Here's the OTL, the Extras file didn't come up. Did I miss a setting?
OTL logfile created on: 3/14/2011 9:39:01 PM - Run 3
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\LoBasso Family\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 39.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 61.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 450.70 Gb Total Space | 189.92 Gb Free Space | 42.14% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 8.38 Gb Free Space | 55.85% Space Free | Partition Type: NTFS
Computer Name: LOBASSO | User Name: LoBasso Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/03/04 21:54:43 | 002,250,024 | ---- | M] () -- c:\LoBasso Programs\mw2\SteamApps\common\far cry 2\installers\PunkBuster\pbsvc.exe
PRC - [2011/03/04 21:46:35 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\LoBasso Family\Desktop\OTL.exe
PRC - [2011/03/02 17:47:13 | 000,407,336 | ---- | M] (Valve Corporation) -- C:\LoBasso Programs\mw2\bin\SteamService.exe
PRC - [2011/01/13 00:40:20 | 003,252,880 | R--- | M] (Carbonite, Inc. (www.carbonite.com)) -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2011/01/13 00:40:20 | 000,931,472 | R--- | M] (Carbonite, Inc.) -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2010/12/25 09:48:18 | 000,233,936 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe
PRC - [2010/12/12 16:18:15 | 000,028,766 | ---- | M] (FilmFanatic) -- C:\Program Files\FilmFanatic\bar\1.bin\pabarsvc.exe
PRC - [2010/12/12 16:18:15 | 000,020,480 | ---- | M] (FilmFanatic) -- C:\Program Files\FilmFanatic\bar\1.bin\pabrmon.exe
PRC - [2010/10/16 01:01:50 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileBackup.exe
PRC - [2010/09/17 22:14:22 | 000,460,144 | ---- | M] () -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
PRC - [2010/04/07 13:57:42 | 000,099,896 | R--- | M] (HP) -- C:\Windows\System32\HPSIsvc.exe
PRC - [2009/08/21 23:37:15 | 000,117,640 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
PRC - [2009/06/24 11:57:04 | 000,136,704 | ---- | M] (HP) -- C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
PRC - [2009/04/10 23:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/10/04 11:58:04 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/10/04 11:58:02 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/09/23 20:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/07/18 05:42:10 | 006,246,400 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/07/18 05:42:08 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTSrv.exe
PRC - [2008/06/13 09:04:02 | 000,025,256 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe
PRC - [2008/06/13 09:04:01 | 000,668,328 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2008/05/23 12:06:08 | 000,128,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/02/27 17:53:25 | 000,594,600 | ---- | M] ( ) -- C:\Windows\System32\lxdxcoms.exe
PRC - [2008/01/20 19:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
========== Modules (SafeList) ========== MOD - [2011/03/04 21:46:35 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\LoBasso Family\Desktop\OTL.exe
MOD - [2010/08/31 08:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Unknown | Stopped] -- -- (getPlusHelper)
SRV - [2011/03/02 17:47:13 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/01/13 00:40:20 | 003,252,880 | R--- | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] -- C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe -- (CarboniteService)
SRV - [2010/12/12 16:18:15 | 000,028,766 | ---- | M] (FilmFanatic) [Auto | Running] -- C:\Program Files\FilmFanatic\bar\1.bin\pabarsvc.exe -- (FilmFanaticService)
SRV - [2010/09/17 22:14:22 | 000,460,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
SRV - [2010/08/23 21:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2010/04/07 13:57:42 | 000,099,896 | R--- | M] (HP) [Auto | Running] -- C:\Windows\System32\HPSIsvc.exe -- (HPSIService)
SRV - [2009/08/21 23:37:15 | 000,117,640 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe -- (Norton AntiVirus)
SRV - [2009/07/23 23:34:42 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/06/24 11:57:04 | 000,136,704 | ---- | M] (HP) [Auto | Running] -- C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe -- (HP LaserJet Service)
SRV - [2009/03/03 17:27:40 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/10/04 11:58:04 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)
SRV - [2008/09/23 20:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2008/07/18 05:42:08 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AERTSrv.exe -- (AERTFilters)
SRV - [2008/02/27 17:53:25 | 000,594,600 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxdxcoms.exe -- (lxdx_device)
SRV - [2008/02/27 17:53:22 | 000,098,984 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe -- (lxdxCATSCustConnectService)
SRV - [2008/01/20 19:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/11 17:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
========== Driver Services (SafeList) ========== DRV - [2011/03/04 23:47:10 | 000,016,968 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hitmanpro35.sys -- (hitmanpro35)
DRV - [2010/08/19 08:32:06 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2010/08/19 08:32:06 | 000,102,448 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2010/03/05 16:40:57 | 000,017,408 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mvusbews.sys -- (mvusbews)
DRV - [2010/02/05 06:16:10 | 000,028,048 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BthAvrcp.sys -- (BthAvrcp)
DRV - [2010/01/27 16:52:40 | 000,482,432 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\NAV\1008000.029\ccHPx86.sys -- (ccHP)
DRV - [2009/10/28 15:37:22 | 000,343,088 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100312.001\IDSvix86.sys -- (IDSVix86)
DRV - [2009/08/21 23:37:16 | 000,310,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\NAV\1008000.029\SYMEFA.SYS -- (SymEFA)
DRV - [2009/08/21 23:37:16 | 000,308,272 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NAV\1008000.029\SRTSP.SYS -- (SRTSP)
DRV - [2009/08/21 23:37:16 | 000,259,632 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\NAV\1008000.029\BHDrvx86.sys -- (BHDrvx86)
DRV - [2009/08/21 23:37:16 | 000,217,136 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\NAV\1008000.029\SYMTDI.SYS -- (SYMTDI)
DRV - [2009/08/21 23:37:16 | 000,089,904 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\NAV\1008000.029\SYMFW.SYS -- (SYMFW)
DRV - [2009/08/21 23:37:16 | 000,048,688 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\NAV\1008000.029\SYMNDISV.SYS -- (SYMNDISV)
DRV - [2009/08/21 23:37:16 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\NAV\1008000.029\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2009/08/18 18:47:09 | 000,124,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2009/08/18 11:59:24 | 000,025,648 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\SymIMV.sys -- (SymIM)
DRV - [2008/11/11 13:41:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2008/10/17 03:24:48 | 003,930,112 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2008/10/17 03:24:48 | 003,930,112 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008/07/21 04:18:20 | 000,027,648 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2008/07/10 04:28:50 | 000,123,904 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/01/20 19:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel®
DRV - [2008/01/20 19:23:21 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.startsearcher.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.startsearcher.com IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepageIE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepageIE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepage IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityrespo...er/fix_homepage IE - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.myyahoo.com/IE - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.startsearcher.comIE - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..\URLSearchHook: {796b75f6-6187-47e2-8f1f-c16e059e6e19} - C:\Program Files\FilmFanatic\bar\1.bin\paSrcAs.dll (FilmFanatic)
IE - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\FilmFanatic\bar\1.bin [2010/12/12 16:18:17 | 000,000,000 | ---D | M]
[2010/12/31 09:40:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LoBasso Family\AppData\Roaming\Mozilla\Extensions
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll (PlaySushi LLC)
O2 - BHO: (Toolbar BHO) - {631acb68-57c3-48af-9cc5-fcec0837ffd3} - C:\Program Files\FilmFanatic\bar\1.bin\pabar.dll (FilmFanatic)
O2 - BHO: (Facetheme) - {66D8FBA6-D90F-40A9-AC55-84896F79CA69} - C:\Program Files\Object\bho_project.dll (Facetheme.com)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Search Assistant BHO) - {d5e9b421-c309-41de-9014-800a2adcdeb0} - C:\Program Files\FilmFanatic\bar\1.bin\paSrcAs.dll (FilmFanatic)
O2 - BHO: (Search Assistant) - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll (MTWB)
O2 - BHO: (Fast Browser Search Toolbar Helper) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()
O3 - HKLM\..\Toolbar: (FilmFanatic) - {0b84b4b4-8af8-4f1f-91fe-074a666f6425} - C:\Program Files\FilmFanatic\bar\1.bin\pabar.dll (FilmFanatic)
O3 - HKLM\..\Toolbar: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..\Toolbar\ShellBrowser: (FilmFanatic) - {0B84B4B4-8AF8-4F1F-91FE-074A666F6425} - C:\Program Files\FilmFanatic\bar\1.bin\pabar.dll (FilmFanatic)
O3 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..\Toolbar\WebBrowser: (FilmFanatic) - {0B84B4B4-8AF8-4F1F-91FE-074A666F6425} - C:\Program Files\FilmFanatic\bar\1.bin\pabar.dll (FilmFanatic)
O3 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..\Toolbar\WebBrowser: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll ()
O3 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [FilmFanatic Browser Plugin Loader] C:\Program Files\FilmFanatic\bar\1.bin\pabrmon.exe (FilmFanatic)
O4 - HKLM..\Run: [HPUsageTrackingLEDM] C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003..\Run: [{527BD3AD-6E31-7316-10B9-24758F1C2FC4}] File not found
O4 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003..\Run: [ISUSPM] File not found
O4 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003..\Run: [ktmudisc] C:\Users\LoBasso Family\AppData\Local\Temp\p2phKEYs.dll ()
O4 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003..\Run: [msnmsgr] File not found
O4 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003..\Run: [Steam] c:\lobasso programs\mw2\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\LoBasso Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKU\S-1-5-21-659033489-2536866663-3761728600-1003\..Trusted Domains: localhost ([]* in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10}
http://cdn.scan.onec...s/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1}
http://www.freerealm...msInstaller.cab (Reg Error: Key error.)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC}
https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1}
https://www.battlefi...er_4.0.53.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://l.yimg.com/jh...aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\LoBasso Family\Pictures\11 01 Rose Parade\Rose Parade.jpg
O24 - Desktop BackupWallPaper: C:\Users\LoBasso Family\Pictures\11 01 Rose Parade\Rose Parade.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{76bad080-1033-11de-a064-0021704b527e}\Shell - "" = AutoRun
O33 - MountPoints2\{76bad080-1033-11de-a064-0021704b527e}\Shell\AutoRun\command - "" = K:\LaunchU3.exe
O33 - MountPoints2\{aa28bad6-376f-11e0-b8d9-0021704b527e}\Shell - "" = AutoRun
O33 - MountPoints2\{aa28bad6-376f-11e0-b8d9-0021704b527e}\Shell\AutoRun\command - "" = M:\SISetup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/03/12 18:34:51 | 000,000,000 | ---D | C] -- C:\Users\LoBasso Family\Documents\New Folder
[2011/03/11 22:05:03 | 000,000,000 | ---D | C] -- C:\Users\LoBasso Family\Documents\Call of Juarez - Bound in Blood
[2011/03/10 23:59:11 | 000,000,000 | ---D | C] -- C:\Users\LoBasso Family\Desktop\FMPA_Updater
[2011/03/04 23:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro
[2011/03/04 21:46:22 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\LoBasso Family\Desktop\OTL.exe
[2011/03/02 00:50:14 | 000,000,000 | ---D | C] -- C:\Users\LoBasso Family\AppData\Roaming\CA Solutions Constructability
[2011/02/28 22:45:53 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live Safety Center
[2011/02/25 08:21:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2011/02/25 00:03:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Lexmark 3600-4600 Series
[2011/02/25 00:00:02 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2011/02/19 11:46:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TurboTax 2010
[2011/02/15 12:26:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2011/02/13 10:31:32 | 000,000,000 | -HSD | C] -- C:\Windows\ftpcache
[2011/02/13 10:26:23 | 000,000,000 | ---D | C] -- C:\Users\LoBasso Family\{64972d2e-4bf9-4742-bacf-772f96ac77c8}
[2011/02/13 10:18:31 | 000,017,408 | ---- | C] (Marvell Semiconductor, Inc.) -- C:\Windows\System32\drivers\mvusbews.sys
[2009/09/12 17:15:26 | 000,438,272 | ---- | C] ( ) -- C:\Windows\System32\LXDXhcp.dll
[2009/09/12 17:15:25 | 000,843,776 | ---- | C] ( ) -- C:\Windows\System32\lxdxusb1.dll
[2009/09/12 17:15:25 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxdxinpa.dll
[2009/09/12 17:15:25 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\lxdxiesc.dll
[2009/09/12 17:15:24 | 001,105,920 | ---- | C] ( ) -- C:\Windows\System32\lxdxserv.dll
[2009/09/12 17:15:24 | 000,647,168 | ---- | C] ( ) -- C:\Windows\System32\lxdxpmui.dll
[2009/09/12 17:15:24 | 000,569,344 | ---- | C] ( ) -- C:\Windows\System32\lxdxlmpm.dll
[2009/09/12 17:15:24 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\lxdxprox.dll
[2009/09/12 17:15:23 | 000,320,168 | ---- | C] ( ) -- C:\Windows\System32\lxdxih.exe
[2009/09/12 17:15:22 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\lxdxhbn3.dll
[2009/09/12 17:15:21 | 000,594,600 | ---- | C] ( ) -- C:\Windows\System32\lxdxcoms.exe
[2009/09/12 17:15:20 | 000,851,968 | ---- | C] ( ) -- C:\Windows\System32\lxdxcomc.dll
[2009/09/12 17:15:20 | 000,376,832 | ---- | C] ( ) -- C:\Windows\System32\lxdxcomm.dll
[2009/09/12 17:15:20 | 000,365,224 | ---- | C] ( ) -- C:\Windows\System32\lxdxcfg.exe
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/03/14 21:18:45 | 000,065,556 | ---- | M] () -- C:\Users\LoBasso Family\Desktop\Rootkit Unhooker
[2011/03/14 21:17:19 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/14 21:17:19 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/14 13:39:35 | 000,000,440 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{D4CF394A-5614-4897-A477-F6515673A8B0}.job
[2011/03/10 07:23:45 | 000,650,972 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/03/10 07:23:45 | 000,121,486 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/03/09 06:40:01 | 000,022,328 | ---- | M] () -- C:\Users\LoBasso Family\AppData\Roaming\PnkBstrK.sys
[2011/03/09 06:37:38 | 000,107,832 | ---- | M] () -- C:\Users\LoBasso Family\AppData\Roaming\PnkBstrB.exe
[2011/03/09 06:37:32 | 002,250,024 | ---- | M] () -- C:\Windows\System32\pbsvc.exe
[2011/03/07 17:17:09 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2011/03/07 17:17:03 | 000,000,276 | ---- | M] () -- C:\Windows\tasks\RtlNICDiagVistaStart.job
[2011/03/07 17:16:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/07 17:16:53 | 3220,365,312 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/05 21:50:50 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011/03/04 23:47:10 | 000,016,968 | ---- | M] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2011/03/04 21:46:35 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\LoBasso Family\Desktop\OTL.exe
[2011/03/04 06:16:21 | 000,459,160 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/03/02 00:22:39 | 000,006,836 | ---- | M] () -- C:\Users\LoBasso Family\AppData\Local\d3d9caps.dat
[2011/02/19 11:46:45 | 000,001,880 | ---- | M] () -- C:\Users\Public\Desktop\TurboTax 2010.lnk
[2011/02/19 10:13:23 | 000,104,960 | ---- | M] () -- C:\Users\LoBasso Family\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/15 21:24:50 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_mvusbews_01007.Wdf
[2011/02/15 21:06:01 | 000,000,210 | ---- | M] () -- C:\Users\LoBasso Family\Desktop\HP LaserJet Professional P1102w - Shortcut.lnk
[2011/02/13 09:24:39 | 000,001,889 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/03/14 21:18:45 | 000,065,556 | ---- | C] () -- C:\Users\LoBasso Family\Desktop\Rootkit Unhooker
[2011/03/07 17:16:53 | 3220,365,312 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/04 23:47:10 | 000,016,968 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys
[2011/02/25 08:19:03 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2011/02/25 08:19:03 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2011/02/25 08:19:03 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
[2011/02/19 11:46:45 | 000,001,880 | ---- | C] () -- C:\Users\Public\Desktop\TurboTax 2010.lnk
[2011/02/15 21:24:50 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_mvusbews_01007.Wdf
[2011/02/15 21:06:01 | 000,000,210 | ---- | C] () -- C:\Users\LoBasso Family\Desktop\HP LaserJet Professional P1102w - Shortcut.lnk
[2011/02/13 10:28:00 | 001,511,424 | ---- | C] () -- C:\Windows\System32\HP1100SM.EXE
[2011/02/13 10:28:00 | 000,147,456 | ---- | C] () -- C:\Windows\System32\HP1100LM.DLL
[2011/02/13 10:18:34 | 000,284,160 | ---- | C] () -- C:\Windows\System32\mvhlewsi.DLL
[2011/02/13 10:18:30 | 000,081,920 | ---- | C] () -- C:\Windows\System32\mvusbews.dll
[2011/02/13 10:18:29 | 000,047,104 | ---- | C] () -- C:\Windows\System32\HP1100SMs.dll
[2010/11/30 19:46:09 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2010/10/14 03:03:29 | 000,000,127 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010/10/05 15:16:28 | 000,001,940 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/07/22 07:11:03 | 000,107,832 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Roaming\PnkBstrB.exe
[2010/07/22 07:10:30 | 002,250,024 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010/04/17 11:27:27 | 000,000,120 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Local\Asomuronece.dat
[2010/04/17 11:27:27 | 000,000,000 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Local\Nziji.bin
[2010/04/17 11:25:44 | 000,000,020 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Roaming\kcmdte.dat
[2010/04/17 11:25:38 | 000,000,004 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Roaming\avdrn.dat
[2010/01/16 15:43:27 | 000,107,832 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/01/16 15:43:27 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2009/12/22 21:20:21 | 000,022,328 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Roaming\PnkBstrK.sys
[2009/12/22 21:17:53 | 002,395,944 | ---- | C] () -- C:\Windows\System32\pbsvc_heroes.exe
[2009/09/12 17:21:26 | 000,360,448 | ---- | C] () -- C:\Windows\System32\lxdxcoin.dll
[2009/09/12 17:20:42 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxdxvs.dll
[2009/09/12 17:18:42 | 000,081,920 | ---- | C] () -- C:\Windows\System32\lxdxcaps.dll
[2009/09/12 17:18:42 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxdxcnv4.dll
[2009/09/12 17:18:41 | 000,782,336 | ---- | C] () -- C:\Windows\System32\lxdxdrs.dll
[2009/09/12 17:17:59 | 000,045,056 | ---- | C] () -- C:\Windows\System32\LXF3PMON.DLL
[2009/09/12 17:17:59 | 000,032,768 | ---- | C] () -- C:\Windows\System32\LXF3FXPU.DLL
[2009/09/12 17:17:38 | 000,053,248 | ---- | C] () -- C:\Windows\System32\lxf3oem.dll
[2009/09/12 17:17:38 | 000,012,288 | ---- | C] () -- C:\Windows\System32\LXF3PMRC.DLL
[2009/09/12 17:15:46 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxdxrwrd.ini
[2009/09/12 17:15:26 | 000,348,160 | ---- | C] () -- C:\Windows\System32\LXDXinst.dll
[2009/09/12 17:15:22 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxdxgrd.dll
[2009/08/07 15:33:17 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/07 15:33:17 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/05/02 20:38:36 | 000,044,544 | ---- | C] () -- C:\Windows\System32\gif89.dll
[2009/05/02 20:38:16 | 000,000,343 | ---- | C] () -- C:\Windows\SIERRA.INI
[2009/04/17 03:11:06 | 000,006,836 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Local\d3d9caps.dat
[2009/04/01 11:48:16 | 000,053,478 | ---- | C] () -- C:\Windows\mvtcpui.ini
[2009/03/25 23:20:31 | 000,051,716 | ---- | C] () -- C:\Windows\System32\pdf995mon.dll
[2009/03/25 23:20:31 | 000,000,095 | ---- | C] () -- C:\Windows\wpd99.drv
[2009/03/14 23:23:00 | 000,104,960 | ---- | C] () -- C:\Users\LoBasso Family\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/14 23:03:05 | 000,152,253 | ---- | C] () -- C:\Windows\UnPHI4.exe
[2009/03/14 23:03:05 | 000,109,056 | ---- | C] () -- C:\Windows\UnPHI4B.exe
[2009/03/14 23:03:05 | 000,000,057 | ---- | C] () -- C:\Windows\phi4.ini
[2009/03/14 17:58:41 | 000,077,824 | ---- | C] () -- C:\Windows\System32\HPZIDS01.dll
[2009/03/13 18:46:03 | 000,000,168 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2009/03/03 19:58:17 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2009/03/03 19:58:17 | 000,176,214 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2009/03/03 19:58:17 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009/03/03 19:58:17 | 000,090,112 | ---- | C] () -- C:\Windows\System32\atibrtmon.exe
[2009/03/03 19:58:17 | 000,081,920 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2009/03/03 19:58:17 | 000,040,960 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2009/03/03 19:54:49 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/03/03 12:03:55 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,459,160 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,650,972 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,121,486 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ========== [2009/04/08 08:55:55 | 000,000,000 | -HSD | M] -- C:\Users\LoBasso Family\AppData\Roaming\.#
[2010/08/30 15:18:12 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\AnVi
[2009/04/05 08:04:27 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Autodesk
[2010/10/13 21:25:31 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Azmaz
[2010/07/25 08:09:06 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Bioshock
[2009/04/14 22:45:07 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\CA Solution For IBI
[2011/03/02 00:50:14 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\CA Solutions Constructability
[2010/08/07 18:33:41 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\CA Solutions IBI
[2009/08/23 11:09:57 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\FileMaker
[2009/07/12 10:46:49 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\FileMaker Pro Advanced
[2010/10/14 03:23:08 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Hosobe
[2009/03/13 19:09:00 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Leadertech
[2011/01/28 20:17:31 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Leawo
[2009/11/27 09:31:30 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Lexmark Productivity Studio
[2010/09/07 19:31:32 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Mount&Blade
[2010/09/09 07:55:44 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Mount&Blade Warband
[2011/01/28 20:17:31 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Moyea
[2009/03/25 23:21:15 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\pdf995
[2009/10/16 15:19:01 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\PlayFirst
[2009/12/26 07:54:31 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Ubisoft
[2009/03/23 14:11:37 | 000,000,000 | ---D | M] -- C:\Users\LoBasso Family\AppData\Roaming\Windows Live Writer
[2011/03/07 17:17:03 | 000,000,276 | ---- | M] () -- C:\Windows\Tasks\RtlNICDiagVistaStart.job
[2011/03/05 21:50:58 | 000,032,602 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/03/14 13:39:35 | 000,000,440 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{D4CF394A-5614-4897-A477-F6515673A8B0}.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5D432CE3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:9AB338B9
< End of report >