Here is the OTL log:
OTL logfile created on: 6/15/2011 5:09:00 PM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Users\Matt Leung\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 35.56% Memory free
6.18 Gb Paging File | 4.30 Gb Available in Paging File | 69.62% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.20 Gb Total Space | 19.62 Gb Free Space | 8.87% Space Free | Partition Type: NTFS
Drive D: | 11.68 Gb Total Space | 1.99 Gb Free Space | 17.07% Space Free | Partition Type: NTFS
Computer Name: FREEPIZZA | User Name: Matt Leung | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/06/15 17:08:08 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Matt Leung\Downloads\OTL.scr
PRC - [2011/05/25 02:00:34 | 002,151,128 | ---- | M] (Lavasoft Limited) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/05/25 02:00:34 | 001,191,216 | ---- | M] (Lavasoft Limited) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/09/19 21:47:01 | 002,969,496 | ---- | M] () -- C:\Program Files\Pando Networks\Media Booster\PMB.exe
PRC - [2010/09/15 13:08:39 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/01/15 05:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008/10/28 23:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/01/20 19:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/09/17 15:48:50 | 002,056,275 | ---- | M] (Cisco Systems, Inc) -- C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
PRC - [2007/09/10 15:12:44 | 000,069,632 | ---- | M] (Software 2000 Limited) -- C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE
PRC - [2007/05/04 13:14:04 | 000,036,864 | ---- | M] ( ) -- C:\Program Files\HP\HP UT\bin\hppusg.exe
PRC - [2006/11/02 20:40:12 | 000,174,656 | ---- | M] () -- C:\Windows\System32\PSIService.exe
PRC - [2005/03/09 20:50:18 | 000,018,944 | ---- | M] (
http://libusb-win32.sourceforge.net) -- C:\Windows\System32\libusbd-nt.exe
========== Modules (SafeList) ========== MOD - [2011/06/15 17:08:08 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Matt Leung\Downloads\OTL.scr
MOD - [2008/01/20 19:23:44 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (npkcmsvc)
SRV - [2011/06/09 06:32:03 | 003,435,096 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_8675ab0.dll -- (Akamai)
SRV - [2011/05/25 02:00:34 | 002,151,128 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/03/06 20:36:19 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/01/15 05:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2008/08/30 14:19:01 | 000,658,432 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/01/20 19:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/03/05 10:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
SRV - [2006/11/02 20:40:12 | 000,174,656 | ---- | M] () [Auto | Start_Pending] -- C:\Windows\System32\PSIService.exe -- (ProtexisLicensing)
SRV - [2005/03/09 20:50:18 | 000,018,944 | ---- | M] (
http://libusb-win32.sourceforge.net) [Auto | Running] -- C:\Windows\System32\libusbd-nt.exe -- (libusbd)
========== Driver Services (SafeList) ========== DRV - [2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/05/25 02:00:36 | 000,064,512 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2011/05/25 02:00:36 | 000,015,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2010/06/06 20:12:22 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2010/05/10 11:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 11:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2008/03/04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2008/01/20 19:23:21 | 000,227,896 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\drivers\volsnap.sys -- (volsnap)
DRV - [2007/10/18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/10/01 08:35:52 | 000,183,352 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007/09/26 13:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel®
DRV - [2007/08/21 01:13:04 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
DRV - [2007/08/08 20:42:08 | 000,045,568 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/07/30 11:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/07/30 10:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/07/11 10:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/18 05:03:26 | 000,141,312 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2006/11/02 00:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2005/03/09 20:50:16 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...ilion&pf=laptopIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...ilion&pf=laptop IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...ilion&pf=laptopIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...ilion&pf=laptopIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://asu.edu/"FF - prefs.js..extensions.enabledItems:
[email protected]:5.0.31.0
FF - prefs.js..extensions.enabledItems:
[email protected]:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.7
FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:3.0.8
FF - prefs.js..extensions.enabledItems:
[email protected]:1.1
FF - prefs.js..extensions.enabledItems: {46868735-c3fa-47ce-8ce7-cce51a66aceb}:1.2
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.2
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/03 22:04:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/03 22:04:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b1\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 1\components [2011/04/08 17:09:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0b1\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 1\plugins
[2009/11/25 09:42:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Extensions
[2009/11/25 09:42:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Extensions\
[email protected][2011/05/31 19:48:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] (oldbar) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\{46868735-c3fa-47ce-8ce7-cce51a66aceb}
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] (MushroomKingdom) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\{BF32D2C8-9C75-404b-ACF4-880DB4679236}
[2010/11/03 15:54:28 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\
[email protected][2011/06/09 00:08:42 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\
[email protected][2011/06/09 00:08:42 | 000,000,000 | ---D | M] (ChaCha Guide App Toolbar) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\
[email protected][2011/06/09 00:08:42 | 000,000,000 | ---D | M] (FIFA Online Web Launcher) -- C:\Users\Matt Leung\AppData\Roaming\Mozilla\Firefox\Profiles\vcgu8hiz.default\extensions\
[email protected][2011/05/03 22:04:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/01 11:55:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/03/03 12:14:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
File not found (No name found) --
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\{02450954-CDD9-410F-B1DA-DB804E18C671}.XPI
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\{36B72FDA-9A37-456C-8CC8-CDDD4A3FE312}.XPI
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\{C50CA3C4-5656-43C2-A061-13E717F73FC8}.XPI
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\{CE6E6E3B-84DD-4CAC-9F63-8D2AE4F30A4B}.XPI
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\{D618933B-9EB4-1C04-949D-0F9B1A39EBB9}.XPI
() (No name found) -- C:\USERS\MATT LEUNG\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VCGU8HIZ.DEFAULT\EXTENSIONS\
[email protected][2011/04/14 09:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/02/07 21:46:12 | 000,087,360 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2008/02/07 21:46:20 | 000,091,448 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2008/02/07 21:46:16 | 000,021,824 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2007/03/16 17:27:00 | 000,479,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2007/03/16 17:27:00 | 000,548,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2007/03/16 17:27:00 | 000,626,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2008/06/17 23:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2010/09/01 11:55:14 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2008/02/07 21:48:26 | 000,419,136 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2008/11/02 00:20:54 | 000,151,552 | ---- | M] (PopCap Games) -- C:\Program Files\Mozilla Firefox\plugins\nppopcaploader.dll
[2008/02/07 21:46:12 | 000,024,384 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2010/01/01 01:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
Hosts file not found
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (ooVoo Toolbar) - {A057A204-BACC-4D26-8087-36EE87E26986} - C:\Program Files\oovooToolbar\oovooToolbar.dll (ooVoo )
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Live Search Club Toolbar) - {719D74AB-1AF9-43A1-8C62-D8750628D93E} - C:\Program Files\Live Search Club Toolbar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ooVoo Toolbar) - {A057A204-BACC-4D26-8087-36EE87E26986} - C:\Program Files\oovooToolbar\oovooToolbar.dll (ooVoo )
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2787EA8E-8D87-48AF-88AD-B30246C917AB} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Live Search Club Toolbar) - {719D74AB-1AF9-43A1-8C62-D8750628D93E} - C:\Program Files\Live Search Club Toolbar\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (ooVoo Toolbar) - {A057A204-BACC-4D26-8087-36EE87E26986} - C:\Program Files\oovooToolbar\oovooToolbar.dll (ooVoo )
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [cleanddm] File not found
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe ()
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WildTangent CDA] C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe (WildTangent, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [GameShadow] File not found
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10k_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\Matt Leung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtualEcho.lnk = File not found
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://zone.msn.com/...ploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Matt Leung\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Matt Leung\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/01 06:57:03 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{0cba5206-6451-11dd-86d6-001d72684f8b}\Shell\AutoRun\command - "" = F:\Launch.exe
O33 - MountPoints2\{3dce7f5c-c59a-11de-8dde-001d72684f8b}\Shell - "" = AutoRun
O33 - MountPoints2\{3dce7f5c-c59a-11de-8dde-001d72684f8b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{9eeeedca-bbd7-11dd-ace8-001d72684f8b}\Shell\Auto\command - "" = F:\Setup.exe
O33 - MountPoints2\{9eeeedca-bbd7-11dd-ace8-001d72684f8b}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Setup.exe
O33 - MountPoints2\{a85aaca1-92f5-11e0-8af6-001d72684f8b}\Shell\AutoRun\command - "" = F:\Get_Started_for_Win.exe
O33 - MountPoints2\{c0b3c010-6c00-11dd-964a-001d72684f8b}\Shell - "" = AutoRun
O33 - MountPoints2\{c0b3c010-6c00-11dd-964a-001d72684f8b}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Get_Started_for_Win.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ========== [2011/06/13 21:55:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/06/13 21:55:38 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/06/13 21:49:45 | 000,000,000 | -HSD | C] -- C:\found.000
[2011/06/13 20:16:38 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/06/13 19:30:04 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/06/13 19:23:36 | 011,419,392 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Matt Leung\Desktop\SUPERAntiSpywarePro.exe
[2011/06/13 19:23:03 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/06/09 22:25:01 | 000,000,000 | ---D | C] -- C:\Users\Matt Leung\AppData\Roaming\AVG10
[2011/06/09 22:22:02 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/06/09 22:18:00 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2011/06/09 22:09:58 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/06/09 16:56:14 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2011/06/09 16:55:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/06/09 16:55:52 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2011/06/08 21:34:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/06/08 21:25:05 | 000,000,000 | ---D | C] -- C:\Users\Matt Leung\Desktop\RK_Quarantine
[2011/05/31 20:20:19 | 000,000,000 | ---D | C] -- C:\Users\Matt Leung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EA Games
[2011/05/19 14:29:53 | 000,049,904 | R--- | C] (Avanquest Software) -- C:\Windows\System32\drivers\BVRPMPR5.SYS
[2011/05/19 14:29:06 | 000,000,000 | ---D | C] -- C:\Netgear
[2011/05/19 13:26:11 | 000,884,736 | ---- | C] (www.chmaas.handshake.de) -- C:\Users\Matt Leung\Desktop\XVI32.exe
[2011/05/18 19:10:57 | 000,000,000 | ---D | C] -- C:\Users\Matt Leung\Desktop\dir615_revE1_FW_501NA
[2 C:\Users\Matt Leung\Documents\*.tmp files -> C:\Users\Matt Leung\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/06/15 17:13:19 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/15 17:13:14 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/06/15 17:13:14 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\HP WEP.job
[2011/06/15 16:51:43 | 000,000,000 | ---- | M] () -- C:\Users\Matt Leung\defogger_reenable
[2011/06/15 16:50:12 | 000,000,428 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{77B5D549-256D-43DA-B957-C1A83D416054}.job
[2011/06/15 16:49:33 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/15 16:49:33 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/15 16:49:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/15 16:49:16 | 3211,108,352 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/14 16:36:11 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2185205771-1825530132-2407171191-1000UA.job
[2011/06/14 16:36:11 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/14 07:36:00 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2185205771-1825530132-2407171191-1000Core.job
[2011/06/13 21:55:43 | 000,001,760 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
[2011/06/13 20:16:36 | 000,000,680 | ---- | M] () -- C:\Users\Matt Leung\AppData\Local\d3d9caps.dat
[2011/06/13 19:33:52 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/13 19:23:08 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2011/06/13 19:23:08 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2011/06/13 19:23:03 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/06/13 19:07:28 | 000,302,592 | ---- | M] () -- C:\Users\Matt Leung\Desktop\xydjetpo.exe
[2011/06/13 18:56:56 | 011,419,392 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Matt Leung\Desktop\SUPERAntiSpywarePro.exe
[2011/06/09 21:18:05 | 000,157,696 | ---- | M] () -- C:\Users\Matt Leung\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/09 19:12:16 | 000,000,903 | ---- | M] () -- C:\Users\Matt Leung\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/09 17:38:39 | 000,002,067 | ---- | M] () -- C:\Users\Matt Leung\Desktop\Google Chrome.lnk
[2011/06/09 17:38:39 | 000,002,029 | ---- | M] () -- C:\Users\Matt Leung\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/09 17:07:07 | 000,117,244 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/09 17:07:06 | 000,000,000 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/09 16:56:16 | 000,000,897 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/05/31 20:20:42 | 000,138,056 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/05/31 20:20:42 | 000,138,056 | ---- | M] () -- C:\Users\Matt Leung\AppData\Roaming\PnkBstrK.sys
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/25 02:00:36 | 000,064,512 | ---- | M] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2011/05/23 22:30:17 | 000,002,587 | ---- | M] () -- C:\Users\Matt Leung\Desktop\Microsoft Office Word 2007.lnk
[2011/05/19 14:34:04 | 000,005,918 | ---- | M] () -- C:\Users\Matt Leung\Desktop\Router_Setup.html
[2011/05/19 13:28:30 | 000,000,835 | ---- | M] () -- C:\Users\Matt Leung\Desktop\XVI32.ini
[2 C:\Users\Matt Leung\Documents\*.tmp files -> C:\Users\Matt Leung\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/06/15 16:59:54 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\HP WEP.job
[2011/06/15 16:51:43 | 000,000,000 | ---- | C] () -- C:\Users\Matt Leung\defogger_reenable
[2011/06/14 06:32:44 | 3211,108,352 | -HS- | C] () -- C:\hiberfil.sys
[2011/06/13 21:55:43 | 000,001,760 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
[2011/06/13 19:24:03 | 000,302,592 | ---- | C] () -- C:\Users\Matt Leung\Desktop\xydjetpo.exe
[2011/06/13 19:23:08 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011/06/13 19:23:08 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/06/09 16:56:16 | 000,000,897 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/05/19 14:34:04 | 000,000,172 | R--- | C] () -- C:\Users\Matt Leung\Desktop\Router Login.url
[2011/05/19 14:34:00 | 000,005,918 | ---- | C] () -- C:\Users\Matt Leung\Desktop\Router_Setup.html
[2011/05/19 13:28:11 | 000,000,835 | ---- | C] () -- C:\Users\Matt Leung\Desktop\XVI32.ini
[2011/05/19 13:26:11 | 000,075,183 | ---- | C] () -- C:\Users\Matt Leung\Desktop\XVI32U.chm
[2011/05/19 13:26:11 | 000,001,246 | -H-- | C] () -- C:\Users\Matt Leung\Desktop\WINEBCDE.XCT
[2011/05/19 13:26:11 | 000,001,246 | -H-- | C] () -- C:\Users\Matt Leung\Desktop\EBCDEWIN.XCT
[2011/05/19 13:26:11 | 000,001,232 | -H-- | C] () -- C:\Users\Matt Leung\Desktop\WINEBCUS.XCT
[2011/05/19 13:26:11 | 000,001,232 | -H-- | C] () -- C:\Users\Matt Leung\Desktop\EBCUSWIN.XCT
[2011/05/19 13:26:11 | 000,000,896 | -H-- | C] () -- C:\Users\Matt Leung\Desktop\WINDOS.XCT
[2011/05/19 13:26:11 | 000,000,896 | -H-- | C] () -- C:\Users\Matt Leung\Desktop\DOSWIN.XCT
[2011/05/01 23:22:49 | 000,002,642 | -HS- | C] () -- C:\Users\Matt Leung\AppData\Local\e6cj5tlvi1v865yfa8f352520352u236
[2011/05/01 23:22:49 | 000,002,642 | -HS- | C] () -- C:\ProgramData\e6cj5tlvi1v865yfa8f352520352u236
[2011/04/25 01:00:39 | 000,033,792 | ---- | C] () -- C:\Windows\System32\drivers\libusb0.sys
[2010/07/31 21:45:32 | 000,000,680 | ---- | C] () -- C:\Users\Matt Leung\AppData\Local\d3d9caps.dat
[2010/03/11 19:37:07 | 000,000,315 | ---- | C] () -- C:\Windows\hegames.ini
[2009/12/07 11:46:22 | 002,427,248 | ---- | C] () -- C:\Windows\System32\pbsvc_heroes.exe
[2009/11/13 14:31:46 | 000,000,952 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2009/09/13 01:22:13 | 000,138,056 | ---- | C] () -- C:\Users\Matt Leung\AppData\Roaming\PnkBstrK.sys
[2009/09/13 01:21:58 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2009/09/09 16:01:06 | 000,091,923 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2009/09/09 16:01:06 | 000,076,956 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2009/09/09 16:01:06 | 000,039,121 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2009/09/09 16:01:06 | 000,027,965 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_JP.dat
[2009/07/08 18:03:02 | 000,058,880 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll
[2009/03/25 23:13:53 | 000,168,448 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/02/08 23:13:49 | 000,000,034 | -H-- | C] () -- C:\Windows\System32\DVDConverter_sysquict.dat
[2009/02/06 15:26:26 | 000,765,952 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/02/06 15:26:26 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/02/04 21:13:30 | 000,005,378 | ---- | C] () -- C:\Windows\PSPICEEV.INI
[2009/02/04 21:13:29 | 000,176,128 | ---- | C] () -- C:\Windows\System32\lffax60n.dll
[2009/02/04 21:13:29 | 000,141,824 | ---- | C] () -- C:\Windows\System32\lfcmp60n.dll
[2009/02/04 21:13:29 | 000,110,080 | ---- | C] () -- C:\Windows\System32\lfpng60n.dll
[2009/02/04 21:13:29 | 000,046,080 | ---- | C] () -- C:\Windows\System32\lftif60n.dll
[2009/02/04 21:13:29 | 000,043,008 | ---- | C] () -- C:\Windows\System32\ltfil60n.dll
[2009/02/04 21:13:29 | 000,023,552 | ---- | C] () -- C:\Windows\System32\lfpcx60n.dll
[2009/02/04 21:13:29 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfpct60n.dll
[2009/02/04 21:13:29 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfeps60n.dll
[2009/02/04 21:13:29 | 000,022,016 | ---- | C] () -- C:\Windows\System32\lfbmp60n.dll
[2009/02/04 21:13:29 | 000,020,480 | ---- | C] () -- C:\Windows\System32\lfpsd60n.dll
[2009/02/04 21:13:29 | 000,019,968 | ---- | C] () -- C:\Windows\System32\lftga60n.dll
[2009/02/04 21:13:29 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwpg60n.dll
[2009/02/04 21:13:29 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwmf60n.dll
[2009/02/04 21:13:29 | 000,018,432 | ---- | C] () -- C:\Windows\System32\lfmsp60n.dll
[2009/02/04 21:13:29 | 000,017,920 | ---- | C] () -- C:\Windows\System32\lfmac60n.dll
[2009/02/04 21:13:29 | 000,017,920 | ---- | C] () -- C:\Windows\System32\implode.dll
[2008/10/28 08:35:26 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1591.dll
[2008/10/28 08:28:36 | 001,498,700 | ---- | C] () -- C:\Windows\System32\igkrng400.bin
[2008/09/26 16:52:18 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2008/09/26 16:52:11 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2008/09/26 16:52:01 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2008/08/23 12:32:04 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2008/08/06 18:15:28 | 000,157,696 | ---- | C] () -- C:\Users\Matt Leung\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/06 17:50:56 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008/08/06 17:50:56 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/07/16 00:23:25 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/07/16 00:23:25 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2008/07/16 00:23:25 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2008/07/01 07:11:20 | 000,101,605 | ---- | C] () -- C:\Windows\hpqins13.dat
[2008/02/11 19:55:18 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1437.dll
[2008/02/11 19:34:48 | 002,215,364 | ---- | C] () -- C:\Windows\System32\igklg400.bin
[2008/02/11 19:34:48 | 001,971,732 | ---- | C] () -- C:\Windows\System32\igklg450.bin
[2008/02/11 19:34:48 | 000,029,932 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.bin
[2008/01/20 19:23:21 | 000,227,896 | ---- | C] () -- C:\Windows\System32\drivers\volsnap.sys
[2007/08/23 10:34:40 | 000,065,536 | ---- | C] () -- C:\Windows\System32\HPPLVS.dll
[2007/07/26 12:01:50 | 000,114,688 | ---- | C] () -- C:\Windows\System32\hppatusg01.dll
[2006/11/02 20:40:12 | 000,174,656 | ---- | C] () -- C:\Windows\System32\PSIService.exe
[2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,306,080 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,117,244 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 03:33:01 | 000,000,000 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2002/04/16 10:14:42 | 000,338,944 | ---- | C] () -- C:\Windows\System32\LFFPX7.DLL
[2002/04/16 10:14:00 | 001,683,456 | ---- | C] () -- C:\Windows\System32\LTCLR13n.dll
[2002/04/16 10:14:00 | 000,118,784 | ---- | C] () -- C:\Windows\System32\LFKODAK.DLL
[1997/06/13 17:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
========== LOP Check ========== [2010/07/28 15:31:41 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\2K Sports
[2008/08/13 23:45:31 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\acccore
[2008/08/06 19:03:27 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Aim
[2008/09/20 23:24:53 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Amazon
[2009/08/13 17:35:02 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Anthropics
[2011/06/09 22:25:01 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\AVG10
[2011/05/03 18:37:13 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Braid
[2008/10/07 15:37:59 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Broken Sword 2.5
[2008/08/14 23:05:19 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Canon
[2008/08/20 16:05:42 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\CiscoCAA
[2009/09/28 16:02:48 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\com.fox.dollhouse.VirtualEcho.8DB2FB41E3AF9617470F9C3E78FDAAA51EF66383.1
[2010/01/20 20:15:59 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\FileOpen
[2011/06/09 22:04:20 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\GetRightToGo
[2011/06/09 00:08:36 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\gtk-2.0
[2011/06/09 00:08:36 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\ICAClient
[2009/01/28 00:17:35 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\iWin
[2008/08/12 00:12:27 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Leadertech
[2010/08/22 01:19:31 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\LimeWire
[2009/09/19 02:06:49 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\LucasArts
[2009/03/25 23:10:51 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\MPEG Streamclip
[2008/08/11 23:43:16 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\muvee Technologies
[2011/04/17 16:54:14 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\NCH Swift Sound
[2009/02/12 14:31:26 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Nexon
[2008/10/24 16:01:39 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\ooVoo Details
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\oovooToolbar
[2010/11/15 16:57:15 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\PKWARE
[2010/11/17 21:02:23 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Roaming
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\SystemRequirementsLab
[2010/02/19 15:26:18 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Unity
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\uTorrent
[2009/03/26 09:59:12 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\WinFF
[2011/06/09 00:08:42 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\Xcelsius
[2010/06/25 15:43:14 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\XcelsiuscustomThemes
[2010/06/25 15:43:14 | 000,000,000 | ---D | M] -- C:\Users\Matt Leung\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2011/06/15 17:12:10 | 000,032,642 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/15 16:50:12 | 000,000,428 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{77B5D549-256D-43DA-B957-C1A83D416054}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/10/28 23:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/28 23:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\explorer.exe
[2008/10/28 23:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 20:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/10 23:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 19:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 19:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/01/20 19:23:43 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/20 19:23:43 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >[2008/01/20 19:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/20 19:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >[2009/04/10 23:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 19:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\System32\winlogon.exe
[2008/01/20 19:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/04/14 09:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/04/14 09:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/04/14 09:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" --show-icons [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" --hide-icons [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\system32\ie4uinit.exe" -hide [2008/01/20 19:24:17 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\system32\ie4uinit.exe" -show [2008/01/20 19:24:17 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\system32\ie4uinit.exe" -reinstall [2008/01/20 19:24:17 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/07/18 14:39:09 | 000,634,648 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/04/14 09:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/04/14 09:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/04/14 09:26:03 | 000,711,672 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011/04/14 09:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" --show-icons [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" --hide-icons [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" --make-default-browser [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Users\Matt Leung\AppData\Local\Google\Chrome\Application\chrome.exe" [2011/06/05 22:28:58 | 001,011,768 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\system32\ie4uinit.exe" -hide [2008/01/20 19:24:17 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\system32\ie4uinit.exe" -show [2008/01/20 19:24:17 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\system32\ie4uinit.exe" -reinstall [2008/01/20 19:24:17 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2009/07/18 14:39:09 | 000,634,648 | ---- | M] (Microsoft Corporation)
========== Alternate Data Streams ========== @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:39ECA677
< End of report >