I was going through my program files and noticed "Ask.com" in there. Upon my deletion of the file, Winpatrol began alerting me that an IE Helper was attempting to install itself. I repeatedly denied this installation until I became frustrated with its repetitive alerts, and then I decided to allow the installation, thinking nothing of harm would come of it. (Bad decision) Following this action, whenever using Google.com, I would be redirected to the URL categoriesworld.com. I used Avast's URL blocker to block the site from being accessed, but anytime I use google, it attempts to redirect my browser there. I have scanned with SAS and MBAM, yet nothing was found.
I also attempted to implement the fix from the "How To Fix Google Redirects" thread with no results either.
Any help that can be offered will be greatly appreciated!
Attached is my OTL log.
Edited to add text of the log.
Thanks everyone,
Taylor
OTL logfile created on: 7/3/2011 1:11:31 PM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Users\Taylor\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.21 Gb Available Physical Memory | 42.18% Memory free
5.95 Gb Paging File | 4.42 Gb Available in Paging File | 74.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.59 Gb Total Space | 275.60 Gb Free Space | 60.49% Space Free | Partition Type: NTFS
Drive D: | 10.17 Gb Total Space | 1.37 Gb Free Space | 13.47% Space Free | Partition Type: NTFS
Drive E: | 645.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: MIKEJONES | User Name: Taylor | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/07/03 13:08:48 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Taylor\Desktop\OTL.exe
PRC - [2011/06/30 21:57:41 | 002,424,192 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2011/06/22 23:19:19 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/15 14:53:20 | 000,325,512 | ---- | M] (BillP Studios) -- C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
PRC - [2011/05/10 07:10:58 | 003,459,712 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/03/21 13:56:16 | 001,230,704 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/06/16 16:42:58 | 000,839,680 | ---- | M] () -- C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe
PRC - [2009/09/09 14:26:36 | 001,148,200 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/04/11 00:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/07/03 11:27:12 | 006,266,880 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/01/20 21:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/04/18 10:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
PRC - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
========== Modules (SafeList) ==========
MOD - [2011/07/03 13:08:48 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Taylor\Desktop\OTL.exe
MOD - [2011/05/10 07:10:55 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/31 10:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2009/04/28 10:05:56 | 000,715,264 | ---- | M] (Agnitum Ltd.) -- c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/10 07:10:57 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/04/26 14:55:48 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009/04/28 10:06:06 | 001,195,008 | ---- | M] (Agnitum Ltd.) [Auto | Running] -- C:\Program Files\Agnitum\Outpost Firewall\acs.exe -- (acssrv)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
========== Driver Services (SafeList) ==========
DRV - [2011/05/10 07:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 07:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 07:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 06:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 06:59:44 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2011/05/10 06:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/04/24 17:14:38 | 000,225,856 | ---- | M] (QFX Software Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\keyscrambler.sys -- (KeyScrambler)
DRV - [2011/04/01 05:11:10 | 004,333,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 120(UVC)
DRV - [2010/05/10 13:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/09/05 15:25:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/04/30 17:00:12 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/04/06 11:37:12 | 000,704,384 | ---- | M] (Agnitum Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\SandBox.sys -- (SandBox)
DRV - [2009/02/25 17:59:51 | 004,385,792 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/02/18 17:27:54 | 000,029,208 | ---- | M] (Agnitum Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\afw.sys -- (afw)
DRV - [2009/02/10 16:12:48 | 000,307,224 | ---- | M] (Agnitum Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afwcore.sys -- (afwcore)
DRV - [2008/08/01 19:51:14 | 001,052,704 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008/05/22 21:49:00 | 007,465,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/05/08 05:05:18 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2008/05/08 05:03:18 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2008/01/25 14:02:04 | 000,132,128 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2008/01/25 14:02:02 | 000,140,832 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2007/10/18 10:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/10/12 10:53:10 | 000,013,312 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvsmu.sys -- (nvsmu)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...resario&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...resario&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...resario&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...resario&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://en-US.start2....en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.1
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.1.1
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.0
FF - prefs.js..extensions.enabledItems: [email protected]:4.3.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.1
FF - prefs.js..extensions.enabledItems: OMG@olive:0.6.080510
FF - prefs.js..extensions.enabledItems: {ada4b710-8346-4b82-8199-5de2b400a6ae}:1.9.9.3.1
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: [email protected]:0.2.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.80
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:20110101
FF - prefs.js..extensions.enabledItems: {421d78a0-6f2e-11de-867e-0002a5d5c51b}:1.02
FF - prefs.js..extensions.enabledItems: [email protected]:3.6
FF - prefs.js..extensions.enabledItems: {586bd060-22d6-11de-8c30-0800200c9a66}:3.6.7
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/25 23:15:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/05/17 16:19:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/05/17 23:53:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/05/17 23:53:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/22 23:19:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/18 16:09:34 | 000,000,000 | ---D | M]
[2008/09/01 11:56:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Extensions
[2011/07/03 13:04:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions
[2011/06/17 23:29:30 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/08/16 16:50:19 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/16 16:48:57 | 000,000,000 | ---D | M] (Alabama Crimson Tide) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{421d78a0-6f2e-11de-867e-0002a5d5c51b}
[2010/12/22 11:05:02 | 000,000,000 | ---D | M] (Revelation) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}
[2011/03/22 23:24:21 | 000,000,000 | ---D | M] (ReminderFox) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae}
[2011/06/21 23:49:37 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/05/17 16:23:49 | 000,000,000 | ---D | M] (BitDefender QuickScan) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2010/12/21 00:16:59 | 000,000,000 | ---D | M] (Redirect Remover) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2010/08/16 16:58:44 | 000,000,000 | ---D | M] (BloodFire 3) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\[email protected]
[2010/12/22 11:05:10 | 000,000,000 | ---D | M] (Virtus Search Opt-in) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\[email protected]
[2009/01/22 22:13:12 | 000,000,000 | ---D | M] ("Adblock Filterset.G Updater") -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\filtersetg@updater
[2011/06/06 11:15:59 | 000,000,000 | ---D | M] (KeyScrambler) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\[email protected]
[2010/08/16 17:07:04 | 000,000,000 | ---D | M] ("Override Mozilla Firefox Guidance") -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\OMG@olive
[2011/02/16 23:10:56 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\[email protected]
[2010/12/22 11:05:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\[email protected]\chrome
[2010/12/22 11:05:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\[email protected]\defaults
[2010/12/22 11:05:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\mozapps\extensions
[2011/06/09 22:11:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/03 18:09:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/24 10:26:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/30 10:03:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/04 02:35:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/21 06:44:00 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/09 22:11:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
[2011/04/14 15:44:16 | 000,000,000 | ---D | M] (XULRunner) -- C:\USERS\TAYLOR\APPDATA\LOCAL\{CA1819D2-9216-4F4A-AB57-5A7EFF90595D}
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170634FE}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{C1970C0D-DBE6-4D91-804F-C9C0DE643A57}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\{D40F5E7B-D2CF-4856-B441-CC613EEFFBE3}.XPI
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\TAYLOR\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LOEM8U10.DEFAULT\EXTENSIONS\[email protected]
[2011/06/22 23:19:20 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/06/09 22:11:42 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/07/18 13:19:40 | 002,998,784 | ---- | M] (Tamarack Software, Inc.) -- C:\Program Files\mozilla firefox\plugins\nptgeqplugin.dll
[2007/04/16 12:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2007/03/09 18:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/26 21:29:11 | 000,435,303 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 14982 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit PDF Creator Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CheckPoint Cleanup] File not found
O4 - HKLM..\Run: [DVDAgent] c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [OutpostMonitor] C:\Program Files\Agnitum\Outpost Firewall\op_mon.exe (Agnitum Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [AdobeUpdater] File not found
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O9 - Extra 'Tools' menuitem : &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O20 - AppInit_DLLs: (c:\progra~1\agnitum\outpos~1\wl_hook.dll) - c:\Program Files\Agnitum\Outpost Firewall\wl_hook.dll (Agnitum Ltd.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Taylor\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Taylor\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/05/05 03:45:19 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/01/19 09:47:13 | 000,467,456 | R--- | M] (Obsidian Entertainment, Inc.) - E:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2005/01/19 09:47:13 | 000,000,715 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{8bbffa42-342a-11dd-b8f7-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{8bbffa42-342a-11dd-b8f7-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe -- [2005/01/19 09:47:13 | 000,467,456 | R--- | M] (Obsidian Entertainment, Inc.)
O33 - MountPoints2\{8d5a8d5f-2d4d-11e0-b2f0-001fc6db897f}\Shell - "" = AutoRun
O33 - MountPoints2\{8d5a8d5f-2d4d-11e0-b2f0-001fc6db897f}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/03 13:08:42 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Taylor\Desktop\OTL.exe
[2011/07/02 22:24:52 | 000,000,000 | ---D | C] -- C:\Users\Taylor\Desktop\GooredFix Backups
[2011/07/01 23:07:09 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2011/07/01 12:22:58 | 000,000,000 | ---D | C] -- C:\Users\Taylor\Desktop\Kotor_2_Vista_fix
[2011/07/01 01:49:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/07/01 01:49:51 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011/06/26 11:06:57 | 000,704,384 | ---- | C] (Agnitum Ltd.) -- C:\Windows\System32\drivers\SandBox.sys
[2011/06/26 11:06:32 | 000,000,000 | ---D | C] -- C:\Users\Taylor\{f1b84d14-8e77-4905-855e-0f330230a8e8}
[2011/06/26 11:06:30 | 000,307,224 | ---- | C] (Agnitum Ltd.) -- C:\Windows\System32\drivers\afwcore.sys
[2011/06/26 11:04:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Agnitum
[2011/06/26 11:04:22 | 000,029,208 | ---- | C] (Agnitum Ltd.) -- C:\Windows\System32\drivers\afw.sys
[2011/06/26 11:04:11 | 000,000,000 | ---D | C] -- C:\Program Files\Agnitum
[2011/06/26 11:03:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Agnitum
[2011/06/26 00:32:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
[2011/06/26 00:32:18 | 000,000,000 | ---D | C] -- C:\Program Files\BillP Studios
[2011/06/26 00:32:17 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2011/06/18 13:19:49 | 000,000,000 | ---D | C] -- C:\Users\Taylor\Desktop\4-27 Tornado
[2011/06/10 12:16:40 | 000,000,000 | ---D | C] -- C:\Users\Taylor\AppData\Roaming\Foxit Software
[2011/06/09 22:25:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/06/09 22:24:53 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/06/09 22:24:51 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/06/09 22:16:41 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/06/09 22:12:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/06/06 23:31:53 | 000,000,000 | ---D | C] -- C:\Users\Taylor\Documents\HTML
[2011/06/06 22:38:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/06/06 22:27:01 | 000,000,000 | ---D | C] -- C:\Users\Taylor\AppData\Roaming\WinPatrol
[2011/06/05 12:55:31 | 000,000,000 | ---D | C] -- C:\Users\Taylor\Desktop\Trevor
========== Files - Modified Within 30 Days ==========
[2011/07/03 13:08:48 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Taylor\Desktop\OTL.exe
[2011/07/03 12:46:31 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/03 12:27:23 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/03 12:27:23 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/03 10:32:05 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/07/03 10:30:04 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/03 10:27:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/07/03 10:27:08 | 3085,393,920 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/01 23:51:48 | 000,000,944 | ---- | M] () -- C:\Users\Taylor\Desktop\swkotor2 - Shortcut.lnk
[2011/07/01 01:37:22 | 000,043,520 | ---- | M] () -- C:\Windows\System32\CmdLineExt03.dll
[2011/06/26 21:29:11 | 000,435,303 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/06/18 16:09:34 | 000,001,898 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/18 13:54:45 | 000,595,446 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/18 13:54:45 | 000,101,144 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/18 13:53:37 | 000,005,632 | ---- | M] () -- C:\Users\Taylor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/09 23:01:18 | 000,434,967 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110626-212911.backup
[2011/06/09 22:25:38 | 000,001,670 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/06/06 23:09:02 | 000,020,992 | ---- | M] () -- C:\Windows\jestertb.dll
[2011/06/06 22:38:49 | 000,000,045 | ---- | M] () -- C:\Windows\System32\initdebug.nfo
[2011/06/05 23:42:28 | 337,199,006 | ---- | M] () -- C:\Windows\MEMORY.DMP
========== Files Created - No Company Name ==========
[2011/07/02 22:34:21 | 3085,393,920 | -HS- | C] () -- C:\hiberfil.sys
[2011/07/01 23:51:48 | 000,000,944 | ---- | C] () -- C:\Users\Taylor\Desktop\swkotor2 - Shortcut.lnk
[2011/07/01 01:37:22 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2011/06/26 11:04:23 | 000,000,049 | ---- | C] () -- C:\Windows\transp.gif
[2011/06/18 16:09:34 | 000,001,898 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/18 16:09:34 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/09 22:25:38 | 000,001,670 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/06/06 23:09:02 | 000,020,992 | ---- | C] () -- C:\Windows\jestertb.dll
[2011/06/06 22:38:33 | 000,000,045 | ---- | C] () -- C:\Windows\System32\initdebug.nfo
[2011/05/23 02:11:56 | 000,004,984 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2011/04/01 05:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2011/04/01 05:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2011/04/01 05:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2011/04/01 04:56:00 | 000,027,872 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2010/11/30 09:28:52 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/11/30 09:26:09 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/11/30 09:26:09 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/11/29 21:35:10 | 000,007,944 | ---- | C] () -- C:\Users\Taylor\AppData\Local\d3d9caps.dat
[2010/11/09 22:46:45 | 000,815,104 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/11/09 22:46:45 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/11/09 22:42:31 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/04/25 23:14:46 | 000,023,113 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/04/25 22:58:45 | 000,077,377 | ---- | C] () -- C:\Windows\hpqins05.dat
[2010/02/22 01:22:47 | 000,139,336 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/02/22 00:53:00 | 000,214,720 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/02/22 00:52:52 | 002,373,712 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2010/02/22 00:52:52 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/05/08 11:13:04 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/04/30 17:00:12 | 000,025,624 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/01/22 19:23:53 | 000,162,304 | ---- | C] () -- C:\Windows\System32\ztvunrar36.dll
[2009/01/22 19:23:53 | 000,077,312 | ---- | C] () -- C:\Windows\System32\ztvunace26.dll
[2009/01/13 17:21:05 | 000,005,632 | ---- | C] () -- C:\Users\Taylor\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/08 14:25:27 | 000,181,944 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2009/01/04 22:33:47 | 000,055,714 | ---- | C] () -- C:\Windows\War3Unin.dat
[2008/10/21 11:40:00 | 000,081,920 | ---- | C] () -- C:\Windows\System32\ATIODE.exe
[2008/10/21 11:40:00 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ATIODCLI.exe
[2008/09/01 17:51:04 | 000,165,447 | ---- | C] () -- C:\Windows\hpoins28.dat
[2008/08/31 21:16:01 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2008/07/31 23:47:27 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/07/31 23:15:27 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008/06/11 09:02:34 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008/06/11 09:02:32 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2008/06/05 08:58:26 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008/05/11 22:49:03 | 000,000,796 | ---- | C] () -- C:\Windows\hpomdl28.dat
[2008/05/05 03:45:32 | 000,691,481 | ---- | C] () -- C:\Windows\unins000.exe
[2008/05/05 03:45:32 | 000,001,446 | ---- | C] () -- C:\Windows\unins000.dat
[2008/05/05 03:25:32 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2008/05/05 03:25:32 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,410,760 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,595,446 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,101,144 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2003/09/08 20:30:31 | 000,011,376 | R--- | C] () -- C:\Windows\System32\drivers\secdrv.sys
[1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys
========== LOP Check ==========
[2010/12/01 02:08:38 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\.minecraft
[2010/12/23 02:46:05 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\Auslogics
[2011/01/21 15:34:26 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\calibre
[2010/09/27 00:54:02 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\fltk.org
[2011/06/10 12:16:40 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\Foxit Software
[2008/09/14 21:34:54 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\LucasArts
[2011/05/20 11:43:09 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\OpenDNS Updater
[2011/05/19 16:07:30 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\QFX Software
[2011/04/17 19:29:50 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\QuickScan
[2008/08/31 18:18:17 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\Snapfish
[2009/04/15 04:07:37 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\SoundSpectrum
[2009/03/29 20:47:41 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\WinBatch
[2011/06/06 22:27:01 | 000,000,000 | ---D | M] -- C:\Users\Taylor\AppData\Roaming\WinPatrol
[2011/07/03 01:43:02 | 000,032,628 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Attached Files
Edited by Uataylor, 03 July 2011 - 04:31 PM.