This is my first post here. I sincerely would appreciate any advice or help.
My Norton AntiVirus software has been blocking and quarantining attacks to my computer for several months now. The scale of the attacks in terms of quantity has escalated since May 2011 and this weekend July 2011 the number of attacks reached an unprecedented level.
I went to the "Norton Antivirus Forum Board Community" yesterday and the members of the community were very friendly. At their suggestion, I ran a recommended software, the "Norton Power Eraser" to check for whether a malicious Rootkit was indeed on my computer. The scan worked fine and isolated a possible problem but the "fix" resulted in a error message. This leads me to believe my computer is indeed infected by malware.
I will try to post jpegs of screenshots if possible to this thread.
Thanks in advance for any help
Dan
______________
OTL logfile created on: 7/19/2011 7:35:47 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Users\lordbyroniv\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 46.02% Memory free
6.19 Gb Paging File | 4.34 Gb Available in Paging File | 70.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 285.18 Gb Total Space | 192.33 Gb Free Space | 67.44% Space Free | Partition Type: NTFS
Drive D: | 12.90 Gb Total Space | 2.01 Gb Free Space | 15.61% Space Free | Partition Type: NTFS
Computer Name: PATRICIACOMPU | User Name: lordbyroniv | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/07/19 19:25:15 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\lordbyroniv\Desktop\OTL.exe
PRC - [2011/04/16 20:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
PRC - [2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\System32\NLSSRV32.EXE
PRC - [2011/01/23 10:18:01 | 000,233,936 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/10/07 16:30:26 | 000,656,896 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.4\J2GTray.exe
PRC - [2008/10/07 16:25:48 | 000,095,744 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
PRC - [2008/09/26 06:36:40 | 001,148,200 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2008/09/25 22:42:24 | 000,189,736 | ---- | M] (CyberLink) -- C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2008/09/25 22:41:44 | 001,152,296 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
PRC - [2008/09/24 22:08:26 | 000,296,320 | ---- | M] () -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
PRC - [2008/09/24 22:08:26 | 000,116,096 | ---- | M] () -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
PRC - [2008/09/23 15:18:52 | 000,365,904 | ---- | M] () -- C:\Program Files\SMINST\BLService.exe
PRC - [2008/09/23 15:03:38 | 000,912,688 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
PRC - [2008/09/11 07:52:52 | 000,237,650 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\stacsv.exe
PRC - [2008/09/11 07:50:38 | 000,446,556 | ---- | M] (IDT, Inc.) -- C:\Program Files\IDT\WDM\sttray.exe
PRC - [2008/06/27 11:53:08 | 000,077,824 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe
PRC - [2008/03/17 10:31:40 | 001,331,200 | ---- | M] (ChangeRequest.com) -- C:\Program Files\ChangeRequest\ChangeRequest Screenshot Tool\ScreenCap.exe
PRC - [2008/01/11 18:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/12/11 16:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
========== Modules (SafeList) ==========
MOD - [2011/07/19 19:25:15 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\lordbyroniv\Desktop\OTL.exe
MOD - [2011/06/15 09:26:03 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
MOD - [2011/06/15 09:26:03 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
MOD - [2011/04/28 20:29:01 | 000,413,112 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\5.1.0.29\asOEHook.dll
MOD - [2010/08/31 11:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/06/28 17:24:34 | 003,435,096 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\netsession_win_e477fed.dll -- (Akamai)
SRV - [2011/04/16 20:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe -- (N360)
SRV - [2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\System32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/09/24 22:08:26 | 000,296,320 | ---- | M] () [Auto | Running] -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe -- (TVCapSvc) TV Background Capture Service (TVBCS)
SRV - [2008/09/24 22:08:26 | 000,116,096 | ---- | M] () [Auto | Running] -- C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe -- (TVSched) TV Task Scheduler (TVTS)
SRV - [2008/09/23 15:18:52 | 000,365,904 | ---- | M] () [Auto | Running] -- C:\Program Files\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/09/11 07:52:52 | 000,237,650 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\stacsv.exe -- (STacSV)
SRV - [2008/06/27 11:53:08 | 000,077,824 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe -- (AESTFilters)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/11 18:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2007/12/11 16:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - [2011/07/07 17:01:40 | 000,367,736 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110716.031\IDSvix86.sys -- (IDSVix86)
DRV - [2011/07/02 16:28:34 | 001,542,392 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110719.003\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/07/02 16:28:33 | 000,086,008 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110719.003\NAVENG.SYS -- (NAVENG)
DRV - [2011/05/19 15:37:06 | 000,810,616 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110701.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/05/12 17:30:13 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/05/12 01:00:00 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/05/09 20:30:38 | 000,105,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/03/30 23:00:09 | 000,516,216 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS -- (SRTSP)
DRV - [2011/03/30 23:00:09 | 000,050,168 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011/03/21 20:39:49 | 000,331,384 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS -- (SYMTDIv)
DRV - [2011/03/14 22:31:23 | 000,744,568 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS -- (SymEFA)
DRV - [2011/01/27 02:47:10 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS -- (SymDS)
DRV - [2011/01/27 01:07:05 | 000,136,312 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS -- (SymIRON)
DRV - [2008/09/26 06:36:34 | 000,059,376 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49})
DRV - [2008/09/13 03:13:00 | 007,391,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/09/11 07:54:44 | 000,389,120 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008/08/28 19:48:46 | 003,664,384 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel®
DRV - [2008/08/05 23:29:26 | 000,044,576 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008/07/22 11:42:34 | 000,123,904 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/07/21 06:53:02 | 000,100,184 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2008/04/28 21:54:58 | 000,054,784 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\enecir.sys -- (enecir)
DRV - [2008/03/27 16:12:12 | 000,024,424 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)
DRV - [2008/03/27 16:11:34 | 000,034,664 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2008/02/29 20:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/01/20 22:23:20 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) Intel®
DRV - [2007/06/18 20:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.order.2: ""
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {BFF829B6-B433-42CE-9A19-E459D3E4E483}:3.6.3
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:3.0
FF - prefs.js..extensions.enabledItems: {5911488E-9D1E-40ec-8CBB-06B231CC153F}:2.0
FF - prefs.js..extensions.enabledItems: {f1e6d946-6b44-4f3a-8c4b-e497675c8e17}:1.0.25
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.0.8
FF - prefs.js..extensions.enabledItems: seostatus@rubyweb:1.5.7
FF - prefs.js..extensions.netassistant.keyword.url: "http://click.w3i.com...93&searchterm="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\lordbyroniv\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/07/07 05:29:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_0_8 [2011/07/19 15:50:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/23 17:57:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/23 17:57:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{BFF829B6-B433-42CE-9A19-E459D3E4E483}: C:\Users\lordbyroniv\AppData\Roaming\My.Freeze.com NetAssistant\ [2010/05/19 14:34:11 | 000,000,000 | ---D | M]
[2009/05/17 21:46:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lordbyroniv\AppData\Roaming\mozilla\Extensions
[2011/07/19 12:15:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lordbyroniv\AppData\Roaming\mozilla\Firefox\Profiles\9dy0g3ib.default\extensions
[2009/09/07 22:06:19 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\lordbyroniv\AppData\Roaming\mozilla\Firefox\Profiles\9dy0g3ib.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/02 11:50:16 | 000,000,000 | ---D | M] (StartNow Toolbar) -- C:\Users\lordbyroniv\AppData\Roaming\mozilla\Firefox\Profiles\9dy0g3ib.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011/07/02 11:50:14 | 000,000,000 | ---D | M] (ShopToWin16) -- C:\Users\lordbyroniv\AppData\Roaming\mozilla\Firefox\Profiles\9dy0g3ib.default\extensions\{f1e6d946-6b44-4f3a-8c4b-e497675c8e17}
[2011/07/16 11:16:43 | 000,000,000 | ---D | M] (SEO Status PageRank/Alexa Toolbar) -- C:\Users\lordbyroniv\AppData\Roaming\mozilla\Firefox\Profiles\9dy0g3ib.default\extensions\seostatus@rubyweb
[2011/07/02 11:50:16 | 000,002,264 | ---- | M] () -- C:\Users\lordbyroniv\AppData\Roaming\Mozilla\Firefox\Profiles\9dy0g3ib.default\searchplugins\bing-zugo.xml
[2011/07/19 12:15:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/12 23:04:22 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011/07/19 15:50:00 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\COFFPLGN_2011_7_0_8
[2011/07/07 05:29:44 | 000,000,000 | ---D | M] (Symantec IPS) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPLGN
[2010/05/19 14:34:11 | 000,000,000 | ---D | M] (My.Freeze.com NetAssistant) -- C:\USERS\LORDBYRONIV\APPDATA\ROAMING\MY.FREEZE.COM NETASSISTANT
[2009/03/31 23:47:26 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\mozilla firefox\components\coFFPlgn.dll
[2010/02/15 18:50:42 | 000,120,296 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npganymedenet.dll
O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [dmadmin.exe] File not found
O4 - HKCU..\Run: [eFax 4.4] C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe (j2 Global Communications, Inc.)
O4 - HKCU..\Run: [gpresult.exe] File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe (Adobe Systems, Inc.)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 68.237.161.12
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\lordbyroniv\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\lordbyroniv\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{7aa6baa1-1fc9-11de-993d-002186df3869}\Shell - "" = AutoRun
O33 - MountPoints2\{7aa6baa1-1fc9-11de-993d-002186df3869}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/19 19:25:07 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Users\lordbyroniv\Desktop\OTL.exe
[2011/07/19 16:27:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arca Solutions
[2011/07/18 22:08:41 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\AppData\Local\NPE
[2011/07/18 22:08:21 | 002,558,968 | ---- | C] (Symantec Corporation) -- C:\Users\lordbyroniv\Desktop\NPE.exe
[2011/07/02 17:52:30 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\Desktop\Adobe Acrobat X
[2011/07/02 16:51:29 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\Adobe Photoshop CS5.1
[2011/07/02 16:49:42 | 000,000,000 | ---D | C] -- C:\Program Files\Photoshop
[2011/07/02 11:57:51 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\.thumbnails
[2011/07/02 11:51:09 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\Documents\gegl-0.0
[2011/07/02 11:51:09 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\.gimp-2.6
[2011/07/02 11:50:14 | 000,000,000 | ---D | C] -- C:\Program Files\StartNow Toolbar
[2011/07/02 11:50:04 | 000,000,000 | ---D | C] -- C:\Program Files\Object
[2011/07/02 11:14:35 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/01 18:35:07 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2011/07/01 18:07:47 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\Adobe Illustrator CS5.1
[2011/07/01 17:57:58 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/07/01 17:57:54 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe Download Assistant
[2011/06/23 17:47:39 | 000,000,000 | ---D | C] -- C:\Users\lordbyroniv\Desktop\LOGOS
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/19 19:25:15 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\lordbyroniv\Desktop\OTL.exe
[2011/07/19 17:49:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/19 17:49:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/19 16:29:46 | 000,148,694 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\HomePage MockUp Screenshot.jpg
[2011/07/19 16:27:11 | 000,002,031 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Screencapture Tool.lnk
[2011/07/19 15:55:21 | 000,651,210 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/07/19 15:55:21 | 000,121,692 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/07/19 15:49:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/07/19 15:49:30 | 3218,034,688 | -HS- | M] () -- C:\hiberfil.sys
[2011/07/19 14:32:47 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011/07/19 12:25:38 | 000,253,819 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\SHIFTING UP THROUGHOUT WEBSITE.jpg
[2011/07/19 12:07:02 | 000,291,415 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\GRAY BACKGROUND HOMEPAGE.jpg
[2011/07/18 22:16:07 | 000,829,832 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\Info20110718221257.xml
[2011/07/18 22:12:53 | 000,007,592 | ---- | M] () -- C:\Users\lordbyroniv\AppData\Local\d3d9caps.dat
[2011/07/18 22:08:32 | 002,558,968 | ---- | M] (Symantec Corporation) -- C:\Users\lordbyroniv\Desktop\NPE.exe
[2011/07/18 11:32:53 | 000,094,196 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\GOLD CHART.jpg
[2011/07/16 15:14:45 | 000,020,890 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\Trademark Registration.jpg
[2011/07/14 13:09:42 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForlordbyroniv.job
[2011/07/14 06:46:03 | 000,075,617 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\High_Quality_Thematic_Link_Building_Proposal.pdf
[2011/07/13 21:10:04 | 000,252,479 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\qaz123456.jpg
[2011/07/13 09:50:31 | 003,742,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/07/07 23:15:30 | 001,981,957 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\fb_pages_manual.pdf
[2011/07/07 15:55:14 | 000,008,982 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\250x250.gif
[2011/07/07 15:41:03 | 000,003,020 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\AD22.gif
[2011/07/07 14:26:51 | 000,002,081 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\adbanner.jpg
[2011/07/06 20:17:07 | 000,255,537 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\UNITED STATES TRADEMARK REGISTRATIONS TRADEMARK LIST.pdf
[2011/07/05 22:29:52 | 000,083,998 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\KITCO.jpg
[2011/07/04 18:06:50 | 000,242,113 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\tvla.jpg
[2011/07/02 20:26:31 | 000,045,054 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\stock-photo-antique-statue-of-justice-44354326.jpg
[2011/07/02 18:06:00 | 001,421,969 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\123logo-final-GreenBackground.eps
[2011/07/02 16:50:06 | 000,001,026 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Download Assistant.lnk
[2011/07/02 16:48:28 | 002,487,648 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\AdobeDownloadAssistant.exe
[2011/07/02 09:29:50 | 000,002,260 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\la9.jpg
[2011/07/02 09:15:16 | 000,013,033 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\LA1jpg.jpg
[2011/06/30 18:38:57 | 000,131,934 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\legal.com_identity_proposal.pdf
[2011/06/27 23:03:36 | 007,944,105 | ---- | M] () -- C:\Users\lordbyroniv\Desktop\Full History.mcf
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/19 16:29:46 | 000,148,694 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\HomePage MockUp Screenshot.jpg
[2011/07/19 16:27:11 | 000,002,031 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Screencapture Tool.lnk
[2011/07/19 12:25:38 | 000,253,819 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\SHIFTING UP THROUGHOUT WEBSITE.jpg
[2011/07/19 12:07:02 | 000,291,415 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\GRAY BACKGROUND HOMEPAGE.jpg
[2011/07/18 22:16:04 | 000,829,832 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\Info20110718221257.xml
[2011/07/18 11:32:52 | 000,094,196 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\GOLD CHART.jpg
[2011/07/16 15:15:04 | 000,020,890 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\Trademark Registration.jpg
[2011/07/14 06:46:01 | 000,075,617 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\High_Quality_Thematic_Link_Building_Proposal.pdf
[2011/07/13 21:10:03 | 000,252,479 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\qaz123456.jpg
[2011/07/07 23:15:20 | 001,981,957 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\fb_pages_manual.pdf
[2011/07/07 15:47:00 | 000,008,982 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\250x250.gif
[2011/07/07 15:41:26 | 000,003,020 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\AD22.gif
[2011/07/07 15:39:46 | 000,002,081 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\adbanner.jpg
[2011/07/06 20:17:06 | 000,255,537 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\UNITED STATES TRADEMARK REGISTRATIONS TRADEMARK LIST.pdf
[2011/07/05 22:30:29 | 000,083,998 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\KITCO.jpg
[2011/07/04 18:06:50 | 000,242,113 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\tvla.jpg
[2011/07/02 20:26:44 | 000,045,054 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\stock-photo-antique-statue-of-justice-44354326.jpg
[2011/07/02 18:05:56 | 001,421,969 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\123logo-final-GreenBackground.eps
[2011/07/02 17:20:36 | 000,001,016 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2011/07/02 17:18:54 | 000,000,978 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2011/07/02 17:18:00 | 000,001,071 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2011/07/02 17:16:10 | 000,001,172 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2011/07/02 17:16:00 | 000,001,340 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2011/07/02 16:50:06 | 000,001,038 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
[2011/07/02 16:50:05 | 000,001,026 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Download Assistant.lnk
[2011/07/02 16:48:23 | 002,487,648 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\AdobeDownloadAssistant.exe
[2011/07/02 09:29:50 | 000,002,260 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\la9.jpg
[2011/07/02 09:15:16 | 000,013,033 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\LA1jpg.jpg
[2011/06/30 18:38:52 | 000,131,934 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\legal.com_identity_proposal.pdf
[2011/06/27 23:03:31 | 007,944,105 | ---- | C] () -- C:\Users\lordbyroniv\Desktop\Full History.mcf
[2011/04/12 23:05:19 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/04/09 10:09:21 | 000,000,133 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/04/09 09:34:35 | 000,000,036 | -H-- | C] () -- C:\Windows\System32\f9t.dat
[2011/01/20 13:26:12 | 000,121,326 | ---- | C] () -- C:\Windows\hpoins15.dat
[2011/01/20 13:26:12 | 000,001,037 | ---- | C] () -- C:\Windows\hpomdl15.dat
[2011/01/07 18:29:09 | 000,163,161 | ---- | C] () -- C:\Windows\hpoins29.dat
[2011/01/07 18:29:09 | 000,000,799 | ---- | C] () -- C:\Windows\hpomdl29.dat
[2010/03/27 23:22:10 | 000,000,256 | ---- | C] () -- C:\Windows\System32\pool.bin
[2010/01/29 17:19:04 | 000,029,521 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat
[2010/01/29 17:19:04 | 000,000,022 | ---- | C] () -- C:\Windows\System32\PICSDK.ini
[2010/01/29 17:19:03 | 000,020,910 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat
[2010/01/29 17:19:03 | 000,020,869 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat
[2010/01/29 17:18:35 | 000,049,152 | ---- | C] () -- C:\Windows\StiRegstEng.dll
[2009/09/16 18:27:58 | 000,508,224 | ---- | C] () -- C:\Windows\System32\ICCProfiles.dll
[2009/09/16 17:39:46 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/16 17:39:46 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/08 12:03:34 | 000,023,886 | ---- | C] () -- C:\Users\lordbyroniv\AppData\Local\tmpMRR.JPG
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/06/19 23:45:31 | 000,006,144 | ---- | C] () -- C:\Users\lordbyroniv\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/05 07:28:51 | 000,007,592 | ---- | C] () -- C:\Users\lordbyroniv\AppData\Local\d3d9caps.dat
[2008/10/21 00:44:36 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/21 00:05:06 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2007/06/27 09:00:00 | 001,777,664 | ---- | C] () -- C:\Windows\System32\ZHP1600R.DLL
[2007/06/27 09:00:00 | 000,749,568 | ---- | C] () -- C:\Windows\System32\AGI1600.DLL
[2007/06/27 09:00:00 | 000,352,256 | ---- | C] () -- C:\Windows\System32\zSHP1600.EXE
[2007/06/27 09:00:00 | 000,299,008 | ---- | C] () -- C:\Windows\System32\ZHHP1600.EXE
[2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 003,742,080 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,651,210 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,121,692 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/03/09 05:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2001/11/14 17:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll
========== LOP Check ==========
[2011/07/02 11:14:35 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/07/01 17:57:58 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2010/05/12 22:34:04 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\Data Protection
[2011/03/29 19:09:48 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\Downloaded Installations
[2009/04/04 11:54:40 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\eFax Messenger
[2011/05/14 17:22:39 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\FileZilla
[2010/02/28 18:31:57 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\GanymedeNet
[2009/04/04 11:34:21 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\j2 Global
[2010/01/29 17:21:51 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\Leadertech
[2010/05/19 14:34:11 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\My.Freeze.com NetAssistant
[2011/03/29 19:13:34 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\Nitro PDF
[2011/04/09 09:41:00 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\Stamps.com Internet Postage
[2010/05/17 11:49:47 | 000,000,000 | -HSD | M] -- C:\Users\lordbyroniv\AppData\Roaming\SystemProc
[2010/05/14 09:03:34 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\Tific
[2009/10/06 16:58:43 | 000,000,000 | ---D | M] -- C:\Users\lordbyroniv\AppData\Roaming\webex
[2011/07/19 14:32:50 | 000,032,594 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >