This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe with OTL Scan Log included [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sooo, i have been fumbling with this Ping.exe virus for the past 3 days's i have run MBAM 5 time's and every time it finds something and supposedly get's rid of it. But the ping.exe just stays there. I noticed alot of people are having issues with this, when its running my CPU % goes up to 99 and most of my memory gets used, and my Google pages redirect all the time. Here is the OTL Log's:

OTL.TXT -
OTL logfile created on: 12/23/2011 12:51:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\lathem\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.23 Gb Available Physical Memory | 74.46% Memory free
6.23 Gb Paging File | 5.18 Gb Available in Paging File | 83.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 99.90 Gb Free Space | 34.68% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.72 Gb Free Space | 57.23% Space Free | Partition Type: NTFS

Computer Name: ETHAN | User Name: lathem | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\lathem\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\PING.EXE (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\libusbd-nt.exe (http://libusb-win32.sourceforge.net)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV - (XMLProvS) – File not found
SRV - (Movielink Core Service) – File not found
SRV - (GoToAssist) – File not found
SRV - (FastUserSwitchingCompatibility) – File not found
SRV - (HiPatchService) – C:\Program Files\Hi-Rez Studios\HiPatchService.exe (Hi-Rez Studios)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Hamachi2Svc) – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (libusbd) – C:\Windows\System32\libusbd-nt.exe (http://libusb-win32.sourceforge.net)


========== Driver Services (SafeList) ==========

DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (IDMWFP) – C:\Windows\System32\drivers\idmwfp.sys (Tonec Inc.)
DRV - (LMIRfsClientNP) – C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (Smb) Message-oriented TCP/IP and TCP/IPv6 Protocol (SMB session) – C:\Windows\System32\drivers\smb.sys ()
DRV - (hamachi) – C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (Mo3Fltr) – C:\Windows\System32\drivers\Mo3Fltr.sys ()
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LMouFilt) – C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (NAL) – C:\Windows\System32\drivers\iqvw32.sys (Intel Corporation )
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80229
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80229
IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…amp;ibd=1080711
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Winamp Search"
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.search.selectedEngine: "Winamp Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.clanaod.net/forums/index.php"
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:7.2.3
FF - prefs.js..extensions.enabledItems: {ab91efd4-6975-4081-8552-1b3922ed79e2}:[removed]
FF - prefs.js..extensions.enabledItems: unplug@compunach:2.050
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:[removed]
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.8.0.8855
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@iWon.com/Plugin: C:\Program Files\iWon\bar\1.bin\NPjfStub.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@eximion.com/KalydoPlayer3.09.00: C:\Users\lathem\AppData\Roaming\Kalydo\KalydoPlayer\npkalydo.dll (Eximion B.V.)
FF - HKCU\Software\MozillaPlugins\@SparkplayMedia.com/Sparkplayer (Beta): C:\Users\lathem\Documents\Sparkplay Media\Sparkplayer (Beta)\npSparkPlayerNS.dll ()
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\lathem\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009/04/15 20:18:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\PROGRA~1\Crawler\Toolbar\firefox\ [2009/12/22 09:29:48 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\iWon\bar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/10/30 17:33:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/23 10:37:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/23 10:37:16 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}: C:\Program Files\PriceGong\2.1.0\FF
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\lathem\AppData\Roaming\IDM\idmmzcc3 [2011/03/07 19:00:43 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\lathem\AppData\Roaming\IDM\idmmzcc3 [2011/03/07 19:00:43 | 000,000,000 | —D | M]

[2010/04/12 20:10:07 | 000,000,000 | —D | M] (No name found) – C:\Users\lathem\AppData\Roaming\Mozilla\Extensions
[2011/12/23 07:57:26 | 000,000,000 | —D | M] (No name found) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions
[2011/03/14 13:47:48 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/04/28 21:39:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/27 21:21:20 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/07/19 00:17:13 | 000,000,000 | —D | M] (HP Detect) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
[2011/02/22 17:51:47 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/02/22 17:51:47 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\[removed]
[2011/02/27 01:08:00 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\[removed]
[2011/09/20 10:44:53 | 000,000,000 | —D | M] ("UnPlug") – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\extensions\unplug@compunach
[2011/02/27 01:08:01 | 000,001,919 | —- | M] () – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\searchplugins\bing-zugo.xml
[2011/02/22 17:52:28 | 000,000,863 | —- | M] () – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\searchplugins\conduit.xml
[2010/10/03 21:14:44 | 000,010,025 | —- | M] () – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\searchplugins\mywebsearch.xml
[2011/03/14 14:22:33 | 000,001,196 | —- | M] () – C:\Users\lathem\AppData\Roaming\Mozilla\Firefox\Profiles\6kde0878.default\searchplugins\winamp-search.xml
[2011/12/10 12:54:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/10 12:54:28 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/12/20 00:29:02 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/10/30 17:33:44 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
[2011/03/07 19:00:43 | 000,000,000 | —D | M] (IDM CC) – C:\USERS\LATHEM\APPDATA\ROAMING\IDM\IDMMZCC3
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/09 04:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java™ Platform SE 6 U20 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.200.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: iWon Toolbar Plugin Stub (Enabled) = C:\Program Files\iWon\bar\1.bin\NPjfStub.dll
CHR - plugin: Sparkplayer (Beta) (Enabled) = C:\Users\lathem\Documents\Sparkplay Media\Sparkplayer (Beta)\npSparkPlayerNS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\lathem\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.1.1_0\
CHR - Extension: Poppit = C:\Users\lathem\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\lathem\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\

Hosts file not found
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PriceGongBHO Class) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll File not found
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll File not found
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll File not found
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll File not found
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - %SystemRoot%\System32\winrnr.dll File not found
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = o
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5F44DC27-BC9E-4F56-937F-D1AB76C410BC}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BE28EF96-0BAC-4D54-AA73-72DBBB87C720}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll File not found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\Toolbar\ctbr.dll (Crawler.com)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img4.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img4.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0a2e57f6-557a-11df-80b5-001d099ca4f2}\Shell - "" = AutoRun
O33 - MountPoints2\{0a2e57f6-557a-11df-80b5-001d099ca4f2}\Shell\AutoRun\command - "" = K:\iStudio.exe
O33 - MountPoints2\{1e74f5b1-0f14-11df-a7f0-001d099ca4f2}\Shell - "" = AutoRun
O33 - MountPoints2\{1e74f5b1-0f14-11df-a7f0-001d099ca4f2}\Shell\AutoRun\command - "" = F:\AUTORUN.EXE
O33 - MountPoints2\{7e063a6d-1d37-11df-b90f-001d099ca4f2}\Shell - "" = AutoRun
O33 - MountPoints2\{7e063a6d-1d37-11df-b90f-001d099ca4f2}\Shell\AutoRun\command - "" = N:\LaunchU3.exe -a
O33 - MountPoints2\{d02d106f-b565-11e0-bd27-001d099ca4f2}\Shell - "" = AutoRun
O33 - MountPoints2\{d02d106f-b565-11e0-bd27-001d099ca4f2}\Shell\AutoRun\command - "" = P:\LaunchU3.exe -a
O33 - MountPoints2\N\Shell - "" = AutoRun
O33 - MountPoints2\N\Shell\AutoRun\command - "" = N:\TC2MInstall.exe
O33 - MountPoints2\P\Shell - "" = AutoRun
O33 - MountPoints2\P\Shell\AutoRun\command - "" = P:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.bdmpeg - C:\Windows\System32\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: vidc.mpeg - C:\Windows\System32\bdmpegv.dll ()
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/23 12:50:18 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\lathem\Desktop\OTL.exe
[2011/12/22 07:29:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/12/22 07:29:37 | 000,000,000 | —D | C] – C:\Program Files\LogMeIn Hamachi
[2011/12/16 08:06:05 | 000,000,000 | —D | C] – C:\Users\lathem\AppData\Local\SWTOR
[2011/12/15 09:56:10 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/12/15 09:56:09 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/12/15 09:56:08 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/12/15 09:56:06 | 002,043,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2011/12/15 09:56:01 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2011/12/15 09:55:56 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2011/12/15 09:55:54 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/12/15 09:55:52 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/12/15 09:55:50 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/12/15 09:55:50 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/12/15 09:55:50 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/12/15 09:55:50 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/12/15 09:55:50 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/12/15 09:55:50 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/12/15 09:55:50 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/12/15 09:55:50 | 000,174,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/12/15 09:55:50 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/12/15 09:55:50 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/12/15 09:55:50 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/12/15 09:55:50 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/12/15 09:55:50 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/12/15 09:55:50 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/12/15 09:55:50 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/12/15 09:55:50 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/12/12 15:27:39 | 000,000,000 | —D | C] – C:\Users\lathem\AppData\Local\Chromium
[2011/12/12 12:32:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hi-Rez Studios
[2011/12/12 12:32:50 | 000,000,000 | —D | C] – C:\Program Files\Hi-Rez Studios
[2011/12/10 12:53:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/12/08 03:43:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
[2011/12/08 03:27:20 | 000,000,000 | —D | C] – C:\Program Files\Electronic Arts
[2011/12/08 03:27:13 | 000,000,000 | —D | C] – C:\Users\lathem\AppData\Roaming\Origin
[2011/12/08 03:26:33 | 000,000,000 | —D | C] – C:\Users\lathem\AppData\Local\Origin
[2011/12/08 03:26:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2011/12/08 03:26:13 | 000,000,000 | —D | C] – C:\Program Files\Origin Games
[2011/12/08 03:26:02 | 000,000,000 | —D | C] – C:\Program Files\Origin
[2011/12/07 10:48:49 | 000,000,000 | —D | C] – C:\Users\lathem\Documents\Stronghold Kingdoms
[2011/12/01 13:01:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/12/01 13:00:55 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/12/01 12:57:54 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/11/26 08:59:56 | 000,000,000 | —D | C] – C:\Users\lathem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Fix
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/23 12:49:51 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\lathem\Desktop\OTL.exe
[2011/12/23 12:39:31 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/23 12:39:31 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/23 12:15:01 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/23 12:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At26.job
[2011/12/23 12:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At25.job
[2011/12/23 11:06:04 | 000,000,354 | —- | M] () – C:\Windows\tasks\At24.job
[2011/12/23 11:06:01 | 000,000,352 | —- | M] () – C:\Windows\tasks\At23.job
[2011/12/23 10:45:10 | 000,915,156 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/23 10:45:10 | 000,210,382 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/12/23 10:40:41 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/23 10:40:29 | 000,000,352 | —- | M] () – C:\Windows\tasks\At17.job
[2011/12/23 10:40:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/23 10:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At22.job
[2011/12/23 10:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At21.job
[2011/12/23 09:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At20.job
[2011/12/23 09:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At19.job
[2011/12/23 08:25:53 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{41F7D201-9173-47E0-9167-17E82134E3D9}.job
[2011/12/23 08:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At18.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At8.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At6.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At4.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At16.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At14.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At12.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\tasks\At10.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At9.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At7.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At5.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At3.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At15.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At13.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\tasks\At11.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\tasks\At48.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\tasks\At46.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\tasks\At44.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\tasks\At2.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\tasks\At47.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\tasks\At45.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\tasks\At43.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\tasks\At1.job
[2011/12/22 20:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At42.job
[2011/12/22 20:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At41.job
[2011/12/22 19:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At40.job
[2011/12/22 19:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At39.job
[2011/12/22 18:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At38.job
[2011/12/22 18:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At37.job
[2011/12/22 17:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At36.job
[2011/12/22 17:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At35.job
[2011/12/22 16:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At34.job
[2011/12/22 16:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At33.job
[2011/12/22 15:26:00 | 000,000,562 | —- | M] () – C:\Windows\tasks\Norton Security Scan for Aaron's.job
[2011/12/22 15:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At32.job
[2011/12/22 15:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At31.job
[2011/12/22 14:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At30.job
[2011/12/22 14:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At29.job
[2011/12/22 13:06:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At28.job
[2011/12/22 13:06:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At27.job
[2011/12/17 20:36:46 | 000,057,344 | —- | M] () – C:\Users\lathem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/16 09:47:50 | 221,850,716 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/16 08:44:49 | 000,000,112 | —- | M] () – C:\ProgramData\mTpGv5Pg.dat
[2011/12/16 08:24:40 | 000,000,000 | —- | M] () – C:\Windows\System32\17V1con7P.com.b
[2011/12/16 08:20:52 | 000,103,365 | —- | M] () – C:\Windows\System32\itusbcore.dat
[2011/12/16 08:20:52 | 000,000,197 | —- | M] () – C:\Windows\System32\itlsvc.dat
[2011/12/16 03:26:26 | 000,277,184 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/12/15 20:00:34 | 000,001,074 | -HS- | M] () – C:\Users\lathem\AppData\Local\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/15 20:00:34 | 000,001,074 | -HS- | M] () – C:\ProgramData\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/12 13:09:50 | 000,001,806 | —- | M] () – C:\Users\Public\Desktop\Tribes Ascend.lnk
[2011/12/12 12:32:56 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\Hi-Command.lnk
[2011/12/12 11:46:45 | 000,001,261 | —- | M] () – C:\Users\lathem\Desktop\Star Wars - The Old Republic.lnk
[2011/12/08 03:26:22 | 000,000,769 | —- | M] () – C:\Users\Public\Desktop\Origin.lnk
[2011/12/06 15:21:20 | 000,001,757 | —- | M] () – C:\Users\lathem\Desktop\Mozilla Firefox.lnk
[2011/12/06 14:24:30 | 000,008,622 | -HS- | M] () – C:\Users\lathem\AppData\Local\261bne73l573x
[2011/12/06 14:24:30 | 000,008,622 | -HS- | M] () – C:\ProgramData\261bne73l573x
[2011/11/29 13:24:12 | 000,000,003 | —- | M] () – C:\Windows\System32\HRUPPROG.DIE.NOW
[2011/11/26 14:40:00 | 000,000,827 | —- | M] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2011/11/26 14:39:57 | 000,000,827 | —- | M] () – C:\Users\lathem\Desktop\Winamp.lnk
[2011/11/26 14:39:38 | 000,000,910 | —- | M] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\VLC media player.lnk
[2011/11/26 14:39:33 | 000,000,910 | —- | M] () – C:\Users\lathem\Desktop\VLC media player.lnk
[2011/11/26 14:39:19 | 000,000,772 | —- | M] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Ventrilo.lnk
[2011/11/26 14:39:07 | 000,000,772 | —- | M] () – C:\Users\lathem\Desktop\Ventrilo.lnk
[2011/11/26 14:30:40 | 000,000,629 | —- | M] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Play League of Legends.lnk
[2011/11/26 14:30:34 | 000,001,775 | —- | M] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/26 09:25:05 | 000,002,032 | —- | M] () – C:\Users\lathem\AppData\Local\d3d9caps.dat
[2011/11/26 09:06:07 | 000,000,456 | —- | M] () – C:\ProgramData\ptWwgKhlkQeXWE
[2011/11/26 09:05:03 | 000,000,320 | —- | M] () – C:\ProgramData\~ptWwgKhlkQeXWE
[2011/11/26 09:05:03 | 000,000,224 | —- | M] () – C:\ProgramData\~ptWwgKhlkQeXWEr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/16 09:47:50 | 221,850,716 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/16 08:24:40 | 000,000,000 | —- | C] () – C:\Windows\System32\17V1con7P.com.b
[2011/12/16 08:20:52 | 000,103,365 | —- | C] () – C:\Windows\System32\itusbcore.dat
[2011/12/16 08:20:52 | 000,000,197 | —- | C] () – C:\Windows\System32\itlsvc.dat
[2011/12/16 08:17:12 | 000,000,112 | —- | C] () – C:\ProgramData\mTpGv5Pg.dat
[2011/12/16 08:17:11 | 000,000,354 | —- | C] () – C:\Windows\tasks\At48.job
[2011/12/16 08:17:10 | 000,000,354 | —- | C] () – C:\Windows\tasks\At46.job
[2011/12/16 08:17:10 | 000,000,352 | —- | C] () – C:\Windows\tasks\At47.job
[2011/12/16 08:17:09 | 000,000,354 | —- | C] () – C:\Windows\tasks\At44.job
[2011/12/16 08:17:09 | 000,000,352 | —- | C] () – C:\Windows\tasks\At45.job
[2011/12/16 08:17:09 | 000,000,352 | —- | C] () – C:\Windows\tasks\At43.job
[2011/12/16 08:17:08 | 000,000,354 | —- | C] () – C:\Windows\tasks\At42.job
[2011/12/16 08:17:08 | 000,000,354 | —- | C] () – C:\Windows\tasks\At40.job
[2011/12/16 08:17:08 | 000,000,352 | —- | C] () – C:\Windows\tasks\At41.job
[2011/12/16 08:17:07 | 000,000,354 | —- | C] () – C:\Windows\tasks\At38.job
[2011/12/16 08:17:07 | 000,000,352 | —- | C] () – C:\Windows\tasks\At39.job
[2011/12/16 08:17:06 | 000,000,354 | —- | C] () – C:\Windows\tasks\At36.job
[2011/12/16 08:17:06 | 000,000,352 | —- | C] () – C:\Windows\tasks\At37.job
[2011/12/16 08:17:06 | 000,000,352 | —- | C] () – C:\Windows\tasks\At35.job
[2011/12/16 08:17:05 | 000,000,354 | —- | C] () – C:\Windows\tasks\At34.job
[2011/12/16 08:17:05 | 000,000,354 | —- | C] () – C:\Windows\tasks\At32.job
[2011/12/16 08:17:05 | 000,000,352 | —- | C] () – C:\Windows\tasks\At33.job
[2011/12/16 08:17:04 | 000,000,354 | —- | C] () – C:\Windows\tasks\At30.job
[2011/12/16 08:17:04 | 000,000,352 | —- | C] () – C:\Windows\tasks\At31.job
[2011/12/16 08:17:04 | 000,000,352 | —- | C] () – C:\Windows\tasks\At29.job
[2011/12/16 08:17:03 | 000,000,354 | —- | C] () – C:\Windows\tasks\At28.job
[2011/12/16 08:17:03 | 000,000,352 | —- | C] () – C:\Windows\tasks\At27.job
[2011/12/16 08:17:02 | 000,000,354 | —- | C] () – C:\Windows\tasks\At26.job
[2011/12/16 08:17:02 | 000,000,354 | —- | C] () – C:\Windows\tasks\At24.job
[2011/12/16 08:17:02 | 000,000,352 | —- | C] () – C:\Windows\tasks\At25.job
[2011/12/16 08:17:01 | 000,000,354 | —- | C] () – C:\Windows\tasks\At22.job
[2011/12/16 08:17:01 | 000,000,352 | —- | C] () – C:\Windows\tasks\At23.job
[2011/12/16 08:17:00 | 000,000,354 | —- | C] () – C:\Windows\tasks\At20.job
[2011/12/16 08:17:00 | 000,000,352 | —- | C] () – C:\Windows\tasks\At21.job
[2011/12/16 08:17:00 | 000,000,352 | —- | C] () – C:\Windows\tasks\At19.job
[2011/12/16 08:16:59 | 000,000,354 | —- | C] () – C:\Windows\tasks\At18.job
[2011/12/16 08:16:59 | 000,000,354 | —- | C] () – C:\Windows\tasks\At16.job
[2011/12/16 08:16:59 | 000,000,352 | —- | C] () – C:\Windows\tasks\At17.job
[2011/12/16 08:16:58 | 000,000,354 | —- | C] () – C:\Windows\tasks\At14.job
[2011/12/16 08:16:58 | 000,000,352 | —- | C] () – C:\Windows\tasks\At15.job
[2011/12/16 08:16:57 | 000,000,354 | —- | C] () – C:\Windows\tasks\At12.job
[2011/12/16 08:16:57 | 000,000,352 | —- | C] () – C:\Windows\tasks\At13.job
[2011/12/16 08:16:56 | 000,000,352 | —- | C] () – C:\Windows\tasks\At11.job
[2011/12/16 08:16:55 | 000,000,354 | —- | C] () – C:\Windows\tasks\At10.job
[2011/12/16 08:16:55 | 000,000,352 | —- | C] () – C:\Windows\tasks\At9.job
[2011/12/16 08:16:54 | 000,000,354 | —- | C] () – C:\Windows\tasks\At8.job
[2011/12/16 08:16:54 | 000,000,352 | —- | C] () – C:\Windows\tasks\At7.job
[2011/12/16 08:16:53 | 000,000,354 | —- | C] () – C:\Windows\tasks\At6.job
[2011/12/16 08:16:53 | 000,000,354 | —- | C] () – C:\Windows\tasks\At4.job
[2011/12/16 08:16:53 | 000,000,352 | —- | C] () – C:\Windows\tasks\At5.job
[2011/12/16 08:16:52 | 000,000,354 | —- | C] () – C:\Windows\tasks\At2.job
[2011/12/16 08:16:52 | 000,000,352 | —- | C] () – C:\Windows\tasks\At3.job
[2011/12/16 08:16:51 | 000,000,352 | —- | C] () – C:\Windows\tasks\At1.job
[2011/12/15 20:00:34 | 000,001,074 | -HS- | C] () – C:\Users\lathem\AppData\Local\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/15 20:00:34 | 000,001,074 | -HS- | C] () – C:\ProgramData\wrtxqe4s5omf0cvp3ugj1w488u8g
[2011/12/12 13:09:50 | 000,001,806 | —- | C] () – C:\Users\Public\Desktop\Tribes Ascend.lnk
[2011/12/12 12:32:56 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\Hi-Command.lnk
[2011/12/12 11:46:45 | 000,001,261 | —- | C] () – C:\Users\lathem\Desktop\Star Wars - The Old Republic.lnk
[2011/12/08 03:26:22 | 000,000,769 | —- | C] () – C:\Users\Public\Desktop\Origin.lnk
[2011/12/06 15:29:49 | 000,001,212 | —- | C] () – C:\Users\lathem\Desktop\exefix_vista.reg
[2011/12/06 12:50:28 | 000,008,622 | -HS- | C] () – C:\Users\lathem\AppData\Local\261bne73l573x
[2011/12/06 12:50:28 | 000,008,622 | -HS- | C] () – C:\ProgramData\261bne73l573x
[2011/11/29 13:24:12 | 000,000,003 | —- | C] () – C:\Windows\System32\HRUPPROG.DIE.NOW
[2011/11/26 14:40:00 | 000,000,827 | —- | C] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2011/11/26 14:39:57 | 000,000,827 | —- | C] () – C:\Users\lathem\Desktop\Winamp.lnk
[2011/11/26 14:39:38 | 000,000,910 | —- | C] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\VLC media player.lnk
[2011/11/26 14:39:33 | 000,000,910 | —- | C] () – C:\Users\lathem\Desktop\VLC media player.lnk
[2011/11/26 14:39:19 | 000,000,772 | —- | C] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Ventrilo.lnk
[2011/11/26 14:39:07 | 000,000,772 | —- | C] () – C:\Users\lathem\Desktop\Ventrilo.lnk
[2011/11/26 14:30:40 | 000,000,629 | —- | C] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Play League of Legends.lnk
[2011/11/26 14:30:34 | 000,001,775 | —- | C] () – C:\Users\lathem\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/26 09:00:01 | 000,000,320 | —- | C] () – C:\ProgramData\~ptWwgKhlkQeXWE
[2011/11/26 09:00:01 | 000,000,224 | —- | C] () – C:\ProgramData\~ptWwgKhlkQeXWEr
[2011/11/26 08:59:42 | 000,000,456 | —- | C] () – C:\ProgramData\ptWwgKhlkQeXWE
[2011/10/13 14:30:24 | 000,042,392 | —- | C] () – C:\Windows\System32\xfcodec.dll
[2011/09/27 15:38:00 | 000,000,127 | —- | C] () – C:\Windows\System32\MRT.INI
[2011/08/03 02:31:54 | 000,311,912 | —- | C] () – C:\Windows\System32\nvStreaming.exe
[2011/07/07 05:43:10 | 000,499,200 | —- | C] () – C:\Windows\System32\WZDPlay.dll
[2011/06/29 01:52:46 | 000,017,089 | —- | C] () – C:\Users\lathem\AppData\Roaming\UserTile.png
[2011/05/03 10:22:36 | 000,000,054 | —- | C] () – C:\Windows\Quicken.ini
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2011/02/28 10:06:31 | 000,153,703 | —- | C] () – C:\Windows\hphins26.dat.temp
[2011/02/28 10:06:31 | 000,000,787 | —- | C] () – C:\Windows\hphmdl26.dat.temp
[2011/02/27 10:55:36 | 000,153,703 | —- | C] () – C:\Windows\hphins26.dat
[2011/02/27 10:55:36 | 000,000,787 | —- | C] () – C:\Windows\hphmdl26.dat
[2011/02/10 22:10:25 | 000,002,032 | —- | C] () – C:\Users\lathem\AppData\Local\d3d9caps.dat
[2010/11/21 23:10:32 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/05/18 16:15:47 | 000,033,792 | —- | C] () – C:\Windows\System32\drivers\libusb0.sys
[2010/05/01 17:49:52 | 000,000,101 | —- | C] () – C:\Windows\lexstat.ini
[2010/05/01 17:49:34 | 000,086,016 | —- | C] () – C:\Windows\System32\LXBKIH.EXE
[2010/05/01 17:49:33 | 000,077,824 | —- | C] () – C:\Windows\System32\LXBKLCNP.DLL
[2010/05/01 17:49:33 | 000,040,960 | —- | C] () – C:\Windows\System32\INSTMON.EXE
[2010/05/01 17:49:32 | 000,040,960 | —- | C] () – C:\Windows\System32\lxbkvs.dll
[2010/04/14 22:30:42 | 000,000,005 | —- | C] () – C:\Windows\treeskp.sys
[2010/04/14 22:30:42 | 000,000,005 | —- | C] () – C:\Windows\sbacknt.bin
[2010/03/22 16:22:55 | 000,003,012 | —- | C] () – C:\Users\lathem\AppData\Roaming\wklnhst.dat
[2010/03/16 22:48:42 | 000,057,344 | —- | C] () – C:\Users\lathem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/23 22:22:29 | 000,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2009/12/23 22:22:28 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2009/12/23 22:22:26 | 000,007,680 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/12/18 01:54:45 | 000,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2009/12/18 01:54:45 | 000,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/12/03 07:56:11 | 000,001,847 | —- | C] () – C:\Windows\hpwmdl23.dat.temp
[2009/11/26 08:42:04 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/09/10 18:30:02 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/10 18:30:02 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/10 18:28:40 | 000,066,560 | —- | C] () – C:\Windows\System32\drivers\smb.sys
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/06/14 20:29:36 | 000,011,136 | —- | C] () – C:\Windows\System32\drivers\Mo3Fltr.sys
[2009/04/15 19:42:17 | 000,186,583 | —- | C] () – C:\Windows\hpwins23.dat
[2009/04/14 02:00:50 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/25 03:30:45 | 000,001,847 | —- | C] () – C:\Windows\hpwmdl23.dat
[2008/07/11 03:40:03 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/07/11 03:40:03 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/07/11 03:40:03 | 000,154,206 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2008/07/11 03:40:03 | 000,081,920 | —- | C] () – C:\Windows\System32\ATIODE.exe
[2008/07/11 03:40:03 | 000,040,960 | —- | C] () – C:\Windows\System32\ATIODCLI.exe
[2008/07/11 03:40:01 | 000,876,544 | —- | C] () – C:\Windows\System32\TEACico2.dll
[2008/07/10 19:46:03 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2006/11/02 06:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:47:37 | 000,277,184 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 04:33:01 | 000,915,156 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,210,382 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2002/09/13 05:40:06 | 000,000,266 | —- | C] () – C:\Windows\System32\lxbkcoin.ini

========== LOP Check ==========

[2010/06/19 04:14:03 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\DAEMON Tools Lite
[2011/12/16 07:50:05 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\DMCache
[2010/12/04 19:23:54 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\DriverCure
[2010/11/07 19:12:09 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Firefly Studios
[2011/06/29 04:03:50 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Hi-Rez Studios
[2011/10/30 17:36:04 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\IDM
[2011/01/30 01:23:31 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Kalydo
[2011/07/24 07:29:53 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Lionhead Studios
[2010/11/04 20:21:25 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\LolClient
[2011/12/08 03:27:39 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Origin
[2010/12/04 19:23:54 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\ParetoLogic
[2011/06/29 01:52:45 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\PeerNetworking
[2011/03/08 22:11:56 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Rovio
[2011/02/02 19:06:26 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\SPORE
[2011/02/28 20:03:59 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\SystemRequirementsLab
[2010/04/22 14:26:58 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Template
[2011/12/16 07:47:05 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\uTorrent
[2010/04/14 22:30:26 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\vghd
[2010/10/06 18:37:54 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\W Photo Studio
[2010/10/06 18:34:24 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\W Photo Studio Viewer
[2010/10/06 18:37:19 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\Walgreens
[2011/02/04 12:50:07 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\wargaming.net
[2011/07/07 05:43:52 | 000,000,000 | —D | M] – C:\Users\lathem\AppData\Roaming\WarZone
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At1.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At10.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At11.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At12.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At13.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At14.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At15.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At16.job
[2011/12/23 10:40:29 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At17.job
[2011/12/23 08:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At18.job
[2011/12/23 09:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At19.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At2.job
[2011/12/23 09:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At20.job
[2011/12/23 10:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At21.job
[2011/12/23 10:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At22.job
[2011/12/23 11:06:01 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At23.job
[2011/12/23 11:06:04 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At24.job
[2011/12/23 12:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At25.job
[2011/12/23 12:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At26.job
[2011/12/22 13:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At27.job
[2011/12/22 13:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At28.job
[2011/12/22 14:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At29.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At3.job
[2011/12/22 14:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At30.job
[2011/12/22 15:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At31.job
[2011/12/22 15:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At32.job
[2011/12/22 16:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At33.job
[2011/12/22 16:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At34.job
[2011/12/22 17:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At35.job
[2011/12/22 17:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At36.job
[2011/12/22 18:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At37.job
[2011/12/22 18:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At38.job
[2011/12/22 19:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At39.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At4.job
[2011/12/22 19:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At40.job
[2011/12/22 20:06:00 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At41.job
[2011/12/22 20:06:00 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At42.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At43.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At44.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At45.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At46.job
[2011/12/23 07:31:43 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At47.job
[2011/12/23 07:31:43 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At48.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At5.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At6.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At7.job
[2011/12/23 07:31:44 | 000,000,354 | —- | M] () – C:\Windows\Tasks\At8.job
[2011/12/23 07:31:44 | 000,000,352 | —- | M] () – C:\Windows\Tasks\At9.job
[2011/12/23 10:39:27 | 000,032,552 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/12/23 08:25:53 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{41F7D201-9173-47E0-9167-17E82134E3D9}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/02/21 22:09:22 | 000,001,024 | —- | M] () – C:\.rnd
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/07/11 03:40:15 | 000,005,025 | RH– | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2010/01/06 19:54:14 | 000,000,272 | —- | M] () – C:\INSTALL.LOG
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/05/01 17:46:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/01 17:46:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/12/23 10:40:22 | 3533,127,680 | -HS- | M] () – C:\pagefile.sys
[2010/12/19 03:33:18 | 000,000,515 | —- | M] () – C:\scramble.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/03/12 21:15:31 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/08/12 09:58:10 | 000,314,880 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp082.dll
[2007/10/20 18:21:50 | 000,278,016 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/12/08 13:11:54 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\LMIproc.dll
[2003/07/29 03:27:40 | 000,078,336 | —- | M] () – C:\Windows\system32\spool\prtprocs\w32x86\LXBKPP5C.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/04/12 20:30:46 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | LS\x00\x00\x00\x00
Hi

Please do the following:

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI