It says it has been removed and doesn't show up when I scan again but now we are having browser redirects constantly and now when the computer is inactive for a while, a weird video will pop up. Its a different video each time and it's grainy and keeps trying to buffer. It says to see more videos click here. Its not porn, just random videos. I ran Microsoft Safety scanner before finding this site and it found nothing. Otherwise, the computer seems to function fine but the browser issues are horrible. We are currently using firefox. IE gives us the same issue when we try using it. I ran the OTL and my log is below. Any help would be greatly appreciated! Thanks in advance!
Robin
OTL logfile created on: 6/5/2011 8:58:17 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Toonsday\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.75 Gb Total Physical Memory | 1.19 Gb Available Physical Memory | 43.18% Memory free
5.49 Gb Paging File | 3.73 Gb Available in Paging File | 67.96% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 136.95 Gb Total Space | 90.79 Gb Free Space | 66.30% Space Free | Partition Type: NTFS
Computer Name: PRISCILLA | User Name: Toonsday | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/05 20:57:57 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Toonsday\Downloads\OTL.exe
PRC - [2011/04/29 16:59:32 | 000,227,840 | ---- | M] (Mp3Tube) -- C:\Program Files (x86)\Mp3Tube Toolbar\Mp3TubeSvc.exe
PRC - [2011/04/29 13:12:50 | 000,184,320 | ---- | M] (Mp3Tube) -- C:\Program Files (x86)\Mp3Tube Toolbar\Mp3TubeVideoToMp3.exe
PRC - [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/10/29 06:47:34 | 000,419,112 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
PRC - [2009/10/21 21:53:42 | 000,181,480 | ---- | M] (Acer Corp.) -- C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
PRC - [2009/09/10 08:42:30 | 000,349,480 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009/08/28 04:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009/08/18 04:42:08 | 001,157,128 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/08/04 00:09:34 | 000,199,464 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
PRC - [2009/07/23 16:51:26 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/23 16:51:26 | 000,645,328 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe
PRC - [2009/07/22 16:16:30 | 000,894,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe
PRC - [2009/07/03 21:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2009/06/16 22:00:46 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/04/09 20:04:30 | 000,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\MSK\msksrver.exe
PRC - [2009/04/09 14:46:14 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/04/09 11:18:50 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe
========== Modules (SafeList) ==========
MOD - [2011/06/05 20:57:57 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Toonsday\Downloads\OTL.exe
MOD - [2009/07/13 20:15:31 | 000,154,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll
MOD - [2009/07/13 20:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll
MOD - [2009/07/13 20:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
MOD - [2009/01/23 13:46:18 | 000,013,840 | ---- | M] () -- C:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2010/11/11 14:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2010/11/11 14:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/10/29 14:10:02 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2009/07/29 07:03:42 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/03 21:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/06/18 13:08:44 | 000,155,456 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV:64bit: - [2009/06/16 23:29:18 | 000,696,848 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2011/04/29 16:59:32 | 000,227,840 | ---- | M] (Mp3Tube) [Auto | Running] -- C:\Program Files (x86)\Mp3Tube Toolbar\Mp3TubeSvc.exe -- (Mp3Tube Toolbar Service)
SRV - [2009/11/05 15:20:00 | 000,332,272 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\ProgramData\Partner\Partner.exe -- (Partner Service)
SRV - [2009/09/10 08:42:46 | 000,305,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009/08/28 04:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009/07/23 16:51:26 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/07/22 16:16:30 | 000,894,136 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/06/16 22:00:46 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/05/22 13:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/04/09 20:04:30 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009/04/09 14:46:14 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/04/09 11:18:50 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009/01/23 13:46:14 | 000,203,280 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2010/10/24 21:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2009/10/04 20:34:00 | 001,542,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/08/21 04:18:16 | 002,978,296 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/29 17:11:24 | 006,038,016 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/07/27 02:04:36 | 000,058,880 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV:64bit: - [2009/07/13 20:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 20:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/18 13:15:16 | 000,307,400 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2009/06/18 13:15:16 | 000,102,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2009/06/18 13:15:16 | 000,049,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfesmfk.sys -- (mfesmfk)
DRV:64bit: - [2009/06/18 13:08:50 | 000,040,904 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdk.sys -- (mferkdk)
DRV:64bit: - [2009/06/18 07:12:32 | 000,272,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/02 06:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009/06/02 06:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009/06/02 06:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2009/05/05 03:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009/05/05 03:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2009/05/04 08:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/04/09 17:23:02 | 000,176,144 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Mpfp.sys -- (MPFP)
DRV:64bit: - [2009/04/03 08:39:58 | 000,034,872 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV - [2009/03/25 22:16:08 | 000,025,608 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\Drivers\DKbFltr.sys -- (DKbFltr) Dritek Keyboard Filter Driver (64-bit)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...h4z195t4812x208
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...h4z195t4812x208
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer...h4z195t4812x208
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search..defaultengine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..defaultenginename: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..order.1: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngine: "Yahoo-Mp3Tube"
FF - prefs.js..browser.search..selectedEngineURL: "http://mp3tubetoolba...={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..keyword.URL: "http://www.questscan...anPB&keywords="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/06/05 11:41:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/06/05 10:59:05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/06/05 10:59:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HBLite\bin\11.0.363.0\firefox\extensions [2011/06/05 12:56:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/05 13:01:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/06/05 13:01:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Toonsday\AppData\Roaming\Mozilla\Extensions
[2011/06/05 13:01:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/05 13:01:27 | 000,000,000 | ---D | M] (QuestScan) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{F0E1168A-B4B5-484C-B77E-0D28E6B64096}
File not found (No name found) --
[2011/06/05 12:56:59 | 000,000,000 | ---D | M] (Hotbar Component) -- C:\PROGRAM FILES (X86)\HBLITE\BIN\11.0.363.0\FIREFOX\EXTENSIONS
[2011/04/14 11:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
[2011/06/05 17:12:42 | 000,001,211 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\Mp3Tube.xml
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2:64bit: - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll ()
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll ()
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Mp3Tube Toolbar) - {46897C77-E7A6-4c33-BFFB-E9C2E2718942} - C:\Program Files (x86)\Mp3Tube Toolbar\mp3tubetb.DLL (Mp3Tube Toolbar)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Mp3Tube Toolbar) - {46897C77-E7A6-4C33-BFFB-E9C2E2718942} - C:\Program Files (x86)\Mp3Tube Toolbar\mp3tubetb.DLL (Mp3Tube Toolbar)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [ArcadeDeluxeAgent] C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (Acer Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll ()
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/05 13:25:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2011/06/05 13:20:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2011/06/05 13:18:21 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\Microsoft Help
[2011/06/05 13:01:35 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\Mozilla
[2011/06/05 13:01:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/06/05 12:57:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mp3Tube Toolbar
[2011/06/05 12:57:09 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\blinkx beat
[2011/06/05 12:57:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Blinkx
[2011/06/05 12:57:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotbar
[2011/06/05 12:56:59 | 000,000,000 | ---D | C] -- C:\ProgramData\HBLiteSA
[2011/06/05 12:56:59 | 000,000,000 | ---D | C] -- C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
[2011/06/05 12:56:57 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\HBLite
[2011/06/05 12:56:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HBLite
[2011/06/05 12:56:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ShoppingReport2
[2011/06/05 12:23:47 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\Diagnostics
[2011/06/05 10:58:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSN Toolbar
[2011/06/05 10:58:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/06/05 10:57:44 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Mozilla
[2011/06/05 10:57:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bing Bar Installer
[2011/06/05 10:57:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP Photo Creations
[2011/06/05 10:57:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
[2011/06/05 10:57:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Coupons
[2011/06/05 10:56:42 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\HpUpdate
[2011/06/05 10:56:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2011/06/05 10:55:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
[2011/06/05 10:54:49 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2011/06/04 16:34:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Search Toolbar
[2011/06/04 15:08:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2011/06/04 15:07:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/06/04 14:37:36 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\NPE
[2011/06/04 14:02:14 | 000,000,000 | ---D | C] -- C:\Windows\NAPP_Dism_Log
[2011/06/04 13:23:43 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\Desktop\The Pink Sink
[2011/06/04 13:16:15 | 000,000,000 | R--D | C] -- C:\Backup
[2011/06/04 13:13:54 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2011/06/04 13:13:53 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2011/06/04 13:13:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD
[2011/06/04 13:13:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2011/06/04 13:11:54 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2011/06/04 13:11:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2011/06/04 13:10:54 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2011/06/04 12:13:40 | 000,253,888 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/06/04 12:12:12 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011/06/04 12:12:12 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/06/04 11:59:22 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/06/04 11:47:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
[2011/06/04 11:36:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2011/06/04 11:35:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2011/06/04 11:35:14 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2011/06/04 11:34:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive
[2011/06/04 11:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/06/04 11:34:34 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\HP
[2011/06/04 11:34:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2011/06/04 11:33:35 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Google
[2011/06/04 11:33:33 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\Google
[2011/06/04 11:32:05 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Desktop\Desktop Icons
[2011/06/04 11:31:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2011/06/04 11:29:12 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2011/06/04 11:29:09 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Atheros_L1e
[2011/06/04 11:28:27 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\ATI
[2011/06/04 11:28:27 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\ATI
[2011/06/04 11:27:44 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Acer
[2011/06/04 11:27:41 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Leadertech
[2011/06/04 11:27:26 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\EgisTec
[2011/06/04 11:27:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
[2011/06/04 11:27:03 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Macromedia
[2011/06/04 11:25:06 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Adobe
[2011/06/04 11:24:40 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/06/04 11:24:40 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Searches
[2011/06/04 11:24:40 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/06/04 11:24:07 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Identities
[2011/06/04 11:24:01 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Contacts
[2011/06/04 11:23:57 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\VirtualStore
[2011/06/04 11:22:41 | 000,000,000 | -H-D | C] -- C:\Users\Toonsday\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/06/04 11:21:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OEM
[2011/06/04 11:20:22 | 000,000,000 | --SD | C] -- C:\Users\Toonsday\AppData\Roaming\Microsoft
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Videos
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Saved Games
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Pictures
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Music
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Links
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Favorites
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Downloads
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\My Documents
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\Desktop
[2011/06/04 11:20:22 | 000,000,000 | R--D | C] -- C:\Users\Toonsday\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\AppData\Local\Temporary Internet Files
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Templates
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Start Menu
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\SendTo
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Recent
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\PrintHood
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\NetHood
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Documents\My Videos
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Documents\My Pictures
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Documents\My Music
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\My Documents
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Local Settings
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\AppData\Local\History
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Cookies
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\Application Data
[2011/06/04 11:20:22 | 000,000,000 | -HSD | C] -- C:\Users\Toonsday\AppData\Local\Application Data
[2011/06/04 11:20:22 | 000,000,000 | -H-D | C] -- C:\Users\Toonsday\AppData
[2011/06/04 11:20:22 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\Temp
[2011/06/04 11:20:22 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Local\Microsoft
[2011/06/04 11:20:22 | 000,000,000 | ---D | C] -- C:\Users\Toonsday\AppData\Roaming\Media Center Programs
[2011/06/04 11:19:59 | 000,000,000 | -HSD | C] -- C:\Recovery
========== Files - Modified Within 30 Days ==========
[2011/06/05 21:00:03 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/05 17:36:54 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/05 17:20:14 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/05 17:20:14 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/05 17:17:40 | 000,717,260 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/05 17:17:40 | 000,617,460 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/06/05 17:17:40 | 000,104,702 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/06/05 17:13:59 | 000,012,011 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2011/06/05 17:12:04 | 000,425,488 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/05 17:11:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/05 17:11:25 | 2211,483,648 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/05 17:10:47 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2011/06/05 13:01:37 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2011/06/05 13:01:27 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/05 10:57:24 | 000,001,105 | ---- | M] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk
[2011/06/05 10:56:10 | 000,002,240 | ---- | M] () -- C:\Users\Public\Desktop\HP Deskjet 1000 J110 series.lnk
[2011/06/04 19:35:04 | 520,138,127 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/06/04 15:09:09 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/06/04 15:08:36 | 000,731,106 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/06/04 14:02:14 | 000,011,453 | ---- | M] () -- C:\Windows\ChangeLang_Done.tag
[2011/06/04 13:18:07 | 000,039,252 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2011/06/04 13:18:07 | 000,039,252 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2011/06/04 13:14:08 | 000,000,006 | ---- | M] () -- C:\Windows\SysNative\PLD_Framework.cmd
[2011/06/04 12:13:40 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/06/04 11:39:52 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job
[2011/06/04 11:39:52 | 000,000,320 | ---- | M] () -- C:\Windows\tasks\McQcTask.job
[2011/06/04 11:33:20 | 000,001,445 | ---- | M] () -- C:\Users\Toonsday\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/04 11:29:39 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2011/06/04 11:21:16 | 000,002,102 | ---- | M] () -- C:\Users\Public\Desktop\Netflix.lnk
[2011/05/10 07:10:44 | 000,253,888 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
========== Files Created - No Company Name ==========
[2011/06/05 17:10:47 | 000,003,288 | ---- | C] () -- C:\bootsqm.dat
[2011/06/05 13:01:37 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/06/05 13:01:27 | 000,001,158 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/06/05 13:01:27 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/06/05 10:59:16 | 000,001,384 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Default Manager.lnk
[2011/06/05 10:57:24 | 000,001,105 | ---- | C] () -- C:\Users\Public\Desktop\HP Photo Creations.lnk
[2011/06/05 10:56:10 | 000,002,240 | ---- | C] () -- C:\Users\Public\Desktop\HP Deskjet 1000 J110 series.lnk
[2011/06/04 19:35:04 | 520,138,127 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/06/04 15:09:09 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/06/04 15:08:36 | 000,731,106 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/06/04 15:08:07 | 000,001,901 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/06/04 14:04:03 | 000,011,453 | ---- | C] () -- C:\Windows\ChangeLang_Done.tag
[2011/06/04 13:09:15 | 000,681,508 | ---- | C] () -- C:\Windows\SysNative\oem3.inf
[2011/06/04 13:07:15 | 2211,483,648 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/04 12:13:40 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2011/06/04 11:55:01 | 000,000,898 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/04 11:54:57 | 000,000,894 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/04 11:47:52 | 000,002,557 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2011/06/04 11:47:20 | 000,001,151 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2011/06/04 11:33:20 | 000,001,445 | ---- | C] () -- C:\Users\Toonsday\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/04 11:29:39 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2011/06/04 11:26:41 | 000,001,417 | ---- | C] () -- C:\Users\Toonsday\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/06/04 11:22:03 | 000,002,079 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer Assist.lnk
[2011/06/04 11:21:16 | 000,002,102 | ---- | C] () -- C:\Users\Public\Desktop\Netflix.lnk
[2011/06/04 11:20:51 | 000,000,342 | ---- | C] () -- C:\Windows\tasks\McDefragTask.job
[2011/06/04 11:20:48 | 000,000,320 | ---- | C] () -- C:\Windows\tasks\McQcTask.job
[2011/06/04 11:20:22 | 000,000,290 | ---- | C] () -- C:\Users\Toonsday\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/06/04 11:20:22 | 000,000,272 | ---- | C] () -- C:\Users\Toonsday\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2009/11/05 15:38:52 | 000,000,000 | ---- | C] () -- C:\Windows\setup.INI
[2009/11/05 14:49:28 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/06/04 11:27:44 | 000,000,000 | ---D | M] -- C:\Users\Toonsday\AppData\Roaming\Acer
[2011/06/05 12:56:57 | 000,000,000 | ---D | M] -- C:\Users\Toonsday\AppData\Roaming\HBLite
[2011/06/04 11:27:41 | 000,000,000 | ---D | M] -- C:\Users\Toonsday\AppData\Roaming\Leadertech
[2011/06/04 11:39:52 | 000,000,342 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2011/06/04 11:39:52 | 000,000,320 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2009/07/14 00:08:49 | 000,004,162 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:F8B49EF2
< End of report >