1. Run Adaware scan
2. Run Antivirus Scan
3. Run TFC (Temp File Cleaner)
4. Set a System Restore Point
5. Run ENRUNT
6. Run Malwarebytes (had numerous error messages on install)
7. Windows update
8. Rootrepeal
9. OTL
RootRepeal
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/19 13:46
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF0B94000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7C97000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEF576000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
-------------------
Path: C:\Documents and Settings\Doylechiro\Application Data\Gmail\gorhv17911194.exe
PID: 2312 Status: Hidden from the Windows API!
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "Lbd.sys" at address 0xf777f87e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "Lbd.sys" at address 0xf777fbfe
==EOF==
OTL
OTL logfile created on: 10/19/2009 1:49:31 PM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Documents and Settings\Doylechiro\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
767.00 Mb Total Physical Memory | 121.52 Mb Available Physical Memory | 15.84% Memory free
1.46 Gb Paging File | 0.84 Gb Available in Paging File | 57.41% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 27.43 Gb Free Space | 36.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DOCFW
Current User Name: Doylechiro
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/10/19 13:48:29 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Doylechiro\Desktop\OTL.exe
PRC - [2009/10/16 13:13:20 | 00,781,656 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/10/16 13:13:18 | 01,170,768 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/09/13 18:52:50 | 01,048,392 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/08/07 18:14:18 | 29,577,216 | ---- | M] (Forté Systems) -- C:\Program Files\Forte Systems\Chiro8000 v12\PM.exe
PRC - [2009/08/06 23:34:38 | 00,380,928 | ---- | M] () -- C:\Program Files\Forte Systems\Chiro8000 v12\FileServer.exe
PRC - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/06/10 17:28:26 | 12,973,336 | ---- | M] () -- C:\Program Files\RegCure\RegCure.exe
PRC - [2009/05/27 07:17:52 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/05/27 07:17:51 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/02/06 05:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2008/11/05 22:59:00 | 04,347,120 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2008/10/16 21:35:28 | 00,116,032 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\RaMaint.exe
PRC - [2008/10/16 21:35:24 | 00,087,360 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2008/07/24 19:46:10 | 00,063,040 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008/02/18 11:16:30 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2007/12/21 13:30:40 | 00,131,072 | ---- | M] (Visioneer Inc.) -- C:\Program Files\Visioneer\OneTouch 4.0\OtService.exe
PRC - [2006/03/02 18:47:35 | 07,166,053 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2005/08/11 17:30:30 | 00,081,920 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2005/03/31 10:26:50 | 00,229,376 | ---- | M] (Yahoo!, Inc.) -- C:\Program Files\Yahoo!\browser\ycommon.exe
PRC - [2005/01/04 12:50:52 | 00,405,583 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
PRC - [2004/10/20 08:40:04 | 00,010,328 | R--- | M] (America Online) -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
PRC - [2004/09/22 19:46:10 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2004/05/24 12:35:52 | 00,322,104 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\System32\drivers\KodakCCS.exe
PRC - [2004/01/08 17:41:40 | 00,073,796 | ---- | M] (Smart Link) -- C:\WINDOWS\System32\slserv.exe
PRC - [2003/09/19 13:11:46 | 00,065,536 | ---- | M] (OLYMPUS Corporation) -- C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
PRC - [2003/08/19 17:21:01 | 00,151,597 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2003/06/24 10:46:30 | 00,245,760 | ---- | M] (Dell) -- C:\Program Files\Common Files\Dell\EUSW\Support.exe
PRC - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2003/05/02 15:19:00 | 00,069,632 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
PRC - [2003/03/05 06:30:10 | 00,155,648 | ---- | M] () -- C:\Program Files\Rainbow Technologies\SPN Combo Installer\1.0.5\Server\WinNT\spnsrvnt.exe
PRC - [2002/12/17 18:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
PRC - [2002/12/17 18:23:32 | 00,074,308 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
PRC - [2002/08/29 05:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\unsecapp.exe
PRC - [2002/03/21 23:41:56 | 00,094,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
PRC - [2000/06/29 03:45:10 | 00,052,224 | ---- | M] (Kenonic Controls Ltd.) -- C:\WINDOWS\System32\crypserv.exe
========== Win32 Services (SafeList) ==========
SRV - File not found -- -- (Pml Driver HPZ12 [On_Demand | Stopped])
SRV - [2009/10/16 13:13:18 | 01,170,768 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc [Auto | Running])
SRV - [2009/05/27 07:17:51 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/10/16 21:35:28 | 00,116,032 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/07/24 19:46:10 | 00,063,040 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn [Auto | Running])
SRV - [2008/04/13 19:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/03/30 10:36:30 | 00,504,104 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
SRV - [2008/02/18 11:16:30 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/12/21 13:30:40 | 00,131,072 | ---- | M] (Visioneer Inc.) -- C:\Program Files\Visioneer\OneTouch 4.0\OtService.exe -- (OneTouch 4.0 Monitor [Auto | Running])
SRV - [2004/10/22 04:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2004/10/20 08:40:04 | 00,010,328 | R--- | M] (America Online) -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS [Auto | Running])
SRV - [2004/10/15 15:54:14 | 00,100,016 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe -- (AOL TopSpeedMonitor [Disabled | Stopped])
SRV - [2004/09/22 19:46:10 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])
SRV - [2004/05/24 12:35:52 | 00,322,104 | ---- | M] (Eastman Kodak Company) -- C:\WINDOWS\System32\drivers\KodakCCS.exe -- (KodakCCS [Auto | Running])
SRV - [2004/01/08 17:41:40 | 00,073,796 | ---- | M] (Smart Link) -- C:\WINDOWS\System32\slserv.exe -- (SLService [Auto | Running])
SRV - [2003/09/19 13:11:46 | 00,065,536 | ---- | M] (OLYMPUS Corporation) -- C:\Program Files\Olympus\DeviceDetector\DM1Service.exe -- (DM1Service [Auto | Running])
SRV - [2003/07/28 13:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2003/05/02 15:19:00 | 00,069,632 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2003/03/05 06:30:10 | 00,155,648 | ---- | M] () -- C:\Program Files\Rainbow Technologies\SPN Combo Installer\1.0.5\Server\WinNT\spnsrvnt.exe -- (SuperProServer [Auto | Running])
SRV - [2003/03/03 13:33:40 | 00,143,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
SRV - [2002/12/17 18:26:22 | 07,520,337 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -- (MSSQLSERVER [Auto | Running])
SRV - [2002/12/17 18:23:30 | 00,311,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE -- (SQLSERVERAGENT [On_Demand | Stopped])
SRV - [2002/12/17 18:23:30 | 00,066,112 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2000/06/29 03:45:10 | 00,052,224 | ---- | M] (Kenonic Controls Ltd.) -- C:\WINDOWS\System32\crypserv.exe -- (Crypkey License [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://news.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....e...-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapp.../search/ie.html
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....r=ytff-msgr&p="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-msgr"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-msgr"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..keyword.URL: "http://search.yahoo....r=ytff-msgr&p="
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/05/27 07:17:55 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/02 18:38:57 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 1.5\Extensions\\Components: C:\Program Files\Mozilla Firefox\Components [2008/04/08 08:02:20 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 1.5\Extensions\\Plugins: C:\Program Files\Mozilla Firefox\Plugins [2009/07/23 03:15:21 | 00,000,000 | ---D | M]
[2009/10/19 08:52:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\mozilla\Firefox\Profiles\1cq29ero.default\extensions
[2009/10/19 08:52:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\mozilla\Firefox\Profiles\1cq29ero.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/29 18:36:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\mozilla\Firefox\Profiles\1cq29ero.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/10/19 08:52:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\mozilla\Firefox\Profiles\1cq29ero.default\extensions\staged-xpis
[2009/10/19 09:02:23 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2006/03/02 18:47:34 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/06/27 10:19:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2008/02/12 12:01:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/19 08:33:31 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/08/12 07:08:50 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/05/27 07:18:14 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2006/03/02 18:47:31 | 00,060,518 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jar50.dll
[2006/03/02 18:47:34 | 00,049,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jsd3250.dll
[2006/03/02 18:47:31 | 00,165,992 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\xpinstal.dll
[2009/05/27 07:17:53 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2006/03/02 18:47:33 | 00,017,024 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2006/12/18 04:18:30 | 00,077,824 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/04/08 08:02:19 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin8.dll
[2006/03/02 18:47:38 | 00,000,680 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.png
[2006/03/02 18:47:38 | 00,000,741 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.src
[2006/03/02 18:47:38 | 00,001,150 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.png
[2006/03/02 18:47:38 | 00,000,539 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.src
[2006/03/02 18:47:38 | 00,000,356 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.png
[2006/03/02 18:47:38 | 00,001,007 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.src
[2006/03/02 18:47:38 | 00,000,210 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.gif
[2006/03/02 18:47:38 | 00,001,056 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.src
[2006/03/02 18:47:38 | 00,001,076 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.gif
[2006/03/02 18:47:38 | 00,000,718 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.src
[2006/03/02 18:47:38 | 00,000,088 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.gif
[2006/03/02 18:47:38 | 00,001,122 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.src
O1 HOSTS File: (2369 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <title>cominstall-adobe-flash.com</title>
O1 - Hosts: <script type="text/javascript" src="/js/general.js"></script>
O1 - Hosts: <script type="text/javascript">
O1 - Hosts: ChkRequestEnc('YToyMTp7aTowO3M6MTk6IjIwMDktMTAtMTcgMDk6MDI6NTciO2k6MTtzOjc6IjMwNzgzMjEiO2k6MjtOO2k6MztzOjEyOiJDcmF6eUJybyAxLjAiO2k6
NDtzOjg1OiIvaC5waHA/Y2FjaGluZ0Rlbnk9LmNvbSZpZD1oLmNvbWluc3RhbGwtYWRvYmUtZmxhc2guY29tJmlwPTEyNy4wLjAuMSZtb2RlPWhvc3RzJmRsbD0xIjtpOjU7czoxMzoi
NzEuMTEzLjI0OS41NSI7aTo2O3M6MjoiMTEiO2k6NztzOjA6IiI7aTo4O3M6MToidCI7aTo5O3M6MjoiVVMiO2k6MTA7czo1OiJURVhBUyI7aToxMTtzOjY6I
klSVklORyI7aToxMjtzOjI6IjE1IjtpOjEzO3M6MjY6ImNvbWluc3RhbGwtYWRvYmUtZmxhc2guY29tIjtpOjE0O3M6OTc6Imh0dHA6Ly9zZWRvcGFya2luZy
5jb20vc2VhcmNoL3JlZ2lzdHJhci5waHA/ZG9tYWluPWNvbWluc3RhbGwtYWRvYmUtZmxhc2guY29tJnJlZ2lzdHJhcj10cmVsbGlhbjUiO2k6MTU7TjtpOjE2O047aToxNztOO2k6MTg7TjtpOjE5O047
aToyMDtOO30=');
O1 - Hosts: </script>
O1 - Hosts: <script type="text/javascript">
O1 - Hosts: var fl = "toolbar";
O1 - Hosts: var u = "/" + fl + ".php";
O1 - Hosts: u = u + "?enc=YToyMTp7aTowO3M6MTk6IjIwMDktMTAtMTcgMDk6MDI6NTciO2k6MTtzOjc6IjMwNzgzMjEiO2k6MjtOO2k6MztzOjEyOiJDcmF6eUJybyAxLjAiO2k6
NDtzOjg1OiIvaC5waHA%2FY2FjaGluZ0Rlbnk9LmNvbSZpZD1oLmNvbWluc3RhbGwtYWRvYmUtZmxhc2guY29tJmlwPTEyNy4wLjAuMSZtb2RlPWhvc3RzJmRsbD0xIjtpOjU7czoxMz
oiNzEuMTEzLjI0OS41NSI7aTo2O3M6MjoiMTEiO2k6NztzOjA6IiI7aTo4O3M6MToidCI7aTo5O3M6MjoiVVMiO2k6MTA7czo1OiJURVhBUyI7aToxMTtzOjY
6IklSVklORyI7aToxMjtzOjI6IjE1IjtpOjEzO3M6MjY6ImNvbWluc3RhbGwtYWRvYmUtZmxhc2guY29tIjtpOjE0O3M6OTc6Imh0dHA6Ly9zZWRvcGFya2lu
Zy5jb20vc2VhcmNoL3JlZ2lzdHJhci5waHA%2FZG9tYWluPWNvbWluc3RhbGwtYWRvYmUtZmxhc2guY29tJnJlZ2lzdHJhcj10cmVsbGlhbjUiO2k6MTU7TjtpOjE2O047aToxNztOO2k6MTg7TjtpOjE5O0
47aToyMDtOO30%3D";
O1 - Hosts: var w = '690';
O1 - Hosts: var h = '320';
O1 - Hosts: var wV = 'scrollbars=no,resizable=yes,toolbar=no,' + 'menubar=no,status=no,location=no,height=' + h + ',width=' + w;
O1 - Hosts: tW = window.open(u, "tWin", wV);
O1 - Hosts: if (null !== tW)
O1 - Hosts: {
O1 - Hosts: tW.blur();
O1 - Hosts: window.focus();
O1 - Hosts: }
O1 - Hosts: </script>
O1 - Hosts: </head>
O1 - Hosts: <frameset rows="100%,*" frameborder="no" border="0" framespacing="0">
O1 - Hosts: <!-- SCC a11 -->
O1 - Hosts: <frame src="http://sedoparking.c...rar=trellian5">
O1 - Hosts: 16 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Suggest) - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll (Yahoo! Inc.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
O4 - HKLM..\Run: [IntelliType] C:\Program Files\Microsoft Hardware\Keyboard\type32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Chiro8000 v12 File Server.lnk = C:\Program Files\Forte Systems\Chiro8000 v12\FileServer.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Doylechiro\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL (Microsoft Corporation)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} https://www.acngroup...tivexviewer.cab (Crystal Report Viewer Control 9)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.micros...ntent/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase8942.cab (Windows Live Safety Center Base Module)
O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} https://accounting.q...147/qboax10.cab (QuickBooks Online Edition Utilities Class v10)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} https://accounting.q....559/qboax8.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA0F2EF5-88BB-4FE6-9192-8FDBCB9713BA} http://validate.meas...ASADownload.CAB (MDASADownload.Complete)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\g7ps {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll (G7 Productivity Systems, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mctp {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/03 16:22:14 | 00,000,000 | ---D | M] - C:\autodoc -- [ NTFS ]
O32 - AutoRun File - [2007/01/21 10:36:34 | 00,000,000 | ---D | M] - C:\Autodoc2 -- [ NTFS ]
O32 - AutoRun File - [2004/10/26 20:50:33 | 00,000,002 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2005/02/02 16:08:53 | 00,000,000 | ---D | M] - C:\autosync -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
NetSvcs: Ip6FwHlp - Service key not found. File not found
========== Files/Folders - Created Within 14 Days ==========
[2009/10/16 13:11:35 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2009/10/16 13:10:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/10/19 08:06:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/16 16:59:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/15 10:12:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Doylechiro\Application Data\Gmail
[2009/10/19 08:07:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Doylechiro\Application Data\Malwarebytes
[2009/10/19 08:04:17 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/10/19 08:06:51 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/16 17:24:26 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2009/10/16 17:17:01 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Live Safety Center
[2009/10/19 13:48:23 | 00,521,216 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Doylechiro\Desktop\OTL.exe
[2009/10/19 13:42:19 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Doylechiro\Desktop\RootRepeal.exe
[2009/10/19 08:08:25 | 04,045,536 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Doylechiro\Desktop\lllkkkiii-setup.exe
[2009/10/19 08:06:55 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/19 08:06:52 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/19 08:05:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/19 07:36:18 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Doylechiro\My Documents\TFC.exe
[2009/10/16 13:14:17 | 00,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
========== Files - Modified Within 14 Days ==========
[2009/10/19 13:48:29 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Doylechiro\Desktop\OTL.exe
[2009/10/19 13:42:19 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Doylechiro\Desktop\RootRepeal.exe
[2009/10/19 13:15:28 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/19 11:01:22 | 00,002,119 | ---- | M] () -- C:\Documents and Settings\Doylechiro\Application Data\JiJFGm1Mat.gif
[2009/10/19 11:01:22 | 00,000,607 | ---- | M] () -- C:\Documents and Settings\Doylechiro\Application Data\JiJFGm1Mzn.gif
[2009/10/19 11:01:22 | 00,000,598 | ---- | M] () -- C:\Documents and Settings\Doylechiro\Application Data\JiJFGm1Mby.gif
[2009/10/19 09:00:22 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2009/10/19 09:00:00 | 00,000,406 | -H-- | M] () -- C:\WINDOWS\tasks\{BED34167-2B86-49AB-8158-03E5F512279A}_DOCFW_Dr. Cody Doyle.job
[2009/10/19 08:50:16 | 00,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/10/19 08:45:35 | 00,000,448 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2009/10/19 08:45:18 | 00,000,398 | ---- | M] () -- C:\WINDOWS\tasks\SDMsgUpdate (SmartDrawTrial).job
[2009/10/19 08:45:18 | 00,000,388 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2009/10/19 08:45:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/19 08:44:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2009/10/19 08:09:46 | 00,000,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/19 08:08:31 | 04,045,536 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Doylechiro\Desktop\lllkkkiii-setup.exe
[2009/10/19 08:04:26 | 00,000,800 | ---- | M] () -- C:\Documents and Settings\Doylechiro\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/19 08:04:23 | 00,000,644 | ---- | M] () -- C:\Documents and Settings\Doylechiro\Desktop\NTREGOPT.lnk
[2009/10/19 08:04:22 | 00,000,625 | ---- | M] () -- C:\Documents and Settings\Doylechiro\Desktop\ERUNT.lnk
[2009/10/19 07:36:23 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Doylechiro\My Documents\TFC.exe
[2009/10/19 04:03:00 | 00,000,360 | ---- | M] () -- C:\WINDOWS\tasks\Scan for Viruses.job
[2009/10/19 02:20:00 | 00,000,620 | ---- | M] () -- C:\WINDOWS\tasks\ACOScheduler_DNS_Cody Doyle (v8)_DNS_Microphone (Mic-In)_DNS_DR_ CODY DOYLE_1.job
[2009/10/18 03:06:01 | 00,000,382 | ---- | M] () -- C:\WINDOWS\tasks\RegCure.job
[2009/10/16 17:24:27 | 00,000,853 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2009/10/16 16:00:00 | 00,000,406 | -H-- | M] () -- C:\WINDOWS\tasks\{DE7218A9-6FB8-487E-B721-575F1A73A2C5}_DOCFW_Dr. Cody Doyle.job
[2009/10/16 16:00:00 | 00,000,406 | -H-- | M] () -- C:\WINDOWS\tasks\{A62B03E9-0DB1-4B15-92A7-381E8981FE71}_DOCFW_Dr. Cody Doyle.job
[2009/10/16 14:40:10 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/16 13:11:33 | 00,000,900 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/10/16 10:08:02 | 00,002,187 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/10/15 03:27:17 | 00,533,408 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/15 03:27:17 | 00,463,200 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2009/10/15 03:27:17 | 00,079,920 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2009/10/15 03:12:24 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/10/14 04:00:00 | 00,000,432 | ---- | M] () -- C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DOCFW-Dr. Cody Doyle).job
========== Files - No Company Name ==========
[2009/10/19 08:06:59 | 00,000,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/19 08:04:26 | 00,000,800 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/19 08:04:23 | 00,000,644 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Desktop\NTREGOPT.lnk
[2009/10/19 08:04:22 | 00,000,625 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Desktop\ERUNT.lnk
[2009/10/16 17:30:12 | 00,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/10/16 17:24:27 | 00,000,853 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2009/10/16 15:02:38 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/10/16 13:15:04 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/16 13:11:33 | 00,000,900 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/10/15 10:22:59 | 00,002,119 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Application Data\JiJFGm1Mat.gif
[2009/10/15 10:22:59 | 00,000,607 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Application Data\JiJFGm1Mzn.gif
[2009/10/15 10:22:59 | 00,000,598 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Application Data\JiJFGm1Mby.gif
[2008/10/15 14:43:48 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\DM510.dll
[2008/02/17 12:35:24 | 00,004,114 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Application Data\SAS7_000.DAT
[2008/02/04 18:23:10 | 00,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/01/21 10:36:40 | 00,003,584 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/10/02 12:51:26 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/04/17 14:45:49 | 00,000,133 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Local Settings\Application Data\fusioncache.dat
[2006/03/10 09:54:57 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Doylechiro\Application Data\DESKTOP.INI
[2006/03/10 09:54:53 | 00,082,416 | ---- | C] () -- C:\Documents and Settings\Doylechiro\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2006/03/10 09:54:49 | 01,578,622 | -H-- | C] () -- C:\Documents and Settings\Doylechiro\Local Settings\Application Data\IconCache.db
[2006/01/27 09:25:39 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2006/01/17 15:58:04 | 00,000,056 | RHS- | C] () -- C:\WINDOWS\System32\BADECEE175.sys
[2006/01/17 15:41:52 | 00,003,350 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2005/09/29 15:00:21 | 00,000,340 | ---- | C] () -- C:\WINDOWS\ptlabels.ini
[2005/08/01 10:04:19 | 00,000,187 | ---- | C] () -- C:\WINDOWS\wiseftp.ini
[2005/04/11 14:49:25 | 00,000,000 | ---- | C] () -- C:\WINDOWS\plclient.INI
[2005/03/03 09:17:05 | 00,000,428 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2005/01/31 16:08:30 | 00,000,032 | ---- | C] () -- C:\WINDOWS\concentr.ini
[2005/01/31 15:10:21 | 00,000,042 | ---- | C] () -- C:\WINDOWS\webica.ini
[2005/01/28 11:45:23 | 00,000,377 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2004/12/09 18:36:40 | 00,000,012 | ---- | C] () -- C:\WINDOWS\clocked.ini
[2004/11/30 11:04:03 | 00,000,072 | ---- | C] () -- C:\WINDOWS\WINTIME.INI
[2004/11/26 21:57:26 | 00,000,567 | ---- | C] () -- C:\WINDOWS\BTI.INI
[2004/11/26 21:56:35 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\SAWZip.dll
[2004/11/26 21:56:35 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2004/11/26 21:56:31 | 00,307,200 | ---- | C] () -- C:\WINDOWS\System32\AppointmentView.dll
[2004/11/26 21:56:27 | 00,345,088 | ---- | C] () -- C:\WINDOWS\System32\ShrLk21.dll
[2004/11/26 21:56:27 | 00,304,128 | ---- | C] () -- C:\WINDOWS\System32\KeyGen.dll
[2004/10/26 20:50:32 | 00,000,121 | ---- | C] () -- C:\WINDOWS\Lname.ini
[2004/10/26 20:50:29 | 00,000,482 | ---- | C] () -- C:\WINDOWS\HITLIST.INI
[2004/10/26 20:50:28 | 00,000,214 | ---- | C] () -- C:\WINDOWS\Browser.ini
[2004/10/26 10:19:45 | 00,000,036 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2004/09/03 08:49:07 | 00,000,039 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/09/03 08:42:34 | 00,000,045 | ---- | C] () -- C:\WINDOWS\IDIGFLGN.ini
[2004/07/17 15:06:12 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Dssole.INI
[2004/07/17 15:06:07 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\DM1USBAPIVB.dll
[2004/07/07 16:32:17 | 00,014,938 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2004/06/30 08:34:22 | 00,000,010 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/06/14 10:46:07 | 00,051,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\atnt40k.sys
[2004/06/08 11:27:17 | 00,000,064 | ---- | C] () -- C:\WINDOWS\qwimp.ini
[2004/06/08 11:27:15 | 00,000,520 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2004/06/08 11:24:14 | 00,001,471 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2004/06/01 10:24:42 | 00,000,049 | ---- | C] () -- C:\WINDOWS\upth.ini
[2004/06/01 10:24:42 | 00,000,024 | ---- | C] () -- C:\WINDOWS\atid.ini
[2004/05/21 13:34:09 | 00,003,399 | R--- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2004/05/21 13:34:09 | 00,000,134 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2004/05/21 13:31:37 | 00,000,103 | ---- | C] () -- C:\WINDOWS\System32\hptrace.ini
[2004/05/21 11:54:13 | 00,001,437 | ---- | C] () -- C:\WINDOWS\hpdj5800.ini
[2004/01/20 07:24:15 | 00,040,278 | ---- | C] () -- C:\Program Files\Copy of Patients.dat
[2003/11/04 11:39:18 | 00,000,005 | ---- | C] () -- C:\WINDOWS\SUPER.INI
[2003/10/20 16:00:28 | 00,000,832 | ---- | C] () -- C:\WINDOWS\efscan.ini
[2003/10/20 16:00:28 | 00,000,021 | ---- | C] () -- C:\WINDOWS\efaxview.ini
[2003/10/09 20:04:56 | 00,000,027 | ---- | C] () -- C:\WINDOWS\UP9ASP.INI
[2003/09/24 16:34:19 | 00,251,392 | ---- | C] () -- C:\WINDOWS\System32\tx32.dll
[2003/09/24 16:34:19 | 00,000,150 | ---- | C] () -- C:\WINDOWS\System32\ic32.ini
[2003/09/24 16:34:13 | 00,010,092 | ---- | C] () -- C:\WINDOWS\exerpro.ini
[2003/09/22 17:13:17 | 00,000,773 | ---- | C] () -- C:\WINDOWS\BLST8.INI
[2003/09/20 11:18:22 | 00,000,173 | ---- | C] () -- C:\WINDOWS\srlink.ini
[2003/09/20 11:18:22 | 00,000,040 | ---- | C] () -- C:\WINDOWS\System32\sx96.ini
[2003/09/20 11:17:42 | 00,021,504 | ---- | C] () -- C:\WINDOWS\System32\docobj.dll
[2003/09/20 11:15:13 | 00,000,213 | ---- | C] () -- C:\WINDOWS\dgnsetup.ini
[2003/09/18 07:51:25 | 00,000,027 | ---- | C] () -- C:\WINDOWS\Crypkey.ini
[2003/09/18 07:51:21 | 00,024,608 | ---- | C] () -- C:\WINDOWS\System32\Ckldrv.sys
[2003/09/18 07:51:21 | 00,018,432 | ---- | C] () -- C:\WINDOWS\Setup_ck.dll
[2003/09/18 07:50:22 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\W32mkrc.dll
[2003/09/18 07:50:22 | 00,097,290 | ---- | C] () -- C:\WINDOWS\System32\Crp32dll.dll
[2003/09/18 07:50:17 | 01,073,152 | ---- | C] () -- C:\WINDOWS\System32\owl53v.dll
[2003/09/18 07:50:17 | 00,906,784 | ---- | C] () -- C:\WINDOWS\System32\Owl52f.dll
[2003/09/18 07:50:17 | 00,017,424 | ---- | C] () -- C:\WINDOWS\System32\FH_BMP.DLL
[2003/09/18 07:50:12 | 00,531,456 | ---- | C] () -- C:\WINDOWS\System32\Bdt52cf.dll
[2003/09/18 07:50:12 | 00,518,080 | ---- | C] () -- C:\WINDOWS\System32\bdt52c.dll
[2003/09/18 07:46:18 | 00,001,640 | ---- | C] () -- C:\WINDOWS\TrackMe.ini
[2003/09/16 10:07:26 | 00,000,036 | ---- | C] () -- C:\WINDOWS\BLST.INI
[2003/09/14 17:23:53 | 00,174,608 | ---- | C] () -- C:\WINDOWS\Tutility.dll
[2003/09/14 16:24:39 | 00,001,371 | ---- | C] () -- C:\WINDOWS\PM4W.INI
[2003/09/14 13:22:47 | 00,009,208 | ---- | C] () -- C:\WINDOWS\hplj1300.ini
[2003/09/14 13:17:09 | 00,000,951 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2003/08/19 17:22:33 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/08/19 17:17:56 | 00,000,885 | ---- | C] () -- C:\WINDOWS\lrun32.ini
[2003/08/19 17:16:47 | 00,001,143 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/08/19 17:11:52 | 00,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/08/19 17:00:08 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/08/19 16:49:32 | 00,000,549 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2003/01/07 16:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/09 09:38:12 | 00,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
[2002/09/03 13:36:02 | 00,000,699 | ---- | C] () -- C:\WINDOWS\WIN.INI
[2002/09/03 13:26:32 | 00,000,246 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2002/09/03 13:26:20 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\DESKTOP.INI
[2002/04/11 13:47:52 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\msmscoin.dll
[2000/09/08 17:53:50 | 00,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll
[1999/01/27 13:39:06 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2009/10/19 08:06:52 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/10/16 13:11:55 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
[2006/01/17 15:54:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Borland
[2006/01/17 15:50:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Corel
[2004/11/26 15:38:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dell
[2004/10/26 10:20:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\G7PS
[2009/01/13 20:08:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2006/01/27 09:30:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Motive
[2007/04/03 14:42:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2008/02/17 12:02:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2004/06/14 09:13:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pure Networks
[2009/08/20 07:11:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2003/08/19 17:13:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2008/02/17 16:39:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2004/01/22 11:09:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com
[2009/10/16 16:59:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2005/02/06 14:03:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/10/19 08:07:25 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Doylechiro\Application Data
[2007/01/10 12:56:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\ActiveDocs
[2008/09/26 12:51:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\FileZilla
[2006/09/27 12:58:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\G7PS
[2009/10/15 10:17:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\Gmail
[2006/04/25 09:02:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\Kana Solution
[2008/03/03 18:46:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\KompoZer
[2008/10/15 14:45:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\LinkManager 4.0
[2007/04/03 14:43:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\MSN6
[2008/02/17 12:07:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\Nuance
[2009/01/27 13:06:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\OpenOffice.org
[2006/09/05 10:07:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\ScanSoft
[2008/03/24 11:52:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Doylechiro\Application Data\Viewpoint
[2009/10/19 02:20:00 | 00,000,620 | ---- | M] () -- C:\WINDOWS\Tasks\ACOScheduler_DNS_Cody Doyle (v8)_DNS_Microphone (Mic-In)_DNS_DR_ CODY DOYLE_1.job
[2009/10/19 13:15:28 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/10/16 14:40:10 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\DESKTOP.INI
[2009/10/14 04:00:00 | 00,000,432 | ---- | M] () -- C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DOCFW-Dr. Cody Doyle).job
[2009/10/19 08:50:16 | 00,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/10/19 08:45:35 | 00,000,448 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2009/10/19 08:45:18 | 00,000,388 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Startup.job
[2009/10/18 03:06:01 | 00,000,382 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2009/10/19 08:45:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/10/19 04:03:00 | 00,000,360 | ---- | M] () -- C:\WINDOWS\Tasks\Scan for Viruses.job
[2009/10/19 08:45:18 | 00,000,398 | ---- | M] () -- C:\WINDOWS\Tasks\SDMsgUpdate (SmartDrawTrial).job
[2009/10/16 16:00:00 | 00,000,406 | -H-- | M] () -- C:\WINDOWS\Tasks\{A62B03E9-0DB1-4B15-92A7-381E8981FE71}_DOCFW_Dr. Cody Doyle.job
[2009/10/19 09:00:00 | 00,000,406 | -H-- | M] () -- C:\WINDOWS\Tasks\{BED34167-2B86-49AB-8158-03E5F512279A}_DOCFW_Dr. Cody Doyle.job
[2009/10/16 16:00:00 | 00,000,406 | -H-- | M] () -- C:\WINDOWS\Tasks\{DE7218A9-6FB8-487E-B721-575F1A73A2C5}_DOCFW_Dr. Cody Doyle.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2005/12/12 13:01:18 | 00,010,920 | ---- | M] () -- C:\aolconnfix.exe
< %systemroot%\system32\eventlog.dll >
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
< %systemroot%\system32\scecli.dll >
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\oldnartvtmp.rtf:SummaryInformation
< End of report >
Any help would be appreicated!