This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus removal

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am helping my dad who received a email this evening and when he clicked on it his computer went blank. All programs and files are no longer there. Any help with this please

I am helping my dad who received a email this evening and when he clicked on it his computer went blank. All programs and files are no longer there. Any help with this please

sorry the name of the virus is boot.tidserve
Hi jeffkush,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


If this is a Vista or Win7 machine instead of double clicking the file to run it you need to rigght click the file and click "Run as Adminstrtor"


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Next

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • both OTL logs
  • aswMBR log
  • MBR.zip (attached)
OTL logfile created on: 10/6/2011 4:30:50 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 82.40% Memory free
5.09 Gb Paging File | 4.57 Gb Available in Paging File | 89.69% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 53.00 Gb Free Space | 22.76% Space Free | Partition Type: NTFS
Drive F: | 37.21 Gb Total Space | 20.26 Gb Free Space | 54.45% Space Free | Partition Type: NTFS
Drive G: | 124.72 Mb Total Space | 28.69 Mb Free Space | 23.00% Space Free | Partition Type: FAT

Computer Name: ARNIE-30F18ED3E | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\PC Tools Security\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\PC Tools Security\avengine\sdkBSCtrl.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Replay Converter 3\ffdshow.ax ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Common Files\Sonic Shared\SonicHDDemuxer.dll ()
MOD - C:\Program Files\Replay Converter 3\ac3filter.ax ()


========== Win32 Services (SafeList) ==========

SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Application Updater) – C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (Roxio UPnP Renderer 9) – C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe (Sonic Solutions)
SRV - (Roxio Upnp Server 9) – C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe (Sonic Solutions)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (MGABGEXE) – C:\WINDOWS\system32\mgabg.exe (Matrox Graphics Inc.)
SRV - (Pml Driver) – C:\WINDOWS\system32\hphipm09.exe (HP)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110930.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110930.002\NAVENG.SYS (Symantec Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TFSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\WINDOWS\system32\drivers\RxFilter.sys (Sonic Solutions)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (G400DH) – C:\WINDOWS\system32\drivers\g400dhm.sys (Matrox Graphics Inc.)
DRV - (Dot4 HPH09) – C:\WINDOWS\system32\drivers\hphid409.sys (HP)
DRV - (Dot4Storage HPH09) Storage Class Driver for IEEE-1284.4 (HPH09) – C:\WINDOWS\system32\drivers\hphs2k09.sys (Hewlett-Packard)
DRV - (Dot4Usb HPH09) – C:\WINDOWS\system32\drivers\hphius09.sys (HP)
DRV - (Dot4Print HPH09) – C:\WINDOWS\system32\drivers\hphipr09.sys (HP)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (G400) – C:\WINDOWS\system32\drivers\G400m.sys (Matrox Graphics Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BC D7 3D 2C AB 2E CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/aolcom/search?invocationType=tb50ffTB50CLie7&query;="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ask.com?o=15866&l;=dis"
FF - prefs.js..extensions.enabledItems: {7affbfae-c4e2-4915-8c0f-00fa3ec610a1}:5.13.15.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019
FF - prefs.js..extensions.enabledItems: [removed]:4.3
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:4.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src;=kw&tb;=MP3R7&o;=15863&locale;=en_US&apn;_uid=A8966E22-90C3-473D-A799-DBBE457B7670&apn;_ptnrs=RV&apn;_sauid=938D82DC-FCCB-492F-BD0C-6751545AE601&apn;_dtid=YYYYYYYYUS&q;="
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=302398&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=302398&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKEY_LOCAL_MACHINE\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/17 18:07:43 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Google\Web Accelerator\firefox [2010/12/19 14:36:47 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011/10/06 00:37:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKEY_CURRENT_USER\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/17 18:07:43 | 000,000,000 | -H-D | M]

[2009/03/10 08:50:49 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Extensions
[2009/03/10 08:50:49 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Extensions\[removed]
[2011/02/28 09:15:04 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions
[2009/08/10 14:17:37 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/04/29 07:48:20 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/10/06 18:15:16 | 000,000,000 | -H-D | M] (AOL Toolbar) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2011/03/29 18:26:11 | 000,000,000 | -H-D | M] (Default Manager) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\DefaultManager@Microsoft
[2011/09/21 15:02:16 | 000,000,000 | -H-D | M] (Ask Toolbar) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\[removed]
[2010/10/06 22:15:11 | 000,000,628 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\searchplugins\aol-search.xml
[2011/02/28 09:15:52 | 000,002,569 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\searchplugins\askcom.xml
[2011/08/27 23:58:26 | 000,000,000 | -H-D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/03/31 08:32:51 | 000,000,000 | -H-D | M] ("searchme") – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/31 08:28:12 | 000,000,000 | -H-D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/07/12 12:33:56 | 000,012,800 | -H– | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2009/03/13 05:39:56 | 000,002,494 | -H– | M] () – C:\Program Files\mozilla firefox\searchplugins\searchme.xml

O1 HOSTS File: ([2009/06/28 16:58:30 | 000,000,736 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDFViewerPlus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (&Google; Web Accelerator Helper) - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CXMon] C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Roxio\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP)
O4 - HKLM..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [ktql] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\yqujqs.t, nnkf File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Matrox Powerdesk] C:\WINDOWS\System32\PDesk\PDesk.exe (Matrox Graphics Inc.)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" File not found
O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDFViewerPlus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [rhmmmp] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\rbuxp.n, hvrc File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [smsj] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\ifuolvt.l, ocjv File not found
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [wvjfk] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\gijkikp.f, fgrk File not found
O4 - HKCU..\Run: [AROReminder] C:\Program Files\ARO 2011\aro.exe (Support.com)
O4 - HKCU..\Run: [DIDfuRcLeJEc.exe] C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe File not found
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKCU..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [nXBPpaqQtFIXr.exe] C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe File not found
O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files\Nuance\PDFViewerPlus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] http in Trusted sites)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1220381305515 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.3.1/…-131_02-win.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.3.1/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/…-131_02-win.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://elementtrading.webex.com/client/T27…ing/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{459989CA-C2A5-45F5-AF05-09CE68B27685}: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (nvdesk32.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (ows\s) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/09/01 17:02:27 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/09/03 10:59:58 | 000,000,000 | -H– | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{2f31da03-1f7f-11e0-9106-00038a000015}\Shell\AutoRun\command - "" = I:\Get_Started_for_Win.exe
O33 - MountPoints2\{4546ecee-b7d4-11dd-8096-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4546ecee-b7d4-11dd-8096-00038a000015}\Shell\AutoRun\command - "" = J:\autorun.exe
O33 - MountPoints2\{4546ecee-b7d4-11dd-8096-00038a000015}\Shell\phone\command - "" = J:\autorun.exe
O33 - MountPoints2\{4546ecef-b7d4-11dd-8096-00038a000015}\Shell\AutoRun\command - "" = K:\magicJack\autorun.exe
O33 - MountPoints2\{4546ecef-b7d4-11dd-8096-00038a000015}\Shell\phone\command - "" = K:\magicJack\autorun.exe
O33 - MountPoints2\{4f557501-86b4-11dd-8072-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{4f557501-86b4-11dd-8072-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4f557501-86b4-11dd-8072-00038a000015}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/10/06 16:26:24 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\OTL.exe
[2011/10/06 09:08:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/10/06 09:08:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/06 08:59:26 | 062,844,048 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe
[2011/10/06 08:59:07 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/10/06 08:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Sammsoft
[2011/10/06 08:54:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ARO 2011
[2011/10/06 08:54:04 | 000,000,000 | —D | C] – C:\Program Files\ARO 2011
[2011/10/06 00:37:33 | 000,184,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2011/10/06 00:37:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/10/06 00:25:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Threat Expert
[2011/10/05 23:50:50 | 000,069,392 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/10/05 23:50:48 | 000,033,552 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/10/05 23:50:43 | 000,051,984 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/10/05 23:48:34 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Recent
[2011/10/05 22:46:48 | 002,189,264 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/10/05 22:46:48 | 002,000,848 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll1047.old
[2011/10/05 22:46:48 | 002,000,848 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll1000.old
[2011/10/05 22:46:48 | 001,533,904 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/10/05 22:46:48 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll1047.old
[2011/10/05 22:46:48 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll1000.old
[2011/10/05 22:46:48 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/10/05 22:20:30 | 000,656,320 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2011/10/05 22:20:30 | 000,338,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/10/05 22:20:30 | 000,252,712 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011/10/05 22:20:28 | 000,326,688 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2011/10/05 22:20:28 | 000,162,200 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011/10/05 22:20:24 | 000,070,664 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2011/10/05 22:20:16 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2011/10/05 22:20:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/10/05 22:20:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\PC Tools
[2011/10/05 22:07:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/10/04 20:07:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Data Restore
[2011/10/04 20:05:23 | 000,347,136 | -H– | C] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe.pctools
[2011/10/04 19:51:47 | 000,466,432 | -H– | C] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe.pctools
[2011/10/04 19:50:39 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Calculations_#76046
[2011/09/19 20:25:03 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/09/18 13:31:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\monitor
[2011/09/18 13:30:46 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\2009 Balcony Assessment 500K
[2011/09/18 13:29:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\WT500
[2011/09/18 13:29:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\SKMBT_50009051410550
[2011/09/18 13:29:44 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\SKMBT_50009041808260
[2011/09/18 13:29:44 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Radzinsky
[2011/09/18 13:29:06 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Pictures
[2011/09/18 13:20:03 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Office 2007
[2010/08/20 20:39:00 | 000,081,408 | -H– | C] (Microsoft Corporation) – C:\Program Files\taskkill.exe
[2008/09/02 22:27:27 | 000,047,360 | -H– | C] (VSO Software) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pcouffin.sys
[2008/09/01 18:20:27 | 000,065,536 | -H– | C] ( ) – C:\WINDOWS\System32\A3d.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/06 16:25:46 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\OTL.exe
[2011/10/06 16:20:59 | 000,002,206 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/06 16:20:10 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/06 09:10:38 | 000,000,896 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/06 09:01:08 | 062,844,048 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe
[2011/10/06 08:54:08 | 000,001,525 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Check PC For Errors.lnk
[2011/10/06 08:54:08 | 000,001,525 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2011/10/06 01:31:33 | 000,105,025 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\history.html
[2011/10/06 00:37:34 | 000,001,664 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2011/10/06 00:35:39 | 000,512,992 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup[1].exe
[2011/10/06 00:22:06 | 000,000,900 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/05 23:42:09 | 000,729,390 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/10/05 22:12:10 | 000,512,992 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup_revwire207.exe
[2011/10/05 22:02:01 | 000,000,250 | -H– | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/10/05 07:20:01 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/05 04:43:42 | 000,518,144 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe.pctools
[2011/10/04 22:12:35 | 000,000,853 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Restore.lnk
[2011/10/04 20:22:28 | 000,000,432 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.pctool
[2011/10/04 20:07:44 | 000,000,288 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjk.pctools
[2011/10/04 20:07:43 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjkr.pctools
[2011/10/04 20:07:30 | 000,000,835 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Data Restore.lnk
[2011/10/04 20:05:23 | 000,347,136 | -H– | M] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe.pctools
[2011/10/04 19:51:02 | 000,466,432 | -H– | M] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe.pctools
[2011/10/04 19:50:39 | 000,031,150 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Calculations_#76046.zip
[2011/10/04 13:43:11 | 000,002,608 | -H– | M] () – C:\WINDOWS\System32\d3d9caps.dat.pctools
[2011/10/03 06:37:00 | 000,000,472 | -H– | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/09/19 08:12:19 | 000,000,000 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\.googlewebacchosts
[2011/09/18 08:18:31 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/09/17 12:58:06 | 000,000,410 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Shortcut to Favorites.lnk
[2011/09/15 03:02:50 | 000,001,374 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2011/09/11 07:56:02 | 000,001,050 | -H– | M] () – C:\WINDOWS\tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job
[2011/09/09 05:12:13 | 000,599,040 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/06 08:54:08 | 000,001,525 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Check PC For Errors.lnk
[2011/10/06 08:54:08 | 000,001,525 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2011/10/06 01:31:33 | 000,105,025 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\history.html
[2011/10/06 00:37:34 | 000,001,664 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2011/10/06 00:35:41 | 000,512,992 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup[1].exe
[2011/10/05 23:40:34 | 000,729,390 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/10/05 22:46:48 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll1047.old
[2011/10/05 22:46:48 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll1000.old
[2011/10/05 22:46:48 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/10/05 22:46:48 | 000,002,125 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/10/05 22:46:48 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/10/05 22:46:48 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/10/05 22:46:48 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/10/05 22:07:27 | 000,512,992 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup_revwire207.exe
[2011/10/05 00:56:11 | 000,518,144 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe.pctools
[2011/10/04 22:12:34 | 000,000,853 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Restore.lnk
[2011/10/04 20:07:43 | 000,000,216 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjkr.pctools
[2011/10/04 20:07:41 | 000,000,288 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjk.pctools
[2011/10/04 20:07:29 | 000,000,835 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Data Restore.lnk
[2011/10/04 20:06:50 | 000,000,432 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.pctool
[2011/10/04 19:50:38 | 000,031,150 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Calculations_#76046.zip
[2011/09/18 13:29:52 | 000,478,564 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\12 Technical Indicators.pdf
[2011/09/18 13:20:03 | 004,308,230 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Trade For Life.pdf
[2011/09/18 13:19:58 | 003,796,115 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Swing-Position Day Trade.pdf
[2011/09/18 13:19:54 | 003,852,393 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\State Farm 2008.pdf
[2011/09/18 13:19:54 | 000,636,141 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Swing Trading Essentials with Jon Markman.pdf
[2011/09/18 13:19:50 | 001,916,535 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Profitable Set-ups for Volatile Markets.pdf
[2011/09/18 13:19:50 | 000,118,297 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\SKMBT_50009041808260.zip
[2011/09/18 13:19:48 | 003,291,789 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Position-Swing-Day Trade.pdf
[2011/09/18 13:19:44 | 004,979,587 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\New Tactics in Technical Analysis.pdf
[2011/09/18 13:19:39 | 000,220,089 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\mastering candlesticks !.pdf
[2011/09/18 13:19:38 | 000,270,121 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Mastering Candlestick Charts Part II.pdf
[2011/09/18 13:19:38 | 000,167,015 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\LEAPS Strategies with Jon Najarian.pdf
[2011/09/18 13:19:38 | 000,084,164 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\KUSHNER.pdf
[2011/09/18 13:19:37 | 000,999,706 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\John L. Person candlestick charting.pdf
[2011/09/18 13:19:36 | 003,513,202 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Jeff Cooper Intraday.pdf
[2011/09/18 13:19:33 | 000,500,242 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Intra–day Market Internals IInternals.pdf
[2011/09/18 13:19:32 | 000,109,269 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Garraway Dismissal letter.pdf
[2011/09/18 13:19:32 | 000,047,214 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Garrawayv.Winston.pdf
[2011/09/18 13:19:31 | 004,246,442 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Gap-Guerilla Trading 2.pdf
[2011/09/18 13:19:27 | 004,005,645 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Gap & Guerilla Trading 1.pdf
[2011/09/18 13:19:23 | 001,144,381 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\FirstNoticeSouthTower.pdf
[2011/09/18 13:19:15 | 006,946,381 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Essential Strategies to Trade for Life.pdf
[2011/09/18 13:19:14 | 003,767,446 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\DVR MANUEL.pdf
[2011/09/18 13:19:10 | 000,823,918 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\DTCForm.pdf
[2011/09/18 13:19:09 | 003,193,484 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Craig Weil.pdf
[2011/09/18 13:19:06 | 000,608,017 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\CCP602712INS.pdf
[2011/09/18 13:19:06 | 000,166,292 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Condo.StaggeredTermsforDirectors.pdf
[2011/09/18 13:19:06 | 000,137,840 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\ClaudiasGang.jpg
[2011/09/18 13:19:06 | 000,098,572 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\condo veto.htm
[2011/09/18 13:19:05 | 000,319,916 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\CCP602712GA.pdf
[2011/09/18 13:19:04 | 000,759,071 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\CandlesticksI.jpg
[2011/09/18 13:19:03 | 000,929,552 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Breadth Internal Indicators for Winning Swing and Position Trading.pdf
[2011/09/18 13:19:02 | 000,352,973 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Amendmeent for screening.pdf
[2011/09/18 13:19:02 | 000,095,264 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\ABB complaint.pdf
[2011/09/18 13:19:01 | 000,018,941 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\2009 Balcony Assessment 500K.zip
[2011/09/18 13:18:54 | 007,108,875 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\21Candlesticks.pdf
[2011/08/30 22:02:54 | 000,035,000 | -H– | C] () – C:\WINDOWS\System32\mxntdfg.exe
[2010/12/19 14:41:57 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\.googlewebacchosts
[2010/10/05 15:26:54 | 000,116,224 | -H– | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2010/09/23 19:16:04 | 000,186,315 | -H– | C] () – C:\WINDOWS\hpwins23.dat.temp
[2010/09/23 19:16:04 | 000,001,847 | -H– | C] () – C:\WINDOWS\hpwmdl23.dat.temp
[2010/09/11 15:48:31 | 000,000,152 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\fusioncache.dat
[2010/07/09 08:04:40 | 000,082,236 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/05/17 18:06:53 | 000,023,117 | -H– | C] () – C:\WINDOWS\hpqins15.dat
[2010/05/03 16:38:55 | 000,077,382 | -H– | C] () – C:\WINDOWS\hpqins05.dat
[2010/05/02 14:40:15 | 000,229,207 | -H– | C] () – C:\WINDOWS\hpwins23.dat
[2010/05/02 14:40:15 | 000,002,075 | -H– | C] () – C:\WINDOWS\hpwmdl23.dat
[2010/02/16 15:42:32 | 000,033,036 | -H– | C] () – C:\WINDOWS\MAXLINK.INI
[2009/08/03 15:07:42 | 000,403,816 | -H– | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H– | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/26 18:12:35 | 000,020,549 | -H– | C] () – C:\WINDOWS\System32\javaw.exe
[2009/06/26 18:12:35 | 000,020,547 | -H– | C] () – C:\WINDOWS\System32\java.exe
[2009/05/24 09:56:56 | 016,742,799 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\vlc-0.9.9-win32.exe
[2009/05/04 07:49:25 | 000,000,164 | -H– | C] () – C:\WINDOWS\install.dat
[2009/03/21 15:12:50 | 000,061,132 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\rx_audio.Cache
[2009/03/07 09:31:26 | 000,000,335 | -H– | C] () – C:\WINDOWS\nsreg.dat
[2009/02/18 09:46:27 | 000,002,496 | -H– | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/01/10 10:11:50 | 000,150,262 | -H– | C] () – C:\WINDOWS\hpwins05.dat
[2009/01/10 10:10:39 | 000,016,050 | -H– | C] () – C:\WINDOWS\hpwscr05.dat
[2009/01/10 10:10:39 | 000,004,785 | -H– | C] () – C:\WINDOWS\hpwmdl05.dat
[2008/12/30 08:33:34 | 000,000,069 | -H– | C] () – C:\WINDOWS\NeroDigital.ini
[2008/12/19 13:22:22 | 000,118,784 | -H– | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2008/12/19 13:22:19 | 000,338,944 | -H– | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2008/12/15 11:20:23 | 000,000,000 | -H– | C] () – C:\WINDOWS\asym.ini
[2008/12/13 09:48:10 | 000,000,031 | -H– | C] () – C:\WINDOWS\sbewin32.INI
[2008/10/18 12:43:50 | 000,000,010 | -H– | C] () – C:\WINDOWS\msoffice.ini
[2008/09/30 02:59:59 | 000,036,864 | -H– | C] () – C:\WINDOWS\System32\BGData.bin
[2008/09/11 13:28:44 | 000,000,000 | -H– | C] () – C:\WINDOWS\iPlayer.INI
[2008/09/10 08:11:21 | 000,027,136 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/04 08:44:25 | 001,691,948 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\rx_image.Cache
[2008/09/02 22:27:27 | 000,087,608 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\inst.exe
[2008/09/02 22:27:27 | 000,007,887 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pcouffin.cat
[2008/09/02 22:27:27 | 000,001,144 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pcouffin.inf
[2008/09/02 21:54:21 | 000,000,705 | -H– | C] () – C:\WINDOWS\csback.exe.lnk
[2008/09/02 14:39:45 | 000,335,872 | -H– | C] () – C:\WINDOWS\System32\ldf252.dll
[2008/09/02 14:36:36 | 000,000,034 | -H– | C] () – C:\WINDOWS\hpfsched.ini
[2008/09/02 11:52:10 | 000,000,000 | -H– | C] () – C:\WINDOWS\vpc32.INI
[2008/09/01 18:40:43 | 000,002,608 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat.pctools
[2008/09/01 18:20:52 | 000,000,066 | -H– | C] () – C:\WINDOWS\SBWIN.INI
[2008/09/01 18:20:27 | 000,047,616 | -H– | C] () – C:\WINDOWS\System32\P16X.dll
[2008/09/01 18:20:27 | 000,002,516 | -H– | C] () – C:\WINDOWS\System32\P16X.ini
[2008/09/01 18:20:27 | 000,000,026 | -H– | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/09/01 18:07:55 | 000,000,376 | -H– | C] () – C:\WINDOWS\ODBC.INI
[2008/09/01 17:43:39 | 000,012,288 | -H– | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2008/09/01 17:04:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/09/01 16:59:35 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/09/01 12:53:12 | 000,004,161 | -H– | C] () – C:\WINDOWS\ODBCINST.INI
[2008/09/01 12:52:09 | 000,364,120 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | -H– | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | -H– | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | -H– | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | -H– | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | -H– | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/06 13:07:30 | 000,462,848 | -H– | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/03/13 18:52:37 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\px.ini
[2007/02/05 14:55:40 | 000,051,960 | -H– | C] () – C:\WINDOWS\System32\besch.exe
[2007/02/05 14:49:44 | 000,035,576 | -H– | C] () – C:\WINDOWS\System32\besched.dll
[2005/08/26 15:28:34 | 000,143,360 | -H– | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 15:27:58 | 000,045,056 | -H– | C] () – C:\WINDOWS\devenum.exe
[2005/03/21 19:48:05 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 19:48:05 | 000,004,627 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 06:00:00 | 000,755,200 | -H– | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 06:00:00 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 06:00:00 | 000,465,784 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 06:00:00 | 000,338,432 | -H– | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 06:00:00 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 06:00:00 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 06:00:00 | 000,200,192 | -H– | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 06:00:00 | 000,183,808 | -H– | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 06:00:00 | 000,120,320 | -H– | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/08/04 06:00:00 | 000,079,670 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 06:00:00 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 06:00:00 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 06:00:00 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 06:00:00 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2003/10/02 01:00:00 | 000,208,896 | -H– | C] () – C:\WINDOWS\System32\lockout.dll
[2003/10/02 01:00:00 | 000,045,056 | -H– | C] () – C:\WINDOWS\System32\lockres.dll
[2003/09/01 11:06:14 | 000,002,696 | -H– | C] () – C:\WINDOWS\MIXDEF.INI
[2001/10/25 10:54:53 | 000,036,864 | -H– | C] () – C:\WINDOWS\hpfsched.exe
[2001/10/25 10:53:34 | 000,003,691 | -H– | C] () – C:\WINDOWS\hphinfs.dat
[2001/07/07 03:00:00 | 000,003,399 | -H– | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/10/26 21:08:43 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\.oit
[2008/09/24 08:45:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\ACD Systems
[2008/09/28 22:02:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\alot
[2011/08/30 22:38:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Avanquest
[2010/07/28 22:04:46 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Backup MyPC
[2010/09/11 23:57:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\CBS Interactive
[2011/03/05 08:44:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Charles Schwab
[2008/09/19 21:41:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/10/18 12:58:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\CompuServe Dialer
[2009/01/12 18:00:24 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\DriverCure
[2010/09/28 20:09:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\DVDFab
[2011/06/19 09:07:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\ElevatedDiagnostics
[2009/09/29 19:34:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\ErrorWiz
[2009/04/05 13:23:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Image Zone Express
[2008/11/21 09:57:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\mjusbsp
[2011/07/23 14:38:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\MP3Rocket
[2010/08/15 15:34:50 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\NCH Swift Sound
[2010/10/26 17:23:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Nuance
[2009/09/03 08:55:38 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Opera
[2010/10/05 15:29:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pdfforge
[2009/01/10 10:26:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Printer Info Cache
[2010/12/11 17:22:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Red Kawa
[2010/12/11 17:23:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Regensoft
[2011/06/24 08:18:41 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\RegistryKeys
[2011/10/06 08:54:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Sammsoft
[2011/08/27 23:59:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Search Settings
[2011/06/25 16:42:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\SpeedMaxPc
[2010/02/20 15:16:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\TeamViewer
[2011/02/18 16:12:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\uTorrent
[2011/06/20 23:17:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Vso
[2010/12/26 16:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\webex
[2011/07/20 16:15:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Windows Desktop Search
[2011/07/20 16:21:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Windows Search
[2010/10/26 17:27:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Zeon
[2009/04/28 08:44:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\1stWorks
[2011/08/30 22:03:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2011/09/19 20:25:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/10/06 09:08:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/10/18 13:01:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CompuServe Dialer
[2009/01/12 17:48:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/10/28 19:43:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Driver Medic
[2010/02/20 15:09:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2008/12/17 09:49:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/07/14 18:42:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2010/10/13 14:05:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MagicSoftware
[2011/10/06 09:08:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/08/15 15:35:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/05/24 09:56:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2010/10/26 17:34:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2009/01/12 17:48:43 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008/09/02 14:19:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/10/26 17:22:50 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/06/25 16:56:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\SpeedMaxPc
[2011/10/06 16:37:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/19 18:17:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/18 13:50:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2010/06/14 21:58:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2009/04/07 08:50:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2011/08/27 08:04:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\YouTube Downloader
[2010/10/26 17:24:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\zeon
[2009/03/13 21:32:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/07/06 22:57:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/10 15:42:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/10/03 06:37:00 | 000,000,472 | -H– | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/15 18:26:01 | 000,000,294 | -H– | M] () – C:\WINDOWS\Tasks\goldenShakeIcon.job
[2011/09/11 07:56:02 | 000,001,050 | -H– | M] () – C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job
[2011/10/05 22:02:01 | 000,000,250 | -H– | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/10/30 22:26:59 | 000,001,024 | -H– | M] () – C:\.rnd
[2011/08/03 23:03:38 | 000,027,996 | -H– | M] () – C:\aaw7boot.log
[2009/09/19 18:33:17 | 000,010,920 | -H– | M] () – C:\aolconnfix.exe
[2009/09/19 18:33:17 | 000,001,039 | -H– | M] () – C:\aolconnfix.txt
[2008/09/01 17:02:27 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2011/09/18 08:18:31 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/09/01 17:02:27 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2010/08/20 20:38:59 | 000,000,000 | -H– | M] () – C:\ieout.txt
[2008/09/01 18:19:01 | 000,000,164 | -H– | M] () – C:\install.dat
[2008/09/01 17:02:27 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/09 08:07:41 | 000,035,800 | -H– | M] () – C:\mombi.log
[2008/09/01 17:02:27 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/05 07:39:24 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/06 16:20:00 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | -H– | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | -H– | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/09/01 17:02:01 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/05/14 14:56:34 | 000,319,488 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp02t.dll
[2008/08/12 10:58:10 | 000,314,880 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp082.dll
[2006/07/03 11:54:12 | 000,091,648 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp4sa.dll
[2008/07/24 13:09:54 | 000,273,920 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp58a.dll
[2010/12/08 14:11:52 | 000,053,632 | -H– | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 13:23:54 | 000,028,552 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/08/20 20:39:00 | 000,081,408 | -H– | M] (Microsoft Corporation) – C:\Program Files\taskkill.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/09/01 12:51:20 | 000,094,208 | -H– | M] () – C:\WINDOWS\System32\config\default.sav
[2008/09/01 12:51:20 | 000,659,456 | -H– | M] () – C:\WINDOWS\System32\config\software.sav
[2008/09/01 12:51:20 | 000,892,928 | -H– | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-28 07:02:59

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2011/10/04 19:54:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp
[2011/10/04 19:54:57 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp\1
[2011/10/04 21:18:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp\2
[2011/10/05 22:55:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp\4

< %temp%\smtmp\*.* /s > >


< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 06:00:00 | 001,032,192 | -H– | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.EXE-05416907.PF >
[2011/10/06 09:11:15 | 000,069,830 | —- | M] () MD5=4BD63E61A889D84FAE439C8CEEB0BD29 – C:\WINDOWS\Prefetch\EXPLORER.EXE-05416907.pf

< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | -H– | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | -H– | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | -H– | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | -H– | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\ie8\iexplore.chm
[2004/08/04 06:00:00 | 000,204,810 | -H– | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/29 03:25:31 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/19 01:25:25 | 000,634,024 | -H– | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 02:34:58 | 000,633,632 | -H– | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 07:25:27 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | -H– | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/19 01:25:30 | 000,634,024 | -H– | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/23 01:56:15 | 000,635,848 | -H– | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 11:12:57 | 000,634,656 | -H– | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2009/08/27 01:18:42 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 04:35:10 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 06:34:43 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/28 02:54:16 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 09:05:43 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | -H– | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | -H– | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\SoftwareDistribution\Download\13d5d266d7681d26b42f8dff88cadc20\SP2GDR\iexplore.exe
[2010/10/18 07:07:43 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/28 02:54:21 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2008/10/15 03:06:26 | 000,633,632 | -H– | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 00:54:41 | 000,636,072 | -H– | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 10:45:15 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:08:29 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/23 01:20:02 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2010/12/20 06:49:55 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/28 00:54:44 | 000,636,088 | -H– | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | -H– | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:43:25 | 000,634,656 | -H– | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\SoftwareDistribution\Download\13d5d266d7681d26b42f8dff88cadc20\SP2QFE\iexplore.exe
[2010/02/23 01:19:59 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 03:00:27 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2010/10/18 06:36:30 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | -H– | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2011/02/14 07:36:55 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 08:17:08 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 07:30:33 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 06:00:00 | 000,093,184 | -H– | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2008/08/23 01:56:16 | 000,635,848 | -H– | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2010/08/25 07:07:58 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 01:18:44 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.000 >
[2007/08/13 18:43:56 | 000,622,080 | -H– | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe.000

< MD5 for: IEXPLORE.EXE.MDMP >
[2011/10/06 00:28:08 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\WER249c.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-06887102.PF >
[2011/10/06 09:11:37 | 000,033,424 | —- | M] () MD5=DD9212145ED3CFAF3A649949CBFFD7F2 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-06887102.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | -H– | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: IEXPLORE.RAR >
[2011/08/03 21:50:58 | 000,248,797 | -H– | M] () MD5=9EFA7DB104C1CAD93001CFB100146517 – C:\Program Files\Internet Explorer\iexplore.rar

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:00:00 | 000,502,272 | -H– | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | -H– | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | -H– | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 241 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:01C66DD9
@Alternate Data Stream - 238 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B9FB94D
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >















Hi jellyfish,

To make cleaning this machine easier

  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


If this is a Vista or Win7 machine instead of double clicking the file to run it you need to rigght click the file and click "Run as Adminstrtor"


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Next

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • both OTL logs
  • aswMBR log
  • MBR.zip (attached)

OTL Extras logfile created on: 10/6/2011 4:30:50 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 82.40% Memory free
5.09 Gb Paging File | 4.57 Gb Available in Paging File | 89.69% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 53.00 Gb Free Space | 22.76% Space Free | Partition Type: NTFS
Drive F: | 37.21 Gb Total Space | 20.26 Gb Free Space | 54.45% Space Free | Partition Type: NTFS
Drive G: | 124.72 Mb Total Space | 28.69 Mb Free Space | 23.00% Space Free | Partition Type: FAT

Computer Name: ARNIE-30F18ED3E | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqfxt08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqfxt08.exe:*:Enabled:hpqfxt08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe" = C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9 – (Sonic Solutions)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\1stWORKS\hotCommCL\BIN\HotComm.exe" = C:\Program Files\1stWORKS\hotCommCL\BIN\HotComm.exe:*:Enabled:hotComm CL – (1stWorks Corporation)
"C:\Program Files\Schwab\SSPro\SSPro.exe" = C:\Program Files\Schwab\SSPro\SSPro.exe:*:Enabled:StreetSmart Pro – (Charles Schwab & Co., Inc.)
"C:\Program Files\1stWORKS\PristineCL\BIN\hotComm.exe" = C:\Program Files\1stWORKS\PristineCL\BIN\hotComm.exe:*:Enabled:Pristine Chat
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows
"C:\Program Files\DAP\DAP.exe" = C:\Program Files\DAP\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)
"C:\Program Files\Common Files\aol\acs\AOLDial.exe" = C:\Program Files\Common Files\aol\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer
"C:\Program Files\Common Files\aol\acs\AOLacsd.exe" = C:\Program Files\Common Files\aol\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service
"C:\Program Files\Common Files\aol\1253398588\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1253398588\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
"C:\Program Files\AOL 9.1\waol.exe" = C:\Program Files\AOL 9.1\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL System Information
"C:\Program Files\Common Files\aol\1254185968\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1254185968\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player – (Apple Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe:*:Enabled:hpofxs08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqfxt08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqfxt08.exe:*:Enabled:hpqfxt08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Ring Factory\RingFactory.exe" = C:\Program Files\Ring Factory\RingFactory.exe:*:Enabled:Ring Factory 3.0
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application – (TeamViewer GmbH)
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service – (TeamViewer GmbH)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe" = C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9 – (Sonic Solutions)
"C:\Program Files\Roxio\Creator Classic 9\Creator9.exe" = C:\Program Files\Roxio\Creator Classic 9\Creator9.exe:*:Enabled:Creator9 – (Sonic Solutions)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{0815D55A-5EFF-4E1B-8C04-7035E914D90D}" = OLYMPUS Master 2
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{097CDB1E-07C9-40F1-9972-F0F9F3A287E4}" = Network
"{0E52A52C-E120-461C-AA1B-21B045BEE842}" = bpd_scan
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 3.3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{294A2E0E-3A0B-4D1F-8282-11DEF2040227}" = InstallIQ Updater
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248E093-5288-4CA9-B3AB-11A675FEA1F9}" = Symantec AntiVirus
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3BE02281-FCCF-44BB-8413-AC4A633059EB}" = BPDSoftware
"{4CCC7F68-A437-4559-A840-F5E010934951}" = HP Driver Diagnostics
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{5646676A-5A97-4B66-BE71-1B1770AD982B}" = StreetSmart Edge
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58D79E62-CFC8-4331-8469-3A1B16E1769C}" = HP Officejet 6500 E709 Series
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B025634-7D5B-4B8D-BE2A-7943C1CF2D5D}" = Status
"{60FFB3E0-6D5B-4D73-AE5B-07E58B83AF0C}" = 32 Bit HP CIO Components Installer
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{664708B3-C730-11D5-ADE7-00B0D07D157A}" = StreetSmart Pro
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{683100FE-EDF8-403B-A234-B3EBEAF7BC82}" = Roxio Creator 9 XE
"{68654483-9629-4CF5-88FF-9FB70B3BECDE}" = ProductContext
"{69192731-44E6-4C08-B0A3-66174478B9E3}" = Nuance PaperPort 12
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{83E222CC-223F-BE8C-0C77-0CEBDC2F9B57}" = Acrobat.com
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8F899627-1EA1-484D-91EA-7B22C05358DB}" = TeleChart 2007
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9294F169-72EE-4D74-AE92-CA25F64B4FF8}" = Fax
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{99F67894-9486-413F-94E1-8B12B1606EAB}" = BPDSoftware_Ini
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA787E05-E835-4812-AA3D-4048C8A46587}" = 6500_E709_eDocs
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe 1.8.15.1
"{B941B1C3-40AF-4E1E-AA5F-ED99EDEA1033}" = SecurDisc Viewer
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BB558CDC-C7BE-44D0-9260-B810D66702C4}" = 6500_E709n
"{BC5DD87B-0143-4D14-AAE6-97109614DC6B}" = SolutionCenter
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{E6098043-1183-4580-89EF-423CBF807188}" = pdfforge Toolbar v4.6
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EC00862A-C16F-4ED0-BC06-34538512E730}" = Nuance PDF Viewer Plus
"{EC047FA6-E83D-4326-9195-E7D306C5B9A2}" = OLYMPUS muvee theaterPack
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F53B432E-BD19-4400-BFA0-2BBD16410F8F}" = 6500_E709_Help
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FF2D46CF-122C-47D8-9846-037C59E7144D}" = Google Web Accelerator
"ACDSee" = ACDSee
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Emergency Connect Utility 1.0" = Uninstall AOL Emergency Connect Utility 1.0
"ARO 2011_is1" = ARO 2011
"AviSynth" = AviSynth 2.5
"Browser Defender_is1" = Browser Defender 3.0
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CompuServe us" = CompuServe
"Defraggler" = Defraggler (remove only)
"DriverAgent.exe" = DriverAgent by eSupport.com
"eCleanNSIS" = eClean 2000 (remove only)
"Golden" = Golden Records Vinyl to CD Converter
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"hp photosmart 1215 series_Driver" = hp photosmart 1215 series
"hp photosmart printer series" = hp photosmart printer series (Remove only)
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"HPOCR" = OCR Software by I.R.I.S. 14.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"JRE 1.3.1_02" = Java 2 Runtime Environment Standard Edition v1.3.1_02
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"Magic DVD Copier_is1" = Magic DVD Copier Version 5.0.1
"Magic DVD Ripper_is1" = Magic DVD Ripper V5.5.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Matrox Graphics Uninstaller" = Matrox Graphics Software (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MVApplication1" = Memorex exPressit Label Design Studio
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OVT Scanner" = Uninstall OVT Scanner
"Pixillion" = Pixillion Image Converter
"PROPLUS" = Microsoft Office Professional Plus 2007
"PROSet" = Intel® PRO Network Adapters and Drivers
"Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.0
"RealPlayer 6.0" = RealPlayer Basic
"Replay Converter 3" = Replay Converter 3
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Spyware Doctor" = Spyware Doctor 8.0
"Stock Assault 2.0 Demo2.0.1.4" = Stock Assault 2.0 Demo
"TeamViewer 6" = TeamViewer 6
"Videora iPhone 3G Converter" = Videora iPhone 3G Converter 6
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YouTube Downloader App" = YouTube Downloader App 3.00

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"3651594166.www.tc2000.com" = TC2000 v11

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/5/2011 9:14:17 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: UltraDefraggerFraud in File: c:\documents
and settings\all users\application data\nxbppaqqtfixr.exe by: Manual scan. Action:
Terminate Process Required. Action Description:

Error - 10/5/2011 9:25:35 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Boot.Tidserv in File: Master Boot Record for
Physical drive number 0 by: Manual scan. Action: Clean failed : Quarantine failed.
Action Description: The file was left unchanged.

Error - 10/5/2011 9:28:25 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: UltraDefraggerFraud in File: c:\documents
and settings\all users\application data\nxbppaqqtfixr.exe by: Manual scan. Action:
Leave Alone succeeded. Action Description: The file was left unchanged.

Error - 10/5/2011 9:28:25 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: (null) in File: c:\documents and settings\all
users\application data\nxbppaqqtfixr.exe by: Manual scan. Action: Leave Alone
succeeded. Action Description: The file was left unchanged.

Error - 10/5/2011 9:28:26 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: UltraDefraggerFraud in File: c:\documents
and settings\all users\application data\nxbppaqqtfixr.exe by: Manual scan. Action:
Terminate Process Required. Action Description:

Error - 10/6/2011 12:17:52 AM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Boot.Tidserv in File: Master Boot Record for
Physical drive number 0 by: Auto-Protect scan. Action: Clean failed : Quarantine
failed : Access allowed. Action Description: The file was left unchanged.

Error - 10/6/2011 2:01:50 AM | Computer Name = ARNIE-30F18ED3E | Source = Application Error | ID = 1000
Description = Faulting application malwaredetective3.exe, version 3.0.0.5, faulting
module commom.dll, version 7.0.0.121, fault address 0x00061d58.

Error - 10/6/2011 2:01:58 AM | Computer Name = ARNIE-30F18ED3E | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/6/2011 9:10:11 AM | Computer Name = ARNIE-30F18ED3E | Source = Userenv | ID = 1508
Description = Windows was unable to load the registry. This is often caused by insufficient
memory or insufficient security rights. DETAIL - The process cannot access the
file because it is being used by another process. for C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local
Settings\Application Data\Microsoft\Windows\\UsrClass.dat

Error - 10/6/2011 9:10:28 AM | Computer Name = ARNIE-30F18ED3E | Source = Userenv | ID = 1505
Description = Windows cannot load the user's profile but has logged you on with
the default profile for the system. DETAIL - The process cannot access the file
because it is being used by another process.

[ Application Events ]
Error - 10/5/2011 9:14:17 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: UltraDefraggerFraud in File: c:\documents
and settings\all users\application data\nxbppaqqtfixr.exe by: Manual scan. Action:
Terminate Process Required. Action Description:

Error - 10/5/2011 9:25:35 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Boot.Tidserv in File: Master Boot Record for
Physical drive number 0 by: Manual scan. Action: Clean failed : Quarantine failed.
Action Description: The file was left unchanged.

Error - 10/5/2011 9:28:25 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: UltraDefraggerFraud in File: c:\documents
and settings\all users\application data\nxbppaqqtfixr.exe by: Manual scan. Action:
Leave Alone succeeded. Action Description: The file was left unchanged.

Error - 10/5/2011 9:28:25 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: (null) in File: c:\documents and settings\all
users\application data\nxbppaqqtfixr.exe by: Manual scan. Action: Leave Alone
succeeded. Action Description: The file was left unchanged.

Error - 10/5/2011 9:28:26 PM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: UltraDefraggerFraud in File: c:\documents
and settings\all users\application data\nxbppaqqtfixr.exe by: Manual scan. Action:
Terminate Process Required. Action Description:

Error - 10/6/2011 12:17:52 AM | Computer Name = ARNIE-30F18ED3E | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Boot.Tidserv in File: Master Boot Record for
Physical drive number 0 by: Auto-Protect scan. Action: Clean failed : Quarantine
failed : Access allowed. Action Description: The file was left unchanged.

Error - 10/6/2011 2:01:50 AM | Computer Name = ARNIE-30F18ED3E | Source = Application Error | ID = 1000
Description = Faulting application malwaredetective3.exe, version 3.0.0.5, faulting
module commom.dll, version 7.0.0.121, fault address 0x00061d58.

Error - 10/6/2011 2:01:58 AM | Computer Name = ARNIE-30F18ED3E | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 10/6/2011 9:10:11 AM | Computer Name = ARNIE-30F18ED3E | Source = Userenv | ID = 1508
Description = Windows was unable to load the registry. This is often caused by insufficient
memory or insufficient security rights. DETAIL - The process cannot access the
file because it is being used by another process. for C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local
Settings\Application Data\Microsoft\Windows\\UsrClass.dat

Error - 10/6/2011 9:10:28 AM | Computer Name = ARNIE-30F18ED3E | Source = Userenv | ID = 1505
Description = Windows cannot load the user's profile but has logged you on with
the default profile for the system. DETAIL - The process cannot access the file
because it is being used by another process.

[ System Events ]
Error - 10/6/2011 9:08:39 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LMIGuardianSvc service
to connect.

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7000
Description = The LMIGuardianSvc service failed to start due to the following error:
%%1053

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%2

Error - 10/6/2011 9:14:25 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10010
Description = The server {1DAEDD8A-30ED-4585-9CF1-13BDF7791DDE} did not register
with DCOM within the required timeout.

Error - 10/6/2011 9:15:58 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 9:16:57 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm PCTSD SAVRT SAVRTPEL SYMTDI TfFsMon TFSysMon

Error - 10/6/2011 4:20:57 PM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 4:21:51 PM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm PCTSD SAVRT SAVRTPEL SYMTDI TfFsMon TFSysMon

Error - 10/6/2011 4:24:32 PM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

[ System Events ]
Error - 10/6/2011 9:08:39 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LMIGuardianSvc service
to connect.

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7000
Description = The LMIGuardianSvc service failed to start due to the following error:
%%1053

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%2

Error - 10/6/2011 9:14:25 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10010
Description = The server {1DAEDD8A-30ED-4585-9CF1-13BDF7791DDE} did not register
with DCOM within the required timeout.

Error - 10/6/2011 9:15:58 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 9:16:57 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm PCTSD SAVRT SAVRTPEL SYMTDI TfFsMon TFSysMon

Error - 10/6/2011 4:20:57 PM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 4:21:51 PM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm PCTSD SAVRT SAVRTPEL SYMTDI TfFsMon TFSysMon

Error - 10/6/2011 4:24:32 PM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

[ System Events ]
Error - 10/6/2011 9:08:39 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LMIGuardianSvc service
to connect.

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7000
Description = The LMIGuardianSvc service failed to start due to the following error:
%%1053

Error - 10/6/2011 9:11:59 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%2

Error - 10/6/2011 9:14:25 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10010
Description = The server {1DAEDD8A-30ED-4585-9CF1-13BDF7791DDE} did not register
with DCOM within the required timeout.

Error - 10/6/2011 9:15:58 AM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 9:16:57 AM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm PCTSD SAVRT SAVRTPEL SYMTDI TfFsMon TFSysMon

Error - 10/6/2011 4:20:57 PM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/6/2011 4:21:51 PM | Computer Name = ARNIE-30F18ED3E | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
eeCtrl Fips intelppm PCTSD SAVRT SAVRTPEL SYMTDI TfFsMon TFSysMon

Error - 10/6/2011 4:24:32 PM | Computer Name = ARNIE-30F18ED3E | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}


< End of report >
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-06 16:57:39 —————————– 16:57:39.984 OS Version: Windows 5.1.2600 Service Pack 3 16:57:39.984 Number of processors: 1 586 0x209 16:57:39.984 ComputerName: ARNIE-30F18ED3E UserName: Administrator 16:57:40.531 Initialize success 17:03:11.203 AVAST engine defs: 11100601 17:04:36.296 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 17:04:36.312 Disk 0 Vendor: ST340014A 3.16 Size: 38146MB BusType: 3 17:04:36.328 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-e 17:04:36.343 Disk 1 Vendor: ST3250310AS 3.AAC Size: 238475MB BusType: 3 17:04:38.390 Disk 1 MBR read successfully 17:04:38.406 Disk 1 MBR scan 17:04:38.484 Disk 1 Windows XP default MBR code 17:04:38.546 Disk 1 scanning sectors +488376000 17:04:38.640 Disk 1 scanning C:\WINDOWS\system32\drivers 17:04:56.421 Service scanning 17:05:00.500 Modules scanning 17:05:04.281 Disk 1 trace - called modules: 17:05:04.312 ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 17:05:04.312 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8afb4ab8] 17:05:04.312 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> [0x8afbfe50] 17:05:04.312 5 PCTCore.sys[f785a0ad] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x8afbfb00] 17:05:05.031 AVAST engine scan C:\WINDOWS 17:05:16.625 AVAST engine scan C:\WINDOWS\system32 17:07:52.343 AVAST engine scan C:\WINDOWS\system32\drivers 17:08:26.093 AVAST engine scan C:\Documents and Settings\Administrator.ARNIE-30F18ED3E 17:10:42.828 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\My Documents\MBR.dat" 17:10:42.937 The log file has been saved successfully to "C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\My Documents\aswMBR.txt"
Hi jeffkush,

Please do not use any temporary files cleaner as all your files have been moved to a temporary location. We will clean those after we have made sure everything has been restored.

There is no need to quote my posts in your replies.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O33 - MountPoints2\{2f31da03-1f7f-11e0-9106-00038a000015}\Shell\AutoRun\command - "" = I:\Get_Started_for_Win.exe
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O4 - HKCU..\Run: [nXBPpaqQtFIXr.exe] C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe File not found
O4 - HKCU..\Run: [DIDfuRcLeJEc.exe] C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe File not found
O4 - HKLM..\Run: [wvjfk] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\gijkikp.f, fgrk File not found
O4 - HKLM..\Run: [smsj] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\ifuolvt.l, ocjv File not found
O4 - HKLM..\Run: [rhmmmp] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\rbuxp.n, hvrc File not found
O4 - HKLM..\Run: [ktql] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\yqujqs.t, nnkf File not found

:Files
xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C
ipconfig /flushdns /c

:Commands
[purity]
[createresrorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.



Download RogueKiller to your desktop

  • Quit all running programs
  • When prompted, type 6 and validate


Please post back with
  • OTL fix log
Are your icons and program files back (click start > highlight All programs)?

Thanks
Great I have the programs and icons but when i open any program the pc freezes completly. I was able to get to task manager once and it is at 100% pc usage. The only way to get it to release is to power cycle it. Any ideas is there another problem or virus??
Hi jeffkush,

Yes, you are still infected , we have just begun to clean this machine.

I need the log produced when you ran the OTL fix. The OTL fix log can be found at C:\_OTL\MovedFiles It will have a file name consisting of numders that reflect the date and time stamp the fix was ran. It will be something similar to 09092010_111009.log . Please copy and paste the contents into your next reply.


Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with the combofix log and the log from OTL.

How's the computer?

Thanks
I am having 3 issues.
1- Computer wont let me run this in anything but safemode.
2- Computer wont let me delete or disable Symantec
3- After running this the computer in regular mode locks up immediatly one you open anything.

Thanks so much for all your help.

Jeff

OTL logfile created on: 10/6/2011 4:30:50 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 82.40% Memory free
5.09 Gb Paging File | 4.57 Gb Available in Paging File | 89.69% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 53.00 Gb Free Space | 22.76% Space Free | Partition Type: NTFS
Drive F: | 37.21 Gb Total Space | 20.26 Gb Free Space | 54.45% Space Free | Partition Type: NTFS
Drive G: | 124.72 Mb Total Space | 28.69 Mb Free Space | 23.00% Space Free | Partition Type: FAT

Computer Name: ARNIE-30F18ED3E | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\PC Tools Security\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\PC Tools Security\avengine\sdkBSCtrl.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Replay Converter 3\ffdshow.ax ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\Common Files\Sonic Shared\SonicHDDemuxer.dll ()
MOD - C:\Program Files\Replay Converter 3\ac3filter.ax ()


========== Win32 Services (SafeList) ==========

SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Application Updater) – C:\Program Files\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (Roxio UPnP Renderer 9) – C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe (Sonic Solutions)
SRV - (Roxio Upnp Server 9) – C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe (Sonic Solutions)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (MGABGEXE) – C:\WINDOWS\system32\mgabg.exe (Matrox Graphics Inc.)
SRV - (Pml Driver) – C:\WINDOWS\system32\hphipm09.exe (HP)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110930.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20110930.002\NAVENG.SYS (Symantec Corporation)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TFSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\WINDOWS\system32\drivers\RxFilter.sys (Sonic Solutions)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (G400DH) – C:\WINDOWS\system32\drivers\g400dhm.sys (Matrox Graphics Inc.)
DRV - (Dot4 HPH09) – C:\WINDOWS\system32\drivers\hphid409.sys (HP)
DRV - (Dot4Storage HPH09) Storage Class Driver for IEEE-1284.4 (HPH09) – C:\WINDOWS\system32\drivers\hphs2k09.sys (Hewlett-Packard)
DRV - (Dot4Usb HPH09) – C:\WINDOWS\system32\drivers\hphius09.sys (HP)
DRV - (Dot4Print HPH09) – C:\WINDOWS\system32\drivers\hphipr09.sys (HP)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (G400) – C:\WINDOWS\system32\drivers\G400m.sys (Matrox Graphics Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BC D7 3D 2C AB 2E CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/aolcom/search?invocationType=tb50ffTB50CLie7&query;="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ask.com?o=15866&l;=dis"
FF - prefs.js..extensions.enabledItems: {7affbfae-c4e2-4915-8c0f-00fa3ec610a1}:5.13.15.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019
FF - prefs.js..extensions.enabledItems: [removed]:4.3
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:4.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src;=kw&tb;=MP3R7&o;=15863&locale;=en_US&apn;_uid=A8966E22-90C3-473D-A799-DBBE457B7670&apn;_ptnrs=RV&apn;_sauid=938D82DC-FCCB-492F-BD0C-6751545AE601&apn;_dtid=YYYYYYYYUS&q;="
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=302398&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&type;=302398&p;="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKEY_LOCAL_MACHINE\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/17 18:07:43 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Google\Web Accelerator\firefox [2010/12/19 14:36:47 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011/10/06 00:37:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\CompuServe 7.0\Extensions\\:
FF - HKEY_CURRENT_USER\software\mozilla\CompuServe 7.0\Extensions\\Components: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\CompuServe 7.0\Extensions\\Plugins: C:\Program Files\Common Files\csshare\plugins0942 [2011/09/15 07:33:05 | 000,000,000 | -H-D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/05/17 18:07:43 | 000,000,000 | -H-D | M]

[2009/03/10 08:50:49 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Extensions
[2009/03/10 08:50:49 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Extensions\[removed]
[2011/02/28 09:15:04 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions
[2009/08/10 14:17:37 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/04/29 07:48:20 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/10/06 18:15:16 | 000,000,000 | -H-D | M] (AOL Toolbar) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
[2011/03/29 18:26:11 | 000,000,000 | -H-D | M] (Default Manager) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\DefaultManager@Microsoft
[2011/09/21 15:02:16 | 000,000,000 | -H-D | M] (Ask Toolbar) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\extensions\[removed]
[2010/10/06 22:15:11 | 000,000,628 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\searchplugins\aol-search.xml
[2011/02/28 09:15:52 | 000,002,569 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Mozilla\Firefox\Profiles\7cd27eji.default\searchplugins\askcom.xml
[2011/08/27 23:58:26 | 000,000,000 | -H-D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/03/31 08:32:51 | 000,000,000 | -H-D | M] ("searchme") – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/03/31 08:28:12 | 000,000,000 | -H-D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/07/12 12:33:56 | 000,012,800 | -H– | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2009/03/13 05:39:56 | 000,002,494 | -H– | M] () – C:\Program Files\mozilla firefox\searchplugins\searchme.xml

O1 HOSTS File: ([2009/06/28 16:58:30 | 000,000,736 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDFViewerPlus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (&Google; Web Accelerator Helper) - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Web Accelerator) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CXMon] C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Roxio\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP)
O4 - HKLM..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [ktql] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\yqujqs.t, nnkf File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Matrox Powerdesk] C:\WINDOWS\System32\PDesk\PDesk.exe (Matrox Graphics Inc.)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" File not found
O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe (Threat Expert Ltd.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDFViewerPlus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [rhmmmp] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\rbuxp.n, hvrc File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [smsj] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\ifuolvt.l, ocjv File not found
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [wvjfk] rundll32 C:\DOCUME~1\ADMINI~1.ARN\APPLIC~1\MICROS~1\Protect\gijkikp.f, fgrk File not found
O4 - HKCU..\Run: [AROReminder] C:\Program Files\ARO 2011\aro.exe (Support.com)
O4 - HKCU..\Run: [DIDfuRcLeJEc.exe] C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe File not found
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O4 - HKCU..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [nXBPpaqQtFIXr.exe] C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe File not found
O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files\Nuance\PDFViewerPlus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: microsoft.com ([support] http in Trusted sites)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1220381305515 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.3.1/…-131_02-win.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.3.1/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/…-131_02-win.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://elementtrading.webex.com/client/T27…ing/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{459989CA-C2A5-45F5-AF05-09CE68B27685}: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (nvdesk32.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (ows\s) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/09/01 17:02:27 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/09/03 10:59:58 | 000,000,000 | -H– | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{2f31da03-1f7f-11e0-9106-00038a000015}\Shell\AutoRun\command - "" = I:\Get_Started_for_Win.exe
O33 - MountPoints2\{4546ecee-b7d4-11dd-8096-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4546ecee-b7d4-11dd-8096-00038a000015}\Shell\AutoRun\command - "" = J:\autorun.exe
O33 - MountPoints2\{4546ecee-b7d4-11dd-8096-00038a000015}\Shell\phone\command - "" = J:\autorun.exe
O33 - MountPoints2\{4546ecef-b7d4-11dd-8096-00038a000015}\Shell\AutoRun\command - "" = K:\magicJack\autorun.exe
O33 - MountPoints2\{4546ecef-b7d4-11dd-8096-00038a000015}\Shell\phone\command - "" = K:\magicJack\autorun.exe
O33 - MountPoints2\{4f557501-86b4-11dd-8072-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{4f557501-86b4-11dd-8072-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4f557501-86b4-11dd-8072-00038a000015}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/10/06 16:26:24 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\OTL.exe
[2011/10/06 09:08:27 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/10/06 09:08:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/10/06 08:59:26 | 062,844,048 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe
[2011/10/06 08:59:07 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/10/06 08:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Sammsoft
[2011/10/06 08:54:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ARO 2011
[2011/10/06 08:54:04 | 000,000,000 | —D | C] – C:\Program Files\ARO 2011
[2011/10/06 00:37:33 | 000,184,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTSD.sys
[2011/10/06 00:37:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/10/06 00:25:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Threat Expert
[2011/10/05 23:50:50 | 000,069,392 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/10/05 23:50:48 | 000,033,552 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/10/05 23:50:43 | 000,051,984 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/10/05 23:48:34 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Recent
[2011/10/05 22:46:48 | 002,189,264 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/10/05 22:46:48 | 002,000,848 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll1047.old
[2011/10/05 22:46:48 | 002,000,848 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll1000.old
[2011/10/05 22:46:48 | 001,533,904 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/10/05 22:46:48 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll1047.old
[2011/10/05 22:46:48 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll1000.old
[2011/10/05 22:46:48 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/10/05 22:20:30 | 000,656,320 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2011/10/05 22:20:30 | 000,338,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/10/05 22:20:30 | 000,252,712 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011/10/05 22:20:28 | 000,326,688 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2011/10/05 22:20:28 | 000,162,200 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011/10/05 22:20:24 | 000,070,664 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2011/10/05 22:20:16 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2011/10/05 22:20:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/10/05 22:20:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\PC Tools
[2011/10/05 22:07:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2011/10/04 20:07:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Data Restore
[2011/10/04 20:05:23 | 000,347,136 | -H– | C] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe.pctools
[2011/10/04 19:51:47 | 000,466,432 | -H– | C] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe.pctools
[2011/10/04 19:50:39 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Calculations_#76046
[2011/09/19 20:25:03 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/09/18 13:31:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\monitor
[2011/09/18 13:30:46 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\2009 Balcony Assessment 500K
[2011/09/18 13:29:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\WT500
[2011/09/18 13:29:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\SKMBT_50009051410550
[2011/09/18 13:29:44 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\SKMBT_50009041808260
[2011/09/18 13:29:44 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Radzinsky
[2011/09/18 13:29:06 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Pictures
[2011/09/18 13:20:03 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Office 2007
[2010/08/20 20:39:00 | 000,081,408 | -H– | C] (Microsoft Corporation) – C:\Program Files\taskkill.exe
[2008/09/02 22:27:27 | 000,047,360 | -H– | C] (VSO Software) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pcouffin.sys
[2008/09/01 18:20:27 | 000,065,536 | -H– | C] ( ) – C:\WINDOWS\System32\A3d.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/06 16:25:46 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\OTL.exe
[2011/10/06 16:20:59 | 000,002,206 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/06 16:20:10 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/06 09:10:38 | 000,000,896 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/06 09:01:08 | 062,844,048 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe
[2011/10/06 08:54:08 | 000,001,525 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Check PC For Errors.lnk
[2011/10/06 08:54:08 | 000,001,525 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2011/10/06 01:31:33 | 000,105,025 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\history.html
[2011/10/06 00:37:34 | 000,001,664 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2011/10/06 00:35:39 | 000,512,992 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup[1].exe
[2011/10/06 00:22:06 | 000,000,900 | -H– | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/05 23:42:09 | 000,729,390 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/10/05 22:12:10 | 000,512,992 | —- | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup_revwire207.exe
[2011/10/05 22:02:01 | 000,000,250 | -H– | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/10/05 07:20:01 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/05 04:43:42 | 000,518,144 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe.pctools
[2011/10/04 22:12:35 | 000,000,853 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Restore.lnk
[2011/10/04 20:22:28 | 000,000,432 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.pctool
[2011/10/04 20:07:44 | 000,000,288 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjk.pctools
[2011/10/04 20:07:43 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjkr.pctools
[2011/10/04 20:07:30 | 000,000,835 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Data Restore.lnk
[2011/10/04 20:05:23 | 000,347,136 | -H– | M] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.exe.pctools
[2011/10/04 19:51:02 | 000,466,432 | -H– | M] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\DIDfuRcLeJEc.exe.pctools
[2011/10/04 19:50:39 | 000,031,150 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Calculations_#76046.zip
[2011/10/04 13:43:11 | 000,002,608 | -H– | M] () – C:\WINDOWS\System32\d3d9caps.dat.pctools
[2011/10/03 06:37:00 | 000,000,472 | -H– | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/09/19 08:12:19 | 000,000,000 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\.googlewebacchosts
[2011/09/18 08:18:31 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/09/17 12:58:06 | 000,000,410 | -H– | M] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Shortcut to Favorites.lnk
[2011/09/15 03:02:50 | 000,001,374 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2011/09/11 07:56:02 | 000,001,050 | -H– | M] () – C:\WINDOWS\tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job
[2011/09/09 05:12:13 | 000,599,040 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/06 08:54:08 | 000,001,525 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Check PC For Errors.lnk
[2011/10/06 08:54:08 | 000,001,525 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2011/10/06 01:31:33 | 000,105,025 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\history.html
[2011/10/06 00:37:34 | 000,001,664 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2011/10/06 00:35:41 | 000,512,992 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup[1].exe
[2011/10/05 23:40:34 | 000,729,390 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/10/05 22:46:48 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll1047.old
[2011/10/05 22:46:48 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll1000.old
[2011/10/05 22:46:48 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/10/05 22:46:48 | 000,002,125 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/10/05 22:46:48 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/10/05 22:46:48 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/10/05 22:46:48 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/10/05 22:07:27 | 000,512,992 | —- | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\sdsetup_revwire207.exe
[2011/10/05 00:56:11 | 000,518,144 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\nXBPpaqQtFIXr.exe.pctools
[2011/10/04 22:12:34 | 000,000,853 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Restore.lnk
[2011/10/04 20:07:43 | 000,000,216 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjkr.pctools
[2011/10/04 20:07:41 | 000,000,288 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjk.pctools
[2011/10/04 20:07:29 | 000,000,835 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Data Restore.lnk
[2011/10/04 20:06:50 | 000,000,432 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk.pctool
[2011/10/04 19:50:38 | 000,031,150 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Calculations_#76046.zip
[2011/09/18 13:29:52 | 000,478,564 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\12 Technical Indicators.pdf
[2011/09/18 13:20:03 | 004,308,230 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Trade For Life.pdf
[2011/09/18 13:19:58 | 003,796,115 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Swing-Position Day Trade.pdf
[2011/09/18 13:19:54 | 003,852,393 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\State Farm 2008.pdf
[2011/09/18 13:19:54 | 000,636,141 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Swing Trading Essentials with Jon Markman.pdf
[2011/09/18 13:19:50 | 001,916,535 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Profitable Set-ups for Volatile Markets.pdf
[2011/09/18 13:19:50 | 000,118,297 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\SKMBT_50009041808260.zip
[2011/09/18 13:19:48 | 003,291,789 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Position-Swing-Day Trade.pdf
[2011/09/18 13:19:44 | 004,979,587 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\New Tactics in Technical Analysis.pdf
[2011/09/18 13:19:39 | 000,220,089 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\mastering candlesticks !.pdf
[2011/09/18 13:19:38 | 000,270,121 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Mastering Candlestick Charts Part II.pdf
[2011/09/18 13:19:38 | 000,167,015 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\LEAPS Strategies with Jon Najarian.pdf
[2011/09/18 13:19:38 | 000,084,164 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\KUSHNER.pdf
[2011/09/18 13:19:37 | 000,999,706 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\John L. Person candlestick charting.pdf
[2011/09/18 13:19:36 | 003,513,202 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Jeff Cooper Intraday.pdf
[2011/09/18 13:19:33 | 000,500,242 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Intra–day Market Internals IInternals.pdf
[2011/09/18 13:19:32 | 000,109,269 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Garraway Dismissal letter.pdf
[2011/09/18 13:19:32 | 000,047,214 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Garrawayv.Winston.pdf
[2011/09/18 13:19:31 | 004,246,442 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Gap-Guerilla Trading 2.pdf
[2011/09/18 13:19:27 | 004,005,645 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Gap & Guerilla Trading 1.pdf
[2011/09/18 13:19:23 | 001,144,381 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\FirstNoticeSouthTower.pdf
[2011/09/18 13:19:15 | 006,946,381 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Essential Strategies to Trade for Life.pdf
[2011/09/18 13:19:14 | 003,767,446 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\DVR MANUEL.pdf
[2011/09/18 13:19:10 | 000,823,918 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\DTCForm.pdf
[2011/09/18 13:19:09 | 003,193,484 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Craig Weil.pdf
[2011/09/18 13:19:06 | 000,608,017 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\CCP602712INS.pdf
[2011/09/18 13:19:06 | 000,166,292 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Condo.StaggeredTermsforDirectors.pdf
[2011/09/18 13:19:06 | 000,137,840 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\ClaudiasGang.jpg
[2011/09/18 13:19:06 | 000,098,572 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\condo veto.htm
[2011/09/18 13:19:05 | 000,319,916 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\CCP602712GA.pdf
[2011/09/18 13:19:04 | 000,759,071 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\CandlesticksI.jpg
[2011/09/18 13:19:03 | 000,929,552 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Breadth Internal Indicators for Winning Swing and Position Trading.pdf
[2011/09/18 13:19:02 | 000,352,973 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\Amendmeent for screening.pdf
[2011/09/18 13:19:02 | 000,095,264 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\ABB complaint.pdf
[2011/09/18 13:19:01 | 000,018,941 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\2009 Balcony Assessment 500K.zip
[2011/09/18 13:18:54 | 007,108,875 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Desktop\21Candlesticks.pdf
[2011/08/30 22:02:54 | 000,035,000 | -H– | C] () – C:\WINDOWS\System32\mxntdfg.exe
[2010/12/19 14:41:57 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\.googlewebacchosts
[2010/10/05 15:26:54 | 000,116,224 | -H– | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2010/09/23 19:16:04 | 000,186,315 | -H– | C] () – C:\WINDOWS\hpwins23.dat.temp
[2010/09/23 19:16:04 | 000,001,847 | -H– | C] () – C:\WINDOWS\hpwmdl23.dat.temp
[2010/09/11 15:48:31 | 000,000,152 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\fusioncache.dat
[2010/07/09 08:04:40 | 000,082,236 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/05/17 18:06:53 | 000,023,117 | -H– | C] () – C:\WINDOWS\hpqins15.dat
[2010/05/03 16:38:55 | 000,077,382 | -H– | C] () – C:\WINDOWS\hpqins05.dat
[2010/05/02 14:40:15 | 000,229,207 | -H– | C] () – C:\WINDOWS\hpwins23.dat
[2010/05/02 14:40:15 | 000,002,075 | -H– | C] () – C:\WINDOWS\hpwmdl23.dat
[2010/02/16 15:42:32 | 000,033,036 | -H– | C] () – C:\WINDOWS\MAXLINK.INI
[2009/08/03 15:07:42 | 000,403,816 | -H– | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H– | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/26 18:12:35 | 000,020,549 | -H– | C] () – C:\WINDOWS\System32\javaw.exe
[2009/06/26 18:12:35 | 000,020,547 | -H– | C] () – C:\WINDOWS\System32\java.exe
[2009/05/24 09:56:56 | 016,742,799 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\vlc-0.9.9-win32.exe
[2009/05/04 07:49:25 | 000,000,164 | -H– | C] () – C:\WINDOWS\install.dat
[2009/03/21 15:12:50 | 000,061,132 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\rx_audio.Cache
[2009/03/07 09:31:26 | 000,000,335 | -H– | C] () – C:\WINDOWS\nsreg.dat
[2009/02/18 09:46:27 | 000,002,496 | -H– | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/01/10 10:11:50 | 000,150,262 | -H– | C] () – C:\WINDOWS\hpwins05.dat
[2009/01/10 10:10:39 | 000,016,050 | -H– | C] () – C:\WINDOWS\hpwscr05.dat
[2009/01/10 10:10:39 | 000,004,785 | -H– | C] () – C:\WINDOWS\hpwmdl05.dat
[2008/12/30 08:33:34 | 000,000,069 | -H– | C] () – C:\WINDOWS\NeroDigital.ini
[2008/12/19 13:22:22 | 000,118,784 | -H– | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2008/12/19 13:22:19 | 000,338,944 | -H– | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2008/12/15 11:20:23 | 000,000,000 | -H– | C] () – C:\WINDOWS\asym.ini
[2008/12/13 09:48:10 | 000,000,031 | -H– | C] () – C:\WINDOWS\sbewin32.INI
[2008/10/18 12:43:50 | 000,000,010 | -H– | C] () – C:\WINDOWS\msoffice.ini
[2008/09/30 02:59:59 | 000,036,864 | -H– | C] () – C:\WINDOWS\System32\BGData.bin
[2008/09/11 13:28:44 | 000,000,000 | -H– | C] () – C:\WINDOWS\iPlayer.INI
[2008/09/10 08:11:21 | 000,027,136 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/04 08:44:25 | 001,691,948 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\rx_image.Cache
[2008/09/02 22:27:27 | 000,087,608 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\inst.exe
[2008/09/02 22:27:27 | 000,007,887 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pcouffin.cat
[2008/09/02 22:27:27 | 000,001,144 | -H– | C] () – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pcouffin.inf
[2008/09/02 21:54:21 | 000,000,705 | -H– | C] () – C:\WINDOWS\csback.exe.lnk
[2008/09/02 14:39:45 | 000,335,872 | -H– | C] () – C:\WINDOWS\System32\ldf252.dll
[2008/09/02 14:36:36 | 000,000,034 | -H– | C] () – C:\WINDOWS\hpfsched.ini
[2008/09/02 11:52:10 | 000,000,000 | -H– | C] () – C:\WINDOWS\vpc32.INI
[2008/09/01 18:40:43 | 000,002,608 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat.pctools
[2008/09/01 18:20:52 | 000,000,066 | -H– | C] () – C:\WINDOWS\SBWIN.INI
[2008/09/01 18:20:27 | 000,047,616 | -H– | C] () – C:\WINDOWS\System32\P16X.dll
[2008/09/01 18:20:27 | 000,002,516 | -H– | C] () – C:\WINDOWS\System32\P16X.ini
[2008/09/01 18:20:27 | 000,000,026 | -H– | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/09/01 18:07:55 | 000,000,376 | -H– | C] () – C:\WINDOWS\ODBC.INI
[2008/09/01 17:43:39 | 000,012,288 | -H– | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2008/09/01 17:04:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/09/01 16:59:35 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/09/01 12:53:12 | 000,004,161 | -H– | C] () – C:\WINDOWS\ODBCINST.INI
[2008/09/01 12:52:09 | 000,364,120 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 21:59:42 | 000,018,904 | -H– | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | -H– | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 10:51:02 | 000,020,698 | -H– | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | -H– | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | -H– | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/06 13:07:30 | 000,462,848 | -H– | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/03/13 18:52:37 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\px.ini
[2007/02/05 14:55:40 | 000,051,960 | -H– | C] () – C:\WINDOWS\System32\besch.exe
[2007/02/05 14:49:44 | 000,035,576 | -H– | C] () – C:\WINDOWS\System32\besched.dll
[2005/08/26 15:28:34 | 000,143,360 | -H– | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 15:27:58 | 000,045,056 | -H– | C] () – C:\WINDOWS\devenum.exe
[2005/03/21 19:48:05 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/21 19:48:05 | 000,004,627 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 06:00:00 | 000,755,200 | -H– | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 06:00:00 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 06:00:00 | 000,465,784 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 06:00:00 | 000,338,432 | -H– | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 06:00:00 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 06:00:00 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 06:00:00 | 000,200,192 | -H– | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 06:00:00 | 000,183,808 | -H– | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 06:00:00 | 000,120,320 | -H– | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2004/08/04 06:00:00 | 000,079,670 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 06:00:00 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 06:00:00 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 06:00:00 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 06:00:00 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2003/10/02 01:00:00 | 000,208,896 | -H– | C] () – C:\WINDOWS\System32\lockout.dll
[2003/10/02 01:00:00 | 000,045,056 | -H– | C] () – C:\WINDOWS\System32\lockres.dll
[2003/09/01 11:06:14 | 000,002,696 | -H– | C] () – C:\WINDOWS\MIXDEF.INI
[2001/10/25 10:54:53 | 000,036,864 | -H– | C] () – C:\WINDOWS\hpfsched.exe
[2001/10/25 10:53:34 | 000,003,691 | -H– | C] () – C:\WINDOWS\hphinfs.dat
[2001/07/07 03:00:00 | 000,003,399 | -H– | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/10/26 21:08:43 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\.oit
[2008/09/24 08:45:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\ACD Systems
[2008/09/28 22:02:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\alot
[2011/08/30 22:38:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Avanquest
[2010/07/28 22:04:46 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Backup MyPC
[2010/09/11 23:57:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\CBS Interactive
[2011/03/05 08:44:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Charles Schwab
[2008/09/19 21:41:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/10/18 12:58:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\CompuServe Dialer
[2009/01/12 18:00:24 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\DriverCure
[2010/09/28 20:09:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\DVDFab
[2011/06/19 09:07:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\ElevatedDiagnostics
[2009/09/29 19:34:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\ErrorWiz
[2009/04/05 13:23:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Image Zone Express
[2008/11/21 09:57:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\mjusbsp
[2011/07/23 14:38:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\MP3Rocket
[2010/08/15 15:34:50 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\NCH Swift Sound
[2010/10/26 17:23:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Nuance
[2009/09/03 08:55:38 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Opera
[2010/10/05 15:29:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\pdfforge
[2009/01/10 10:26:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Printer Info Cache
[2010/12/11 17:22:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Red Kawa
[2010/12/11 17:23:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Regensoft
[2011/06/24 08:18:41 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\RegistryKeys
[2011/10/06 08:54:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Sammsoft
[2011/08/27 23:59:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Search Settings
[2011/06/25 16:42:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\SpeedMaxPc
[2010/02/20 15:16:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\TeamViewer
[2011/02/18 16:12:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\uTorrent
[2011/06/20 23:17:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Vso
[2010/12/26 16:43:18 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\webex
[2011/07/20 16:15:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Windows Desktop Search
[2011/07/20 16:21:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Windows Search
[2010/10/26 17:27:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Application Data\Zeon
[2009/04/28 08:44:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\1stWorks
[2011/08/30 22:03:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2011/09/19 20:25:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/10/06 09:08:27 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/10/18 13:01:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CompuServe Dialer
[2009/01/12 17:48:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/10/28 19:43:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Driver Medic
[2010/02/20 15:09:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2008/12/17 09:49:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/07/14 18:42:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2010/10/13 14:05:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MagicSoftware
[2011/10/06 09:08:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/08/15 15:35:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/05/24 09:56:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2010/10/26 17:34:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2009/01/12 17:48:43 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2008/09/02 14:19:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/10/26 17:22:50 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/06/25 16:56:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\SpeedMaxPc
[2011/10/06 16:37:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/09/19 18:17:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/18 13:50:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2010/06/14 21:58:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2009/04/07 08:50:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2011/08/27 08:04:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\YouTube Downloader
[2010/10/26 17:24:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\zeon
[2009/03/13 21:32:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/07/06 22:57:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/04/10 15:42:04 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/10/03 06:37:00 | 000,000,472 | -H– | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/09/15 18:26:01 | 000,000,294 | -H– | M] () – C:\WINDOWS\Tasks\goldenShakeIcon.job
[2011/09/11 07:56:02 | 000,001,050 | -H– | M] () – C:\WINDOWS\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job
[2011/10/05 22:02:01 | 000,000,250 | -H– | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/10/30 22:26:59 | 000,001,024 | -H– | M] () – C:\.rnd
[2011/08/03 23:03:38 | 000,027,996 | -H– | M] () – C:\aaw7boot.log
[2009/09/19 18:33:17 | 000,010,920 | -H– | M] () – C:\aolconnfix.exe
[2009/09/19 18:33:17 | 000,001,039 | -H– | M] () – C:\aolconnfix.txt
[2008/09/01 17:02:27 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2011/09/18 08:18:31 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/09/01 17:02:27 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2010/08/20 20:38:59 | 000,000,000 | -H– | M] () – C:\ieout.txt
[2008/09/01 18:19:01 | 000,000,164 | -H– | M] () – C:\install.dat
[2008/09/01 17:02:27 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/09 08:07:41 | 000,035,800 | -H– | M] () – C:\mombi.log
[2008/09/01 17:02:27 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/05 07:39:24 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/06 16:20:00 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | -H– | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | -H– | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | -H– | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/09/01 17:02:01 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2010/05/14 14:56:34 | 000,319,488 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp02t.dll
[2008/08/12 10:58:10 | 000,314,880 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp082.dll
[2006/07/03 11:54:12 | 000,091,648 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp4sa.dll
[2008/07/24 13:09:54 | 000,273,920 | -H– | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp58a.dll
[2010/12/08 14:11:52 | 000,053,632 | -H– | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2007/04/09 13:23:54 | 000,028,552 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | -H– | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/08/20 20:39:00 | 000,081,408 | -H– | M] (Microsoft Corporation) – C:\Program Files\taskkill.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/09/01 12:51:20 | 000,094,208 | -H– | M] () – C:\WINDOWS\System32\config\default.sav
[2008/09/01 12:51:20 | 000,659,456 | -H– | M] () – C:\WINDOWS\System32\config\software.sav
[2008/09/01 12:51:20 | 000,892,928 | -H– | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-09-28 07:02:59

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2011/10/04 19:54:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp
[2011/10/04 19:54:57 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp\1
[2011/10/04 21:18:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp\2
[2011/10/05 22:55:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\..\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\smtmp\4

< %temp%\smtmp\*.* /s > >


< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | -H– | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 06:00:00 | 001,032,192 | -H– | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: EXPLORER.EXE-05416907.PF >
[2011/10/06 09:11:15 | 000,069,830 | —- | M] () MD5=4BD63E61A889D84FAE439C8CEEB0BD29 – C:\WINDOWS\Prefetch\EXPLORER.EXE-05416907.pf

< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | -H– | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | -H– | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | -H– | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | -H– | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\ie8\iexplore.chm
[2004/08/04 06:00:00 | 000,204,810 | -H– | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/29 03:25:31 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/19 01:25:25 | 000,634,024 | -H– | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 02:34:58 | 000,633,632 | -H– | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 07:25:27 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | -H– | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/19 01:25:30 | 000,634,024 | -H– | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/23 01:56:15 | 000,635,848 | -H– | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 11:12:57 | 000,634,656 | -H– | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2009/08/27 01:18:42 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 04:35:10 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 06:34:43 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/28 02:54:16 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 09:05:43 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | -H– | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | -H– | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\SoftwareDistribution\Download\13d5d266d7681d26b42f8dff88cadc20\SP2GDR\iexplore.exe
[2010/10/18 07:07:43 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/28 02:54:21 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2008/10/15 03:06:26 | 000,633,632 | -H– | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 00:54:41 | 000,636,072 | -H– | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 10:45:15 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:08:29 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/23 01:20:02 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2010/12/20 06:49:55 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/28 00:54:44 | 000,636,088 | -H– | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | -H– | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:43:25 | 000,634,656 | -H– | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | -H– | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\SoftwareDistribution\Download\13d5d266d7681d26b42f8dff88cadc20\SP2QFE\iexplore.exe
[2010/02/23 01:19:59 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 03:00:27 | 000,634,632 | -H– | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2010/10/18 06:36:30 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | -H– | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2011/02/14 07:36:55 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 08:17:08 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 07:30:33 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 06:00:00 | 000,093,184 | -H– | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2008/08/23 01:56:16 | 000,635,848 | -H– | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2010/08/25 07:07:58 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 01:18:44 | 000,634,648 | -H– | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.000 >
[2007/08/13 18:43:56 | 000,622,080 | -H– | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe.000

< MD5 for: IEXPLORE.EXE.MDMP >
[2011/10/06 00:28:08 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Administrator.ARNIE-30F18ED3E\Local Settings\Temp\WER249c.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-06887102.PF >
[2011/10/06 09:11:37 | 000,033,424 | —- | M] () MD5=DD9212145ED3CFAF3A649949CBFFD7F2 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-06887102.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | -H– | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: IEXPLORE.RAR >
[2011/08/03 21:50:58 | 000,248,797 | -H– | M] () MD5=9EFA7DB104C1CAD93001CFB100146517 – C:\Program Files\Internet Explorer\iexplore.rar

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:00:00 | 000,502,272 | -H– | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | -H– | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | -H– | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 241 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:01C66DD9
@Alternate Data Stream - 238 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B9FB94D
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >
ComboFix 11-10-06.04 - Administrator 10/06/2011 23:22:45.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2941 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\ACD Systems\ACDSee\ImageDB.ddf
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\alot
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\ErrorWiz
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\ErrorWiz\Backup\Automatic Backup_09-29-2009_19-33-59.reg
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\ErrorWiz\settings.ini
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Protect\gijkikp.f
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Protect\ifuolvt.l
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Protect\rbuxp.n
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\Microsoft\Protect\yqujqs.t
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Data Restore
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Data Restore\Data Restore.lnk
c:\documents and settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Data Restore\Uninstall Data Restore.lnk
c:\documents and settings\Administrator.ARNIE-30F18ED3E\WINDOWS
c:\documents and settings\All Users\Application Data\6DSS92c31Apgjk.exe.pctools
c:\documents and settings\All Users\Application Data\DIDfuRcLeJEc.exe.pctools
c:\documents and settings\All Users\Application Data\nXBPpaqQtFIXr.exe.pctools
c:\documents and settings\All Users\Application Data\vlc-0.9.9-win32.exe
c:\program files\Common Files\Uninstall
.
.
((((((((((((((((((((((((( Files Created from 2011-09-07 to 2011-10-07 )))))))))))))))))))))))))))))))
.
.
2011-10-06 23:46 . 2011-10-06 23:46 63115 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-10-06 23:46 . 2011-10-06 23:46 4599 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-10-06 23:46 . 2011-10-06 23:46 6429 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-10-06 23:46 . 2011-10-06 23:46 8646 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-10-06 23:46 . 2011-10-06 23:46 9310 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2011-10-06 23:46 . 2011-10-06 23:46 5927 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2011-10-06 23:46 . 2011-10-06 23:46 8613 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2011-10-06 23:46 . 2011-10-06 23:46 1651 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2011-10-06 23:46 . 2011-10-06 23:46 6910 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2011-10-06 23:45 . 2011-10-06 23:45 18541 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2011-10-06 23:45 . 2011-10-06 23:45 6208 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2011-10-06 23:45 . 2011-10-06 23:45 8288 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2011-10-06 23:40 . 2011-10-06 23:40 51852 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2011-10-06 23:40 . 2011-10-06 23:40 20719 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-10-06 23:40 . 2011-10-06 23:40 23327 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-10-06 23:40 . 2011-10-06 23:40 8782 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-10-06 23:40 . 2011-10-06 23:40 7271 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-10-06 23:00 . 2011-10-06 23:00 ——– d—–w- C:\_OTL
2011-10-06 13:08 . 2011-10-06 13:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Common Files
2011-10-06 13:08 . 2011-10-06 13:08 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-10-06 12:59 . 2011-10-06 13:01 ——– d—–w- c:\program files\Trend Micro
2011-10-06 12:54 . 2011-10-06 12:54 ——– d—–w- c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\Sammsoft
2011-10-06 12:54 . 2011-10-06 12:54 ——– d—–w- c:\program files\ARO 2011
2011-10-06 04:37 . 2011-08-18 13:31 184536 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2011-10-06 04:25 . 2011-10-06 04:25 ——– d—–w- c:\documents and settings\Administrator.ARNIE-30F18ED3E\Local Settings\Application Data\Threat Expert
2011-10-06 03:50 . 2010-12-31 13:36 69392 –s—w- c:\windows\system32\drivers\TfSysMon.sys
2011-10-06 03:50 . 2010-12-31 13:36 33552 –s—w- c:\windows\system32\drivers\TfNetMon.sys
2011-10-06 03:50 . 2010-12-31 13:36 51984 –s—w- c:\windows\system32\drivers\TfFsMon.sys
2011-10-06 02:46 . 2011-09-01 15:39 1533904 —-a-w- c:\windows\PCTBDRes.dll
2011-10-06 02:46 . 2011-09-01 15:39 149456 —-a-w- c:\windows\SGDetectionTool.dll
2011-10-06 02:46 . 2011-09-01 15:39 2189264 —-a-w- c:\windows\PCTBDCore.dll
2011-10-06 02:46 . 2011-09-01 15:38 767952 —-a-w- c:\windows\BDTSupport.dll
2011-10-06 02:20 . 2011-07-19 13:18 252712 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-10-06 02:20 . 2010-07-16 18:59 656320 —-a-w- c:\windows\system32\drivers\pctEFA.sys
2011-10-06 02:20 . 2010-07-16 18:59 338880 —-a-w- c:\windows\system32\drivers\pctDS.sys
2011-10-06 02:20 . 2011-08-23 15:45 326688 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2011-10-06 02:20 . 2011-03-02 15:39 162200 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-10-06 02:20 . 2011-07-19 13:23 70664 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2011-10-06 02:20 . 2011-10-07 03:16 ——– d—–w- c:\program files\PC Tools Security
2011-10-06 02:20 . 2011-10-06 02:25 ——– d—–w- c:\program files\Common Files\PC Tools
2011-10-06 02:20 . 2011-10-06 02:20 ——– d—–w- c:\documents and settings\Administrator.ARNIE-30F18ED3E\Application Data\PC Tools
2011-10-06 02:07 . 2011-10-06 03:50 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2011-09-20 00:25 . 2011-09-20 00:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Cisco Systems
2011-09-18 17:30 . 2011-09-18 17:30 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2004-08-04 10:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-08-03 18:08 . 2008-09-03 01:53 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2011-08-03 18:07 . 2008-09-03 01:52 24576 —-a-w- c:\windows\system32\prefscpl.cpl
2011-07-27 16:29 . 2008-09-03 07:48 276352 ——w- c:\windows\system32\XceedSco.dll
2011-07-27 02:45 . 2011-06-17 10:27 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2004-08-04 10:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 15:20 . 2011-07-12 15:20 83816 -c–a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 -c–a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 -c–a-w- c:\windows\system32\dnssdX.dll
2010-08-21 00:39 . 2010-08-21 00:39 81408 -c–a-w- c:\program files\taskkill.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-24 01:20 1515688 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\documents and settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-11 68856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-07-18 451872]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-04-17 95536]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-08-09 1176064]
"AROReminder"="c:\program files\ARO 2011\aro.exe" [2011-01-25 2312048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 48752]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2005-06-23 85696]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-10-25 311296]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"IndexSearch"="c:\program files\Nuance\PaperPort\IndexSearch.exe" [2010-02-11 46368]
"PaperPort PTD"="c:\program files\Nuance\PaperPort\pptd40nt.exe" [2010-02-11 29984]
"PPort12reminder"="c:\program files\Nuance\PaperPort\Ereg\Ereg.exe" [2010-02-09 328992]
"PDFHook"="c:\program files\Nuance\PDFViewerPlus\pdfpro5hook.exe" [2010-02-08 1369376]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-08-17 534880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"Matrox Powerdesk"="c:\windows\system32\PDesk\PDesk.exe" [2002-02-14 651264]
"ISTray"="c:\program files\PC Tools Security\pctsGui.exe" [2011-09-01 1600984]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-25 196608]
"DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2007-02-12 109304]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-08-24 887976]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2011-08-03 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-04-17 54576]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-09-01 247760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
CompuServe 7.0 Tray Icon.lnk - c:\program files\CompuServe 7.0a\cstray.exe [2011-8-3 32840]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
HP OfficeJet T Series Startup.lnk - c:\program files\Hewlett-Packard\HP OfficeJet T Series\Bin\HPOstr05.exe [N/A]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-08 18:11 87424 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator.ARNIE-30F18ED3E^Start Menu^Programs^Startup^eClean 2000.lnk]
path=c:\documents and settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Startup\eClean 2000.lnk
backup=c:\windows\pss\eClean 2000.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator.ARNIE-30F18ED3E^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Administrator.ARNIE-30F18ED3E\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Google Web Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Google Web Accelerator.lnk
backup=c:\windows\pss\Run Google Web Accelerator.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 16:55 937920 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InstallIQUpdater]
2011-08-09 21:02 1176064 —-a-w- c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF5 Registry Controller]
2010-02-08 22:31 62752 —-a-w- c:\program files\Nuance\PDFViewerPlus\RegistryController.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\1stWORKS\\hotCommCL\\BIN\\HotComm.exe"=
"c:\\Program Files\\Schwab\\SSPro\\SSPro.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Smart Web Printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Sonic Shared\\RoxioUPnPRenderer9.exe"=
"c:\\Program Files\\Roxio\\Creator Classic 9\\Creator9.exe"=
"c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/5/2011 10:20 PM 326688]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [10/5/2011 10:20 PM 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [10/5/2011 10:20 PM 656320]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [10/5/2011 10:20 PM 252712]
S1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [10/6/2011 12:37 AM 184536]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys –> c:\program files\LogMeIn\x86\RaInfo.sys [?]
S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [10/25/2001 10:54 AM 18864]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [9/2/2008 10:27 PM 47360]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [10/5/2011 10:20 PM 70664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 21:53 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2010-09-15 c:\windows\Tasks\goldenShakeIcon.job
- c:\program files\NCH Swift Sound\Golden\golden.exe [2010-08-15 19:34]
.
2011-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-18 17:06]
.
2011-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-18 17:06]
.
2011-09-11 c:\windows\Tasks\RCHubTask 0 0 {2E6E3A14-F6F5-404E-AC33-87F20083074D} 0~0.job
- c:\program files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe [2007-02-13 22:51]
.
2011-10-06 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-08-24 01:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Open with PDF Viewer Plus - c:\program files\Nuance\PDFViewerPlus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: microsoft.com\support
TCP: DhcpNameServer = 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
HKU-Default-RunOnce-AutoLaunch - c:\program files\Lavasoft\Ad-Aware\AutoLaunch.exe
MSConfigStartUp-ErrorWiz - c:\program files\ErrorWiz\ErrorWiz.exe
MSConfigStartUp-LogMeIn GUI - c:\program files\LogMeIn\x86\LogMeInSystray.exe
MSConfigStartUp-NeroCheck - c:\windows\system32\NeroCheck.exe
MSConfigStartUp-RegistryMechanic - c:\program files\Registry Mechanic\RegMech.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-AOL Emergency Connect Utility 1.0 - c:\program files\Common Files\AOL\ECU\uninst.exe
AddRemove-OVT Scanner - c:\windows\omniuns.exe USB\Vid_05a9&PID_1550 OVT Scanner
AddRemove-3651594166.www.tc2000.com - c:\program files\Microsoft Silverlight\4.0.51204.0\Silverlight.Configuration.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-06 23:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bf,29,a7,b8,18,57,1e,40,b3,df,c8,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2011-10-06 23:50:26
ComboFix-quarantined-files.txt 2011-10-07 03:50
.
Pre-Run: 56,807,907,328 bytes free
Post-Run: 57,046,003,712 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - F090359F4E4A9381E682685075E00382
Hi jeffkush, Symantec can be difficult to remove especialy the version you have installed. Give me a bit to see if I can find an uninstaller for it. Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI