I've had some bad laptop problems these past few days. I got a google redirect virus on Monday. I followed the tutorial included here to solve it, and unfortunately was unsuccesful. Tdsskiller wouldn't find infected files, only one suspicious one that I could only delete. I tried other sites and fixes, the virus would go away and come back throughout the day. Finally, I decided to delete the file that tdsskiller kept finding (stpd.sys). This was my first mistake. Now my computer wouldn't start, blue screen of death. Tried to search the error, realized there was now a problem with my ATI driver, I think I ended up re-downloading it, and things were okay. More blue screen of death, lots of errors, and did check registry fixes. Now when I boot the computer I get multiple error messages. Here are a few of them:
Microsoft VIsual C++ Runtime LIbrary
Runtime Error
Program: C:/Program File
This application has requested the Runtime to terminate it in an unusual way. Please contact the application's support team.
DivXUpdate.exe _ Application Error
The Application Failed to initialize properly (0xc0000005)
Client Gateway 3.5.18 has encountered a problem and needs to close.
TCP/IP Services Application
Generic Host Process for Win32 Services has
DW20.exe the application failed to nitialize properly
In addition to this, firefox continuously crashed, at least every 30 minutes and I can't notice a pattern into why. Above all this, I still have the google re-direct virus. Any help would be GREATLY appreciated!! I am no expert but I can usually figure things out with good instructions. This time I think I might have messed up my computer since I didn't really know what I was doing.
Thank you kindly,
Maxime
OTL logfile created on: 1/13/2011 1:19:03 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 40.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.89 Gb Total Space | 11.51 Gb Free Space | 20.60% Space Free | Partition Type: NTFS
Drive D: | 7.58 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: YOUR-2B7C71599F | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/01/13 13:18:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
PRC - [2011/01/04 11:05:06 | 000,083,440 | ---- | M] (Google) -- C:\Documents and Settings\user\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2010/12/10 23:25:08 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/12/10 23:25:03 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/09/15 03:34:02 | 001,094,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 20:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2009/10/30 22:03:24 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2008/05/21 16:26:10 | 000,451,896 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe
PRC - [2008/05/16 05:11:44 | 000,648,504 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2008/05/16 05:11:44 | 000,648,504 | ---- | M] (Pure Networks, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/29 16:38:31 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007/04/03 15:18:08 | 001,516,584 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2007/01/11 12:57:22 | 000,291,760 | ---- | M] () -- C:\Program Files\Lexmark 5400 Series\lxctmon.exe
PRC - [2006/07/25 17:03:42 | 000,100,032 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2006/07/13 15:27:16 | 000,528,384 | ---- | M] ( ) -- C:\WINDOWS\system32\lxctcoms.exe
PRC - [2006/04/25 19:57:00 | 000,299,008 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe
PRC - [2006/04/04 16:57:18 | 000,053,248 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
PRC - [2006/03/16 15:27:26 | 000,634,880 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
PRC - [2006/02/02 14:11:38 | 000,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
PRC - [2005/12/20 14:17:48 | 000,114,688 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TODDSrv.exe
PRC - [2005/12/15 13:41:28 | 000,188,416 | ---- | M] (Agere Systems) -- C:\Program Files\ltmoh\ltmoh.exe
PRC - [2005/12/06 00:06:10 | 001,077,322 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
PRC - [2005/11/02 03:41:04 | 000,978,944 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2005/09/26 13:22:28 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2005/06/06 11:58:44 | 000,024,576 | ---- | M] (TOSHIBA) -- C:\WINDOWS\system32\ZoomingHook.exe
PRC - [2005/05/31 19:16:44 | 000,282,624 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSMain.exe
PRC - [2005/05/31 19:16:24 | 000,045,056 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSBattM.exe
PRC - [2005/01/17 03:38:38 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2004/08/27 11:37:00 | 000,155,648 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\RAMASST.exe
PRC - [2004/08/27 11:33:00 | 000,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\DVDRAMSV.exe
PRC - [2004/08/04 07:00:00 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\freecell.exe
========== Modules (SafeList) ==========
MOD - [2011/01/13 13:18:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2010/11/25 14:23:40 | 001,375,992 | ---- | M] (Lavasoft) [On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/03/25 20:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/03/02 12:18:06 | 000,689,392 | ---- | M] (Radialpoint Inc.) [Auto | Stopped] -- C:\Program Files\Videotron\Videotron Service Agent\ServicepointService.exe -- (ServicepointService)
SRV - [2009/06/26 08:26:20 | 000,085,504 | ---- | M] (PC Pitstop LLC) [Disabled | Stopped] -- C:\Program Files\PCPitstop\PCPitstopScheduleService.exe -- (PCPitstop Scheduling)
SRV - [2008/07/26 07:27:42 | 000,141,848 | ---- | M] (Logitech Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe -- (LVSrvLauncher)
SRV - [2008/05/21 16:25:30 | 000,012,800 | ---- | M] (Pure Networks, Inc.) [On_Demand | Stopped] -- C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe -- (nmraapache)
SRV - [2008/05/16 05:11:44 | 000,648,504 | ---- | M] (Pure Networks, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2008/04/13 19:12:02 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2008/01/29 16:38:31 | 000,583,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service)
SRV - [2007/04/03 15:18:08 | 001,516,584 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2006/07/25 17:03:42 | 002,119,360 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE -- (LiveUpdate)
SRV - [2006/07/25 17:03:42 | 000,100,032 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2006/07/13 15:27:16 | 000,528,384 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxctcoms.exe -- (lxct_device)
SRV - [2005/12/20 14:17:48 | 000,114,688 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\WINDOWS\system32\TODDSrv.exe -- (TODDSrv)
SRV - [2005/09/26 13:22:28 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2005/01/17 03:38:38 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2004/08/27 11:33:00 | 000,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
========== Driver Services (SafeList) ==========
DRV - [2010/11/07 15:37:53 | 000,015,264 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2010/07/12 03:55:39 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/02/11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009/06/30 10:37:16 | 000,028,552 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot)
DRV - [2008/09/02 03:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2008/05/16 05:10:32 | 000,023,992 | ---- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp)
DRV - [2008/05/16 05:10:30 | 000,025,272 | ---- | M] (Pure Networks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\purendis.sys -- (purendis)
DRV - [2008/04/13 13:46:20 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008/04/13 13:46:20 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008/04/13 13:46:10 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msdv.sys -- (MSDV)
DRV - [2008/04/13 13:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 11:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/10/12 00:56:22 | 000,490,776 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2007/04/03 15:17:08 | 000,306,295 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2007/03/06 16:54:40 | 000,041,376 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007/03/06 16:52:46 | 002,261,792 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVMVdrv.sys -- (LVMVDrv)
DRV - [2007/03/06 16:50:30 | 001,669,664 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Lvckap.sys -- (LVcKap)
DRV - [2007/03/06 16:48:46 | 001,273,504 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007/03/06 16:48:46 | 000,014,240 | ---- | M] (Labtec Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2007/01/31 12:45:06 | 000,127,376 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
DRV - [2007/01/18 13:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2006/04/25 11:01:48 | 000,043,776 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tvs.sys -- (Tvs)
DRV - [2006/04/18 17:12:00 | 000,098,816 | ---- | M] (TOSHIBA Corporation) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tdudf.sys -- (tdudf)
DRV - [2006/04/17 18:31:26 | 004,262,912 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/04/01 19:46:28 | 000,471,264 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2006/03/17 18:36:42 | 001,155,584 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/03/17 04:24:09 | 001,520,640 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/03/02 20:49:50 | 000,015,360 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2006/01/05 18:31:20 | 000,011,264 | ---- | M] (TOSHIBA ) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TPwSav.sys -- (TPwSav)
DRV - [2005/06/01 14:33:00 | 000,102,384 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2005/01/26 07:22:20 | 000,280,344 | ---- | M] (Zone Labs LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2004/11/15 03:22:08 | 000,101,874 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/08/03 17:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/06/27 21:35:24 | 000,069,760 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)
DRV - [2003/09/19 03:47:00 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc)
DRV - [2003/09/11 01:36:54 | 000,021,060 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iviaspi.sys -- (Iviaspi)
DRV - [2003/01/29 01:35:00 | 000,012,032 | ---- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio)
DRV - [2002/01/24 16:43:40 | 000,006,528 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Tbiosdrv.sys -- (TBiosDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Swag Bucks Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Swag Bucks Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.2
FF - prefs.js..extensions.enabledItems: {987311C6-B504-4aa2-90BF-60CC49808D42}:2.2
FF - prefs.js..extensions.enabledItems: [email protected]:3.5
FF - prefs.js..extensions.enabledItems: {b055c535-4a3a-11db-9659-00e08161166f}:1.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.9.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CB56AAF9-68C8-41bd-8E5C-7B53232CF7B9}:1.9.37
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}:3.2.5.2
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..keyword.URL: "http://flvdirect.iam...c=tops&search="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/24 16:21:28 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/10 23:25:16 | 000,000,000 | ---D | M]
[2010/03/01 16:08:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2010/03/01 16:08:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions\[email protected]
[2011/01/13 12:16:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions
[2010/04/27 10:52:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/04 21:56:36 | 000,000,000 | ---D | M] (Swag Bucks Community Toolbar) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
[2009/11/06 19:19:51 | 000,000,000 | ---D | M] (BugMeNot) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2009/05/13 11:30:48 | 000,000,000 | ---D | M] (TV5 - Dictionnaires) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{b055c535-4a3a-11db-9659-00e08161166f}
[2010/10/05 08:36:11 | 000,000,000 | ---D | M] (dragdropupload) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{CB56AAF9-68C8-41bd-8E5C-7B53232CF7B9}
[2011/01/04 21:56:38 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/02/15 18:51:23 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/05/20 06:36:38 | 000,000,000 | ---D | M] ("Better Gmail 2") -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\[email protected]
[2011/01/04 21:56:34 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\[email protected]
[2010/02/15 21:51:29 | 000,000,000 | ---D | M] (Dictionnaire français «Réforme 1990») -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\[email protected]
[2010/10/02 08:48:54 | 000,000,000 | ---D | M] (Dictionnaire français «Classique») -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\extensions\[email protected]
[2010/08/19 20:33:02 | 000,000,923 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\searchplugins\conduit.xml
[2011/01/13 11:06:01 | 000,001,540 | ---- | M] () -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\erodl7l0.default\searchplugins\swagbuckscom.xml
[2011/01/13 12:16:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/17 11:55:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/13 23:28:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/03/01 16:06:27 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2007/06/21 17:38:54 | 000,079,432 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2007/06/21 17:38:56 | 000,071,240 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2007/06/21 17:39:18 | 000,034,376 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\logging.dll
[2010/07/17 04:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/06/21 17:39:34 | 000,325,200 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2007/06/21 17:40:02 | 000,030,280 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
O1 HOSTS File: ([2011/01/11 09:07:05 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Foxit Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe (TOSHIBA CO.,LTD.)
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [LXCTCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCTtime.DLL (Lexmark International Inc.)
O4 - HKLM..\Run: [lxctmon.exe] C:\Program Files\Lexmark 5400 Series\lxctmon.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Pure Networks, Inc.)
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [VideotronSA.exe] C:\Program Files\Videotron\Videotron Service Agent\VideotronSA.exe (Vidéotron)
O4 - HKLM..\Run: [ZoomingHook] C:\WINDOWS\System32\ZoomingHook.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O15 - HKCU\..Trusted Domains: acdi-cida.gc.ca ([]https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553538000} http://fpdownload2.m...ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantac...ad/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcp.../PCPitStop2.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/05 12:58:42 | 000,000,007 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{40610602-f00a-11df-a950-0016d426eef7}\Shell - "" = AutoRun
O33 - MountPoints2\{40610602-f00a-11df-a950-0016d426eef7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{40610602-f00a-11df-a950-0016d426eef7}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{d19d3852-0a0c-11df-a79f-00059a3c7800}\Shell\AutoRun\command - "" = F:\JAN\J-1-2-34-000000AAAA-11111111111-5555555555-111\Max.exe
O33 - MountPoints2\{d19d3852-0a0c-11df-a79f-00059a3c7800}\Shell\open\command - "" = F:\JAN\J-1-2-34-000000AAAA-11111111111-5555555555-111\Max.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/13 13:18:41 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
[2011/01/12 09:06:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\GetRightToGo
[2011/01/12 08:45:13 | 000,000,000 | ---D | C] -- C:\spoolerlogs
[2011/01/11 09:23:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\GooredFix Backups
[2011/01/11 09:23:02 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\user\Desktop\GooredFix.exe
[2011/01/11 08:52:21 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/01/11 08:50:50 | 000,519,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTM.exe
[2011/01/11 08:49:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\ERUNT
[2011/01/11 08:45:36 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/01/07 10:02:30 | 000,028,552 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2011/01/07 10:01:02 | 000,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2011/01/05 10:45:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\_My Filing Cabinet
[2011/01/05 10:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Organizer And Filing Cabinet
[2011/01/05 10:29:22 | 000,000,000 | ---D | C] -- C:\Program Files\Organizer And Filing Cabinet
[2011/01/02 10:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\Teav school stuff
[2010/12/23 12:22:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\Vouchers
[2010/12/22 12:50:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Ectaco
[2010/12/22 12:39:48 | 000,000,000 | ---D | C] -- C:\Program Files\LingvoSoft
[2010/12/18 20:04:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\com.inm.fusion.PixtorioViewer.744790F1545733D757EA034B675902690507C2E8.1
[2010/12/18 20:04:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2008/10/26 19:51:11 | 000,409,600 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctinpa.dll
[2008/10/26 19:51:10 | 001,187,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctserv.dll
[2008/10/26 19:51:10 | 000,983,040 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctusb1.dll
[2008/10/26 19:51:10 | 000,393,216 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctiesc.dll
[2008/10/26 19:51:10 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctprox.dll
[2008/10/26 19:51:09 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctpmui.dll
[2008/10/26 19:51:09 | 000,528,384 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctlmpm.dll
[2008/10/26 19:51:09 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctpplc.dll
[2008/10/26 19:51:08 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcthbn3.dll
[2008/10/26 19:51:07 | 000,667,648 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctcomc.dll
[2008/10/26 19:51:07 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\lxctcomm.dll
========== Files - Modified Within 30 Days ==========
[2011/01/13 13:18:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTL.exe
[2011/01/13 13:08:00 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2210832384-2747458650-1879816375-1006UA.job
[2011/01/13 10:57:14 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/13 10:51:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/13 10:51:48 | 1474,408,448 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/13 00:01:20 | 000,083,968 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/12 13:13:59 | 063,938,560 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2011/01/12 12:51:57 | 003,072,054 | ---- | M] () -- C:\Documents and Settings\user\Desktop\suspicious.bmp
[2011/01/12 09:03:51 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/11 18:40:27 | 000,099,801 | ---- | M] () -- C:\Documents and Settings\user\Desktop\MaximeMichelCV.docx
[2011/01/11 17:01:04 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/11 10:05:08 | 001,535,244 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Alumni_fr.pdf
[2011/01/11 09:24:59 | 001,232,020 | ---- | M] () -- C:\Documents and Settings\user\Desktop\tdsskiller.zip
[2011/01/11 09:23:04 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\user\Desktop\GooredFix.exe
[2011/01/11 09:07:05 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2011/01/11 08:51:00 | 000,519,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTM.exe
[2011/01/10 23:08:04 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2210832384-2747458650-1879816375-1006Core.job
[2011/01/07 15:03:48 | 000,015,173 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Caitlin.xlsx
[2011/01/07 14:15:08 | 000,213,595 | ---- | M] () -- C:\Documents and Settings\user\Desktop\00066010403_SCS3100D.pdf
[2011/01/07 11:31:34 | 000,010,060 | ---- | M] () -- C:\Documents and Settings\user\Desktop\David Gillies.docx
[2011/01/06 14:16:05 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/01/05 10:29:37 | 000,001,866 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Organizer And Filing Cabinet.lnk
[2011/01/02 11:22:39 | 000,015,915 | ---- | M] () -- C:\Documents and Settings\user\Desktop\MaximeMichelLetter.docx
[2011/01/01 17:51:46 | 000,048,128 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Copy of lawrences-christmas-shopping-budget.xls
[2011/01/01 17:42:33 | 000,007,827 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Xmas gift expenses 2010.xlsx
[2010/12/31 11:21:14 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Michel,Maxime.doc
[2010/12/17 11:04:56 | 000,064,901 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Teav Calendar 2011.xlsx
[2010/12/17 11:04:47 | 000,064,901 | ---- | M] () -- C:\Documents and Settings\user\My Documents\PracticalSpreadsheets_2011Calendar1.xlsx
[2010/12/16 09:34:16 | 000,150,792 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/15 16:42:22 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/12/15 13:02:35 | 000,041,984 | ---- | M] () -- C:\Documents and Settings\user\My Documents\bourquet.doc
[2010/12/15 00:52:32 | 000,733,410 | ---- | M] () -- C:\Documents and Settings\user\My Documents\WritingandStyleGuide2010-2011_001.pdf
========== Files Created - No Company Name ==========
[2011/01/12 13:40:38 | 1474,408,448 | -HS- | C] () -- C:\hiberfil.sys
[2011/01/12 12:51:56 | 003,072,054 | ---- | C] () -- C:\Documents and Settings\user\Desktop\suspicious.bmp
[2011/01/11 10:05:08 | 001,535,244 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Alumni_fr.pdf
[2011/01/11 09:24:44 | 001,232,020 | ---- | C] () -- C:\Documents and Settings\user\Desktop\tdsskiller.zip
[2011/01/07 14:15:08 | 000,213,595 | ---- | C] () -- C:\Documents and Settings\user\Desktop\00066010403_SCS3100D.pdf
[2011/01/07 14:07:09 | 000,015,173 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Caitlin.xlsx
[2011/01/07 11:29:30 | 000,010,060 | ---- | C] () -- C:\Documents and Settings\user\Desktop\David Gillies.docx
[2011/01/05 10:29:37 | 000,001,866 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Organizer And Filing Cabinet.lnk
[2011/01/02 11:22:39 | 000,015,915 | ---- | C] () -- C:\Documents and Settings\user\Desktop\MaximeMichelLetter.docx
[2011/01/01 17:42:32 | 000,007,827 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Xmas gift expenses 2010.xlsx
[2010/12/31 11:18:55 | 000,040,960 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Michel,Maxime.doc
[2010/12/17 11:04:55 | 000,064,901 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Teav Calendar 2011.xlsx
[2010/12/17 11:04:46 | 000,064,901 | ---- | C] () -- C:\Documents and Settings\user\My Documents\PracticalSpreadsheets_2011Calendar1.xlsx
[2010/12/15 00:52:32 | 000,733,410 | ---- | C] () -- C:\Documents and Settings\user\My Documents\WritingandStyleGuide2010-2011_001.pdf
[2010/10/21 10:06:15 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/01/22 23:50:58 | 000,000,416 | ---- | C] () -- C:\WINDOWS\scummvm.ini
[2009/12/18 22:05:16 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini
[2009/12/18 22:02:29 | 000,000,765 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/11/16 22:41:05 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\user\Application Data\avdrn.dat
[2009/08/31 23:43:55 | 000,000,518 | ---- | C] () -- C:\WINDOWS\YUKON.INI
[2009/05/23 06:09:16 | 000,000,262 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/05/22 03:58:05 | 000,010,236 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\NetMailTmp.bin
[2008/10/26 19:56:15 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxctvs.dll
[2008/10/26 19:56:12 | 000,335,872 | ---- | C] () -- C:\WINDOWS\System32\lxctcoin.dll
[2008/10/26 19:55:12 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxctdrs.dll
[2008/10/26 19:55:12 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxctcaps.dll
[2008/10/26 19:55:12 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxctcnv4.dll
[2008/10/26 19:53:55 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxctpmon.dll
[2008/10/26 19:53:55 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXCTFXPU.DLL
[2008/10/26 19:51:11 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\LXCTinst.dll
[2008/10/26 19:51:08 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\lxctgrd.dll
[2008/10/12 13:12:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ToDisc.INI
[2008/10/06 15:40:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\TPTray.INI
[2008/09/15 19:14:24 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/08/28 18:13:56 | 000,000,745 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/07/04 23:25:03 | 000,083,968 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/05 18:47:14 | 000,001,400 | ---- | C] () -- C:\Documents and Settings\user\Application Data\default.cfg
[2008/06/05 17:40:32 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2008/06/05 17:40:32 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2008/06/05 17:40:32 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2008/06/05 17:40:32 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2008/06/05 17:40:09 | 000,006,528 | ---- | C] () -- C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/10/12 00:11:58 | 000,051,370 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007/04/03 15:18:26 | 000,197,672 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2007/04/03 15:18:06 | 000,193,576 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2007/03/06 16:50:30 | 001,669,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\Lvckap.sys
[2006/05/04 21:33:04 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/05/03 16:13:51 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/05/03 16:09:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/05/03 16:07:00 | 000,036,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/05/03 16:07:00 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/05/03 16:04:16 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/05/03 16:04:16 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/05/03 16:04:16 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/05/03 16:04:16 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/05/03 16:04:16 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/05/03 16:04:16 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/05/03 15:58:30 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\EBLib.DLL
[2006/05/03 15:55:22 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/05/03 13:54:56 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/05/03 13:32:48 | 000,002,392 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/05/03 13:32:34 | 000,003,584 | ---- | C] () -- C:\WINDOWS\System32\nt.dll
[2006/05/03 06:44:12 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2006/01/05 20:49:34 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\HWS_Ctrl.dll
[2006/01/05 19:36:22 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\EKECioCtl.dll
[2005/12/09 16:36:30 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\TPeculiarity.dll
[2005/11/23 15:55:42 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\SPCtl.dll
========== LOP Check ==========
[2008/10/26 19:53:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\5400 Series
[2010/03/25 14:36:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2009/08/23 23:23:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2008/10/10 20:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2008/10/11 21:08:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Launcher
[2010/09/07 16:45:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/11/04 13:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Radialpoint
[2010/11/04 13:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Videotron
[2010/08/07 15:25:31 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/09/10 22:28:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\5400 Series
[2010/12/18 20:04:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\com.inm.fusion.PixtorioViewer.744790F1545733D757EA034B675902690507C2E8.1
[2009/08/23 23:32:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DAEMON Tools Lite
[2010/12/22 12:51:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Ectaco
[2009/06/12 17:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Emulators
[2010/06/09 20:15:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Facebook
[2010/02/15 18:51:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Foxit
[2010/02/26 11:08:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Foxit Software
[2008/07/11 20:04:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\GarageGames
[2011/01/12 09:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\GetRightToGo
[2010/02/21 12:28:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Gmail Backup
[2008/10/06 23:54:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\ICAClient
[2008/07/02 23:21:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\InterVideo
[2009/08/18 13:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\LANCITE
[2008/08/29 15:33:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Leadertech
[2006/05/03 16:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\toshiba
[2010/11/04 13:45:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Videotron
[2009/04/28 09:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Xerox
[2011/01/06 14:16:05 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/01/13 10:57:14 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
< End of report >
Edited by maximem, 13 January 2011 - 01:08 PM.