Hi,
Below are the OTL results. Running MBR now.
OTL logfile created on: 12/6/2011 8:27:52 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Derek\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 72.66% Memory free
4.84 Gb Paging File | 4.17 Gb Available in Paging File | 86.19% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 763.11 Gb Free Space | 81.92% Space Free | Partition Type: NTFS
Drive E: | 11.17 Gb Total Space | 10.27 Gb Free Space | 91.94% Space Free | Partition Type: FAT32
Drive X: | 931.51 Gb Total Space | 420.21 Gb Free Space | 45.11% Space Free | Partition Type: NTFS
Computer Name: DEREK | User Name: Derek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Derek\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
========== Win32 Services (SafeList) ==========
SRV - (ZuneBusEnum) – File not found
SRV - (WSearch) – File not found
SRV - (ThreatFire) – File not found
SRV - (srv3844) – File not found
SRV - (sdCoreService) – File not found
SRV - (sdAuxService) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (MSCamSvc) – File not found
SRV - (JavaQuickStarterService) – File not found
SRV - (CCALib8) – File not found
SRV - (AsSysCtrlService) – File not found
SRV - (AppMgmt) – File not found
SRV - (ADVService) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) – C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirMailService) – C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (WMZuneComm) – c:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – c:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (NMSAccess) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
========== Driver Services (SafeList) ==========
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avkmgr) – C:\WINDOWS\system32\drivers\avkmgr.sys (Avira GmbH)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (szkg5) – C:\WINDOWS\system32\drivers\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (mv91cons) – C:\WINDOWS\system32\DRIVERS\mv91cons.sys (Marvell Semiconductor Inc.)
DRV - (mv91xx) – C:\WINDOWS\system32\DRIVERS\mv91xx.sys (Marvell Semiconductor, Inc.)
DRV - (nusb3xhc) – C:\WINDOWS\system32\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV - (nusb3hub) – C:\WINDOWS\system32\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (MSHUSBVideo) – C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
DRV - (mv61xx) – C:\WINDOWS\system32\DRIVERS\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (AlesisFirewire) – C:\WINDOWS\system32\drivers\AlesisFirewire.sys (Alesis)
DRV - (AlesisFirewireAudio) – C:\WINDOWS\system32\drivers\AlesisFirewireAudio.sys (Alesis)
DRV - (AlesisFirewireMidi) – C:\WINDOWS\system32\drivers\AlesisFirewireMidi.sys (Alesis)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (SUSTUCAU) – C:\WINDOWS\system32\drivers\sustucau.sys (Susteen, Inc.)
DRV - (SUSTUCAP) – C:\WINDOWS\system32\drivers\sustucap.sys (Susteen, Inc.)
DRV - (SUSTUCAM) – C:\WINDOWS\system32\drivers\sustucam.sys (Susteen, Inc.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (DiceAudioStrm) – C:\WINDOWS\system32\drivers\DiceAudioStrm.sys (TC Tech Inc.)
DRV - (Dice1394) – C:\WINDOWS\system32\drivers\Dice1394.sys (TC Tech Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (Lynx) – C:\WINDOWS\SYSTEM32\DRIVERS\Lynx.SYS (Lynx Studio Technology, Inc.)
DRV - (banshee) – C:\WINDOWS\system32\drivers\banshee.sys (3Dfx Interactive, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.msn.com/?ocid=OIE8HP&PC;=B8DF
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.98
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {ecdee021-0d17-467f-a1ff-c7a115230949}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..keyword.URL: "
http://search.search-go.net/?sid=10101052100&s;="
FF - prefs.js..network.proxy.type: 0
FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "
http://search.search-go.net/?sid=10101052100&s;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/05/11 05:15:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/12/26 05:18:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/02 10:35:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/02 10:35:40 | 000,000,000 | —D | M]
[2011/11/30 07:51:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Extensions
[2011/12/06 06:25:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions
[2011/03/29 07:45:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/14 07:35:32 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/09/14 11:54:44 | 000,000,000 | —D | M] (NCH) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}
[2011/12/02 12:41:21 | 000,000,000 | —D | M] (Microsoft Choice Guard) – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\extensions\ChoiceGuard@Microsoft
[2010/01/20 12:16:28 | 000,000,939 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\conduit.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Mozilla\Firefox\Profiles\laih9axv.default\searchplugins\Search_Results.xml
[2011/12/02 10:35:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/23 07:26:01 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/12/02 10:35:38 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/29 18:01:26 | 000,302,904 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2003/03/18 21:20:00 | 001,060,864 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\mfc71.dll
[2003/02/21 04:42:22 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\msvcr71.dll
[2011/11/29 18:01:23 | 000,176,952 | —- | M] (Cisco WebEx LLC) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2010/05/21 11:16:22 | 000,155,648 | —- | M] (IBM Corporation) – C:\Program Files\mozilla firefox\plugins\npmfv.dll
[2011/12/02 10:35:33 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2009/09/25 11:39:22 | 000,003,700 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.png
[2009/09/25 11:39:22 | 000,001,963 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fast.xml
[2011/11/29 06:56:12 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2011/12/02 10:35:33 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll (IBM Corporation)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\Windows iLivid Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No CLSID value found.
O3 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe ()
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKU\.DEFAULT..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-18..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-299502267-1682526488-839522115-1004..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LynxONE TaskBar Icon.lnk = C:\Program Files\Lynx Studio Technology\Mixer.exe (Lynx Studio Technology, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKU\S-1-5-21-299502267-1682526488-839522115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O15 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\..Trusted Domains: microsoft.com ([www.update] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B}
https://wimpro.cce.hp.com/ChatEntry/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1238886182500 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20614.www2.hp.com/ediags/gmd/Insta…hpdetect118.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5}
https://wimpro.cce.hp.com/ChatEntry/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8}
http://3dlifeplayer.dl.3dvia.com/player/in…r_installer.exe (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://splicesoftware.webex.com/client/T27…ort/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmincdn.com/gcp/ie/2.9.3.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B0D9737B-FE70-4AAF-8488-91E2AB77D517}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D7CBB56E-AA01-4B35-8F5B-FD8CB4A59325}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\SKYPE\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc)
O20 - AppInit_DLLs: (C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll) -C:\Program Files\Windows iLivid Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - (TPSvc.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Derek\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/04 14:16:45 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{35b89d1f-ef10-11de-834f-00248c5e6886}\Shell\AutoRun\command - "" = F:\MI.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\S-1-5-21-299502267-1682526488-839522115-1004\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: srv3844 - File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
File not found – C:\WINDOWS\System32\
[2011/12/06 06:09:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1206
[2011/12/05 20:13:32 | 000,000,000 | —D | C] – C:\VS2010-VPC
[2011/12/05 19:41:52 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2011/12/05 17:20:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Picasa 3
[2011/12/05 17:17:51 | 000,000,000 | —D | C] – C:\Program Files\Picasa3
[2011/12/05 12:52:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\Flagstar Statements
[2011/12/05 08:17:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1205
[2011/12/02 12:41:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Tracing
[2011/12/02 12:39:59 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/12/02 12:37:52 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/12/02 12:37:34 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2011/12/02 12:37:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
[2011/12/02 12:37:08 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/12/02 12:33:29 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/12/02 06:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1202
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/12/01 08:41:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\STOPzilla
[2011/12/01 08:41:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/12/01 07:46:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/01 06:59:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\1201
[2011/11/30 19:45:38 | 000,547,880 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/11/30 07:14:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/11/29 18:34:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\New Folder
[2011/11/29 18:01:38 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Derek\My Documents\cache
[2011/11/29 18:01:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\webex
[2011/11/29 09:45:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONTACTS
[2011/11/29 06:57:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\Ilivid Player
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\AppData
[2011/11/29 06:56:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/11/29 06:56:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/11/29 06:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\PackageAware
[2011/11/24 11:07:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/11/24 11:04:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Digiarty
[2011/11/24 11:04:49 | 000,000,000 | —D | C] – C:\Program Files\Digiarty
[2011/11/24 11:04:25 | 008,249,312 | —- | C] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:36:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NCH Software Suite
[2011/11/23 22:32:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\My Documents\HP Photosmart Projects
[2011/11/23 22:31:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\HP
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/23 22:25:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Visan
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2011/11/23 22:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP Photo Creations
[2011/11/23 07:25:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/11/21 11:45:56 | 005,073,240 | —- | C] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/21 08:38:35 | 000,000,000 | —D | C] – C:\CTCTOutlook
[2011/11/21 08:32:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Constant Contact
[2011/11/18 09:27:30 | 000,000,000 | —D | C] – C:\Program Files\Constant Contact
[2011/11/17 08:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Application Data\Avira
[2011/11/17 08:09:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/11/17 08:09:16 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:09:10 | 000,134,344 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:09:10 | 000,074,640 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/17 08:09:10 | 000,036,000 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/15 07:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\SCANS for Derek
[2011/11/15 03:00:40 | 000,016,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/11/14 17:11:41 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/11/14 17:10:58 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[2011/11/14 14:43:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Allison's Music
[2011/11/14 12:07:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2011/11/14 12:06:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2011/11/14 12:05:09 | 000,600,680 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\easyupdatusapiu.dll
[2011/11/14 12:03:28 | 017,186,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/11/14 12:03:28 | 002,387,560 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/11/14 12:03:28 | 002,090,088 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/11/14 12:03:28 | 000,914,024 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco32.dll
[2011/11/14 12:03:28 | 000,875,112 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco32.dll
[2011/11/14 12:03:28 | 000,061,440 | —- | C] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/11/14 12:02:46 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2011/11/14 12:01:51 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/14 12:00:23 | 001,691,480 | —- | C] (Creative) – C:\WINDOWS\System32\drivers\Ambfilt.sys
[2011/11/14 11:59:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Renesas Electronics
[2011/11/14 11:59:15 | 000,000,000 | —D | C] – C:\Program Files\Renesas Electronics
[2011/11/14 11:44:53 | 000,023,456 | —- | C] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:44:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Local Settings\Application Data\eSupport.com
[2011/11/11 15:48:16 | 001,564,976 | —- | C] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 13:22:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Derek\Desktop\Virus-Spyware
[2011/11/10 14:08:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\CONCEPTUAL ARTS
[2011/11/10 05:21:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/09 11:48:25 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/09 09:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2011/08/09 09:40:30 | 004,500,784 | —- | C] (Amazon.com ) – C:\Program Files\AmazonUnboxVideo.exe
[2011/01/29 17:24:59 | 038,147,376 | —- | C] (Apple Inc.) – C:\Program Files\QuickTimeInstaller.exe
[2011/01/28 07:47:42 | 004,770,043 | —- | C] (Canneverbe Limited ) – C:\Program Files\cdbxp_setup_4.3.8.2474.exe
[2010/05/18 12:59:40 | 002,942,176 | —- | C] (Siber Systems) – C:\Program Files\AiRoboForm.exe
[2010/03/02 11:14:39 | 169,720,592 | —- | C] (IMSIDesign ) – C:\Program Files\TurboCAD-Deluxe-16-2.exe
[2009/05/29 05:27:46 | 000,301,384 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\All Users\Application Data\dxwebsetup.exe
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
File not found – C:\WINDOWS\System32\
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job
[2011/12/06 07:50:00 | 000,000,476 | —- | M] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/12/06 06:47:41 | 000,482,856 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/06 06:47:41 | 000,085,286 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/06 06:45:24 | 000,000,744 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/06 06:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/06 06:06:33 | 000,000,433 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shared Folder.lnk
[2011/12/05 20:17:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/05 19:49:42 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/05 19:48:38 | 000,000,815 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/05 19:26:31 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/12/05 19:26:31 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/12/05 19:21:43 | 000,280,276 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\tasks\File Backup.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\tasks\Update Tasks.job
[2011/12/05 17:20:17 | 000,000,684 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 17:04:11 | 000,039,424 | —- | M] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/05 12:51:51 | 000,394,108 | —- | M] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/05 06:22:48 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/02 15:05:15 | 000,002,231 | —- | M] () – C:\Documents and Settings\Derek\Desktop\Shortcut to VMRecorder.exe.lnk
[2011/12/01 07:44:02 | 000,000,071 | —- | M] () – C:\WINDOWS\Pex.INI
[2011/11/30 19:45:38 | 000,547,880 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/11/30 19:45:38 | 000,134,184 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/11/30 19:45:38 | 000,024,616 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/11/30 19:45:36 | 000,482,344 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/11/30 19:45:36 | 000,457,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/11/30 19:45:36 | 000,392,232 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/11/30 19:45:36 | 000,232,488 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/11/30 19:45:36 | 000,105,512 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/11/30 19:45:36 | 000,101,416 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/11/30 19:45:36 | 000,068,648 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/11/30 19:45:36 | 000,030,248 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/11/30 19:45:34 | 000,740,392 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/11/29 09:55:54 | 000,043,976 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/29 09:55:53 | 002,809,162 | —- | M] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\tasks\Clone Backup.job
[2011/11/24 11:04:32 | 008,249,312 | —- | M] (Digiarty Software,Inc. ) – C:\Program Files\winx-mov-to-wmv.exe
[2011/11/23 22:30:54 | 000,019,497 | —- | M] () – C:\WINDOWS\hpqins13.dat
[2011/11/21 11:55:48 | 005,073,240 | —- | M] (Microsoft Corporation) – C:\Program Files\vcredist_x86.exe
[2011/11/17 08:07:43 | 000,028,520 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/17 08:07:42 | 000,036,000 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/17 08:07:41 | 000,134,344 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/17 08:07:40 | 000,074,640 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/15 03:39:09 | 000,275,760 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/14 13:29:22 | 000,000,014 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2011/11/14 12:25:23 | 000,000,298 | RHS- | M] () – C:\boot.ini
[2011/11/14 12:04:55 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 11:44:53 | 000,023,456 | —- | M] (Phoenix Technologies) – C:\WINDOWS\System32\drivers\DrvAgent32.sys
[2011/11/14 11:36:19 | 000,177,751 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/11/14 11:31:54 | 000,210,085 | —- | M] () – C:\MGlogs.zip
[2011/11/11 15:48:16 | 001,564,976 | —- | M] (Kaspersky Lab ZAO) – C:\Program Files\TDSSKiller.exe
[2011/11/11 14:07:16 | 000,001,037 | —- | M] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/11 09:17:52 | 000,000,000 | —- | M] () – C:\WINDOWS\2771026874
[2011/11/10 22:44:02 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/06 06:45:17 | 000,000,744 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/12/05 17:20:17 | 000,000,684 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2011/12/05 17:20:17 | 000,000,666 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Picasa 3.lnk
[2011/12/05 12:51:51 | 000,394,108 | —- | C] () – C:\Documents and Settings\Derek\My Documents\StatementViewer.pdf
[2011/12/05 07:21:00 | 000,234,813 | —- | C] () – C:\Documents and Settings\Derek\Desktop\Portland-20111203-00069.jpg
[2011/12/02 10:35:42 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/29 09:55:53 | 002,809,162 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.WAV
[2011/11/29 09:55:53 | 000,043,976 | —- | C] () – C:\Documents and Settings\All Users\Documents\US Silver.pk
[2011/11/23 22:37:57 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\photopadShakeIcon.job
[2011/11/23 22:36:40 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\PhotoPad Image Editor.lnk
[2011/11/23 22:29:08 | 000,019,497 | —- | C] () – C:\WINDOWS\hpqins13.dat
[2011/11/23 22:24:51 | 000,000,476 | —- | C] () – C:\WINDOWS\tasks\HP Photo Creations Communicator.job
[2011/11/15 03:00:43 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/11/14 12:04:55 | 000,280,276 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/11/14 12:04:55 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/11/14 12:04:55 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/11/14 12:03:28 | 002,128,778 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/11/14 12:03:28 | 000,003,249 | —- | C] () – C:\WINDOWS\System32\nvinfo.pb
[2011/11/09 11:48:32 | 000,001,037 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/11/09 08:31:28 | 000,000,000 | —- | C] () – C:\WINDOWS\2771026874
[2011/09/06 11:00:03 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2011/09/03 08:17:59 | 000,080,416 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/09/03 08:08:27 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/09/03 08:08:27 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/09/02 17:52:48 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/08/09 09:41:01 | 001,894,912 | —- | C] () – C:\Program Files\Amazon Unbox Video.msi
[2011/08/09 09:41:01 | 000,006,129 | —- | C] () – C:\Program Files\0x0409.ini
[2011/05/20 11:27:40 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2011/05/19 03:36:13 | 000,413,024 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/01/28 07:48:11 | 000,005,504 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/12/15 11:11:36 | 000,278,398 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/11/19 06:25:02 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/11/19 06:22:09 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\start
[2010/11/19 05:25:05 | 000,000,006 | —- | C] () – C:\Documents and Settings\Derek\Application Data\completescan
[2010/11/19 05:11:16 | 000,000,010 | —- | C] () – C:\Documents and Settings\Derek\Application Data\install
[2010/10/05 04:24:10 | 000,038,469 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (Windows).ADR
[2010/09/15 16:36:38 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/06/16 11:06:00 | 003,535,754 | —- | C] () – C:\Program Files\VoiceMergeRecorder.zip
[2010/04/22 07:09:11 | 000,000,088 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2010/04/09 04:53:39 | 000,122,880 | —- | C] () – C:\WINDOWS\UnGins.exe
[2009/11/10 06:51:59 | 000,057,236 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/28 13:53:31 | 000,020,992 | —- | C] () – C:\WINDOWS\jestertb.dll
[2009/08/21 09:46:45 | 000,000,014 | —- | C] () – C:\WINDOWS\System32\nvModes.dat
[2009/08/20 07:44:43 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/07/01 06:38:25 | 000,105,290 | —- | C] () – C:\WINDOWS\HPFins09.dat.temp
[2009/07/01 06:38:25 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat.temp
[2009/05/18 05:18:31 | 000,039,424 | —- | C] () – C:\Documents and Settings\Derek\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 06:15:23 | 000,013,000 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).CAL
[2009/04/26 07:28:30 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/04/17 12:15:45 | 000,038,472 | —- | C] () – C:\Documents and Settings\Derek\Application Data\Comma Separated Values (DOS).ADR
[2009/04/10 09:03:17 | 013,190,496 | —- | C] () – C:\Program Files\winzip120.exe
[2009/04/07 11:44:45 | 000,389,344 | —- | C] () – C:\Program Files\Setup024m.exe
[2009/04/07 08:44:10 | 000,002,451 | —- | C] () – C:\Program Files\Alesis Firewire Control Panel.lnk
[2009/04/07 07:38:20 | 000,413,183 | —- | C] () – C:\Program Files\ASIO4ALL_2_9_English.exe
[2009/04/07 05:40:50 | 000,001,747 | —- | C] () – C:\Program Files\Start Download Manager.lnk
[2009/04/06 12:18:42 | 000,000,984 | —- | C] () – C:\Program Files\HP Solution Center.lnk
[2009/04/06 11:53:39 | 000,102,833 | —- | C] () – C:\WINDOWS\HPFins09.dat
[2009/04/06 11:53:39 | 000,003,732 | —- | C] () – C:\WINDOWS\hpfmdl09.dat
[2009/04/06 11:53:27 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2009/04/05 16:09:11 | 000,446,464 | —- | C] () – C:\WINDOWS\System32\DspfxCro.dll
[2009/04/05 16:09:11 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\DspfxDll.dll
[2009/04/05 16:09:11 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\DspfxCom.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS9.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS8.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS6.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS5.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS4.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS3.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS2.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS15.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS14.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS13.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS12.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxS1.dll
[2009/04/05 16:09:11 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\DspfxDw.dll
[2009/04/05 16:09:11 | 000,015,040 | —- | C] () – C:\WINDOWS\System32\Mxmidi16.dll
[2009/04/05 12:44:01 | 000,000,772 | —- | C] () – C:\Program Files\DriveImage XML.lnk
[2009/04/04 17:44:52 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/04 17:37:05 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\AvgLdx86.sys
[2009/04/04 14:59:29 | 000,000,000 | —- | C] () – C:\WINDOWS\msicpl.ini
[2009/04/04 14:50:18 | 000,131,072 | R— | C] () – C:\WINDOWS\System32\smdll.dll
[2009/04/04 14:50:14 | 000,258,048 | R— | C] () – C:\WINDOWS\System32\HookMAp.dll
[2009/04/04 14:50:14 | 000,032,768 | R— | C] () – C:\WINDOWS\System32\Auxiliary.dll
[2009/04/04 14:50:13 | 000,262,144 | R— | C] () – C:\WINDOWS\System32\HookShield.dll
[2009/04/04 14:38:48 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\AsIO.dll
[2009/04/04 14:22:50 | 000,036,537 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009/04/04 14:22:23 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/04/04 14:22:17 | 000,035,944 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/04/04 14:22:17 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/04/04 14:17:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/04/04 14:14:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/04/04 06:07:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/04/04 06:06:07 | 000,275,760 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/02 19:16:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2004/08/04 04:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 04:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 04:00:00 | 000,482,856 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 04:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 04:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 04:00:00 | 000,085,286 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 04:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 04:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 04:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 04:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 04:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 04:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/01/30 08:37:50 | 000,000,092 | R— | C] () – C:\WINDOWS\System32\FTDIUN2K.INI
[2002/03/01 13:43:34 | 000,028,008 | —- | C] () – C:\WINDOWS\System32\SUSUSB.SYS
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2011/08/09 09:41:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2011/11/29 06:56:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/06/05 09:39:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\espionServerData
[2009/05/12 14:00:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2011/09/23 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/04/05 09:53:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PureEdge
[2009/12/26 05:19:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2011/12/06 08:15:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/12/06 06:43:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 09:32:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/11/23 22:25:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2010/01/22 07:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/17 14:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ArcVP
[2011/01/28 07:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Canneverbe Limited
[2009/10/26 05:50:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoffeeCup Software
[2009/05/19 09:03:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\CoreFTP
[2011/09/24 07:14:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\DD83E66D5FAF4DC27D3466A7C9D66E4F
[2011/11/24 12:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Digiarty
[2011/09/13 12:22:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Dropbox
[2009/12/08 07:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\FileZilla
[2010/12/10 12:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GARMIN
[2009/11/10 09:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\GetRightToGo
[2011/12/05 17:11:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Image Zone Express
[2010/03/02 11:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\IMSIDesign
[2011/09/20 12:42:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\ImTOO
[2010/11/07 06:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\JAM Software
[2010/04/22 07:09:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Leadertech
[2009/09/28 14:28:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Memeo
[2009/11/12 11:23:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Motion Technologies
[2009/08/24 18:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Pamela
[2011/01/05 11:51:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\PureEdge
[2011/11/29 06:57:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchquband
[2011/11/29 06:57:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\searchqutoolbar
[2011/09/23 06:54:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TeamViewer
[2011/11/14 11:56:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\TMP
[2011/05/20 09:36:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Ulead Systems
[2011/11/23 22:50:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Visan
[2011/11/29 18:01:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\webex
[2009/05/11 08:27:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Desktop Search
[2009/05/12 19:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Derek\Application Data\Windows Search
[2011/11/26 00:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\Tasks\Clone Backup.job
[2010/12/31 06:40:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\disketchShakeIcon.job
[2011/12/05 18:00:00 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\File Backup.job
[2011/11/26 22:37:01 | 000,000,280 | —- | M] () – C:\WINDOWS\Tasks\photopadShakeIcon.job
[2011/12/05 17:45:00 | 000,000,334 | —- | M] () – C:\WINDOWS\Tasks\Update Tasks.job
[2011/12/06 08:32:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{D07FB967-02EC-4F68-A7FA-D05A55F7A08C}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 04:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/04/04 16:11:25 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\MGtools\temp\SPF\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 04:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 04:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2007/07/12 13:35:02 | 000,305,176 | R— | M] (Intel Corporation) MD5=2358C53F30CB9DCD1D3843C4E2F299B2 – C:\cmdcons\iastor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 04:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATA.SYS >
[2006/10/18 14:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\nvata.sys
< MD5 for: NVATABUS.SYS >
[2006/10/18 13:31:38 | 000,105,472 | R— | M] (NVIDIA Corporation) MD5=EF9941593B2E9B436F64A87DDB570D1A – C:\cmdcons\NvAtaBus.sys
< MD5 for: SCECLI.DLL >
[2004/08/04 04:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< MD5 for: SYMMPI.SYS >
[2007/02/09 19:06:00 | 000,100,096 | R— | M] (LSI Logic) MD5=A42F863305943869BA00A613C8EE8C7E – C:\cmdcons\symmpi.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/04/04 06:04:49 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/04/04 06:04:48 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/04/04 06:04:48 | 000,937,984 | —- | M] () – C:\WINDOWS\System32\config\system.sav
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB28633$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >