Yes I am getting that error when it first starts up but it finishes and here is the log. Also OTL does not give me extras log no more. It only gave it to me first time I ran it. Thank you.
ComboFix 09-07-19.02 - DeeBo 07/19/2009 18:58.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1690 [GMT -4:00]
Running from: c:\documents and settings\DeeBo\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: NVIDIA Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-17 19:28 . 2009-07-15 10:07 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-16_03.47.32 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-03-07 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-03-07 169984]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
"ASKUpgrade"=2 (0x2)
"ASKService"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
R3 RTCore32;RTCore32;c:\program files\EVGA Precision\RTCore32.sys [2005-05-25 4608]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-06-23 7408]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-06-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-06-23 72944]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.plushieworks.com/
uInternet Settings,ProxyOverride = *.local
IE: &Search - ?p=ZJfox000
FF - ProfilePath - c:\docume~1\DeeBo\APPLIC~1\Mozilla\Firefox\Profiles\exoar423.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.whizzles-arcade.com/
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
.
------- File Associations -------
.
inffile=c:\windows\system32\Notepad2.exe %1
inifile=c:\windows\system32\Notepad2.exe %1
txtfile=c:\windows\system32\Notepad2.exe %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-19 19:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
geyekrurhkqnvq.dll 10000000 32768 \\?\globalroot\systemroot\system32\geyekrurhkqnvq.dll
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'lsass.exe'(692)
geyekrurhkqnvq.dll 10000000 32768 \\?\globalroot\systemroot\system32\geyekrurhkqnvq.dll
c:\windows\system32\WININET.dll
.
Completion time: 2009-07-19 19:10
ComboFix-quarantined-files.txt 2009-07-19 23:10
ComboFix2.txt 2009-07-16 03:51
Pre-Run: 137,365,975,040 bytes free
Post-Run: 137,366,573,056 bytes free
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
142 --- E O F --- 2009-07-15 12:47
OTL logfile created on: 7/19/2009 7:18:17 PM - Run 6
OTL by OldTimer - Version 3.0.9.2 Folder = C:\Documents and Settings\DeeBo\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 76.53% Memory free
3.85 Gb Paging File | 3.57 Gb Available in Paging File | 92.65% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 127.95 Gb Free Space | 85.85% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DEEBO-2E38CCA01
Current User Name: DeeBo
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\DeeBo\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Disabled | Stopped]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Computer, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dlbt_device [On_Demand | Stopped]) -- C:\WINDOWS\System32\dlbtcoms.exe (Dell)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (ForcewareWebInterface [Auto | Running]) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (nSvcIp [Auto | Running]) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (nvsvc [Auto | Running]) -- C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (catchme [On_Demand | Running]) -- File not found
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RTCore32 [On_Demand | Stopped]) -- C:\Program Files\EVGA Precision\RTCore32.sys ()
DRV - (SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.plushieworks.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://www.whizzles-arcade.com/" FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/17 15:28:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/17 15:28:27 | 00,000,000 | ---D | M]
[2009/05/14 09:21:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\mozilla\Extensions
[2009/05/14 09:21:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/15 06:00:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\mozilla\Firefox\Profiles\exoar423.default\extensions
[2009/07/15 22:40:46 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/07/17 15:28:21 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/17 15:28:21 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/07/17 15:28:23 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/05 07:02:03 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/02/02 18:15:00 | 03,771,296 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll
[2009/06/24 07:27:00 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/24 07:27:00 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/24 07:27:00 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/24 07:27:00 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/24 07:27:00 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/24 07:27:00 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/24 07:27:00 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (317082 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 10879 more lines...
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (StylerToolBar) - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Search - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKLM\..Trusted Domains: 56 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 56 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1242310585812 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/13 20:14:24 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ========== [2009/07/19 19:07:24 | 00,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/07/19 18:35:42 | 03,147,475 | R--- | C] () -- C:\Documents and Settings\DeeBo\Desktop\Combo-Fix.exe
[2009/07/19 14:39:07 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\DeeBo\Desktop\OTL.exe
[2009/07/19 14:29:46 | 00,261,295 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\Plombie_family.psd
[2009/07/19 01:40:21 | 00,034,281 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\kanye_west_glasses.jpg
[2009/07/18 21:24:12 | 05,222,480 | ---- | C] () -- C:\Documents and Settings\DeeBo\My Documents\07-18-2009 09;24;11PM.PSD
[2009/07/16 13:45:22 | 01,511,190 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\slaton.psd
[2009/07/16 11:36:10 | 00,095,567 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\knickles_sig.png
[2009/07/16 09:04:31 | 00,031,089 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\icon_biggrin.psd
[2009/07/16 02:12:34 | 06,576,362 | ---- | C] () -- C:\Documents and Settings\DeeBo\My Documents\07-16-2009 02;12;34AM.PSD
[2009/07/16 02:09:18 | 01,539,298 | ---- | C] () -- C:\Documents and Settings\DeeBo\My Documents\07-16-2009 02;09;17AM.PSD
[2009/07/15 23:20:45 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/07/15 23:20:45 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/07/15 23:20:45 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/07/15 23:20:45 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/07/15 23:20:45 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/07/15 23:20:45 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/07/15 23:20:45 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/07/15 23:19:56 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/07/15 22:55:00 | 00,265,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\DeeBo\Desktop\TFC.exe
[2009/07/15 22:22:37 | 00,975,894 | ---- | C] () -- C:\Documents and Settings\DeeBo\My Documents\07-15-2009 10;22;37PM.PSD
[2009/07/15 09:02:49 | 00,024,592 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klim5.sys
[2009/07/15 08:50:42 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/07/15 08:46:29 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009/07/15 06:58:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2009/07/15 06:44:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2009/07/15 06:44:20 | 00,000,000 | ---D | C] -- C:\Program Files\xerox
[2009/07/15 06:44:20 | 00,000,000 | ---D | C] -- C:\Program Files\movie maker
[2009/07/15 06:44:18 | 00,000,000 | ---D | C] -- C:\Program Files\netmeeting
[2009/07/15 06:44:18 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2009/07/15 06:44:16 | 00,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2009/07/15 06:38:08 | 02,189,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/07/15 06:38:08 | 02,066,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/07/15 06:38:08 | 01,614,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/07/15 06:38:08 | 01,033,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/07/15 06:38:08 | 00,989,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/07/15 06:38:08 | 00,927,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/07/15 06:38:08 | 00,915,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/07/15 06:38:08 | 00,792,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/07/15 06:38:08 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/07/15 06:38:08 | 00,578,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/07/15 06:38:08 | 00,507,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/07/15 06:38:08 | 00,435,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/07/15 06:38:08 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/07/15 06:38:08 | 00,361,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/07/15 06:38:08 | 00,295,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/07/15 06:38:08 | 00,182,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/07/15 06:38:08 | 00,167,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\appmgmts.dll
[2009/07/15 06:38:08 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/07/15 06:38:08 | 00,110,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/07/15 06:38:08 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/07/15 06:38:08 | 00,082,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/07/15 06:38:08 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/07/15 06:38:08 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/07/15 06:38:08 | 00,036,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/07/15 06:38:08 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/07/15 06:38:08 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/07/15 06:38:08 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/07/15 06:38:08 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/07/15 06:38:08 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/07/15 06:38:08 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/07/15 06:38:08 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/07/15 06:38:08 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/07/15 06:38:08 | 00,011,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/07/15 06:38:08 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/07/15 06:38:08 | 00,004,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/07/15 06:38:08 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/07/15 06:38:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dllcache\cache
[2009/07/15 06:21:44 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/07/15 06:21:39 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/07/15 06:21:38 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/07/15 06:19:44 | 00,219,648 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/07/15 06:07:36 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/15 03:07:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2009/07/15 03:00:14 | 43,985,744 | ---- | C] (Kaspersky Lab) -- C:\Documents and Settings\DeeBo\Desktop\kis8.0.0.506en.exe
[2009/07/15 03:00:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\My Documents\Downloads
[2009/07/15 02:46:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/07/15 02:44:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\Local Settings\Application Data\ApplicationHistory
[2009/07/15 02:41:24 | 00,098,989 | ---- | C] () -- C:\MGlogs.zip
[2009/07/15 02:41:21 | 00,000,000 | ---D | C] -- C:\MGtools
[2009/07/15 02:18:30 | 00,046,157 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\DeeBo\Desktop\GooredFix.exe
[2009/07/15 01:40:08 | 01,343,301 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\MGtools.exe
[2009/07/15 01:39:45 | 00,469,504 | ---- | C] ( ) -- C:\Documents and Settings\DeeBo\Desktop\RootRepeal.exe
[2009/07/15 01:34:43 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/07/14 23:41:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\Local Settings\Application Data\AVG Security Toolbar
[2009/07/14 23:39:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/07/14 23:39:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/07/14 23:37:41 | 00,000,104 | ---- | C] () -- C:\WINDOWS\System32\NvApps.xml
[2009/07/14 23:37:33 | 00,002,206 | ---- | C] () -- C:\WINDOWS\System32\wpa.dbl
[2009/07/14 23:18:45 | 00,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2009/07/14 05:38:32 | 01,183,173 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\gta_wp.psd
[2009/07/13 21:14:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/07/06 14:55:37 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/07/06 14:55:30 | 00,140,288 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNMLM7D.DLL
[2009/07/06 14:55:30 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7D.DLL
[2009/07/05 07:22:33 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/07/05 07:22:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/07/05 07:22:00 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/07/05 07:22:00 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/07/05 07:16:50 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/07/03 20:03:53 | 00,001,580 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\Defraggler.lnk
[2009/07/03 20:03:52 | 00,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2009/07/03 03:00:17 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2009/07/02 02:27:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\Local Settings\Application Data\KodakGallery
[2009/07/02 02:27:30 | 00,066,560 | R--- | C] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/07/02 02:27:30 | 00,058,368 | R--- | C] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/07/02 02:27:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\Application Data\Skinux
[2009/07/02 02:24:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/07/02 02:22:39 | 00,001,817 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Kodak EasyShare.lnk
[2009/07/02 02:22:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Kodak
[2009/07/02 02:22:26 | 00,000,000 | ---D | C] -- C:\Program Files\Kodak
[2009/07/02 02:21:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Kodak
[2009/06/30 01:11:55 | 00,000,180 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/06/28 04:33:38 | 00,001,150 | ---- | C] () -- C:\Documents and Settings\DeeBo\Desktop\favicon.ico
[2009/06/28 00:00:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\Desktop\PW
[2009/06/27 12:48:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\My Documents\My Google Gadgets
[2009/06/27 12:47:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\DeeBo\Local Settings\Application Data\Google
[2009/06/27 12:47:51 | 00,000,000 | ---D | C] -- C:\Program Files\Google
[2009/06/10 09:42:38 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/06/07 14:56:28 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2009/06/05 05:43:43 | 00,010,752 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/06/05 05:43:43 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/06/05 05:43:13 | 00,000,036 | -H-- | C] () -- C:\WINDOWS\System32\swk.ini
[2009/05/15 19:07:26 | 00,000,525 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2009/05/15 18:57:54 | 00,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlbtinsb.dll
[2009/05/15 18:57:54 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\dlbtcub.dll
[2009/05/15 18:57:53 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\dlbtins.dll
[2009/05/15 18:57:53 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\dlbtinsr.dll
[2009/05/15 18:57:53 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbtcu.dll
[2009/05/15 18:57:53 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbtvs.dll
[2009/05/15 18:57:53 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\dlbtcur.dll
[2009/05/15 18:57:52 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\dlbtcoin.dll
[2009/05/15 18:57:52 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\dlbtjswr.dll
[2009/05/15 18:57:52 | 00,126,976 | ---- | C] () -- C:\WINDOWS\System32\dlbtsnls.dll
[2009/05/15 18:57:49 | 00,397,312 | ---- | C] () -- C:\WINDOWS\System32\dlbtutil.dll
[2009/05/13 20:05:53 | 00,012,442 | ---- | C] () -- C:\WINDOWS\System32\Notepad2.ini
[2009/05/13 20:05:52 | 00,175,616 | ---- | C] () -- C:\WINDOWS\System32\mmm.dll
[2009/05/01 00:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/05/01 00:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/05/01 00:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/05/01 00:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/10/07 09:13:30 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2001/08/23 23:00:00 | 00,000,507 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 23:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ========== [2009/07/19 19:10:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/07/19 19:07:01 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/07/19 18:57:57 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/07/19 18:57:23 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/07/19 18:35:42 | 03,147,475 | R--- | M] () -- C:\Documents and Settings\DeeBo\Desktop\Combo-Fix.exe
[2009/07/19 14:39:07 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\DeeBo\Desktop\OTL.exe
[2009/07/19 14:29:46 | 00,261,295 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\Plombie_family.psd
[2009/07/19 14:29:25 | 00,031,089 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\icon_biggrin.psd
[2009/07/19 01:40:21 | 00,034,281 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\kanye_west_glasses.jpg
[2009/07/18 21:24:12 | 05,222,480 | ---- | M] () -- C:\Documents and Settings\DeeBo\My Documents\07-18-2009 09;24;11PM.PSD
[2009/07/17 15:14:52 | 00,001,150 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\favicon.ico
[2009/07/17 02:50:55 | 01,183,173 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\gta_wp.psd
[2009/07/16 14:25:26 | 00,000,104 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2009/07/16 14:22:16 | 01,511,190 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\slaton.psd
[2009/07/16 13:58:40 | 00,095,567 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\knickles_sig.png
[2009/07/16 02:12:34 | 06,576,362 | ---- | M] () -- C:\Documents and Settings\DeeBo\My Documents\07-16-2009 02;12;34AM.PSD
[2009/07/16 02:09:18 | 01,539,298 | ---- | M] () -- C:\Documents and Settings\DeeBo\My Documents\07-16-2009 02;09;17AM.PSD
[2009/07/16 00:24:02 | 00,012,442 | ---- | M] () -- C:\WINDOWS\System32\Notepad2.ini
[2009/07/15 22:55:00 | 00,265,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\DeeBo\Desktop\TFC.exe
[2009/07/15 22:22:37 | 00,975,894 | ---- | M] () -- C:\Documents and Settings\DeeBo\My Documents\07-15-2009 10;22;37PM.PSD
[2009/07/15 08:47:38 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/07/15 07:56:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/07/15 06:21:45 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/07/15 06:15:17 | 00,098,989 | ---- | M] () -- C:\MGlogs.zip
[2009/07/15 06:07:36 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/15 03:12:02 | 00,000,507 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/07/15 03:12:02 | 00,000,211 | ---- | M] () -- C:\Boot.bak
[2009/07/15 03:01:32 | 43,985,744 | ---- | M] (Kaspersky Lab) -- C:\Documents and Settings\DeeBo\Desktop\kis8.0.0.506en.exe
[2009/07/15 02:18:30 | 00,046,157 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\DeeBo\Desktop\GooredFix.exe
[2009/07/15 01:40:13 | 01,343,301 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\MGtools.exe
[2009/07/15 01:34:43 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/07/13 13:36:34 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/13 13:36:12 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/13 05:48:54 | 00,219,648 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/07/12 21:39:46 | 00,469,504 | ---- | M] ( ) -- C:\Documents and Settings\DeeBo\Desktop\RootRepeal.exe
[2009/07/07 11:10:56 | 24,539,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/07/06 14:38:06 | 00,000,525 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[2009/07/05 07:24:09 | 01,439,624 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/03 20:23:38 | 00,029,664 | ---- | M] () -- C:\Documents and Settings\DeeBo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/07/03 20:03:53 | 00,001,580 | ---- | M] () -- C:\Documents and Settings\DeeBo\Desktop\Defraggler.lnk
[2009/07/02 05:43:54 | 00,066,560 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/07/02 05:43:54 | 00,058,368 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/07/02 02:22:39 | 00,001,817 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Kodak EasyShare.lnk
[2009/06/30 18:04:22 | 04,807,814 | -H-- | M] () -- C:\Documents and Settings\DeeBo\Local Settings\Application Data\IconCache.db
[2009/06/30 01:11:56 | 00,000,180 | ---- | M] () -- C:\WINDOWS\wininit.ini
========== LOP Check ========== [2009/07/15 06:58:23 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/07/14 23:41:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/05/15 01:27:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2009/07/06 14:55:37 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/05/14 16:48:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/07/15 22:55:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/02 02:27:21 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\DeeBo\Application Data
[2009/06/08 05:20:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Alien Skin
[2009/06/03 10:00:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Artweaver
[2009/06/10 11:42:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Azureus
[2009/07/19 14:29:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\FileZilla
[2009/07/16 14:21:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\HLSW
[2009/05/13 23:17:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Nvu
[2009/06/09 02:20:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\PeaZip
[2009/06/02 21:00:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Search Settings
[2009/07/02 02:27:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Skinux
[2009/05/13 20:26:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\Styler
[2009/05/13 21:50:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\SystemRequirementsLab
[2009/05/28 01:09:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\DeeBo\Application Data\teamspeak2
[2009/07/15 07:56:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 23:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/07/19 19:10:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >