-0595-4274-BC88-CB38B3E9CD5F}.job
[2010/08/16 08:23:30 | 000,767,248 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/16 08:23:30 | 000,649,438 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/16 08:23:30 | 000,121,660 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/16 08:16:50 | 000,000,056 | -HS- | M] () – C:\_PartitionInfo
[2010/08/16 08:16:40 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:16:39 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/16 08:16:39 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/16 08:16:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/16 08:16:23 | 4253,650,944 | -HS- | M] () – C:\hiberfil.sys
[2010/08/15 23:52:15 | 000,524,288 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/08/15 23:52:15 | 000,065,536 | -HS- | M] () – C:\Users\James Angehr\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/08/15 23:52:09 | 001,878,094 | -H– | M] () – C:\Users\James Angehr\AppData\Local\IconCache.db
[2010/08/15 23:07:00 | 000,000,282 | —- | M] () – C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
[2010/08/14 12:21:36 | 000,359,929 | —- | M] () – C:\Users\James Angehr\Desktop\dds.scr
[2010/08/13 20:49:42 | 000,000,732 | —- | M] () – C:\Users\James Angehr\AppData\Local\d3d9caps64.dat
[2010/08/13 19:58:14 | 000,363,520 | —- | M] () – C:\Users\James Angehr\Desktop\rkill.com
[2010/08/13 18:33:16 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/12 09:26:16 | 000,470,488 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/07/17 15:17:28 | 000,225,655 | —- | M] () – C:\Windows\SysNative\LexFiles.ulf
[2010/07/17 15:13:33 | 000,001,836 | —- | M] () – C:\Users\Public\Desktop\Launch Lexmark Printer Home.LNK
========== Files Created - No Company Name ==========
[2010/08/14 12:24:52 | 000,359,929 | —- | C] () – C:\Users\James Angehr\Desktop\dds.scr
[2010/08/13 21:39:47 | 4253,650,944 | -HS- | C] () – C:\hiberfil.sys
[2010/08/13 20:19:33 | 000,000,732 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d9caps64.dat
[2010/08/13 20:03:50 | 000,363,520 | —- | C] () – C:\Users\James Angehr\Desktop\rkill.com
[2010/08/13 18:33:16 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/18 07:52:41 | 000,000,252 | —- | C] () – C:\ProgramData\FastPics.log
[2010/07/17 15:33:13 | 000,014,050 | —- | C] () – C:\ProgramData\lxebJSW.log
[2010/07/17 15:14:54 | 000,109,056 | —- | C] () – C:\Windows\SysNative\lxebvs.dll
[2010/07/17 15:14:45 | 000,065,106 | —- | C] () – C:\Windows\SysNative\lxebprpr.chm
[2010/07/17 15:14:45 | 000,065,024 | —- | C] () – C:\Windows\SysNative\lxebgcfg.dll
[2010/07/17 15:14:44 | 000,399,360 | —- | C] () – C:\Windows\SysNative\lxebcui.dll
[2010/07/17 15:14:44 | 000,148,480 | —- | C] () – C:\Windows\SysNative\lxebcuir.dll
[2010/07/17 15:14:44 | 000,008,694 | —- | C] () – C:\Windows\SysNative\lxebcommuilogo_rtl.bmp
[2010/07/17 15:14:44 | 000,008,694 | —- | C] () – C:\Windows\SysNative\lxebcommuilogo.bmp
[2010/07/17 15:14:39 | 000,009,592 | —- | C] () – C:\ProgramData\lxebscan.log
[2010/07/17 15:13:33 | 000,001,836 | —- | C] () – C:\Users\Public\Desktop\Launch Lexmark Printer Home.LNK
[2010/07/17 15:13:03 | 000,000,044 | -H– | C] () – C:\Windows\SysNative\lxebrwrd.ini
[2010/07/17 15:13:01 | 000,385,024 | —- | C] () – C:\Windows\SysWow64\LXEBinst.dll
[2010/07/17 15:13:01 | 000,344,064 | —- | C] () – C:\Windows\SysWow64\lxebcomx.dll
[2010/07/17 15:13:00 | 000,323,584 | —- | C] () – C:\Windows\SysWow64\lxebins.dll
[2010/07/17 15:13:00 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\lxebinsb.dll
[2010/07/17 15:13:00 | 000,253,952 | —- | C] () – C:\Windows\SysWow64\lxebcu.dll
[2010/07/17 15:13:00 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\lxebinsr.dll
[2010/07/17 15:13:00 | 000,090,112 | —- | C] () – C:\Windows\SysWow64\lxebcub.dll
[2010/07/17 15:13:00 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\lxebjswr.dll
[2010/07/17 15:13:00 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\lxebcur.dll
[2010/07/17 15:12:58 | 000,002,057 | —- | C] () – C:\Windows\SysWow64\lxeb.loc
[2010/07/17 15:12:46 | 000,585,216 | —- | C] () – C:\Windows\SysNative\LXEBinst.dll
[2010/07/17 15:12:46 | 000,225,655 | —- | C] () – C:\Windows\SysNative\LexFiles.ulf
[2010/07/17 15:12:43 | 000,450,048 | —- | C] () – C:\Windows\SysNative\lxebins.dll
[2010/07/17 15:12:43 | 000,298,496 | —- | C] () – C:\Windows\SysNative\lxebgrd.dll
[2010/07/17 15:12:43 | 000,245,248 | —- | C] () – C:\Windows\SysNative\lxebinsb.dll
[2010/07/17 15:12:43 | 000,090,624 | —- | C] () – C:\Windows\SysNative\lxebinsr.dll
[2010/07/17 15:12:43 | 000,040,448 | —- | C] () – C:\Windows\SysNative\lxebjswr.dll
[2010/07/17 15:12:42 | 000,378,368 | —- | C] () – C:\Windows\SysNative\lxebcu.dll
[2010/07/17 15:12:42 | 000,073,216 | —- | C] () – C:\Windows\SysNative\lxebcub.dll
[2010/07/17 15:12:42 | 000,022,016 | —- | C] () – C:\Windows\SysNative\lxebcur.dll
[2010/07/17 15:12:41 | 000,002,057 | —- | C] () – C:\Windows\SysNative\lxeb.loc
[2010/07/17 15:11:18 | 000,000,000 | —- | C] () – C:\ProgramData\LxWbGwLog.log
[2010/07/17 15:11:18 | 000,000,000 | —- | C] () – C:\ProgramData\cmn_upld.log
[2010/07/17 15:11:11 | 000,000,000 | —- | C] () – C:\ProgramData\UpdaterLog.txt
[2010/07/17 15:09:03 | 000,299,008 | —- | C] () – C:\Windows\SysWow64\LXEBsm.dll
[2010/07/17 15:09:03 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\LXEBsmr.dll
[2010/07/17 15:09:03 | 000,023,552 | —- | C] () – C:\Windows\SysNative\lxebsmr.dll
[2010/07/17 15:09:01 | 000,381,440 | —- | C] () – C:\Windows\SysNative\lxebsm.dll
[2010/06/15 19:34:39 | 000,000,680 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d9caps.dat
[2010/05/03 09:48:09 | 000,026,624 | —- | C] () – C:\Users\James Angehr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/12 20:55:23 | 000,000,552 | —- | C] () – C:\Users\James Angehr\AppData\Local\d3d8caps.dat
[2009/12/17 21:41:45 | 000,428,116 | —- | C] () – C:\Users\James Angehr\AppData\Local\dd_vcredistMSI490A.txt
[2009/12/17 21:41:45 | 000,011,472 | —- | C] () – C:\Users\James Angehr\AppData\Local\dd_vcredistUI490A.txt
[2009/12/03 09:41:39 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/03 09:40:30 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/23 13:08:03 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2009/11/05 19:03:50 | 000,002,836 | —- | C] () – C:\ProgramData\hpzinstall.log
[2009/11/05 15:54:13 | 000,061,678 | —- | C] () – C:\Users\James Angehr\AppData\Roaming\PFP120JPR.{PB
[2009/11/05 15:54:13 | 000,012,358 | —- | C] () – C:\Users\James Angehr\AppData\Roaming\PFP120JCM.{PB
[2009/11/05 10:43:18 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/11/03 11:45:55 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2009/11/03 11:45:55 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2009/11/03 11:45:55 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2009/11/03 11:45:55 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2009/11/03 11:45:55 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2009/11/03 11:45:55 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2009/10/28 11:01:22 | 000,209,920 | —- | C] () – C:\Windows\SysWow64\nmNsp.dll
[2009/10/28 11:01:22 | 000,160,256 | —- | C] () – C:\Windows\SysWow64\CESpy.dll
[2009/09/29 23:28:28 | 002,101,248 | —- | C] () – C:\Windows\SysWow64\Apblend.dll
[2009/09/29 23:27:50 | 000,057,344 | —- | C] () – C:\Windows\AsfHelper.dll
[2009/09/29 23:27:45 | 000,241,664 | —- | C] () – C:\Windows\SysWow64\3DImageRenderer.dll
[2009/09/29 23:18:59 | 000,262,144 | —- | C] () – C:\Windows\SysWow64\SBarHook.DLL
[2009/07/24 09:20:22 | 000,775,020 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2008/08/27 20:29:00 | 000,033,792 | —- | C] () – C:\Windows\SysWow64\OnekeyDM.dll
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
========== LOP Check ==========
[2010/03/19 10:15:26 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\BitTorrent
[2010/06/25 13:07:27 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Canon
[2010/08/16 08:35:09 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\CE
[2010/05/20 08:08:38 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\ID Vault
[2009/10/24 05:10:23 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\Lenovo
[2009/11/11 12:16:10 | 000,000,000 | —D | M] – C:\Users\James Angehr\AppData\Roaming\WildTangent
[2010/08/15 23:07:00 | 000,000,282 | —- | M] () – C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2010/08/15 23:52:17 | 000,032,564 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/08/16 08:41:59 | 000,000,470 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{F63E9C45-0595-4274-BC88-CB38B3E9CD5F}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/07/02 18:35:36 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2009/10/28 11:01:36 | 000,011,733 | —- | M] () – C:\ceInstall.log
[2010/08/16 08:41:41 | 001,243,000 | —- | M] () – C:\ceProcesses.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/08/16 08:16:51 | 001,867,531 | —- | M] () – C:\FaceProv.log
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2010/08/16 08:16:23 | 4253,650,944 | -HS- | M] () – C:\hiberfil.sys
[2010/08/12 09:25:47 | 000,000,520 | —- | M] () – C:\ICAutoUpdate.log.bak
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006/12/02 01:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2010/08/16 08:16:20 | 272,285,695 | -HS- | M] () – C:\pagefile.sys
[2009/09/29 23:10:08 | 000,002,096 | —- | M] () – C:\RHDSetup.log
[2010/08/16 08:37:10 | 000,000,499 | —- | M] () – C:\rkill.log
[2010/08/16 08:35:12 | 017,457,851 | —- | M] () – C:\sysiclog.txt
[2010/06/25 18:42:19 | 027,679,426 | —- | M] () – C:\sysiclog.txt.bak
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/08/16 08:16:50 | 000,000,056 | -HS- | M] () – C:\_PartitionInfo
< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/06/25 17:58:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >
< %systemroot%\*. /mp /s >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\user32.dll /md5 >
[2009/04/11 01:26:45 | 000,648,704 | —- | M] (Microsoft Corporation) MD5=D29FDB5DEDBDC1BD882164DC6DC4DD53 – C:\Windows\SysWOW64\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2008/01/20 21:50:35 | 000,179,200 | —- | M] (Microsoft Corporation) MD5=B304D47D5744BA20FCB99FB8B2C07B0B – C:\Windows\SysWOW64\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2006/11/02 04:44:30 | 000,004,608 | —- | M] (Microsoft Corporation) MD5=17C0671BF57057108A6D949510EE42C8 – C:\Windows\SysWOW64\ws2help.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >