Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

More Google Redirects...


  • Please log in to reply

#1
ShannonL73

ShannonL73

    New Member

  • Member
  • Pip
  • 3 posts
I ran all OTM, rootkiller thingy - basically I did everything in the help section and I'm still having issues.

If I click a direct link, it works fine. If I search in google for something (I've tried in both explorer and firefox) then click a link from the search results it either keeps reloading the search page or takes me through a string of redirect sites - the latest being some Jewish Lung organization...If I click the back button a few times, it usually brings me to the page I wanted to begin with.

This is the OTM log (is it supposed to be this long??)

OTL logfile created on: 9/1/2011 8:10:44 PM - Run 2
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Users\Shannon\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.86 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 38.45% Memory free
5.73 Gb Paging File | 2.98 Gb Available in Paging File | 52.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.34 Gb Total Space | 227.15 Gb Free Space | 80.17% Space Free | Partition Type: NTFS

Computer Name: SHANNON-PC | User Name: Shannon | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2011/09/01 20:10:17 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\Shannon\Downloads\OTL(1).exe
PRC - [2011/09/01 06:33:43 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/19 00:29:42 | 004,484,952 | ---- | M] () -- C:\Program Files (x86)\bfgclient\bfgclient.exe
PRC - [2011/07/05 18:05:57 | 000,058,288 | ---- | M] (Absolute Software Corp.) -- C:\Windows\SysWOW64\rpcnet.exe
PRC - [2011/04/18 17:40:08 | 002,334,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgtray.exe
PRC - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
PRC - [2011/01/05 13:11:04 | 004,321,112 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AIM\aim.exe
PRC - [2010/10/08 11:01:14 | 000,086,184 | ---- | M] (Absolute Software) -- C:\Program Files (x86)\Absolute Software\Absolute Notifier\AbsoluteNotifier.exe
PRC - [2010/10/08 11:01:14 | 000,010,408 | ---- | M] (Microsoft) -- C:\Program Files (x86)\Absolute Software\Absolute Notifier\AbsoluteNotifierService.exe
PRC - [2010/09/03 02:45:02 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe
PRC - [2010/08/20 19:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2010/08/09 10:32:50 | 000,139,944 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
PRC - [2010/08/09 10:32:48 | 000,770,728 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
PRC - [2010/07/21 12:36:02 | 000,783,680 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2010/02/09 14:34:00 | 001,807,680 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/10/15 04:10:28 | 000,498,160 | ---- | M] () -- C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/10/01 00:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/10/01 00:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/06/24 17:21:38 | 000,409,744 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
PRC - [2009/06/09 10:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- c:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe


========== Modules (No Company Name) ==========

MOD - [2011/09/01 06:33:41 | 001,846,232 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/08/19 00:29:44 | 001,535,320 | ---- | M] () -- C:\Program Files (x86)\bfgclient\bfgcommon.dll
MOD - [2011/08/19 00:29:42 | 004,484,952 | ---- | M] () -- C:\Program Files (x86)\bfgclient\bfgclient.exe
MOD - [2011/08/11 06:42:40 | 000,997,888 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\7cc7d753f499e27b4bd8a45c3e81c73e\System.Management.ni.dll
MOD - [2011/08/11 06:37:53 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\9875d60b4fda5bbda499e9286e12bdb4\System.Web.Services.ni.dll
MOD - [2011/08/11 06:37:45 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\456d5e9d3a0a37697ab28c150e9ac5b7\System.Runtime.Remoting.ni.dll
MOD - [2011/08/11 06:37:17 | 012,431,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad9c2f4737e1e07fa774af31a7d74235\System.Windows.Forms.ni.dll
MOD - [2011/08/11 06:37:10 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eba4ec48e3f7f16864c6d96f510fafd9\System.Drawing.ni.dll
MOD - [2011/08/11 06:36:50 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\155679a9c8991cc33f90d6b27bac1977\System.Xml.ni.dll
MOD - [2011/08/11 06:36:46 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\0bddc91cbf37d143f08f6684b2919566\System.Configuration.ni.dll
MOD - [2011/08/11 06:36:45 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\610374fef100556da252243e673ac64b\System.ni.dll
MOD - [2011/08/11 06:36:38 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\23bc3936180ff789f44259a211dfc7fc\mscorlib.ni.dll
MOD - [2011/08/05 19:28:06 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\bfgclient\zlib1.dll
MOD - [2011/06/28 17:53:05 | 006,271,136 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
MOD - [2011/01/05 13:06:43 | 000,176,128 | ---- | M] () -- C:\Program Files (x86)\AIM\nssckbi.dll
MOD - [2010/11/17 14:16:56 | 000,067,872 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010/08/09 10:32:50 | 000,139,944 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
MOD - [2010/08/09 10:32:48 | 000,770,728 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
MOD - [2010/07/21 12:36:02 | 000,783,680 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2010/07/21 12:34:20 | 000,079,168 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
MOD - [2010/07/21 12:34:00 | 000,075,072 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
MOD - [2010/07/21 12:33:58 | 000,111,936 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
MOD - [2010/07/21 12:33:52 | 000,121,152 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
MOD - [2010/07/21 12:33:50 | 000,128,320 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
MOD - [2010/07/21 12:33:46 | 000,234,816 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
MOD - [2010/07/21 12:33:22 | 001,123,648 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll
MOD - [2010/04/01 13:24:28 | 001,159,168 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleadrs.dll
MOD - [2010/04/01 13:23:27 | 000,389,120 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleascw.dll
MOD - [2010/02/09 14:34:00 | 001,807,680 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
MOD - [2010/02/09 14:34:00 | 000,275,776 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll
MOD - [2010/02/09 14:34:00 | 000,152,896 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll
MOD - [2010/02/09 14:34:00 | 000,095,552 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll
MOD - [2010/02/09 14:34:00 | 000,058,688 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll
MOD - [2010/02/09 14:34:00 | 000,017,728 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll
MOD - [2009/11/26 04:49:41 | 000,086,180 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\DLEAcfg.dll
MOD - [2009/10/15 04:10:28 | 000,498,160 | ---- | M] () -- C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2009/06/22 09:08:44 | 000,196,608 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epoemdll.dll
MOD - [2009/06/22 09:08:43 | 000,045,056 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epstring.dll
MOD - [2009/06/22 09:08:41 | 002,203,648 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epwizres.dll
MOD - [2009/06/22 09:08:27 | 000,708,608 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epwizard.dll
MOD - [2009/06/22 09:06:32 | 000,159,744 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\customui.dll
MOD - [2009/06/22 09:06:09 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\epfunct.dll
MOD - [2009/06/22 09:06:03 | 000,114,688 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\eputil.dll
MOD - [2009/06/22 09:05:49 | 000,139,264 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\imagutil.dll
MOD - [2009/05/27 08:16:50 | 000,192,512 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleadatr.dll
MOD - [2009/04/07 15:25:27 | 000,409,600 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\iptk.dll
MOD - [2009/03/10 01:43:49 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleacaps.dll
MOD - [2009/03/05 13:55:33 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleacnv4.dll
MOD - [2009/03/02 10:25:47 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Dell V310-V510 Series\dleaptp.dll
MOD - [2009/02/20 04:50:18 | 000,028,672 | ---- | M] () -- C:\Windows\SysWOW64\DLEAsmr.dll
MOD - [2009/02/20 04:49:37 | 000,299,008 | ---- | M] () -- C:\Windows\SysWOW64\DLEAsm.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/14 14:01:38 | 000,245,352 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV:64bit: - [2011/04/14 14:01:38 | 000,200,056 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2011/04/14 14:01:38 | 000,149,032 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2010/10/07 21:34:28 | 000,509,416 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/05/21 18:20:07 | 001,052,328 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\dleacoms.exe -- (dlea_device)
SRV:64bit: - [2010/05/21 18:20:02 | 000,045,224 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dleaserv.exe -- (dleaCATSCustConnectService)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2010/03/10 11:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2009/12/29 15:19:12 | 000,873,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009/11/17 22:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2009/06/09 10:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2011/07/05 18:05:57 | 000,058,288 | ---- | M] (Absolute Software Corp.) [Auto | Running] -- C:\Windows\SysWOW64\rpcnet.exe -- (rpcnet) Remote Procedure Call (RPC)
SRV - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/10/27 08:47:46 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2010/10/08 11:01:14 | 000,010,408 | ---- | M] (Microsoft) [Auto | Running] -- C:\Program Files (x86)\Absolute Software\Absolute Notifier\AbsoluteNotifierService.exe -- (AbsoluteNotifier)
SRV - [2010/09/03 02:45:02 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe -- (McComponentHostService)
SRV - [2010/08/20 19:53:08 | 000,689,472 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE -- (SftService)
SRV - [2010/05/21 18:19:52 | 000,598,696 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysWow64\dleacoms.exe -- (dlea_device)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/10/01 00:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2009/10/01 00:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/05/21 09:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- c:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/04/14 21:28:24 | 000,118,864 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV:64bit: - [2011/04/14 14:01:38 | 000,530,304 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,441,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2011/04/14 14:01:38 | 000,283,744 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,190,520 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,121,376 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,094,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:64bit: - [2011/04/14 14:01:38 | 000,075,160 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,063,056 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2011/04/05 00:59:54 | 000,377,936 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2011/03/16 16:03:18 | 000,037,456 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2011/03/11 02:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/01 14:25:18 | 000,041,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2011/02/22 08:12:46 | 000,026,704 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV:64bit: - [2011/02/10 07:53:34 | 000,029,264 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV:64bit: - [2011/01/07 06:41:44 | 000,304,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2010/09/28 16:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/09/23 01:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/05/07 15:19:58 | 000,245,792 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/05/07 06:44:32 | 000,321,584 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/04/01 10:47:10 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/03/30 23:58:06 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010/03/30 23:58:06 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010/03/30 23:58:06 | 000,053,800 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btusbflt.sys -- (btusbflt)
DRV:64bit: - [2010/03/30 23:58:06 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010/03/30 23:58:06 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/03/03 23:51:40 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/02/27 11:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010/02/04 01:38:32 | 000,271,872 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2010/02/03 09:13:06 | 003,058,168 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/02/02 18:13:08 | 000,020,984 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcmvwl64.sys -- (BcmVWL)
DRV:64bit: - [2009/12/22 13:18:50 | 000,074,280 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2009/09/17 16:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/09 04:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/15 14:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...039&form=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = g.msn.com/USCON/1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.608
FF - prefs.js..keyword.URL: "http://www.bing.com/...form=ZGAADF&q="


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/08/30 07:19:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2011/08/28 17:38:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/01 06:33:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/08/28 18:41:36 | 000,000,000 | ---D | M]

[2010/11/26 15:11:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Shannon\AppData\Roaming\Mozilla\Extensions
[2011/05/05 21:39:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Shannon\AppData\Roaming\Mozilla\Firefox\Profiles\ib13br2q.default\extensions
[2011/03/04 17:50:28 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Users\Shannon\AppData\Roaming\Mozilla\Firefox\Profiles\ib13br2q.default\extensions\[email protected]
[2011/02/12 11:37:43 | 000,001,919 | ---- | M] () -- C:\Users\Shannon\AppData\Roaming\Mozilla\Firefox\Profiles\ib13br2q.default\searchplugins\bing-zugo.xml
[2011/05/11 17:32:10 | 000,001,385 | ---- | M] () -- C:\Users\Shannon\AppData\Roaming\Mozilla\Firefox\Profiles\ib13br2q.default\searchplugins\product-seeker-search.xml
[2011/08/28 14:29:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/11/26 18:24:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/28 11:46:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/08/28 14:29:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/09/01 06:33:44 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2010/12/12 14:28:19 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\NPcol400.dll
[2010/12/12 14:28:19 | 000,466,944 | ---- | M] (Catalina Marketing Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\NPcol500.dll
[2009/11/19 18:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/19 05:05:25 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 18:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/05/05 22:33:46 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/05/19 14:54:50 | 000,001,949 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2011/08/28 18:38:18 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\mcafee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20110513075414.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Dell Toolbar) - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll ()
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\mcafee\MSK\mskapbho.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20110513075414.dll (McAfee, Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Dell Toolbar) - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4:64bit: - HKLM..\Run: [dleamon.exe] C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe ()
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Absolute Notifier] C:\Program Files (x86)\Absolute Software\Absolute Notifier\AbsoluteNotifier.exe (Absolute Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Dell V310-V510 Series] C:\Program Files (x86)\Dell V310-V510 Series\fm3032.exe ()
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] c:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKLM..\RunOnce: [DSUpdateLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe (Dell)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe (Softthinks)
O4 - Startup: C:\Users\Shannon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9:64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6C26413C-6017-4E44-87FC-6B5E26EC8459}: DhcpNameServer = 192.168.1.1 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B1E7614A-27B8-402B-9283-CA5039282806}: DhcpNameServer = 192.168.1.1 209.18.47.61 209.18.47.62
O18:64bit: - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart) - C:\Program Files (x86)\AVG\AVG10\avgrsa.exe (AVG Technologies CZ, s.r.o.)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/01 17:40:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/08/28 18:59:18 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/08/28 18:52:28 | 000,000,000 | ---D | C] -- C:\Users\Shannon\Desktop\GooredFix Backups
[2011/08/28 18:37:58 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/08/28 17:40:21 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\AVG10
[2011/08/28 17:38:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2011
[2011/08/28 17:38:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG
[2011/08/28 17:36:47 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2011/08/28 17:36:47 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG
[2011/08/28 17:35:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2011/08/28 17:31:37 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2011/08/28 17:31:25 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2011/08/28 14:29:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/08/28 11:03:43 | 000,000,000 | ---D | C] -- C:\Users\Shannon\Desktop\Killer
[2011/08/28 10:54:10 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\RegistryKeys
[2011/08/28 10:47:34 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/08/27 14:05:19 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\PeaceCraft2
[2011/08/27 14:03:09 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Kingdom for the Princess II
[2011/08/27 14:03:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My Kingdom for the Princess II
[2011/08/27 14:03:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Kingdom for the Princess II
[2011/08/23 18:49:04 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Youda Fisherman Survey
[2011/08/23 18:49:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Youda Fisherman Survey
[2011/08/23 18:49:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Youda Fisherman Survey
[2011/08/20 13:28:57 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Twilight Games
[2011/08/18 20:06:46 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Private Moon Studios
[2011/08/18 19:23:23 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\RobinsonCrusoe
[2011/08/16 19:24:23 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Local\MLS2
[2011/08/15 19:21:42 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\cerasus.media
[2011/08/15 19:21:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World's Best Board Games 2009
[2011/08/15 19:21:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\World's Best Board Games 2009
[2011/08/14 20:17:11 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\MA
[2011/08/14 19:22:09 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\NatGeoGames
[2011/08/14 19:22:09 | 000,000,000 | ---D | C] -- C:\ProgramData\NatGeoGames
[2011/08/14 13:44:53 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\AlawarSouthpoint
[2011/08/14 13:44:53 | 000,000,000 | ---D | C] -- C:\ProgramData\AlawarSouthpoint
[2011/08/14 13:12:37 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Game Mill Entertainment
[2011/08/14 10:51:48 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Floodlight Games
[2011/08/14 10:51:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Floodlight Games
[2011/08/13 21:03:20 | 000,000,000 | -H-D | C] -- C:\ProgramData\Rpcnet
[2011/08/12 19:36:52 | 000,000,000 | ---D | C] -- C:\ProgramData\CrioGames
[2011/08/06 14:39:22 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Alawar Entertainment
[2011/08/03 13:48:38 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Path To Success
[2011/08/03 13:48:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Path To Success
[2011/08/03 13:48:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Path To Success
[2011/08/03 09:18:46 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\Funzai!
[2011/08/03 08:59:29 | 000,000,000 | ---D | C] -- C:\Users\Shannon\AppData\Roaming\IBU_ST
[2010/12/10 19:03:50 | 005,943,480 | ---- | C] (Absolute Software Corp. ) -- C:\Users\Shannon\AppData\Roaming\LoJackSetup.exe
[2010/12/06 15:35:34 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\dleapmui.dll
[2010/12/06 15:35:34 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dleainpa.dll
[2010/12/06 15:35:34 | 000,344,064 | ---- | C] ( ) -- C:\Windows\SysWow64\dleaiesc.dll
[2010/12/06 15:35:32 | 001,048,576 | ---- | C] ( ) -- C:\Windows\SysWow64\dleaserv.dll
[2010/12/06 15:35:32 | 000,847,872 | ---- | C] ( ) -- C:\Windows\SysWow64\dleausb1.dll
[2010/12/06 15:35:32 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\dlealmpm.dll
[2010/12/06 15:35:31 | 000,802,816 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacomc.dll
[2010/12/06 15:35:31 | 000,688,128 | ---- | C] ( ) -- C:\Windows\SysWow64\dleahbn3.dll
[2010/12/06 15:35:31 | 000,598,696 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacoms.exe
[2010/12/06 15:35:31 | 000,372,736 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacomm.dll
[2010/12/06 15:35:31 | 000,324,264 | ---- | C] ( ) -- C:\Windows\SysWow64\dleaih.exe
[2010/12/06 15:35:30 | 000,373,416 | ---- | C] ( ) -- C:\Windows\SysWow64\dleacfg.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Shannon\AppData\Local\*.tmp files -> C:\Users\Shannon\AppData\Local\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/01 19:36:02 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/01 17:49:02 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/01 17:49:02 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/01 17:46:08 | 130,752,495 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/09/01 17:39:45 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/01 17:39:25 | 000,058,288 | ---- | M] (Absolute Software Corp.) -- C:\Windows\SysWow64\rpcnet.dll
[2011/09/01 17:39:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/01 17:39:03 | 2306,211,840 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/01 06:34:13 | 000,002,014 | ---- | M] () -- C:\Users\Shannon\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/08/31 19:46:52 | 000,002,030 | -H-- | M] () -- C:\Users\Shannon\Documents\Default.rdp
[2011/08/28 18:38:18 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2011/08/28 17:38:28 | 000,000,915 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/08/28 17:38:25 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/08/28 17:38:25 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/08/27 14:03:57 | 000,002,051 | ---- | M] () -- C:\Users\Public\Desktop\Play My Kingdom for the Princess II.lnk
[2011/08/27 14:03:57 | 000,001,290 | ---- | M] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2011/08/24 07:58:16 | 000,730,320 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/08/24 07:58:16 | 000,627,082 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/08/24 07:58:16 | 000,107,366 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/08/23 18:49:12 | 000,001,995 | ---- | M] () -- C:\Users\Public\Desktop\Play Youda Fisherman Survey.lnk
[2011/08/20 19:46:54 | 000,001,226 | ---- | M] () -- C:\Users\Public\Desktop\Preview Hidden Expedition - Amazon.lnk
[2011/08/15 19:21:29 | 000,001,126 | ---- | M] () -- C:\Users\Public\Desktop\World's Best Board Games 2009.lnk
[2011/08/14 10:45:34 | 000,186,460 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Shannon\AppData\Local\*.tmp files -> C:\Users\Shannon\AppData\Local\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/01 17:46:08 | 130,752,495 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/08/28 17:38:28 | 000,000,915 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2011/08/28 17:38:25 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/08/28 17:38:25 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/08/27 14:03:57 | 000,002,051 | ---- | C] () -- C:\Users\Public\Desktop\Play My Kingdom for the Princess II.lnk
[2011/08/27 14:03:57 | 000,001,290 | ---- | C] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2011/08/23 18:49:12 | 000,001,995 | ---- | C] () -- C:\Users\Public\Desktop\Play Youda Fisherman Survey.lnk
[2011/08/20 19:46:54 | 000,001,226 | ---- | C] () -- C:\Users\Public\Desktop\Preview Hidden Expedition - Amazon.lnk
[2011/08/15 19:21:29 | 000,001,126 | ---- | C] () -- C:\Users\Public\Desktop\World's Best Board Games 2009.lnk
[2011/08/14 10:45:34 | 000,186,460 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/07/16 22:18:41 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/07/12 16:36:53 | 000,743,534 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/06/15 17:51:21 | 000,000,000 | ---- | C] () -- C:\Users\Shannon\AppData\Local\{51774798-511B-4E04-81D8-8E0511BEC012}
[2011/05/23 11:06:28 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/05/23 11:06:28 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/05/18 16:20:10 | 000,011,994 | -HS- | C] () -- C:\Users\Shannon\AppData\Local\ukkbx3ej241h1wi32l5g40826jf48s6a3jj
[2011/05/18 16:20:10 | 000,011,994 | -HS- | C] () -- C:\ProgramData\ukkbx3ej241h1wi32l5g40826jf48s6a3jj
[2010/12/10 19:03:20 | 000,000,046 | ---- | C] () -- C:\Users\Shannon\AppData\Roaming\FactoryInstaller.xml
[2010/12/09 17:35:40 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/06 15:35:35 | 000,331,776 | ---- | C] () -- C:\Windows\SysWow64\DLEAinst.dll
[2010/12/06 15:35:34 | 000,344,064 | ---- | C] () -- C:\Windows\SysWow64\dleacomx.dll
[2010/12/06 15:35:34 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dleainsr.dll
[2010/12/06 15:35:34 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\dleajswr.dll
[2010/12/06 15:35:34 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dleacur.dll
[2010/12/06 15:35:33 | 000,323,584 | ---- | C] () -- C:\Windows\SysWow64\dleains.dll
[2010/12/06 15:35:33 | 000,262,144 | ---- | C] () -- C:\Windows\SysWow64\dleainsb.dll
[2010/12/06 15:35:33 | 000,253,952 | ---- | C] () -- C:\Windows\SysWow64\dleacu.dll
[2010/12/06 15:35:33 | 000,090,112 | ---- | C] () -- C:\Windows\SysWow64\dleacub.dll
[2010/12/06 15:35:30 | 000,086,180 | ---- | C] () -- C:\Windows\SysWow64\DLEAcfg.dll
[2010/12/06 15:34:46 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\DLEAsmr.dll
[2010/12/06 15:34:45 | 000,299,008 | ---- | C] () -- C:\Windows\SysWow64\DLEAsm.dll
[2010/11/30 23:17:28 | 000,000,019 | ---- | C] () -- C:\Windows\popcinfo.dat
[2010/10/27 11:07:47 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010/10/27 11:07:47 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/10/27 11:07:47 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/10/27 11:07:47 | 000,104,636 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010/10/27 11:07:45 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010/10/27 09:09:49 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/03/07 21:48:49 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\1morebee
[2010/12/07 13:29:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\2monkeys
[2011/02/25 16:18:39 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\A Gypsy's Tale - The Tower of Secrets
[2010/12/10 19:07:52 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Absolute
[2010/12/16 11:07:32 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Absolute Software
[2010/12/06 14:04:31 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\acccore
[2011/05/20 19:26:29 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Aerohills
[2011/01/15 12:22:26 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Aisle 5 Games, Inc
[2011/05/26 16:46:30 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Alawar
[2011/08/06 14:39:22 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Alawar Entertainment
[2011/08/14 13:44:53 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\AlawarSouthpoint
[2011/02/25 18:27:14 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\AlderGames
[2011/03/30 20:09:16 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\aliasworlds
[2011/06/18 11:14:31 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Anarchy
[2011/01/27 22:55:54 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Anvate Games
[2011/07/28 06:55:16 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Artifex Mundi
[2011/08/12 17:10:11 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Artogon
[2011/01/18 18:41:29 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Aveyond 3
[2011/08/28 17:40:21 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\AVG10
[2011/06/23 18:43:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Awem
[2011/05/14 17:07:23 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Az-Art
[2011/02/28 23:08:44 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Big Fish Games
[2010/12/16 20:41:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\BlamGames
[2011/01/04 13:54:11 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\BLG
[2011/08/03 09:54:13 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Blue Tea Games
[2011/08/07 16:15:10 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Boolat Games
[2011/08/26 19:46:49 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Boomzap
[2011/01/17 10:52:54 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Casual Arts
[2010/12/12 14:28:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Catalina Marketing Corp
[2011/01/13 15:40:38 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\CatmoonGames
[2011/07/16 22:18:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\CattaleGames
[2011/08/15 19:21:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\cerasus.media
[2011/05/15 15:54:21 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Colibri Games
[2011/05/30 16:27:34 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Crown
[2011/03/13 17:14:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\CursedOnboard
[2011/06/19 12:04:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\DailyMagic
[2011/01/15 15:21:45 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\DarkParablesBriarRose_BFG
[2011/01/06 09:05:37 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Dekovir
[2011/03/28 21:13:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\DGform
[2011/08/14 13:56:53 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\DivoGames
[2011/05/31 10:51:54 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\DragonsEye Studios
[2011/02/18 16:22:16 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Dying for Daylight
[2011/02/18 15:29:46 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Dying for Daylight Shared
[2011/07/01 22:01:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\EleFun Games
[2011/08/06 16:54:57 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Elephant Games
[2011/05/14 09:21:37 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Enki Games
[2011/04/07 17:39:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Enlightenus2_BFG
[2011/02/28 00:31:15 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ERS G-Studio
[2011/08/11 19:43:46 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ERS Game Studios
[2010/12/18 15:12:19 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Fabulous Finds
[2011/01/13 11:24:41 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Farm Mania
[2011/03/20 19:05:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Farm Mania 2.1
[2011/02/20 14:17:38 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\FarmerJane
[2011/07/02 21:18:44 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\fillup
[2011/08/14 10:51:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Floodlight Games
[2011/01/30 18:14:54 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\FlyWheelGames
[2011/08/13 21:02:00 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Freeze Tag
[2011/02/24 14:19:13 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\freshgames
[2011/07/26 20:00:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Friday's games
[2011/01/18 16:14:07 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\FriendsGamesNetwork
[2011/07/16 10:23:40 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Frogwares
[2010/12/07 20:38:05 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Fugazo
[2011/04/20 19:45:24 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Funlinker
[2011/04/30 13:59:36 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Funswitch
[2011/08/03 09:18:46 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Funzai!
[2011/02/23 15:23:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Fuzzy Bug Interactive
[2011/04/15 21:08:18 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\G-HeadGames
[2011/08/14 13:12:37 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Game Mill Entertainment
[2011/08/14 12:06:05 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\GameInvest
[2011/08/09 19:15:23 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\GameMill Entertainment
[2011/02/09 19:18:51 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Gamers Digital
[2010/12/09 23:54:32 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\GamesCafe
[2011/02/26 21:55:49 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\GAMESHASTRA
[2011/02/27 20:09:54 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\GAMGO
[2011/01/30 16:47:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Ghost Ship Studios
[2011/08/09 21:47:08 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Gogii
[2011/07/12 14:28:22 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Gogii Games
[2011/02/08 20:38:24 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\GoldSunGames
[2011/01/16 18:11:25 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Green Clover Games
[2011/04/23 15:01:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Happy Muffin Top
[2011/03/23 11:25:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Happyville__
[2011/08/23 19:49:47 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\HdO Adventure
[2011/07/03 17:04:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\HiT-MM
[2011/05/24 14:15:59 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\HitPoint Studios
[2011/03/01 21:42:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\IBAGroup
[2011/08/03 08:59:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\IBU_ST
[2011/01/14 23:42:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\InImages
[2011/01/24 10:35:19 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Islands
[2011/06/20 18:47:29 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Islands2
[2011/06/04 16:59:25 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\iWin
[2010/12/09 12:55:55 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Jane s Hotel 3
[2011/07/23 14:34:47 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Jetdogs Studios
[2011/01/25 18:01:10 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\kingdom
[2011/02/23 16:27:01 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Ladia Group
[2011/05/24 19:13:00 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Lazy Turtle Games
[2011/07/29 14:51:40 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\LestaStudio
[2011/01/20 18:01:18 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\LittleGamesCompany
[2011/08/14 20:17:15 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\MA
[2011/03/10 22:59:09 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\MA2
[2011/01/06 14:44:56 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Magic Academy 2
[2011/04/01 19:04:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\MagicIndie
[2011/05/11 11:32:57 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Manifesto Games
[2011/03/05 10:44:24 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\margrave3_full
[2011/04/09 09:39:17 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\margrave3_se
[2011/06/28 19:49:05 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Mariaglorum
[2011/05/26 18:34:52 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Maximize Games
[2011/08/21 00:14:23 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Meridian93
[2011/06/06 22:57:28 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Merscom
[2011/07/01 17:35:46 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\MoMB_Full_Eng
[2011/05/09 19:34:30 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Monkey Barrel Games
[2011/05/27 15:47:13 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\MumboJumbo
[2011/02/07 18:16:41 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Muse
[2011/01/27 18:44:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\My Games
[2011/02/26 12:43:08 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Mystery of Mortlake Mansion
[2011/06/24 20:08:31 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Namco
[2011/08/14 19:22:09 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\NatGeoGames
[2011/06/02 17:55:15 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\NevoSoft
[2011/02/10 13:12:36 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Nevosoft-Breeze
[2011/02/24 15:22:00 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Nucleosys
[2011/06/25 16:13:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\OpenCandy
[2011/06/17 20:49:04 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Orneon
[2011/07/06 19:19:50 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\PathToSuccess
[2010/11/30 13:09:05 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Peace Craft
[2011/08/27 14:42:16 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\PeaceCraft2
[2011/04/22 22:46:20 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Ph03nixNewMedia
[2011/01/07 09:27:06 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Phantasmat_bf_ce1
[2011/07/24 18:07:33 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Phantasmat_bf_se1
[2011/06/16 18:58:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Pi Eye Games
[2011/07/12 18:39:40 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Picsoft
[2011/08/20 20:01:09 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\playfirst
[2011/06/19 13:53:04 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\playmink
[2011/02/09 21:33:47 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Pogo Games
[2011/08/18 20:06:46 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Private Moon Studios
[2011/04/12 19:52:58 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\QB9
[2011/08/28 10:54:10 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\RegistryKeys
[2011/08/18 19:24:01 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\RobinsonCrusoe
[2011/04/30 19:40:36 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Sahmon Games
[2011/02/25 14:41:19 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Scholastic
[2011/02/26 11:43:14 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\SevenSails
[2011/07/30 19:55:24 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ShaoLin
[2011/01/13 17:31:38 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ShinyTales
[2011/05/07 20:32:29 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Silverback Productions
[2011/04/28 20:28:22 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Skunk Studios
[2011/01/06 20:35:29 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Spark Plug Games
[2011/03/11 22:23:06 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Specialbit
[2011/06/23 18:16:25 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\SpinTop Games
[2011/02/22 23:13:43 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\SprillBermudeEng
[2011/06/04 21:33:06 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Stand O'Food 3
[2011/02/25 14:05:00 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Sudden Games LLC
[2011/07/09 20:24:02 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\SulusGames
[2011/01/01 11:29:03 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Super-Cow
[2010/12/03 22:17:29 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Supermarket Mania 2
[2011/06/06 16:08:47 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Teyon
[2011/01/09 07:18:57 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\TFS2
[2011/06/16 20:23:48 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\The Witch and The Warrior
[2011/03/06 19:48:45 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\TheFixerUpper
[2011/07/12 11:54:54 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\thejoyoffarming
[2011/01/23 10:56:17 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\TikisLab
[2011/04/05 20:15:41 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\TOMI3
[2011/02/25 21:30:21 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Top Evidence
[2011/05/20 17:36:10 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\TrickySoftware
[2011/08/20 13:28:57 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Twilight Games
[2010/12/07 08:21:36 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\V310-V510 Series
[2011/02/18 11:23:53 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ValuSoft
[2011/07/09 13:55:37 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\VampireSagaHL
[2011/01/27 18:07:28 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Vasilek Games
[2011/08/06 13:21:36 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Vast Studios
[2011/07/02 17:01:32 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\VendelGAMES
[2011/02/23 11:46:50 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\ViquaSoft
[2011/01/28 10:57:42 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Virtual Prophecy
[2011/08/19 16:54:15 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\Vogat Interactive
[2011/06/16 21:44:53 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\WendigoStudios
[2011/01/27 16:45:23 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\WhiteBirdsProductions
[2011/02/22 13:02:59 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\World-Loom
[2011/08/23 18:50:08 | 000,000,000 | ---D | M] -- C:\Users\Shannon\AppData\Roaming\YoudaGames
[2011/08/27 09:43:19 | 000,032,594 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:4A392155
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:B648F38E
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:12D2EB9C
@Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:E690114B
@Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:17C48B08
@Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:1419F1F4
@Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:0C5AF2AA
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:C07A6A6B
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:89E1BAF5
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:28CDD861
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:A296A63F
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:74091520
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:95198126
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:6C13E971
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:45912F61
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:F1F936DF
@Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:2DF93164
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:149327FE
@Alternate Data Stream - 235 bytes -> C:\ProgramData\TEMP:2F8138B7
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:9D03192E
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:178093AE
@Alternate Data Stream - 228 bytes -> C:\ProgramData\TEMP:D01ACC06
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:E6C6EB3B
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:44E16D4A
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:38FF076E
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:FF9C44FE
@Alternate Data Stream - 223 bytes -> C:\ProgramData\TEMP:C9B27A06
@Alternate Data Stream - 220 bytes -> C:\ProgramData\TEMP:69FE2EE4
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:663B62CA
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:063969F8
@Alternate Data Stream - 215 bytes -> C:\ProgramData\TEMP:E6EC5C2A
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:ACCEFF0E
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:1CDEDE11
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:0DFE2AE1
@Alternate Data Stream - 213 bytes -> C:\ProgramData\TEMP:3C9B05C4
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:F44D3C53
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:D2397415
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:AA60673F
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:461BD06D
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:F84B8DB5
@Alternate Data Stream - 199 bytes -> C:\ProgramData\TEMP:04560D68
@Alternate Data Stream - 189 bytes -> C:\ProgramData\TEMP:F7F6E6CB
@Alternate Data Stream - 185 bytes -> C:\ProgramData\TEMP:DDEB08FD
@Alternate Data Stream - 162 bytes -> C:\ProgramData\TEMP:E80E2213
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:BB916ED8
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:B190BE3A
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:0D669858
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:8AED9359
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:68A41423
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:63210866
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:E8C44CB4
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:CAF8DAC8
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0785072C
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:3AD6342E
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F53B274A
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C5DC2B0C
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:BF6C81B2
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:9C3AAD57
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:981456CB
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:943971F5
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:6E2D80C8
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:46283136
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:19474103
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:FAB64002
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:F5B51004
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:EA10407C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:A652BC99
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:6E11933F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:62AC0CCE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:491270B8
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:3C0887BF
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:371A321E
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:13019F4B
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:FD38E906
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:DA5888A7
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:B0193F8E
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:751D6870
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:5D10C56A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:413E2927
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:2CC32B31
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:12D9D48F
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:0DE96CF5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:ED2D63E4
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:83BAA24B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:6EE8565A
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:5C4A588B
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:5C0940F1
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:4D551822
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3969ACF7
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:F142DBA9
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:AD020DC3
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A4E7D25F
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A26AFC00
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:8CFBA95C
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:870649A4
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:7F62E6D0
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:F89F2593
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:DDF112BD
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:CEE4A457
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:A6D89509
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:79875988
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:53DF59D1
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:512E1728
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:3EC5BC08
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:397D67BA
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:2E3F04BC
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:164561C8
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E9900C74
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E6BEADB7
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:BC1F7CAE
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:99B20AD0
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:9720EBEF
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:8BE8BFCD
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:63B94956
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:4149A170
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:2CDB9CA3
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:0A74923C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:EE198B1F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E883A78D
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E732B44B
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:C37283B5
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:A5584049
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:9A8F071F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:90595C34
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:4FE884C2
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:2EB79F01
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:29C0641D
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:18DEBC51
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:16F4BC64
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A88BE334
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A76A1B1B
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:96646EC1
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:737160C1
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:689AB7E9
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:012BC84F
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:E99D1D3C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:C76CFF82
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:BD34FFC5
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:9C337CCE
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:65684E14
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:571CCF8E
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:53DF4438
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:038F4577
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:EBCF5924
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:E5B07840
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:D4558A0B
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:CF1334B0
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A42FABF7
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:9F3CEEE6
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:961B84C5
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:587F3582
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:2C250258
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:2216A431
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D3A89E47
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:C48905F4
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:BF6A2C54
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:BE6B5FC3
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A5241382
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:A01F3A87
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:902C848D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:8AE92FD3
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:8855A119
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:553056F1
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:512336B9
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:4A01545C
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3B454A5C
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:2BE0B2D7
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:0BBF232A
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:08801FDB
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:EB4FEEF5
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:DE875C30
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:CCB49694
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:C4A88D6B
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B54E4B5A
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:983B4DC0
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:90C320E1
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:87A3A233
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:75798D9A
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:59465B40
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:53B8C5D2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:43A31AEA
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:3B07E6F4
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:0FE0A03C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:E40D7F76
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:CFA8C6E3
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:BEACE4C8
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:E5496666
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:CE8A42A3
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:BD8010FE
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:B0456F0C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:609CAC7C
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:4B244549
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:35629AE6
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:2211E7A0
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:18A6D2CC
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:16ADBA30
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:0915A718
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:06C34166
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D9771F40
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D9656460
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:99AC3203
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:94B46CA2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:852F2262
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:5CE65446
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:F5FC5DCE
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:EC0279DC
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D3A82449
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:B8EB1B99
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:A9056F42
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6BFA43EB
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:4A966CC2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:41884BBE
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:1C201DEB
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:DE9AC04F
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:D5BF78B4
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:BEE39E9B
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:AAA06E15
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:7DC5D762
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:581B0446
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:51E66512
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5080697C
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:2C678471
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:23834E1E
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:E83EE313
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:B1E64E47
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:5D351BC6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:54380FEC
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:52C24010
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:3BAD65EA
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:31F2397C
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2AE74FF9
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:090FB735
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:CB299F13
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:BED8A204
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:A5FC8FA1
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:8BCF4DE2
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:73461BFA
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:3E200C29
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:124B94C0
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0ACF1AF5
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:F422F8F1
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:E8CB831A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:E894A3ED
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D576A536
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C0A9B815
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A17CCD03
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9725F1BC
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:905BCB57
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:7AF9CAEB
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6A0A47E7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:5E8C18F1
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:20E32CC7
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:0E8117B1
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:F5D01D7C
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:E5DE9C8F
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:BA5EEDA7
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:B38BEEEE
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:927EC486
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:834DD57E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:7C8AA9A6
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:5025C6E4
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:4A93D042
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:3DB6F365
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:2BC498A4
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:206470A5
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:19C3BC3A
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:FB647F34
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E2CFA9CD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:CA23BCFD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:C36D0DFD
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:C0893153
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:AE9351E0
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:A5264343
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:98982C88
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:8204AA35
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:71612023
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:2DF54B62
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:2652902F
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0EC7A545
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:07D9FF25
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E9FAC3AB
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:D9987109
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:AEBFFE08
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:90876BA3
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:8B4B9596
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:52B3B2D1
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:40DA0795
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:38DE6D05
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:358505CF
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:3086B95F
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:225CD7D5
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:0988A428
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:041C0562
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:BA05E0C4
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A8606E6E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A6D6E537
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:84BD8B63
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:5520ED93
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3571475C
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:217A2A36
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:073139EC
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:E411AA0D
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:B139DDF3
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:ADFAD95A
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:9B721CFF
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:7EBCAF87
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:69E3AF64
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:68EF6203
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:24C072FF
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:0B3B557D
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:DD95E6D9
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:C0913157
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BD27B7FC
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:701B92FB
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:2B9555D8
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:101708D3
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:CA0CE093
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:831C6B2D
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:2D2461E7
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:0968E571
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:E412AAF2
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:AA0017FD
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:6423D635
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:4DDE401B
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:378824DE
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:2C86E2AD
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:27974442
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:169E7AC5
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:ECF3C50F
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:E0888117
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:AFB24B00
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:AECF4772
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:86B7FDDB
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:72A1B66A
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:65B8AF94
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:63F8EC77
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:63C29481
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:545C78AF
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4EFA2FC7
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4EC7F009
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:361800A8
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:2ADF9928
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:14362DF8
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:0F4FC8CD
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:00AA4B31
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:F6A0889A
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:D882BE37
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:CB16385F
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:CAC06C34
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A57500CB
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:7ADB695A
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:774A0E14
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:57B2B96C
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:03A039A3
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:D28EBF99
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:5345C8F6
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:78ADFF54
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:2342AE46
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DF0BC727
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:D92485C9
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:56AD65A1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:067BF339
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:27C3CD07
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:FD604D11
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:52E1DB1D
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:3595B780
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:062AF572
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:753A0081
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:6EC8F6C5
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:49EB0FDC
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:AABCC5A7
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A384652A
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:98AE08EA
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:592D7272
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:514E900B
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:1B927722
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:F52A6209
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:C74009E5
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:67BA17B9
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:47408F84
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A7DA2BCD
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:561B1D2B
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:1AFC2166
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:A97118EB

< End of report >
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,012 posts
  • MVP
Download the McAfee Removal tool
http://download.mcaf...atches/MCPR.exe
Uninstall McAfee, run the McAfee uninstall tool, reboot.



Copy the text in the code box by highlighting and Ctrl + c

:processes
killallprocesses

:OTL
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
[2010/11/26 18:24:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/28 11:46:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/05/18 16:20:10 | 000,011,994 | -HS- | C] () -- C:\Users\Shannon\AppData\Local\ukkbx3ej241h1wi32l5g40826jf48s6a3jj
[2011/05/18 16:20:10 | 000,011,994 | -HS- | C] () -- C:\ProgramData\ukkbx3ej241h1wi32l5g40826jf48s6a3jj
[2011/06/15 17:51:21 | 000,000,000 | ---- | C] () -- C:\Users\Shannon\AppData\Local\{51774798-511B-4E04-81D8-8E0511BEC012}

:files
xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\3 "%AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C

     
:Commands
[purity]
[Reboot]


then Rightclick on OTL and select Run As Administrator to start. Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the RUN FIX button (NOT THE QUICK SCAN button!) at the top
Let the program run unhindered, OTL will reboot the PC when it is done.


If one of the following will not run then just skip to the next one then go back and try the things that wouldn't run again after finishing the others.

Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:

http://www.malwarebytes.org/mbam.php

SAVE Malwarebytes' Anti-Malware to your desktop.

Rightclick on Malwarebytes' Anti-Malware and select Run As Administrator and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.

* Once the program has loaded, select Perform Quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.



ComboFix

:!: It must be saved to your desktop, do not run it from your browser:!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on ComboFix and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.


Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then right click and Run as Administrator

If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

change the a-v scan to None.
uncheck trace disk IO calls
Click the "Scan" button to start scan


On completion of the scan (Note if the Fix button is enabled and tell me) click save log, save it to your desktop and post in your next reply


Open OTL again and select the All option in the Extra Registry group then the Run Scan button. Post the two logs it produces in your next reply.

Ron
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP