We have been experiencing pop-ups from AV Security, as well as programs that we didn't download such as Weatherbug and this Yooohoo (note: not Yahoo)pg. Tried running OTL & Malwarebytes but every link I clicked on I was blocked out. Started the computer in Safe Mode and ran the VIPR scan and eventually Malwarebytes, which found approximately 37 threats and trojans. I removed them, was finally able to run OTL, the log file is posted below. ARO is still coming up and the computer is still running "loudly" as if there are a lot of programs/processes running at once. There's also a "testendonline" pop up that keeps coming up and redirecting my IE pages... I would appreciate any help you can provide! Thank you so much in advance, Alisha
OTL logfile created on: 11/18/2011 3:09:46 AM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\The Sinons\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.75 Gb Total Physical Memory | 0.92 Gb Available Physical Memory | 52.48% Memory free
3.74 Gb Paging File | 2.86 Gb Available in Paging File | 76.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144.30 Gb Total Space | 44.19 Gb Free Space | 30.62% Space Free | Partition Type: NTFS
Drive D: | 144.03 Gb Total Space | 143.94 Gb Free Space | 99.94% Space Free | Partition Type: NTFS
Computer Name: THESINONS-PC | User Name: The Sinons | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/18 03:09:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\The Sinons\Desktop\OTL.exe
PRC - [2011/10/06 01:18:38 | 000,210,744 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe
PRC - [2011/05/06 17:20:33 | 000,235,168 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10p_ActiveX.exe
PRC - [2011/04/16 19:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/29 01:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/09/10 22:37:36 | 000,024,576 | ---- | M] (Intuit) -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2008/04/24 12:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2007/06/14 03:15:34 | 000,598,960 | ---- | M] ( ) -- C:\Windows\System32\lxdkcoms.exe
PRC - [2007/06/14 03:15:24 | 000,099,248 | ---- | M] (Lexmark International, Inc.) -- C:\Windows\System32\spool\drivers\w32x86\3\lxdkserv.exe
PRC - [2007/04/04 20:54:08 | 000,266,343 | ---- | M] (CyberLink) -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
PRC - [2007/02/07 02:04:26 | 000,457,512 | ---- | M] (HiTRSUT) -- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
PRC - [2007/01/31 21:18:42 | 000,053,248 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
PRC - [2006/12/29 19:51:56 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
========== Modules (No Company Name) ==========
MOD - [2007/03/14 08:54:58 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2006/11/02 04:46:10 | 000,227,328 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/04/16 19:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe -- (NAV)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/08/24 07:47:07 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/09/10 22:37:36 | 000,024,576 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2008/08/08 21:10:46 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2008/04/24 12:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe -- (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2)
SRV - [2007/06/14 03:15:34 | 000,598,960 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxdkcoms.exe -- (lxdk_device)
SRV - [2007/06/14 03:15:24 | 000,099,248 | ---- | M] () [Auto | Running] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdkserv.exe -- (lxdkCATSCustConnectService)
SRV - [2007/04/04 20:54:08 | 000,266,343 | ---- | M] (CyberLink) [Auto | Running] -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -- (Acer HomeMedia Connect Service)
SRV - [2007/02/07 02:04:26 | 000,457,512 | ---- | M] (HiTRSUT) [Auto | Running] -- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe -- (eDataSecurity Service)
SRV - [2007/01/31 21:18:42 | 000,053,248 | ---- | M] (Acer Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService)
SRV - [2006/12/29 19:51:56 | 000,028,672 | ---- | M] () [Auto | Running] -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe -- (AcerMemUsageCheckService)
========== Driver Services (SafeList) ==========
DRV - [2011/11/09 03:05:45 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/11/09 03:05:45 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/10/30 22:21:20 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20111110.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/10/30 22:21:20 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20111110.002\NAVENG.SYS -- (NAVENG)
DRV - [2011/10/14 18:10:08 | 000,818,808 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20111027.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2011/08/22 23:17:32 | 000,368,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20111109.030\IDSvix86.sys -- (IDSVix86)
DRV - [2011/08/12 13:22:05 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/03/30 22:00:09 | 000,516,216 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NAV\1206000.01D\SRTSP.SYS -- (SRTSP)
DRV - [2011/03/30 22:00:09 | 000,050,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\NAV\1206000.01D\SRTSPX.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011/03/21 19:39:49 | 000,331,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\NAV\1206000.01D\SYMTDIV.SYS -- (SYMTDIv)
DRV - [2011/03/14 21:31:23 | 000,744,568 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\system32\drivers\NAV\1206000.01D\SYMEFA.SYS -- (SymEFA)
DRV - [2011/01/27 01:47:10 | 000,340,088 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\NAV\1206000.01D\SYMDS.SYS -- (SymDS)
DRV - [2011/01/27 00:07:05 | 000,136,312 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\system32\drivers\NAV\1206000.01D\Ironx86.SYS -- (SymIRON)
DRV - [2010/11/09 13:56:12 | 000,098,392 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2007/03/14 09:04:28 | 002,427,392 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007/02/02 03:37:36 | 000,982,272 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2006/12/07 21:12:02 | 000,076,584 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15)
DRV - [2006/11/10 14:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
DRV - [2006/10/29 22:22:26 | 000,008,192 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2005/08/17 07:47:48 | 000,073,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM)
DRV - [2005/08/17 07:46:26 | 000,093,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2005/08/17 07:46:20 | 000,008,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2005/08/17 07:45:00 | 000,058,352 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2005/06/24 17:36:16 | 000,039,036 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2005/05/26 10:01:36 | 000,038,144 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2005/05/26 10:01:18 | 000,021,344 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2004/05/21 14:16:14 | 000,471,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lvcm.sys -- (QCMerced)
DRV - [2004/05/21 14:15:31 | 000,019,968 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\The Sinons\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\The Sinons\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\The Sinons\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Users\The Sinons\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/09/28 06:28:23 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\FriendsChecker\DynConFf\
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX\u00AE Content Upload Plugin (Enabled) = C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\The Sinons\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\The Sinons\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Move Media Player 7 (Enabled) = C:\Users\The Sinons\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\The Sinons\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Poppit = C:\Users\The Sinons\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
Hosts file not found
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - No CLSID value found.
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (Dallas Cowboys BHO) - {69CE821F-3668-475A-B66F-94719B322DE3} - C:\Program Files\Dallas Cowboys\Toolbar.dll ()
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Common Files\FreeCause\DCA\dca-bho.dll (Compete, Inc.)
O2 - BHO: (Philadelphia Phillies Toolbar) - {f722f063-925c-43d2-8308-584cfc1297fe} - C:\Program Files\Philadelphia_Phillies\tbPhi0.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (Dallas Cowboys) - {27E7F580-724E-46EB-846F-96C2396D23ED} - C:\Program Files\Dallas Cowboys\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Philadelphia Phillies Toolbar) - {f722f063-925c-43d2-8308-584cfc1297fe} - C:\Program Files\Philadelphia_Phillies\tbPhi0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKCU\..\Toolbar\WebBrowser: (Dallas Cowboys) - {27E7F580-724E-46EB-846F-96C2396D23ED} - C:\Program Files\Dallas Cowboys\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKCU\..\Toolbar\WebBrowser: (Philadelphia Phillies Toolbar) - {F722F063-925C-43D2-8308-584CFC1297FE} - C:\Program Files\Philadelphia_Phillies\tbPhi0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acer Tour] File not found
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSConfig] C:\Windows\System32\msconfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SpeetItUpFree] "C:\Program Files\SpeedItup Free\speeditupfree.exe" File not found
O4 - HKCU..\Run: [AROReminder] C:\Program Files\ARO 2011\ARO.exe (Support.com)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.64.150 68.87.75.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6F5AA97B-53B2-4075-9F14-7231E4641C09}: DhcpNameServer = 68.87.64.150 68.87.75.198
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\The Sinons\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\The Sinons\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29 - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{f44f06c7-2c22-11e0-ab89-001c2554e967}\Shell - "" = AutoRun
O33 - MountPoints2\{f44f06c7-2c22-11e0-ab89-001c2554e967}\Shell\AutoRun\command - "" = J:\Photokinz.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/18 03:09:17 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\The Sinons\Desktop\OTL.exe
[2011/11/18 02:24:42 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\Sammsoft
[2011/11/18 02:24:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ARO 2011
[2011/11/18 02:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\ARO 2011
[2011/11/17 19:58:02 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/11/17 19:58:02 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\sbbd.exe
[2011/11/17 19:57:21 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2011/11/17 19:44:59 | 000,000,000 | ---D | C] -- C:\Program Files\EBC76
[2011/11/17 19:29:28 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\QkUVrlOBtPySiD
[2011/11/17 19:29:28 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\d4amH5sWJdLg
[2011/11/17 15:25:27 | 000,000,000 | ---D | C] -- C:\Program Files\LP
[2011/11/17 15:23:17 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\zVrlOBtxPySiD
[2011/11/17 15:23:17 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\ZnF4amH5s
[2011/11/17 08:37:04 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\UwjUCelIBzy
[2011/11/17 08:37:04 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\Q4pmG5sQJdKfZh
[2011/11/17 07:21:08 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\dyxA0uvS2b3n5Q6
[2011/11/17 07:21:08 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\BK7fRL9gTqYeI
[2011/11/16 21:59:51 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\lG5aQH6dW7R9TqY
[2011/11/16 21:59:50 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\zxA0uvS2iF
[2011/11/16 21:45:21 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\j2onF4pmHsJdK
[2011/11/16 21:25:09 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\kXqjYCekIrOtAuS
[2011/11/16 21:25:08 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\XbF3pnG5aHdKfLg
[2011/11/16 21:22:47 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\u5sA1uvSo
[2011/11/16 21:22:47 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\PkIBrzONyAuSiFp
[2011/11/16 17:24:31 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\EBC76
[2011/11/16 17:23:58 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\303EB
[2011/11/16 17:23:57 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\tG4amH6sW7E8T
[2011/11/16 17:23:57 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\gqhYCwkUVlBxySi
[2011/11/16 17:23:53 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\ThYXwjUVeItP
[2011/11/16 17:23:52 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\TYCwkUVrlBx0c1v
[2011/11/16 17:23:52 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\aNtxxPucS1iDoGa
[2011/11/11 14:04:35 | 000,000,000 | ---D | C] -- C:\Program Files\Surf Canyon
[2011/11/11 13:54:44 | 000,000,000 | ---D | C] -- C:\Users\The Sinons\AppData\Roaming\Fighters
[2011/11/11 13:54:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Fighters
[2011/11/11 13:54:16 | 000,000,000 | ---D | C] -- C:\Program Files\Free Offers from Freeze.com
[2011/11/11 13:53:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2011/11/11 13:53:50 | 000,000,000 | ---D | C] -- C:\ProgramData\WeCareReminder
[2011/11/11 13:53:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2008/02/18 00:01:31 | 000,434,176 | ---- | C] ( ) -- C:\Windows\System32\lxdkhcp.dll
[2008/02/18 00:01:31 | 000,356,352 | ---- | C] ( ) -- C:\Windows\System32\lxdkinpa.dll
[2008/02/18 00:01:30 | 000,950,272 | ---- | C] ( ) -- C:\Windows\System32\lxdkusb1.dll
[2008/02/18 00:01:30 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\lxdkiesc.dll
[2008/02/18 00:01:29 | 001,200,128 | ---- | C] ( ) -- C:\Windows\System32\lxdkserv.dll
[2008/02/18 00:01:29 | 000,647,168 | ---- | C] ( ) -- C:\Windows\System32\lxdkpmui.dll
[2008/02/18 00:01:29 | 000,565,248 | ---- | C] ( ) -- C:\Windows\System32\lxdklmpm.dll
[2008/02/18 00:01:29 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\lxdkprox.dll
[2008/02/18 00:01:28 | 000,320,432 | ---- | C] ( ) -- C:\Windows\System32\lxdkih.exe
[2008/02/18 00:01:27 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\lxdkhbn3.dll
[2008/02/18 00:01:26 | 000,860,160 | ---- | C] ( ) -- C:\Windows\System32\lxdkcomc.dll
[2008/02/18 00:01:26 | 000,598,960 | ---- | C] ( ) -- C:\Windows\System32\lxdkcoms.exe
[2008/02/18 00:01:26 | 000,365,488 | ---- | C] ( ) -- C:\Windows\System32\lxdkcfg.exe
[2008/02/18 00:01:26 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxdkcomm.dll
[2008/01/14 01:32:51 | 000,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
[2007/04/16 20:09:21 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\Interop.Shell32.dll
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/18 03:10:31 | 000,000,432 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{5E74FB6E-B0A5-4C81-AA2F-BECAC1E7FC9D}.job
[2011/11/18 03:09:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\The Sinons\Desktop\OTL.exe
[2011/11/18 03:07:21 | 000,000,416 | ---- | M] () -- C:\Windows\tasks\PC Optimizer Pro startups.job
[2011/11/18 03:07:17 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/18 03:06:55 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/18 03:06:55 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/18 03:06:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/18 03:06:37 | 1878,515,712 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/18 02:28:10 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/18 02:24:33 | 000,001,657 | ---- | M] () -- C:\Users\The Sinons\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2011/11/18 02:24:33 | 000,001,651 | ---- | M] () -- C:\Users\The Sinons\Desktop\Check PC For Errors.lnk
[2011/11/17 19:56:54 | 105,930,752 | ---- | M] () -- C:\Users\The Sinons\Desktop\VIPRERescue11067.exe
[2011/11/17 19:47:58 | 000,617,662 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/17 19:47:58 | 000,103,440 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/11/17 19:37:56 | 000,000,216 | ---- | M] () -- C:\Windows\tasks\0.job
[2011/11/17 15:26:04 | 000,000,394 | ---- | M] () -- C:\Windows\tasks\At1.job
[2011/11/17 07:19:05 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[6 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/18 03:06:37 | 1878,515,712 | -HS- | C] () -- C:\hiberfil.sys
[2011/11/18 02:24:33 | 000,001,657 | ---- | C] () -- C:\Users\The Sinons\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2011/11/18 02:24:33 | 000,001,651 | ---- | C] () -- C:\Users\The Sinons\Desktop\Check PC For Errors.lnk
[2011/11/17 19:56:38 | 105,930,752 | ---- | C] () -- C:\Users\The Sinons\Desktop\VIPRERescue11067.exe
[2011/11/17 19:37:56 | 000,000,216 | ---- | C] () -- C:\Windows\tasks\0.job
[2011/11/17 15:25:27 | 000,000,394 | ---- | C] () -- C:\Windows\tasks\At1.job
[2011/11/11 14:13:17 | 000,000,416 | ---- | C] () -- C:\Windows\tasks\PC Optimizer Pro startups.job
[2011/10/05 14:16:24 | 000,000,094 | ---- | C] () -- C:\Users\The Sinons\AppData\Roaming\wklnhst.dat
[2011/08/12 11:40:56 | 005,353,987 | ---- | C] () -- C:\Users\The Sinons\AppData\Roaming\SMRBackup162.dat
[2010/12/04 17:40:55 | 000,000,039 | ---- | C] () -- C:\Windows\WININIT.INI
[2010/06/28 23:04:31 | 000,000,680 | ---- | C] () -- C:\Users\The Sinons\AppData\Local\d3d9caps.dat
[2009/08/04 22:06:12 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/03/03 22:49:47 | 025,049,120 | -HS- | C] () -- C:\Windows\System32\drivers\fidbox.dat
[2009/02/11 22:17:19 | 000,000,091 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2008/12/21 16:28:24 | 000,471,232 | ---- | C] () -- C:\Windows\System32\drivers\lvcm.sys
[2008/12/21 16:28:24 | 000,019,968 | ---- | C] () -- C:\Windows\System32\drivers\LVUSBSta.sys
[2008/12/21 16:28:24 | 000,005,993 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2008/10/13 16:05:58 | 000,000,412 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2008/05/06 11:03:46 | 000,001,680 | ---- | C] () -- C:\Windows\_delis32.ini
[2008/05/06 11:03:11 | 000,081,920 | ---- | C] () -- C:\Windows\bwUnin-6.1.4.68-8876480L.exe
[2008/04/07 20:26:00 | 000,235,520 | ---- | C] () -- C:\Users\The Sinons\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/03/07 07:58:03 | 000,005,364 | ---- | C] () -- C:\ProgramData\lxdk
[2008/02/20 21:05:44 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008/02/20 21:03:24 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008/02/18 11:30:45 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/02/18 00:05:24 | 000,348,160 | ---- | C] () -- C:\Windows\System32\lxdkcoin.dll
[2008/02/18 00:03:25 | 000,045,056 | ---- | C] () -- C:\Windows\System32\LXDKPMON.DLL
[2008/02/18 00:03:25 | 000,032,768 | ---- | C] () -- C:\Windows\System32\LXDKFXPU.DLL
[2008/02/18 00:03:04 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxdkoem.dll
[2008/02/18 00:01:44 | 000,000,060 | ---- | C] () -- C:\Windows\System32\lxdkrwrd.ini
[2008/02/18 00:01:31 | 000,348,160 | ---- | C] () -- C:\Windows\System32\lxdkinst.dll
[2008/02/18 00:01:27 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxdkgrd.dll
[2008/01/14 01:33:34 | 000,000,044 | ---- | C] () -- C:\Windows\Acer(Normal).ini
[2008/01/14 01:33:34 | 000,000,042 | ---- | C] () -- C:\Windows\Acer(Wide).ini
[2008/01/14 01:32:51 | 000,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
[2007/05/22 12:22:21 | 000,692,224 | ---- | C] () -- C:\Windows\System32\lxdkdrs.dll
[2007/05/22 05:10:00 | 000,065,536 | ---- | C] () -- C:\Windows\System32\lxdkcaps.dll
[2007/04/16 20:41:33 | 000,001,024 | RH-- | C] () -- C:\Windows\System32\NTIBUN4.dll
[2007/04/16 20:09:21 | 000,331,776 | ---- | C] () -- C:\Windows\System32\ScrollBarLib.dll
[2007/04/16 19:28:29 | 000,000,818 | ---- | C] () -- C:\Windows\generic.ini
[2007/04/16 19:28:29 | 000,000,125 | ---- | C] () -- C:\Windows\Alaunch.ini
[2007/04/16 19:28:26 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2007/04/16 19:28:26 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007/04/16 19:28:25 | 000,143,676 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2007/02/14 09:35:07 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxdkcnv4.dll
[2007/02/07 01:58:10 | 000,204,800 | ---- | C] () -- C:\Windows\System32\NotesActnMenu.dll
[2007/02/07 01:57:58 | 000,266,240 | ---- | C] () -- C:\Windows\System32\NotesExtmngr.dll
[2007/02/07 01:57:20 | 000,086,016 | ---- | C] () -- C:\Windows\System32\MSNSpook.dll
[2007/02/07 01:56:30 | 000,028,672 | ---- | C] () -- C:\Windows\System32\BatchCrypto.dll
[2007/02/07 01:56:28 | 000,073,728 | ---- | C] () -- C:\Windows\System32\APISlice.dll
[2007/02/07 01:52:08 | 000,063,488 | ---- | C] () -- C:\Windows\System32\ShowErrMsg.dll
[2006/12/25 17:44:48 | 000,022,016 | ---- | C] () -- C:\Windows\System32\MailFormat_U.dll
[2006/11/13 07:50:06 | 000,071,680 | ---- | C] () -- C:\Windows\System32\HTCA_SelfExtract.bin
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,317,272 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,617,662 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,103,440 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/11/02 02:22:43 | 000,099,999 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2006/11/02 02:22:43 | 000,018,271 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006/07/31 20:53:18 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxdkvs.dll
[2001/12/26 17:12:30 | 000,065,536 | ---- | C] () -- C:\Windows\System32\multiplex_vcd.dll
[2001/09/04 00:46:38 | 000,110,592 | ---- | C] () -- C:\Windows\System32\Hmpg12.dll
[2001/07/30 17:33:56 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC.dll
[2001/07/23 23:04:36 | 000,118,784 | ---- | C] () -- C:\Windows\System32\HMPV2_ENC_MMX.dll
[1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll
[1997/06/13 06:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll
========== LOP Check ==========
[2011/11/17 21:36:56 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\303EB
[2008/02/18 00:09:07 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\5300 Series
[2008/02/17 23:58:29 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Acer
[2008/07/16 12:55:06 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Acoustica
[2011/11/16 17:23:52 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\aNtxxPucS1iDoGa
[2010/01/30 20:48:26 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\AnvSoft
[2010/12/24 22:36:12 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Barnes & Noble
[2011/11/17 07:21:09 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\BK7fRL9gTqYeI
[2009/01/10 11:57:46 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Canon
[2011/11/17 19:29:28 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\d4amH5sWJdLg
[2011/11/17 07:21:08 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\dyxA0uvS2b3n5Q6
[2011/11/17 15:23:52 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\EBC76
[2011/11/11 21:45:09 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Fighters
[2010/12/25 10:32:54 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Fisher-Price
[2011/11/16 17:23:57 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\gqhYCwkUVlBxySi
[2008/12/05 21:19:17 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\iWin
[2011/11/16 21:45:21 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\j2onF4pmHsJdK
[2011/11/16 21:25:09 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\kXqjYCekIrOtAuS
[2008/02/17 23:58:28 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Leadertech
[2008/02/18 00:15:15 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Lexmark Productivity Studio
[2011/11/16 21:59:51 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\lG5aQH6dW7R9TqY
[2009/02/13 18:17:18 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\LimeWire
[2011/02/02 20:11:18 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Ludia
[2008/03/05 09:26:34 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\MusicNet
[2011/11/16 21:22:47 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\PkIBrzONyAuSiFp
[2011/11/17 08:37:04 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Q4pmG5sQJdKfZh
[2011/11/17 19:29:28 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\QkUVrlOBtPySiD
[2011/11/18 02:24:42 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Sammsoft
[2008/10/13 16:05:43 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\ScanSoft
[2011/10/05 14:16:28 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\Template
[2011/11/16 17:23:57 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\tG4amH6sW7E8T
[2011/11/16 17:23:53 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\ThYXwjUVeItP
[2011/11/16 17:23:52 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\TYCwkUVrlBx0c1v
[2011/11/16 21:22:47 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\u5sA1uvSo
[2011/11/17 08:37:04 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\UwjUCelIBzy
[2010/02/24 21:01:47 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\WeatherBug
[2011/11/16 21:25:08 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\XbF3pnG5aHdKfLg
[2011/11/17 15:23:17 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\ZnF4amH5s
[2011/11/17 15:23:17 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\zVrlOBtxPySiD
[2011/11/16 21:59:50 | 000,000,000 | ---D | M] -- C:\Users\The Sinons\AppData\Roaming\zxA0uvS2iF
[2011/11/17 19:37:56 | 000,000,216 | ---- | M] () -- C:\Windows\Tasks\0.job
[2011/11/17 15:26:04 | 000,000,394 | ---- | M] () -- C:\Windows\Tasks\At1.job
[2011/11/18 03:07:21 | 000,000,416 | ---- | M] () -- C:\Windows\Tasks\PC Optimizer Pro startups.job
[2011/11/17 15:26:53 | 000,032,550 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/18 03:10:31 | 000,000,432 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{5E74FB6E-B0A5-4C81-AA2F-BECAC1E7FC9D}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\The Sinons\Documents\Livvy Laughing.MPG:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\The Sinons\Documents\Livvy Crawling.MPG:TOC.WMV
< End of report >
Edited by ztastorm, 18 November 2011 - 05:02 AM.