I appear to be the latest victim of these Google redirect issues. Initially I was going to try a system restore but alas, the oldest restore point available was right around the time the issues with redirection started, so I'm going to assume that whatever I have, deleted all my restore points. I've run some virus scans with AVG and McAfee as well as Malwarebytes' Anti-malware. I also tried Hitman Pro 3.5 and that got rid of a lot of nasty stuff hiding in my system too, but the problem still persisted. Rather than attempting to dig around in my computer to try and figure it out myself, I figured I would leave it to the experts. I was typically only getting redirected when using the Google toolbar, and after the virus scans and whatnot I cleared out some junk and the toolbar doesn't seem to redirect me anymore. However, when on the Google homepage and I click one of the links for search results, it either delays and something like "http://cioreasearch.com/" followed by my search topic appears, or I will be directed to a completely unrelated webpage entirely. I'm currently running Windows Vista and my browser is Firefox 4.0.1. Any help with this would be hugely appreciated! Thanks in advance. =)
Here's the OTL log.
OTL logfile created on: 17/05/2011 10:23:04 AM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Christina\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.98 Gb Total Space | 202.52 Gb Free Space | 70.82% Space Free | Partition Type: NTFS
Drive D: | 12.11 Gb Total Space | 1.94 Gb Free Space | 16.02% Space Free | Partition Type: NTFS
Computer Name: CHRISTINA-PC | User Name: Christina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/17 10:07:42 | 000,515,584 | -HS- | M] () -- c:\Windows\spwizuiwow.exe
PRC - [2011/05/16 17:11:29 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Christina\Desktop\OTL.exe
PRC - [2011/05/16 13:21:25 | 001,392,640 | ---- | M] () -- C:\Windows\SysWOW64\XpsGdiConverter32.exe
PRC - [2011/05/16 13:21:25 | 001,392,640 | ---- | M] () -- C:\ProgramData\lsmproxy32.exe
PRC - [2011/05/11 00:07:33 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010/10/02 22:33:19 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/08/25 21:07:00 | 000,066,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2010/06/01 16:50:00 | 000,185,664 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
PRC - [2010/06/01 16:50:00 | 000,140,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
PRC - [2010/06/01 16:50:00 | 000,120,128 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
PRC - [2010/06/01 16:50:00 | 000,075,072 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\McTray.exe
PRC - [2010/01/15 09:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008/10/06 13:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files (x86)\SMINST\BLService.exe
========== Modules (SafeList) ==========
MOD - [2011/05/16 17:11:29 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Christina\Desktop\OTL.exe
MOD - [2011/04/08 16:56:28 | 000,018,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/08/31 12:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2010/08/25 21:07:00 | 000,077,968 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2009/07/14 01:34:04 | 000,946,688 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\iked.exe -- (iked)
SRV:64bit: - [2009/07/12 19:55:02 | 000,050,688 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\dtpd.exe -- (dtpd)
SRV:64bit: - [2009/07/12 19:51:08 | 000,690,688 | ---- | M] () [Auto | Running] -- C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe -- (ipsecd)
SRV:64bit: - [2008/01/20 23:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2007/10/17 20:37:22 | 000,412,672 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2011/05/16 13:21:25 | 001,392,640 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\XpsGdiConverter32.exe -- (McAfee SiteAdvisor Service32)
SRV - [2011/02/16 15:49:08 | 000,101,048 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe -- (McAfee SiteAdvisor Service)
SRV - [2010/08/25 21:07:00 | 000,181,480 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe -- (McShield)
SRV - [2010/08/25 21:07:00 | 000,066,880 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
SRV - [2010/08/25 21:07:00 | 000,020,792 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe -- (McAfeeEngineService)
SRV - [2010/06/01 16:50:00 | 000,120,128 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 09:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/03/30 01:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/10/06 13:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\SMINST\BLService.exe -- (Recovery Service for Windows)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/05/17 10:07:26 | 000,020,040 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hitmanpro35.sys -- (hitmanpro35)
DRV:64bit: - [2011/02/18 17:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/08/25 21:07:00 | 000,470,808 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2010/08/25 21:07:00 | 000,120,224 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2010/08/25 21:07:00 | 000,098,088 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2010/08/25 21:07:00 | 000,084,424 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfetdik.sys -- (mfetdik)
DRV:64bit: - [2010/08/25 21:07:00 | 000,078,768 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:64bit: - [2010/08/25 20:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/09/30 21:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/04/29 07:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV:64bit: - [2009/01/16 04:58:26 | 000,020,480 | ---- | M] (Shrew Soft Inc) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\vfilter.sys -- (vflt)
DRV:64bit: - [2008/12/20 04:03:08 | 001,344,000 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\athrx.sys -- (athr)
DRV:64bit: - [2008/12/11 00:52:00 | 000,012,800 | ---- | M] (Shrew Soft Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\virtualnet.sys -- (vnet)
DRV:64bit: - [2008/09/19 21:43:58 | 000,068,096 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTSTOR64.SYS -- (RTSTOR)
DRV:64bit: - [2008/06/29 11:52:44 | 000,126,976 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel®
DRV:64bit: - [2008/06/10 16:58:48 | 000,170,496 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:64bit: - [2008/06/05 13:59:50 | 000,264,704 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2008/04/17 15:05:20 | 000,324,656 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP)
DRV:64bit: - [2008/01/20 23:46:57 | 003,154,432 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NETw3v64.sys -- (NETw3v64) Intel®
DRV:64bit: - [2008/01/20 23:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\sdbus.sys -- (sdbus)
DRV:64bit: - [2007/10/31 23:22:50 | 001,481,216 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_DPV.sys -- (HSF_DPV)
DRV:64bit: - [2007/10/31 23:19:46 | 000,293,376 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys -- (CAXHWAZL)
DRV:64bit: - [2007/10/31 23:18:32 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys -- (winachsf)
DRV:64bit: - [2007/10/17 20:37:10 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.sys -- (XAudio)
DRV:64bit: - [2006/10/03 22:45:36 | 000,273,408 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\yk60x64.sys -- (yukonx64)
DRV:64bit: - [2006/09/18 18:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\Wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2006/06/18 19:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 1D C2 4F 13 BF 58 25 4D 97 63 1C DA BA 83 FC FB [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.youtube.com/"
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/05/04 12:52:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/16 14:59:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/16 14:59:11 | 000,000,000 | ---D | M]
[2009/10/18 14:51:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christina\AppData\Roaming\Mozilla\Extensions
[2009/10/18 14:51:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christina\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/05/16 16:33:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\qfcs0rwo.default\extensions
[2009/10/20 21:46:53 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\qfcs0rwo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/16 14:40:29 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\qfcs0rwo.default\extensions\[email protected]
[2011/05/16 14:40:33 | 000,002,568 | ---- | M] () -- C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\qfcs0rwo.default\searchplugins\askcom.xml
[2009/12/02 19:34:14 | 000,001,504 | ---- | M] () -- C:\Users\Christina\AppData\Roaming\Mozilla\Firefox\Profiles\qfcs0rwo.default\searchplugins\givoogle.xml
[2011/02/21 19:05:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/25 18:00:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/13 14:50:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/15 11:10:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/21 19:05:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) --
[2011/05/04 12:52:15 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2011/05/11 00:07:32 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/08/25 21:07:00 | 000,023,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\components\Scriptff.dll
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/12/17 14:16:14 | 000,065,536 | ---- | M] ( ) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npkimi.dll
[2011/05/11 00:07:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/05/16 16:22:33 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\scriptsn.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {0A2918EA-E5B7-48D8-BE6B-DA45A839FFC8} - File not found
O2 - BHO: (no name) - {134FC21D-58BF-4D25-9763-1CDABA83FCFb} - File not found
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [fdwnetwow.exe] File not found
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Plugin Install] C:\Program Files (x86)\QuickTime\Plugins\DeleteMe1.exe ()
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [spwizuiwow.exe] c:\Windows\spwizuiwow.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [EA Core] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\ProgramData\AuthFWGP32.dll) - C:\ProgramData\AuthFWGP32.dll (Borland Software Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Christina\Pictures\pink_skull_myspace_background_by_Rose_Coloured_Bullet2.jpg
O24 - Desktop BackupWallPaper: C:\Users\Christina\Pictures\pink_skull_myspace_background_by_Rose_Coloured_Bullet2.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/17 10:08:58 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{30E45C4A-B430-418E-8827-F33A4CB165E3}
[2011/05/17 10:07:38 | 000,246,272 | ---- | C] (Borland Software Corporation) -- C:\ProgramData\AuthFWGP32.dll
[2011/05/16 17:11:22 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Christina\Desktop\OTL.exe
[2011/05/16 16:22:32 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/05/16 16:20:21 | 000,519,680 | ---- | C] (OldTimer Tools) -- C:\Users\Christina\Desktop\OTM.exe
[2011/05/16 15:59:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hitman Pro 3.5
[2011/05/16 15:59:24 | 000,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3.5
[2011/05/16 15:58:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro
[2011/05/16 14:10:01 | 000,000,000 | ---D | C] -- C:\Users\Christina\FrostWire
[2011/05/16 14:09:48 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire
[2011/05/16 14:09:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2011/05/16 14:04:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QT Lite
[2011/05/16 13:34:46 | 000,000,000 | ---D | C] -- C:\ProgramData\1828992860
[2011/05/16 13:31:45 | 000,000,000 | -HSD | C] -- C:\ProgramData\SysWoW32
[2011/05/16 13:31:29 | 000,000,000 | ---D | C] -- C:\ProgramData\1083295140
[2011/05/16 13:31:21 | 000,000,000 | -HSD | C] -- C:\ProgramData\83939D568CCE9C15649BC4F6BE0A257C
[2011/05/16 12:15:22 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{9FBF96BA-C401-492D-A18A-E4C56BD9CFAF}
[2011/05/14 22:11:09 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{2C735B74-8C4C-4E75-A9E2-8A8629062F33}
[2011/05/14 14:55:05 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{9599D92E-FFD2-46E1-9BE0-FEE2A45A3A3B}
[2011/05/13 10:40:48 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{F8D100F2-DC91-41ED-B486-7B935135CBA6}
[2011/05/11 14:37:25 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{180B7BB8-BF97-46F3-AD70-6C85FF71126B}
[2011/05/10 22:49:13 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{D286990B-8271-484D-B875-F55B1A156785}
[2011/05/09 17:58:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/09 17:56:55 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/09 17:56:47 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/09 17:56:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/05/09 17:52:36 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/09 17:52:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011/05/09 17:41:02 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{9913BD52-59EE-44DF-84C3-C42C5FE755B3}
[2011/05/08 22:44:45 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{DE47E771-87AF-4EB6-A30F-BA0C1D9EF793}
[2011/05/06 23:31:37 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{3EEF195A-83E2-4B7C-BACE-CAF4090ED84C}
[2011/05/06 10:25:34 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{27C59F21-CAB5-4105-AAFF-3139566977AA}
[2011/05/04 12:48:11 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{541255FE-8CF7-412E-A4A4-E32C493DFE0F}
[2011/05/02 09:26:06 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{842B12F1-FE49-484F-B9E3-E07AF8F93AAF}
[2011/04/29 07:37:38 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{E12E258A-40CE-47D1-894B-AE1839529C58}
[2011/04/28 18:02:17 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{963D5186-A9AE-44FC-9A76-21B46C80BF0D}
[2011/04/27 22:51:55 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{5215ED02-366D-444B-A600-765A084FFE31}
[2011/04/25 23:44:48 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{085542B9-EB96-4DFC-845A-FDF8195498C2}
[2011/04/25 10:37:26 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{3A812827-06B8-45AD-B0F1-EAD58C56CD59}
[2011/04/24 22:00:09 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{AC4D544F-6AEB-4F25-B918-E5B850938DD4}
[2011/04/24 09:59:23 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{84566CFE-ADA1-449E-95AE-ABC551400163}
[2011/04/22 20:31:34 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{255EC262-3888-4F58-9599-94FD20B12067}
[2011/04/21 12:10:08 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{DE3CDB47-3B5F-4987-BB34-78E0AE693FBC}
[2011/04/20 23:12:30 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{7427F4D6-E9EE-49A6-B9E0-FEAB05559B8A}
[2011/04/19 13:34:37 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{7951C64E-B326-4B7A-9536-D02B1903332B}
[2011/04/18 23:43:16 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{0956A725-9EAD-4A4C-B9EA-F641BAE43293}
[2011/04/17 23:15:45 | 000,000,000 | ---D | C] -- C:\Users\Christina\AppData\Local\{EA4E536F-CBC4-4E79-A563-A78DB2B0843C}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/17 10:16:58 | 000,000,037 | ---- | M] () -- C:\ProgramData\2223a5c4
[2011/05/17 10:08:38 | 000,000,290 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2011/05/17 10:07:43 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/17 10:07:42 | 000,515,584 | -HS- | M] () -- C:\Windows\spwizuiwow.exe
[2011/05/17 10:07:42 | 000,003,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/17 10:07:38 | 000,246,272 | ---- | M] (Borland Software Corporation) -- C:\ProgramData\AuthFWGP32.dll
[2011/05/17 10:07:38 | 000,000,106 | ---- | M] () -- C:\Windows\SysWow64\135116212
[2011/05/17 10:07:26 | 000,020,040 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/05/17 10:07:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/17 10:07:19 | 4193,456,128 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/16 17:18:47 | 000,000,350 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2011/05/16 17:11:29 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Christina\Desktop\OTL.exe
[2011/05/16 16:20:31 | 000,519,680 | ---- | M] (OldTimer Tools) -- C:\Users\Christina\Desktop\OTM.exe
[2011/05/16 16:11:10 | 000,001,185 | ---- | M] () -- C:\ProgramData\47831487
[2011/05/16 14:58:59 | 000,001,756 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/16 14:50:56 | 000,000,144 | -HS- | M] () -- C:\ProgramData\586412691
[2011/05/16 13:31:45 | 000,000,141 | ---- | M] () -- C:\ProgramData\sl1125277697
[2011/05/16 13:31:29 | 000,203,776 | -HS- | M] () -- C:\ProgramData\unrar.exe
[2011/05/16 13:31:07 | 000,209,408 | ---- | M] () -- C:\Windows\SysWow64\lsmproxy32.exe
[2011/05/16 13:21:25 | 001,392,640 | ---- | M] () -- C:\Windows\SysWow64\XpsGdiConverter32.exe
[2011/05/16 13:21:25 | 001,392,640 | ---- | M] () -- C:\ProgramData\lsmproxy32.exe
[2011/05/09 17:58:37 | 000,001,694 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/09 00:19:05 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForChristina.job
[2011/05/06 13:42:20 | 000,015,872 | ---- | M] () -- C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/24 10:02:01 | 000,001,917 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/17 10:07:56 | 000,515,584 | -HS- | C] () -- C:\Windows\spwizuiwow.exe
[2011/05/16 16:12:04 | 000,000,350 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2011/05/16 15:59:25 | 000,020,040 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/05/16 14:05:59 | 000,001,756 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/16 13:59:10 | 000,000,037 | ---- | C] () -- C:\ProgramData\2223a5c4
[2011/05/16 13:31:45 | 000,001,185 | ---- | C] () -- C:\ProgramData\47831487
[2011/05/16 13:31:45 | 000,000,141 | ---- | C] () -- C:\ProgramData\sl1125277697
[2011/05/16 13:31:29 | 000,203,776 | -HS- | C] () -- C:\ProgramData\unrar.exe
[2011/05/16 13:31:29 | 000,000,144 | -HS- | C] () -- C:\ProgramData\586412691
[2011/05/16 13:31:10 | 001,392,640 | ---- | C] () -- C:\ProgramData\lsmproxy32.exe
[2011/05/16 13:31:07 | 001,392,640 | ---- | C] () -- C:\Windows\SysWow64\XpsGdiConverter32.exe
[2011/05/16 13:31:07 | 000,209,408 | ---- | C] () -- C:\Windows\SysWow64\lsmproxy32.exe
[2011/05/16 13:31:07 | 000,000,106 | ---- | C] () -- C:\Windows\SysWow64\135116212
[2011/05/11 00:07:48 | 000,000,900 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/09 17:58:37 | 000,001,694 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/08/25 20:34:30 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 20:34:30 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 20:34:30 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2010/08/25 19:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/08/25 19:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/07/27 11:47:17 | 000,819,200 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010/07/27 11:47:16 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/12/16 19:21:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/12/03 13:03:16 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/12/03 13:02:40 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/12/03 13:02:11 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/20 11:49:12 | 000,015,872 | ---- | C] () -- C:\Users\Christina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/12 23:31:08 | 000,001,272 | ---- | C] () -- C:\Users\Christina\AppData\Roaming\wklnhst.dat
[2009/10/26 14:12:31 | 000,005,972 | ---- | C] () -- C:\Users\Christina\AppData\Local\d3d9caps.dat
[2009/10/19 23:28:05 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2009/09/10 05:27:12 | 000,000,290 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2009/04/23 20:23:57 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/07/06 17:20:48 | 000,147,172 | ---- | C] () -- C:\Windows\SysWow64\igfcg550.bin
[2008/01/20 23:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 12:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 09:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 09:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 09:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 06:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[1999/01/22 15:46:58 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\MSRTEDIT.DLL
========== LOP Check ==========
[2010/09/05 01:53:06 | 000,000,000 | ---D | M] -- C:\Users\Christina\AppData\Roaming\BitTorrent
[2010/11/19 02:10:35 | 000,000,000 | ---D | M] -- C:\Users\Christina\AppData\Roaming\Dev-Cpp
[2011/05/16 14:38:00 | 000,000,000 | ---D | M] -- C:\Users\Christina\AppData\Roaming\FrostWire
[2010/10/18 19:34:07 | 000,000,000 | ---D | M] -- C:\Users\Christina\AppData\Roaming\OpenOffice.org
[2009/11/12 23:31:20 | 000,000,000 | ---D | M] -- C:\Users\Christina\AppData\Roaming\Template
[2011/05/16 17:50:28 | 000,032,604 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >