Hi Tomk, Thx for the help, I have run the OTL scan and It follows: Extras.Txt OTL Extras logfile created on: 8/14/2011 8:53:04 PM - Run 1
OTL by OldTimer - Version 3.2.26.3 Folder = C:\Documents and Settings\b\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 46.06% Memory free
3.35 Gb Paging File | 2.57 Gb Available in Paging File | 76.55% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 61.53 Gb Free Space | 82.55% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 7.87 Gb Free Space | 1.69% Space Free | Partition Type: NTFS
Drive G: | 149.01 Gb Total Space | 45.18 Gb Free Space | 30.32% Space Free | Partition Type: FAT32
Computer Name: A | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [Bridge] – G:\Adobe InDesign Cs5\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\b\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\b\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Documents and Settings\b\Application Data\mjusbsp\magicJack.exe" = C:\Documents and Settings\b\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack – (magicJack L.P.)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgam.exe" = C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:AVG Alert manager – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02EED746-8C5A-43C8-BB3D-D29C8B363A4D}" = TOSHIBA Zooming Hotkey Hook
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{20EAC554-95F9-4926-8D9A-C4FF3EC44C72}" = AVG 2011
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{59FDFDFB-52FE-45B1-8A2A-A00079B07FF0}" = TOSHIBA Power Saver Driver
"{5BCA8D15-BCB6-421E-9654-238B43456A4F}" = TOSHIBA Controls Driver
"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64212898-097F-4F3F-AECA-6D34A7EF82DF}" = TOSHIBA Zooming Utility
"{695B13B2-7919-4EC5-8601-092F0D2DE069}" = AVG 2011
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142050}" = Java 2 Runtime Environment, SE v1.4.2_05
"{71D658CF-4E0D-4DA8-AA67-8C0B6F1C01FE}" = Atheros Client Utility
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{73B69C5C-87D6-471E-B695-0BD736C4B644}" = Retrospect 6.5
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for TOSHIBA
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3DDA019-40B7-491C-AC88-62B94491FE8A}" = TouchPad On/Off Utility
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}" = TOSHIBA Controls
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A89DEBCA-F743-3412-97F6-B2E489194551}" = Google Talk Plugin
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{B65F99AF-CAE1-48EA-BB88-5A410C136ED3}" = PC Backup Free Trial
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}" = WinZip 15.5
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9789BA3-4033-4D81-9B10-7EE99EFA4691}" = OpenOffice.org 1.9.79
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F9450605-65E7-45E4-B071-BD759E10F072}" = TOSHIBA Hotkey Utility
"{F9766AC1-1461-1033-B862-DF8FE1C033BE}" = Adobe InDesign CS5
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"alotToolbar" = ALOT Toolbar
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2011
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 7_is1" = AVS Video Converter 8
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"conduitEngine" = Conduit Engine
"ffdshow_is1" = ffdshow [rev 3124] [2009-11-03]
"HP Photo & Imaging" = HP Image Zone 4.2
"InstallShield_{A3DDA019-40B7-491C-AC88-62B94491FE8A}" = TouchPad On/Off Utility
"InstallShield_{F9450605-65E7-45E4-B071-BD759E10F072}" = TOSHIBA Hotkey Utility
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSNINST" = MSN
"PC Diagnostic Tool" = TOSHIBA PC Diagnostic Tool
"Power Saver" = TOSHIBA Power Saver
"QuestScan" = QuestScan 1.0 build 172 powered by FIRST SEARCH BAR
"Security Task Manager" = Security Task Manager 1.8d
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"Trillian" = Trillian
"Trusted Software Assistant_is1" = File Type Assistant
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WMFDist11" = Windows Media Format 11 runtime
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"ZoomPlayer" = Zoom Player (remove only)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"magicJack" = magicJack
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/3/2011 11:50:42 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 8/3/2011 11:50:51 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 8/4/2011 2:23:12 AM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
gcswf32.dll, version 10.3.181.36, fault address 0x003a8533.
Error - 8/5/2011 7:56:10 PM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.
Error - 8/5/2011 7:57:24 PM | Computer Name = A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 8/5/2011 11:09:01 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application YahooMessenger.exe, version 11.0.0.2009, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/5/2011 11:09:03 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application YahooMessenger.exe, version 11.0.0.2009, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/6/2011 3:18:01 PM | Computer Name = A | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 8/10/2011 12:08:02 PM | Computer Name = A | Source = Application Hang | ID = 1002
Description = Hanging application WINZIP32.EXE, version 25.0.9510.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/10/2011 12:08:41 PM | Computer Name = A | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x01be51f2.
[ System Events ]
Error - 8/11/2011 9:57:16 AM | Computer Name = A | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service ntmssvc with
arguments "-Service" in order to run the server: {D61A27C6-8F53-11D0-BFA0-00A024151983}
Error - 8/11/2011 9:59:37 AM | Computer Name = A | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 8/14/2011 9:36:13 PM | Computer Name = A | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBT service which failed
to start because of the following error: %%31
Error - 8/14/2011 9:36:13 PM | Computer Name = A | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31
Error - 8/14/2011 9:36:13 PM | Computer Name = A | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31
Error - 8/14/2011 9:36:13 PM | Computer Name = A | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31
Error - 8/14/2011 9:36:13 PM | Computer Name = A | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Avgldx86 Avgmfx86 Avgtdix Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV
SASKUTIL
SerTVOutCtlr
SrvcEKIOMngr
SrvcSSIOMngr
SrvcTPIOMngr
Tcpip
Error - 8/14/2011 9:36:58 PM | Computer Name = A | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 8/14/2011 9:37:04 PM | Computer Name = A | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 8/14/2011 10:07:53 PM | Computer Name = A | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
OTL.TXT OTL logfile created on: 8/14/2011 8:53:04 PM - Run 1
OTL by OldTimer - Version 3.2.26.3 Folder = C:\Documents and Settings\b\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 46.06% Memory free
3.35 Gb Paging File | 2.57 Gb Available in Paging File | 76.55% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 61.53 Gb Free Space | 82.55% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 7.87 Gb Free Space | 1.69% Space Free | Partition Type: NTFS
Drive G: | 149.01 Gb Total Space | 45.18 Gb Free Space | 30.32% Space Free | Partition Type: FAT32
Computer Name: A | User Name: b | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\b\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
PRC - C:\WINDOWS\system32\TCtrlIOHook.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
PRC - C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\b\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\pdf.dll ()
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\Locales\en-US.dll ()
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\icudt.dll (The ICU Project)
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\chrome.dll (Google Inc.)
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\avutil-50.dll ()
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\avformat-52.dll ()
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\avcodec-52.dll ()
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1390_0\plugins\avgxpl.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1390_0\plugins\avgnpss.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Documents and Settings\b\Local Settings\Application Data\Google\Chrome\Application\13.0.782.112\gcswf32.dll ()
MOD - C:\Program Files\AVG\AVG10\avgcorex.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
MOD - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
MOD - C:\Program Files\Malwarebytes' Anti-Malware\mbamnet.dll (Malwarebytes Corporation)
MOD - C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll (Malwarebytes Corporation)
MOD - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
MOD - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
MOD - C:\Program Files\AVG\AVG10\avgxpl.dll (AVG Technologies CZ, s.r.o.)
MOD - c:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
MOD - C:\Program Files\AVG\AVG10\avgcslx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
MOD - C:\Program Files\AVG\AVG10\avgwd.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avglngx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgcfgx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avguires.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\WINDOWS\system32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
MOD - C:\Program Files\AVG\AVG10\avgcclix.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgchjwx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avglogx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgsched.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgidpsdkx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe ()
MOD - C:\Program Files\AVG\AVG10\avgwdwsc.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgsrmx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgamnot.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgclitx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgcertx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgchclx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgam.exe (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\avgameh.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Program Files\AVG\AVG10\imsdk32.dll (Winco Sistemas)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wucltui.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wups2.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll (Microsoft Corporation)
MOD - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
MOD - C:\WINDOWS\system32\mscms.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wmvcore.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\PortableDeviceApi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wmasf.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\PortableDeviceTypes.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\TPeculiarity.dll (TOSHIBA )
MOD - C:\WINDOWS\system32\CeEKPolicy.dll (COMPAL ELECTRONIC INC.)
MOD - C:\WINDOWS\system32\CeTPPolicy.dll (COMPAL ELECTRONIC INC.)
MOD - C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
MOD - C:\WINDOWS\system32\TCtrlIOHook.exe (TOSHIBA)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\mfc42.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wzcdlg.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dsound.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dinput8.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\modemui.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\mapi32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\unimdmat.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\sti.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcrt40.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcirt.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\xmlprovi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\shfolder.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\qmgrprxy.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\riched32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\TCtrlIO.dll (TOSHIBA )
MOD - C:\WINDOWS\system32\athcfg11.dll (Atheros)
MOD - C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
MOD - C:\WINDOWS\system32\TCtrlCommon.dll (TOSHIBA Corporation)
MOD - C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\dla\tfswcres.dll (Sonic Solutions)
MOD - C:\WINDOWS\system32\tfswapi.dll (Sonic Solutions)
MOD - C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
MOD - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
MOD - C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll (ATI Technologies, Inc.)
MOD - C:\Program Files\ATI Technologies\ATI Control Panel\atrpuixx.enu (ATI Technologies, Inc.)
MOD - C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll (ATI Technologies, Inc.)
MOD - C:\WINDOWS\system32\ati2edxx.dll (ATI Technologies, Inc.)
MOD - C:\WINDOWS\system32\acs.exe ()
MOD - C:\WINDOWS\system32\AegisE5.dll (Meetinghouse Data Communications)
MOD - C:\Program Files\TOSHIBA\TOSHIBA Controls\TBtnCommon.dll (TOSHIBA Corporation)
MOD - C:\Program Files\TOSHIBA\ConfigFree\CFP2API.dll (TOSHIBA CORPORATION)
MOD - C:\Program Files\TOSHIBA\ConfigFree\VENAPI.dll (TOSHIBA)
MOD - C:\WINDOWS\system32\hpotscl.dll (Hewlett-Packard Co.)
MOD - C:\WINDOWS\system32\hpgwiamd.dll (Hewlett-Packard)
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpm310.dll (HP)
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpz2ku10.dll (HP)
MOD - C:\WINDOWS\system32\hpzsnt10.dll (HP)
MOD - C:\Program Files\TOSHIBA\ConfigFree\NDSParts.dll (TOSHIBA CORPORATION)
MOD - C:\Program Files\TOSHIBA\ConfigFree\CFUPNP.dll (TOSHIBA)
MOD - C:\Program Files\TOSHIBA\ConfigFree\NDSAPI.dll (TOSHIBA CORPORATION)
MOD - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
MOD - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\TPSMainCtl.dll (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\CpuPerf.dll (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\TPwrCfg.dll (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\TPSTrace.dll (TOSHIBA Corporation)
MOD - C:\WINDOWS\system32\TPwrReg.dll (TOSHIBA Corporation)
MOD - C:\Program Files\TOSHIBA\ConfigFree\IpAdrSet.dll (TOSHIBA CORPORATION)
MOD - C:\Program Files\TOSHIBA\ConfigFree\QCDPJ.dll (Toshiba)
MOD - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
MOD - C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
MOD - C:\Program Files\TOSHIBA\E-KEY\KeybdHook.dll (COMPAL ELECTRONIC INC.)
MOD - C:\Program Files\TOSHIBA\TouchPad\KeybdHook.dll (COMPAL ELECTRONIC INC.)
MOD - C:\Program Files\TOSHIBA\Touch and Launch\PadHook.dll ( )
MOD - C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
MOD - C:\Program Files\Apoint2K\ApCommon.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\ApMain.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\ApOthers.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Dantz\Retrospect\bdrock20.dll (Dantz Development Corporation)
MOD - C:\Program Files\Dantz\Retrospect\bdrockui.dll (Dantz Development Corporation)
MOD - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
MOD - C:\Program Files\Apoint2K\ApPad.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\ApStick.dll (ALPS Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\ApMouse.dll (ALPS Electric Co., Ltd.)
MOD - C:\Program Files\ltmoh\mohapi.dll (Agere Systems)
MOD - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
MOD - C:\Program Files\Apoint2K\ApString.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
MOD - C:\WINDOWS\system32\Vxdif.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\EzLaunch.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\EzCapt.dll (Alps Electric Co., Ltd.)
MOD - C:\Program Files\Apoint2K\ApDual.dll (Alps Electric Co., Ltd.)
MOD - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
MOD - C:\Program Files\TOSHIBA\ConfigFree\NDSNLS.dll (TOSHIBA CORPORATION)
MOD - C:\Program Files\TOSHIBA\ConfigFree\OpenProp.dll (TOSHIBA CORPORATION)
MOD - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
MOD - C:\Program Files\Apoint2K\EzAuto.dll (Alps Electric Co., Ltd.)
MOD - C:\WINDOWS\system32\msvcr70.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (RetroWDSvc) – C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
========== Driver Services (SafeList) ==========
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (TPwSav) – C:\WINDOWS\System32\DRIVERS\TPwSav.sys (TOSHIBA )
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (TCtrlIO) – C:\WINDOWS\system32\drivers\TCtrlIO.sys (TOSHIBA )
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcTPIOMngr) – C:\WINDOWS\system32\drivers\TPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SerTVOutCtlr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ESMCR) – C:\WINDOWS\system32\drivers\ESM7SK.sys (ENE Technology Inc.)
DRV - (EMSCR) – C:\WINDOWS\system32\drivers\EMS7SK.sys (ENE Technology Inc.)
DRV - (ESDCR) – C:\WINDOWS\system32\drivers\ESD7SK.sys (ENE Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (caboagp) – C:\WINDOWS\system32\DRIVERS\atisgkaf.sys (ATI Technologies Inc.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (TBiosDrv) – C:\WINDOWS\system32\drivers\Tbiosdrv.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://dts.search-results.com/sidebar.html…mp;systemid=406
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\b\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\b\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\b\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/08/09 12:01:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/08/09 12:01:40 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (ALOT Toolbar Helper) - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\alot.dll (Vertro)
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - Reg Error: Value error. File not found
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Vertro)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Trillian Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\system32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [WD Button Manager] C:\WINDOWS\System32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\system32\ZoomingHook.exe (TOSHIBA)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (c:\progra~1\window~4\datamngr\datamngr.dll) - c:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (c:\progra~1\window~4\datamngr\iebho.dll) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\b\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\b\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/02 00:19:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/08/10 17:24:23 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2011/08/10 09:07:50 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\PriceGong
[2011/08/10 08:27:58 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/08/10 07:32:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2011/08/10 07:32:16 | 000,000,000 | —D | C] – C:\Program Files\Security Task Manager
[2011/08/10 07:24:24 | 000,000,000 | —D | C] – C:\Program Files\Hijack This
[2011/08/09 17:28:46 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Mozilla
[2011/08/06 19:20:48 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\SUPERAntiSpyware.com
[2011/08/06 19:20:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/08/06 19:20:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/08/06 19:20:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/08/06 19:20:18 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/08/06 12:58:11 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Malwarebytes
[2011/08/06 12:58:01 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/08/06 12:58:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/06 12:58:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/08/06 12:57:57 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/08/06 12:57:57 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/08/05 21:24:45 | 000,000,000 | —D | C] – C:\Program Files\QuestScan
[2011/08/05 21:24:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/08/05 18:09:38 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/08/05 16:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/08/05 16:55:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/08/05 16:53:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/08/05 08:07:10 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Bandoo
[2011/08/05 08:07:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/08/04 17:03:38 | 000,000,000 | —D | C] – C:\Program Files\Graboid
[2011/08/04 16:52:42 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\vlc
[2011/08/04 16:49:51 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\Ilivid Player
[2011/08/04 16:47:45 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\searchqutoolbar
[2011/08/04 16:47:37 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/08/04 16:47:05 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\PackageAware
[2011/08/03 18:29:44 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\Unity
[2011/08/03 17:21:36 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\Unity
[2011/08/02 11:09:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Yahoo! Messenger
[2011/08/02 11:09:00 | 000,014,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/08/02 08:49:00 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Desktop\Greg_s Resume
[2011/07/28 17:39:18 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\U3
[2011/07/27 12:15:50 | 000,000,000 | —D | C] – C:\Program Files\GameHouse
[2011/07/20 11:52:19 | 000,000,000 | —D | C] – C:\Documents and Settings\b\My Documents\Scaffold Handbook_files
[2011/07/20 10:09:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/07/20 10:07:51 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/07/20 10:00:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2011/07/20 10:00:42 | 000,000,000 | —D | C] – C:\Program Files\SAMSUNG
[2011/07/20 09:58:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/07/20 09:58:19 | 000,000,000 | —D | C] – C:\Program Files\REALTEK Semiconductor Corp
[2011/07/17 15:33:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/07/17 15:33:42 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\Adobe
[2011/07/17 14:57:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe
[2011/07/17 14:57:34 | 000,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2011/07/17 14:38:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/07/17 13:59:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2011/07/16 17:41:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/07/16 12:36:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Uniblue
[2011/07/16 12:34:52 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\WinZip
[2011/07/16 12:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\OpenCandy
[2011/07/16 12:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\OpenCandy
[2011/07/16 12:34:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2011/07/16 12:34:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/07/16 12:34:04 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2011/07/16 12:14:08 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Start Menu\Programs\AVS4YOU
[2011/07/16 12:13:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVS4YOU
[2011/07/16 12:13:24 | 010,833,920 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\libmfxsw32.dll
[2011/07/16 12:13:23 | 010,915,840 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\libmfxhw32.dll
[2011/07/16 11:55:46 | 000,000,000 | —D | C] – C:\extensions
[2011/07/16 11:55:45 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/07/16 11:55:43 | 000,000,000 | —D | C] – C:\Program Files\ConduitEngine
[2011/07/16 11:55:43 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\ConduitEngine
[2011/07/16 11:55:43 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\BitTorrentBar
[2011/07/16 11:55:42 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Local Settings\Application Data\Conduit
[2011/07/16 11:55:41 | 000,000,000 | —D | C] – C:\Program Files\BitTorrentBar
[2011/07/16 11:55:39 | 000,000,000 | —D | C] – C:\Program Files\BitTorrent
[2011/07/16 11:54:23 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\BitTorrent
[2011/07/16 11:37:43 | 000,000,000 | R–D | C] – C:\Documents and Settings\b\My Documents\My Videos
[2011/07/16 11:37:40 | 000,000,000 | —D | C] – C:\Documents and Settings\b\Application Data\AVS4YOU
[2011/07/16 11:36:23 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVSMedia
[2011/07/16 11:36:11 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\umdf
[2011/07/16 11:35:19 | 000,000,000 | —D | C] – C:\55bbda32bf0df8748e7983a176b6
[2011/07/16 11:34:51 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2011/07/16 11:33:56 | 001,700,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\GdiPlus.dll
[2011/07/16 11:33:56 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml3a.dll
[2011/07/16 11:33:56 | 000,000,000 | —D | C] – C:\Program Files\AVS4YOU
[2011/07/16 11:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2011/04/07 18:46:24 | 000,028,672 | —- | C] ( ) – C:\WINDOWS\System32\ControlACS.exe
[2004/09/02 00:03:29 | 000,131,072 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/14 20:25:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006UA.job
[2011/08/14 20:25:00 | 000,000,910 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-495781045-3759577209-3036343489-1006Core.job
[2011/08/14 20:20:00 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/14 20:01:00 | 000,000,226 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/08/14 19:15:17 | 128,059,913 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/08/14 19:09:46 | 000,000,872 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/14 19:09:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/14 19:09:40 | 1609,617,408 | -HS- | M] () – C:\hiberfil.sys
[2011/08/14 18:35:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/10 17:24:09 | 110,424,064 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/08/10 09:09:20 | 000,061,952 | —- | M] () – C:\Documents and Settings\b\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/10 08:26:15 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-A-b.job
[2011/08/09 17:27:14 | 000,002,263 | —- | M] () – C:\Documents and Settings\b\Desktop\Google Chrome.lnk
[2011/08/09 17:27:14 | 000,002,241 | —- | M] () – C:\Documents and Settings\b\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/08/09 12:01:58 | 000,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/08/06 19:20:23 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/08/06 15:08:26 | 000,130,508 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/08/06 12:58:01 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/05 21:24:47 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\06807e882eed5f29381fe74271ecdccf_c
[2011/08/02 18:26:50 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/08/02 15:59:15 | 000,000,152 | -HS- | M] () – C:\WDRetrospect.dat
[2011/08/02 11:09:36 | 000,000,829 | —- | M] () – C:\Documents and Settings\b\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/08/02 11:09:36 | 000,000,811 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/07/27 12:56:10 | 000,000,515 | —- | M] () – C:\Documents and Settings\b\Desktop\Shortcut to eroticxray.lnk
[2011/07/20 11:52:19 | 000,707,522 | —- | M] () – C:\Documents and Settings\b\My Documents\Scaffold Handbook.htm
[2011/07/19 18:22:21 | 000,001,868 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MSN Installer.lnk
[2011/07/17 18:58:32 | 003,422,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/16 12:34:38 | 000,001,743 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/07/16 12:14:10 | 000,000,957 | —- | M] () – C:\Documents and Settings\b\Desktop\AVS4YOU Software Navigator.lnk
[2011/07/16 12:13:40 | 000,000,901 | —- | M] () – C:\Documents and Settings\b\Desktop\AVS Video Converter.lnk
[2011/07/16 11:55:39 | 000,000,661 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2011/07/16 11:36:21 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/16 11:36:16 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/14 19:15:17 | 128,059,913 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/08/14 19:09:40 | 1609,617,408 | -HS- | C] () – C:\hiberfil.sys
[2011/08/10 08:26:15 | 000,000,334 | —- | C] () – C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-A-b.job
[2011/08/06 19:20:23 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/08/06 15:08:25 | 000,130,508 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/08/06 12:58:01 | 000,000,795 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/05 21:24:47 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\06807e882eed5f29381fe74271ecdccf_c
[2011/08/05 16:55:50 | 000,000,701 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/08/02 15:59:15 | 000,000,152 | -HS- | C] () – C:\WDRetrospect.dat
[2011/08/02 11:09:36 | 000,000,829 | —- | C] () – C:\Documents and Settings\b\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2011/08/02 11:09:36 | 000,000,811 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2011/07/27 12:56:10 | 000,000,515 | —- | C] () – C:\Documents and Settings\b\Desktop\Shortcut to eroticxray.lnk
[2011/07/20 11:52:09 | 000,707,522 | —- | C] () – C:\Documents and Settings\b\My Documents\Scaffold Handbook.htm
[2011/07/20 10:08:09 | 000,000,876 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/20 10:08:08 | 000,000,872 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/19 18:22:21 | 000,001,868 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MSN Installer.lnk
[2011/07/17 15:17:27 | 000,000,563 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe InDesign CS5.lnk
[2011/07/17 15:01:17 | 000,000,545 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge CS5.lnk
[2011/07/17 14:59:43 | 000,000,943 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Media Encoder CS5.lnk
[2011/07/17 14:38:59 | 000,000,665 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2011/07/17 14:38:34 | 000,001,155 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2011/07/17 14:38:12 | 000,000,739 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Help.lnk
[2011/07/17 14:15:59 | 000,000,734 | —- | C] () – C:\Documents and Settings\b\Desktop\hosts
[2011/07/16 12:34:38 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2011/07/16 12:14:10 | 000,000,957 | —- | C] () – C:\Documents and Settings\b\Desktop\AVS4YOU Software Navigator.lnk
[2011/07/16 12:13:40 | 000,000,901 | —- | C] () – C:\Documents and Settings\b\Desktop\AVS Video Converter.lnk
[2011/07/16 11:55:39 | 000,000,661 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2011/06/25 10:49:57 | 000,103,509 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2011/06/25 10:49:57 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2011/06/01 20:57:08 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/06/01 20:57:08 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/06/01 17:27:15 | 000,061,952 | —- | C] () – C:\Documents and Settings\b\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 07:40:39 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/22 13:21:22 | 000,000,113 | —- | C] () – C:\WINDOWS\(null)toolkit.ini
[2011/04/07 18:46:24 | 000,241,664 | —- | C] () – C:\WINDOWS\System32\ControlWZCS.exe
[2011/04/07 18:46:23 | 000,218,003 | —- | C] () – C:\WINDOWS\dssec.dat
[2011/04/07 18:46:23 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2011/04/07 18:46:23 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2011/04/07 18:33:17 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2011/04/07 18:33:17 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2011/04/07 18:33:17 | 000,010,165 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2011/04/07 18:33:17 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2011/04/07 18:32:33 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2004/09/02 10:15:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/09/02 09:33:41 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/09/02 09:13:04 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2004/09/02 09:12:35 | 000,045,163 | —- | C] () – C:\WINDOWS\System32\javaw.exe
[2004/09/02 09:12:35 | 000,045,161 | —- | C] () – C:\WINDOWS\System32\java.exe
[2004/09/02 09:10:55 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/09/02 09:10:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/09/02 09:10:04 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/09/02 09:10:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/09/02 09:10:04 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/09/02 09:10:04 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/09/02 09:10:04 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/09/02 09:06:23 | 000,000,000 | —- | C] () – C:\WINDOWS\TPTray.INI
[2004/09/02 00:30:55 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2004/09/02 00:30:40 | 000,356,352 | —- | C] () – C:\WINDOWS\System32\EMCRI.dll
[2004/09/02 00:28:11 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/09/02 00:28:11 | 000,001,048 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2004/09/02 00:28:11 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\alcxhweq.dat
[2004/09/02 00:23:18 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/09/02 00:21:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/09/02 00:17:12 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/09/02 00:03:29 | 000,385,024 | —- | C] () – C:\WINDOWS\System32\ati2evxx.exe
[2004/09/02 00:03:29 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2004/09/02 00:02:55 | 000,002,388 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/09/02 00:02:26 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/09/02 00:02:26 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/02 00:02:23 | 000,380,918 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/09/02 00:02:23 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/09/02 00:02:23 | 000,053,166 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/09/02 00:02:23 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/09/02 00:02:23 | 000,004,631 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/09/02 00:02:21 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/09/02 00:02:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/09/02 00:02:16 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/09/02 00:02:16 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/09/02 00:02:10 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/09/02 00:02:03 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/09/01 17:12:06 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/01 17:11:14 | 003,422,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/07/12 07:18:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
========== LOP Check ==========
[2011/08/06 19:20:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/08/05 16:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/08/05 21:29:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/08/05 08:07:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/04/09 09:22:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/10 22:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2011/08/05 16:47:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/07/11 16:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2011/08/05 21:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuestScan
[2011/07/17 15:33:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/07/17 13:41:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2011/07/20 09:58:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/08/10 07:34:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2011/06/01 20:56:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/07/16 12:34:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/06/01 20:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\alot
[2011/04/09 09:24:04 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\AVG10
[2011/08/05 08:07:10 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Bandoo
[2011/07/29 12:36:05 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\BitTorrent
[2011/08/10 08:27:58 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2004/09/02 09:08:28 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\InterTrust
[2011/06/04 21:11:41 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\InterVideo
[2011/05/25 20:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\mjusbsp
[2011/07/16 12:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\OpenCandy
[2011/08/03 07:51:33 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\OpenOffice.org1.9.79
[2011/08/10 09:07:50 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\PriceGong
[2011/08/04 16:47:46 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\searchqutoolbar
[2004/09/02 09:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\toshiba
[2011/04/22 13:18:28 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Trillian
[2011/08/03 18:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\b\Application Data\Unity
[2011/04/07 18:45:57 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 1.job
[2011/08/14 20:01:00 | 000,000,226 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/09/02 00:19:26 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/04/07 18:46:00 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/09/02 00:19:26 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/08/14 19:09:40 | 1609,617,408 | -HS- | M] () – C:\hiberfil.sys
[2004/09/02 00:19:26 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2004/09/02 00:19:26 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 05:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/08/14 19:09:39 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/08/14 19:10:04 | 001,348,760 | —- | M] () – C:\TPSLog.txt
[2011/08/02 15:59:15 | 000,000,152 | -HS- | M] () – C:\WDRetrospect.dat
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/09/02 00:18:47 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2003/10/22 23:17:52 | 000,053,248 | —- | M] (TOSHIBA) – C:\WINDOWS\cfdemo.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/09/01 17:10:54 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/09/01 17:10:54 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/09/01 17:10:54 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2004/09/02 00:19:34 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2011/04/07 18:49:54 | 000,001,763 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\PC Backup Free Trial.lnk
[2004/09/02 00:19:34 | 000,001,607 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2004/09/02 00:19:34 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2004/09/02 00:19:34 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2004/08/29 23:40:17 | 000,016,384 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-10 18:41:31
< End of report >
Thx for the help, I know my system may be beyond help and am resigned to a complete reinstall but find that option a real pain, If it is salvageable I would sooner save what I have. Thx again, Jason