Here are the anwMBR and OTL scan logs (OTL log is the scan with what you told me to paste into the custom scan/fixes box)
OTL logfile created on: 6/2/2011 8:31:24 PM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Nutrition City\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.37 Mb Total Physical Memory | 668.46 Mb Available Physical Memory | 65.83% Memory free
2.39 Gb Paging File | 2.21 Gb Available in Paging File | 92.69% Paging File free
Paging file location(s): C:\pagefile.sys 1522 1522 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 50.60 Gb Total Space | 22.83 Gb Free Space | 45.12% Space Free | Partition Type: NTFS
Computer Name: NUTRITIONCITY | User Name: Admin | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/05/26 17:48:25 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nutrition City\My Documents\Downloads\OTL.exe
PRC - [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ========== MOD - [2011/05/26 17:48:25 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Nutrition City\My Documents\Downloads\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/12/20 18:08:58 | 000,363,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/12/09 07:08:10 | 000,305,600 | ---- | M] () [Auto | Stopped] -- C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe -- (Cleaner_Validator)
SRV - [2010/10/08 13:42:07 | 000,435,008 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2010/08/27 14:59:38 | 001,051,968 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/08/27 14:56:30 | 000,030,016 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2009/02/27 08:54:22 | 000,870,672 | ---- | M] (Intel® Corporation) [Auto | Stopped] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2009/02/27 07:55:20 | 000,909,312 | ---- | M] (Intel® Corporation) [Auto | Stopped] -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2009/02/27 07:38:38 | 000,473,360 | ---- | M] (Intel® Corporation) [Auto | Stopped] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2008/11/06 14:57:32 | 000,382,320 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2008/08/13 18:32:40 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/04/13 19:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2008/04/13 19:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (SMTPSVC) Simple Mail Transfer Protocol (SMTP)
SRV - [2008/04/13 19:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2008/01/08 12:02:16 | 001,213,728 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe -- (sprtlisten)
SRV - [2007/03/07 15:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)
SRV - [2005/05/19 15:48:34 | 000,053,248 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\LxrSII1s.exe -- (LxrSII1s)
SRV - [2004/09/29 13:14:36 | 000,069,632 | ---- | M] (HP) [Auto | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2004/06/23 15:04:38 | 000,077,824 | ---- | M] (SEIKO EPSON Corp.) [Auto | Stopped] -- C:\WINDOWS\System32\EpStsSrv.exe -- (EPSON ESCPOS Status Service)
SRV - [2002/01/30 08:33:14 | 000,077,824 | ---- | M] () [Auto | Stopped] -- C:\Program Files\EPSON\ESM2\eEBSvc.exe -- (EpsonBidirectionalService)
========== Driver Services (SafeList) ========== DRV - [2011/05/29 21:57:30 | 000,011,496 | ---- | M] (UVNC BVBA) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mv2.sys -- (mv2)
DRV - [2011/04/01 17:07:59 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/04/01 17:07:59 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/03/24 15:36:20 | 000,353,096 | ---- | M] (BitDefender) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bdfsfltr.sys -- (bdfsfltr)
DRV - [2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/12/09 07:15:18 | 000,033,232 | ---- | M] (Windows ® Win 7 DDK provider) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\CFRPD.sys -- (CFRPD)
DRV - [2010/12/09 07:14:56 | 000,066,584 | ---- | M] (Windows ® Win 7 DDK provider) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\CFRMD.sys -- (CFRMD)
DRV - [2010/08/12 00:11:27 | 000,177,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\XRNBO.sys -- (XRNBO)
DRV - [2010/06/17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 15:27:12 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Stopped] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010/02/24 14:41:50 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010/02/11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009/12/30 11:20:56 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/06/25 16:58:10 | 000,048,128 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2009/06/25 16:25:58 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2009/06/25 16:10:48 | 000,044,544 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2008/08/13 18:23:56 | 000,011,904 | ---- | M] (Intel Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2008/04/13 13:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/01/07 15:36:16 | 002,216,064 | R--- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2007/07/01 16:52:20 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2007/05/10 11:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007/02/25 12:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)
DRV - [2005/11/01 02:30:00 | 000,054,784 | ---- | M] (SEIKO EPSON CORPORATION) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\EpsCe.sys -- (EpsCe)
DRV - [2005/09/08 06:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/09/08 06:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/09/08 06:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/09/08 06:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/09/08 06:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/09/08 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/09/08 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/08/25 13:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/08/25 13:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/08/12 18:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/08/05 04:32:16 | 000,045,312 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 04:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 04:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 04:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/07/14 13:14:34 | 000,027,904 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\risdptsk.sys -- (risdptsk)
DRV - [2005/05/19 15:48:24 | 000,070,016 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\LxrSII1d.sys -- (LxrSII1d)
DRV - [2004/10/07 20:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/09/20 13:44:48 | 000,005,652 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bvrp_pci.sys -- (bvrp_pci)
DRV - [2004/08/04 06:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2004/08/04 06:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2004/07/14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2004/05/11 19:11:02 | 000,099,968 | ---- | M] (Aladdin Knowledge Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb)
DRV - [2004/04/28 10:03:08 | 000,328,448 | ---- | M] (Aladdin Knowledge Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp)
DRV - [2003/07/23 16:57:51 | 000,073,728 | ---- | M] (Rainbow Technologies, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\Drivers\SENTINEL.SYS -- (Sentinel)
DRV - [2003/07/23 16:57:41 | 000,020,032 | ---- | M] (Rainbow Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SNTNLUSB.SYS -- (SNTNLUSB)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.co...-inc&channel=usIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co...-inc&channel=usIE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.co...-inc&channel=usIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co...-inc&channel=usIE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell.comIE - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.co...html?channel=usIE - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.netIE - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/19 18:46:48 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/19 20:14:29 | 000,000,000 | ---D | M]
[2008/10/05 17:09:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Application Data\Mozilla\Extensions
[2011/06/02 19:18:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\9dr71bp0.default\extensions
[2011/06/02 19:18:08 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\9dr71bp0.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/05/19 18:46:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/05/19 00:00:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/05/19 00:00:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions(2)
[2011/04/30 13:01:54 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions(2)\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
File not found (No name found) --
[2011/04/14 11:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2007/12/19 07:57:38 | 000,310,272 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
[2008/05/06 16:25:10 | 000,159,744 | ---- | M] (CNN) -- C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/05/26 19:06:17 | 000,000,021 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - No CLSID value found.
O3 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickCare] C:\Program Files\Qwest\Quickcare\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011..\RunOnce: [scan_after_setup] c:\program files\avira\antivir desktop\avcenter.exe (Avira GmbH)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1275088399-1222994124-422907164-1011\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {33704B0F-9EB7-434B-B752-EA6CFFB87423}
http://ncmpls.viewne...00/JpegInst.cab (pmjpegaudio Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.mi...b?1203400379750 (MUWebControl Class)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EAEFAD15-8753-45EF-94B0-1BAA7970CC21}
http://ncmpls.viewne...om/MpegInst.cab (pmpeg4cam Class)
O16 - DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B}
http://192.168.0.253/JpegInst.cab (pmjpegcam Class)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{2b520081-933f-11dd-9329-0014229ff624}\Shell - "" = AutoRun
O33 - MountPoints2\{2b520081-933f-11dd-9329-0014229ff624}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2b520081-933f-11dd-9329-0014229ff624}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{3197c4fe-94a8-11dc-92db-0014229ff624}\Shell - "" = AutoRun
O33 - MountPoints2\{3197c4fe-94a8-11dc-92db-0014229ff624}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3197c4fe-94a8-11dc-92db-0014229ff624}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{46faac96-328d-11dd-930e-0014229ff624}\Shell\AutoRun\command - "" = E:\setupSNK.exe
O33 - MountPoints2\{b9e977c3-6a38-11dd-9319-0014229ff624}\Shell - "" = AutoRun
O33 - MountPoints2\{b9e977c3-6a38-11dd-9319-0014229ff624}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9e977c3-6a38-11dd-9319-0014229ff624}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (defrag_native) - C:\WINDOWS\System32\defrag_native.exe (UltraDefrag Development Team)
O34 - HKLM BootExecute: (ecute settings...) - File not found
O34 - HKLM BootExecute: (ountPoints2\E\) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ========== [2011/05/29 21:52:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\Avira
[2011/05/29 21:19:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/05/29 21:19:28 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/05/29 21:19:24 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/05/29 21:19:24 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/05/29 21:19:24 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/05/29 21:19:24 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/05/29 21:19:23 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/05/29 21:19:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2011/05/29 21:02:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\My Documents\Downloads
[2011/05/29 21:00:57 | 001,431,344 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Admin\Desktop\TDSSKiller.exe
[2011/05/29 21:00:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\WinRAR
[2011/05/29 20:53:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\BitDefender
[2011/05/29 20:52:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Application Data\Malwarebytes
[2011/05/29 20:22:49 | 000,000,000 | ---D | C] -- C:\RyanZip
[2011/05/28 14:48:30 | 000,190,032 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/28 11:37:24 | 000,021,480 | ---- | C] (UVNC BVBA) -- C:\WINDOWS\System32\mv2.dll
[2011/05/28 11:37:24 | 000,011,496 | ---- | C] (UVNC BVBA) -- C:\WINDOWS\System32\drivers\mv2.sys
[2011/05/27 19:09:19 | 000,149,520 | ---- | C] (BitDefender S.R.L. Bucharest, ROMANIA) -- C:\WINDOWS\System32\drivers\bdfm.sys
[2011/05/27 19:04:11 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender
[2011/05/27 18:49:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender
[2011/05/27 18:49:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2011/05/27 18:45:18 | 000,308,296 | ---- | C] (BitDefender S.R.L.) -- C:\WINDOWS\System32\drivers\Trufos.sys
[2011/05/27 18:45:10 | 000,012,960 | ---- | C] (BITDEFENDER LLC) -- C:\WINDOWS\System32\drivers\bdrawpr.sys
[2011/05/27 16:02:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\COMODO
[2011/05/27 16:02:25 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2011/05/26 15:24:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/26 15:24:54 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/26 15:24:49 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/19 21:38:01 | 000,114,688 | ---- | C] (RICOH) -- C:\WINDOWS\System32\RicohMediadriverVer.dll
[2011/05/19 15:27:16 | 000,027,064 | ---- | C] (VS Revo Group) -- C:\WINDOWS\System32\drivers\revoflt.sys
[2011/05/19 15:27:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro
[2011/05/19 15:27:08 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2011/05/19 03:05:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Best Uninstall Tool
[2011/05/19 03:05:36 | 000,000,000 | ---D | C] -- C:\Program Files\Best Uninstall Tool
[2011/05/19 00:21:48 | 000,000,000 | ---D | C] -- C:\Program Files\ScottradeELITE
[2011/05/18 23:52:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Cache
[2011/05/18 23:52:42 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/05/17 16:03:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2011/05/14 18:43:12 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/05/07 13:27:27 | 000,000,000 | -HSD | C] -- C:\RECYCLER(2)
[2011/05/07 13:26:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client(2)
[2011/05/07 12:52:46 | 000,000,000 | ---D | C] -- C:\cmdcons
[2011/05/07 12:47:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/06/02 20:28:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/06/02 20:26:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/06/02 19:38:57 | 000,000,330 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2011/06/02 19:33:48 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/06/02 19:31:16 | 000,074,768 | ---- | M] () -- C:\WINDOWS\cscmondump.bin
[2011/06/02 19:31:08 | 000,887,512 | ---- | M] () -- C:\WINDOWS\CSC_ServiceDump.dat
[2011/06/02 19:31:08 | 000,090,116 | ---- | M] () -- C:\WINDOWS\CSC_ActiveCleanLog.dat
[2011/06/02 19:27:53 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/06/02 19:27:12 | 000,000,098 | ---- | M] () -- C:\fraglist.luar
[2011/06/02 16:03:59 | 000,000,468 | ---- | M] () -- C:\WINDOWS\tasks\COMODO Updater.job
[2011/06/02 10:28:07 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\null
[2011/05/29 21:57:30 | 000,021,480 | ---- | M] (UVNC BVBA) -- C:\WINDOWS\System32\mv2.dll
[2011/05/29 21:57:30 | 000,011,496 | ---- | M] (UVNC BVBA) -- C:\WINDOWS\System32\drivers\mv2.sys
[2011/05/29 21:19:41 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2011/05/29 21:02:30 | 000,073,957 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\bdinstall.bin
[2011/05/28 15:09:26 | 000,011,264 | ---- | M] () -- C:\WINDOWS\DCEBoot.exe
[2011/05/28 15:03:36 | 000,190,032 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/28 11:00:35 | 000,000,436 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/05/28 10:36:53 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/05/27 19:24:05 | 000,000,415 | ---- | M] () -- C:\WINDOWS\System32\user_gensett.xml
[2011/05/27 16:19:07 | 000,002,619 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/05/27 16:19:07 | 000,001,792 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2011/05/27 16:19:07 | 000,000,002 | RHS- | M] () -- C:\WINDOWS\winstart.bat
[2011/05/27 16:02:55 | 000,000,835 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\COMODO System-Cleaner.lnk
[2011/05/26 19:06:17 | 000,000,021 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/05/26 15:24:55 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/25 07:10:16 | 001,431,344 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Admin\Desktop\TDSSKiller.exe
[2011/05/21 18:26:33 | 000,012,080 | ---- | M] () -- C:\WINDOWS\System32\drivers\D7B90406.bin
[2011/05/19 21:15:43 | 001,160,120 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/19 21:07:38 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/05/19 19:19:54 | 000,002,285 | ---- | M] () -- C:\WINDOWS\System32\LexFiles.ulf
[2011/05/19 18:46:51 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/05/19 15:27:22 | 000,000,925 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/05/19 03:05:53 | 000,000,042 | ---- | M] () -- C:\WINDOWS\System32\AK083E209605E394C.lie
[2011/05/19 01:28:04 | 000,664,358 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/19 01:28:04 | 000,143,252 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/19 01:00:05 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/05/19 00:50:56 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/06/02 19:27:12 | 000,000,098 | ---- | C] () -- C:\fraglist.luar
[2011/05/29 21:19:41 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2011/05/28 15:09:26 | 000,011,264 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2011/05/27 19:24:05 | 000,000,415 | ---- | C] () -- C:\WINDOWS\System32\user_gensett.xml
[2011/05/27 18:45:00 | 000,073,957 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bdinstall.bin
[2011/05/27 16:21:27 | 000,074,768 | ---- | C] () -- C:\WINDOWS\cscmondump.bin
[2011/05/27 16:21:17 | 000,887,512 | ---- | C] () -- C:\WINDOWS\CSC_ServiceDump.dat
[2011/05/27 16:21:17 | 000,090,116 | ---- | C] () -- C:\WINDOWS\CSC_ActiveCleanLog.dat
[2011/05/27 16:19:07 | 000,000,002 | RHS- | C] () -- C:\WINDOWS\winstart.bat
[2011/05/27 16:03:03 | 000,000,468 | ---- | C] () -- C:\WINDOWS\tasks\COMODO Updater.job
[2011/05/27 16:02:55 | 000,000,835 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\COMODO System-Cleaner.lnk
[2011/05/26 15:24:55 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/19 21:01:19 | 000,225,262 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msimain.sdb
[2011/05/19 19:17:41 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/05/19 18:46:51 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/19 15:27:22 | 000,000,925 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Revo Uninstaller Pro.lnk
[2011/05/19 03:05:53 | 000,000,042 | ---- | C] () -- C:\WINDOWS\System32\AK083E209605E394C.lie
[2011/05/07 12:52:54 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011/05/07 12:52:51 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/09/24 02:49:00 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\lua5.1a_gui.exe
[2010/09/24 02:49:00 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\lua5.1a.exe
[2010/09/24 02:48:58 | 000,092,160 | ---- | C] () -- C:\WINDOWS\System32\lua5.1a.dll
[2010/08/12 00:11:58 | 000,012,080 | ---- | C] () -- C:\WINDOWS\System32\drivers\D7B90406.bin
[2010/08/12 00:11:26 | 000,177,152 | ---- | C] () -- C:\WINDOWS\System32\drivers\XRNBO.sys
[2010/07/08 10:37:14 | 000,101,544 | ---- | C] () -- C:\Program Files\Common Files\LinkInstaller.exe
[2010/05/11 13:02:03 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\PT27F.DLL
[2010/05/11 13:02:03 | 000,000,972 | ---- | C] () -- C:\WINDOWS\System32\PT27L.INI
[2010/01/26 15:26:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\counter.cfg
[2009/09/28 15:24:17 | 000,001,387 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2008/10/05 17:11:22 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\mp4spvd.dll
[2008/10/05 16:27:19 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Admin\Local Settings\Application Data\fusioncache.dat
[2008/08/27 11:14:13 | 000,102,006 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2008/08/27 11:14:13 | 000,017,218 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2008/05/26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/12/26 11:49:40 | 000,001,138 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2007/11/26 06:32:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\STMMain.INI
[2007/11/26 06:28:58 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\EEBAPI.dll
[2007/11/26 06:28:58 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\EEBDSCVR.dll
[2007/11/26 06:28:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\EBAPI.dll
[2007/11/26 06:28:58 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT.DAT
[2007/11/17 13:19:30 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\EpsStmEW.DLL
[2007/11/17 13:19:30 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\SharpImg.dll
[2007/10/02 10:08:30 | 000,070,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\LxrSII1d.sys
[2007/10/02 10:08:30 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\LxrSII1s.exe
[2007/10/02 10:08:29 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\LxrUnplug.exe
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/07/01 16:52:20 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2007/07/01 16:51:43 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\QLSlksvr.dll
[2007/07/01 16:51:42 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\QLSimgsvr.dll
[2007/07/01 16:51:41 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\QLSPortMonitorInstaller.dll
[2007/07/01 16:51:41 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\QLSwinpt.dll
[2007/07/01 16:51:41 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\qlsbcchk.dll
[2007/07/01 16:51:41 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\QLSColorXForm.dll
[2007/07/01 16:51:41 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\QLSHASP.dll
[2007/07/01 16:51:41 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\QLSMacroWork.dll
[2007/07/01 16:51:41 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\QLSDataWriterMon.dll
[2007/07/01 16:51:41 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\QLSDataWriterMonUI.dll
[2007/07/01 16:51:40 | 000,368,640 | ---- | C] () -- C:\WINDOWS\System32\qlsbc32.dll
[2007/07/01 16:51:40 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\Astro32.dll
[2007/07/01 16:51:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\QLSbmger.dll
[2007/07/01 16:51:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\QLSbmfre.dll
[2007/07/01 16:51:40 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\QLScvger.dll
[2007/07/01 16:51:40 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\QLScvfre.dll
[2007/07/01 16:51:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\QLSadtxt.dll
[2007/07/01 16:51:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\LKsvrger.dll
[2007/07/01 16:51:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\LKsvrfre.dll
[2007/07/01 16:51:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\dirport.dll
[2007/07/01 16:51:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AST32ger.dll
[2007/07/01 16:51:40 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\AST32fre.dll
[2007/07/01 16:51:40 | 000,040,756 | ---- | C] () -- C:\WINDOWS\System32\QLSPM_LANG.DAT
[2007/07/01 16:51:40 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\Q97comm.dll
[2007/07/01 16:51:40 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\QLSALFSvr.dll
[2007/07/01 16:51:40 | 000,007,808 | ---- | C] () -- C:\WINDOWS\System32\QLSSV_LANG.DAT
[2007/07/01 16:51:40 | 000,005,451 | ---- | C] () -- C:\WINDOWS\System32\QLSDB_LANG.DAT
[2007/07/01 16:51:40 | 000,003,048 | ---- | C] () -- C:\WINDOWS\System32\QLSQU_LANG.DAT
[2007/03/11 15:39:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxctpmon.dll
[2007/03/11 15:39:26 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXCTFXPU.DLL
[2007/01/31 14:50:32 | 000,913,408 | ---- | C] () -- C:\WINDOWS\System32\xreglib.dll
[2007/01/22 23:55:52 | 000,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini
[2007/01/13 06:28:59 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2007/01/13 03:25:12 | 000,091,648 | ---- | C] () -- C:\WINDOWS\gzip.exe
[2006/12/29 08:22:43 | 000,086,304 | ---- | C] () -- C:\WINDOWS\RHVIDEO.DLL
[2006/12/23 11:12:25 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/10/12 08:24:34 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/08/27 19:07:11 | 000,021,791 | ---- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
[2006/08/27 19:07:10 | 000,001,037 | ---- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
[2006/08/27 19:06:42 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2006/08/27 19:06:42 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2006/08/27 19:06:41 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2006/08/11 21:46:23 | 000,000,504 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2006/07/23 13:50:00 | 000,005,652 | ---- | C] () -- C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2006/05/18 12:39:56 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\qllmk08O.dll
[2006/03/22 12:47:45 | 000,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/03/22 12:47:45 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\3ACE6F9E19.sys
[2006/03/16 16:44:04 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/16 16:31:17 | 000,000,126 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/03/16 16:30:08 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2006/03/16 16:23:50 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/03/16 16:21:17 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/03/16 16:18:07 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2006/03/16 15:53:08 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/03/16 15:52:24 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 09:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/07/06 01:00:30 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\ISP2000.dll
[2005/07/06 01:00:26 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2005/07/06 01:00:26 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\lfkodak.dll
[2004/08/11 18:24:19 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 18:19:30 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/11 18:12:14 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 18:07:24 | 000,004,349 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/11 18:06:43 | 001,160,120 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 18:00:30 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/11 18:00:28 | 000,664,358 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/11 18:00:28 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/11 18:00:28 | 000,143,252 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/11 18:00:28 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/11 18:00:27 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/11 18:00:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/11 18:00:24 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2004/08/11 18:00:19 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/11 18:00:19 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/11 18:00:12 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/11 18:00:04 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/11/19 17:36:30 | 000,028,779 | ---- | C] () -- C:\WINDOWS\System32\javaw.exe
[2003/11/19 17:36:26 | 000,024,681 | ---- | C] () -- C:\WINDOWS\System32\java.exe
[2003/07/23 16:57:53 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\IMPLODE.DLL
[2001/07/06 16:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ========== [2011/05/29 20:53:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\BitDefender
[2009/08/20 23:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\Windows Desktop Search
[2009/09/19 13:08:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Application Data\Windows Search
[2007/03/11 15:39:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\5400 Series
[2011/05/27 19:59:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2006/10/15 20:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2006/10/15 20:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2006/08/11 21:47:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2006/10/12 08:24:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2009/12/14 17:24:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2006/10/15 20:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Riverdeep Interactive Learning Limited
[2009/09/17 15:09:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/05/19 19:18:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/08 13:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2006/10/12 08:24:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2006/03/16 16:25:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/10/08 13:40:52 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2009/12/14 16:16:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\.BitTornado
[2011/05/27 19:07:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\BitDefender
[2009/10/15 19:39:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\Chessmaster Challenge
[2009/06/10 03:28:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\GlarySoft
[2011/05/27 18:52:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\QuickScan
[2009/10/15 19:23:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\SpinTop
[2010/10/08 13:41:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\TuneUp Software
[2011/06/02 20:24:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\uTorrent
[2009/06/10 03:19:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\Windows Desktop Search
[2009/06/10 03:42:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Nutrition City\Application Data\Windows Search
[2011/06/02 19:38:57 | 000,000,330 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2004/08/04 06:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\i386\svchost.exe
[2004/08/04 06:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >[2004/08/04 06:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\i386\userinit.exe
[2004/08/04 06:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2004/08/04 06:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\i386\winlogon.exe
[2004/08/04 06:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/04/14 11:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/04/14 11:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/04/14 11:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/02/18 06:49:53 | 000,173,568 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/02/18 06:49:53 | 000,173,568 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/02/18 06:49:53 | 000,173,568 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation)
========== Alternate Data Streams ========== @Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\netware.drv:SummaryInformation
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D158BAF9
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-02 19:05:41
-----------------------------
19:05:41.484 OS Version: Windows 5.1.2600 Service Pack 3
19:05:41.484 Number of processors: 1 586 0xD08
19:05:41.484 ComputerName: NUTRITIONCITY UserName: Admin
19:05:43.234 Initialize success
19:05:44.375 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:05:44.375 Disk 0 Vendor: ST960822A 8.03 Size: 55796MB BusType: 3
19:05:44.406 Disk 0 MBR read successfully
19:05:44.421 Disk 0 MBR scan
19:05:44.437 Disk 0 Windows XP default MBR code
19:05:44.453 Disk 0 scanning sectors +114254280
19:05:44.546 Disk 0 scanning C:\WINDOWS\system32\drivers
19:06:00.437 Service scanning
19:06:26.890 Disk 0 trace - called modules:
19:06:26.921 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys
19:06:26.937 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87307ab8]
19:06:26.953 3 CLASSPNP.SYS[f76d6fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x87324940]
19:06:26.953 Scan finished successfully
19:06:33.640 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Nutrition City\My Documents\Ryan\MBR.dat"
19:06:33.656 The log file has been saved successfully to "C:\Documents and Settings\Nutrition City\My Documents\Ryan\aswMBR.txt"