Malware bytes' Anti-Malware
rkill
Ccleaner
Fix NCR.exe
After running these programs my computer seems to run normal without the memory being taken but it will not connect to the internet. I always receive the "IE cannot display the web page". After running the diagnose connection problems I receive problem with win sock provider catalog. A few hours ago I found a thread and performed the following:
Posted 30 September 2008 - 07:49 AM
try this...
TCP/IP stack repair options for use with Windows XP with SP2.
For these commands click on Start.... Run..... type in...CMD ....to open a command prompt box Reset WINSOCK entries to installation defaults...type in ... netsh winsock reset catalog .... press ...enter Reset TCP/IP stack to installation defaults...type in...... netsh int ip reset reset.log ... press ...enter
then...
Please go to the malware forum Start HERE....
That will help you clean up 80 percent of all problems by yourself. If at the end of the process you are still having difficulty (and you may not be) then start a new topic in the MALWARE FORUM forum here...
if your still having problems AFTER getting a all clean from the malware guys...post back here
This post has been edited by happyrock: 01 October 2008 - 05:51 AM
Now I get a message that tells me to contact the company that provides Windows XP product support. I have checked all connections, rebooted router, etc.
My system stats:
Windows XP SP3
McAfee
Below is my OTL:
OTL logfile created on: 12/29/2011 4:38:21 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Mike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 79.33% Memory free
3.85 Gb Paging File | 3.32 Gb Available in Paging File | 86.26% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 98.62 Gb Free Space | 66.17% Space Free | Partition Type: NTFS
Drive E: | 461.74 Mb Total Space | 421.71 Mb Free Space | 91.33% Space Free | Partition Type: FAT
Computer Name: HP25032670924 | User Name: Mike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/29 16:35:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mike\Desktop\OTL.exe
PRC - [2011/12/03 16:51:37 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2011/09/23 19:46:28 | 001,195,408 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/04/14 13:01:38 | 000,188,136 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/04/14 13:01:38 | 000,171,168 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/03/13 10:45:14 | 000,148,520 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\system32\mfevtps.exe
PRC - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/13 18:12:14 | 000,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2005/10/15 03:01:00 | 000,114,688 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Sonic Shared\CineTray.exe
PRC - [2005/10/04 16:23:10 | 000,086,016 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HPQ\HP ProtectTools Security Manager\pthosttr.exe
PRC - [2005/09/28 03:10:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2005/08/23 10:39:40 | 000,147,456 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\BellSouthBrowser.exe
PRC - [2005/03/06 21:52:20 | 000,476,160 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2005/03/06 21:52:16 | 000,276,480 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsty.exe
========== Modules (No Company Name) ==========
MOD - [2009/10/23 17:01:58 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/12/03 16:51:37 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/04/14 13:01:38 | 000,188,136 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2011/04/14 13:01:38 | 000,171,168 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2011/03/13 10:45:14 | 000,148,520 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\WINDOWS\system32\mfevtps.exe -- (mfevtp)
SRV - [2011/02/02 10:57:54 | 000,052,288 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) getPlus®
SRV - [2010/10/07 19:34:28 | 000,364,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/09/22 15:31:56 | 000,856,064 | ---- | M] () [Auto | Stopped] -- C:\Program Files\TVersity\Media Server\MediaServer.exe -- (TVersityMediaServer)
SRV - [2009/03/03 12:53:08 | 000,033,176 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus® Helper) getPlus®
SRV - [2005/03/06 21:52:20 | 000,476,160 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
========== Driver Services (SafeList) ==========
DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/07/22 10:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2011/07/12 15:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/04/14 13:01:38 | 000,314,088 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/04/14 13:01:38 | 000,153,280 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/04/14 13:01:38 | 000,088,736 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendiskmp)
DRV - [2011/04/14 13:01:38 | 000,088,736 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mfendisk.sys -- (mfendisk)
DRV - [2011/04/14 13:01:38 | 000,084,488 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/04/14 13:01:38 | 000,084,200 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdi2k.sys -- (mfetdi2k)
DRV - [2011/04/14 13:01:38 | 000,056,064 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cfwids.sys -- (cfwids)
DRV - [2011/04/14 13:01:38 | 000,052,320 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/03/13 10:20:10 | 000,459,728 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/03/13 10:20:10 | 000,118,784 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2010/07/27 03:47:30 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2010/07/27 03:47:10 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2010/02/11 06:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2006/03/17 10:24:10 | 001,520,640 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/09/28 03:10:00 | 000,092,700 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/09/28 03:10:00 | 000,087,004 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/09/28 03:10:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/09/28 03:10:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/09/28 03:10:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/09/28 03:10:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/09/28 03:10:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/09/23 16:56:28 | 003,966,976 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/07/07 07:03:34 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/07/07 07:02:56 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/04/07 23:25:34 | 000,132,352 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2005/03/04 15:21:36 | 000,065,664 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\baspxp32.sys -- (Blfp)
DRV - [2005/01/07 12:07:16 | 000,145,920 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hdaudio.sys -- (HdAudAddService)
DRV - [2004/11/22 17:36:39 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5)
DRV - [2004/11/22 17:36:34 | 000,019,345 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMPR5.sys -- (MREMPR5)
DRV - [2004/08/03 18:29:50 | 000,019,455 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2004/08/03 18:29:48 | 000,012,063 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2004/08/03 18:29:46 | 000,025,471 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5)
DRV - [2004/08/03 18:29:46 | 000,023,615 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2004/08/03 18:29:46 | 000,022,271 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6)
DRV - [2004/08/03 18:29:44 | 000,033,599 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2004/08/03 18:29:44 | 000,019,551 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2004/08/03 18:29:42 | 000,029,311 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2004/08/03 18:29:42 | 000,011,871 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7)
DRV - [2004/08/03 18:29:40 | 000,011,807 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5)
DRV - [2004/08/03 18:29:40 | 000,011,295 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6)
DRV - [2004/08/03 18:29:38 | 000,161,020 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004/08/03 18:29:38 | 000,012,415 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2004/08/03 18:29:38 | 000,012,127 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2004/08/03 18:29:38 | 000,011,775 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2002/04/04 00:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://hometab.bellsouth.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.att.net
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://www.att.net"
FF - prefs.js..extensions.enabledItems: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.4.0
FF - prefs.js..extensions.enabledItems: [email protected]:7
FF - prefs.js..extensions.enabledItems: {efa37648-2754-4e3b-ad97-dc088c8805cd}:1.0.0.0
FF - prefs.js..extensions.enabledItems: [email protected]:5.2.0.0
FF - prefs.js..keyword.URL: "http://www.bing.com/...te=20111008&q="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 54505
FF - prefs.js..network.proxy.type: 1
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@ei.Guffins.com/Plugin: C:\Program Files\GuffinsEI\Installr\1.bin\NPu4EISB.dll (Guffins)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Mike\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\WINDOWS\Downloaded Program Files\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\@adobe.com/Acrobat,version=5.1: C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Mike\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Documents and Settings\Mike\Local Settings\Application Data\RobloxVersions\version-fb3436d54f9e4598\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Mike\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/11/09 16:12:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/02 14:27:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/12 13:46:57 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\Mike\Application Data\Move Networks [2009/12/01 13:17:35 | 000,000,000 | ---D | M]
[2009/09/26 09:17:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mike\Application Data\Mozilla\Extensions
[2011/11/27 17:28:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\p36iv0ru.default\extensions
[2009/09/26 09:34:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\p36iv0ru.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/08 06:52:52 | 000,000,000 | ---D | M] (Outspark Toolbar) -- C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\p36iv0ru.default\extensions\{efa37648-2754-4e3b-ad97-dc088c8805cd}
[2010/12/15 11:34:58 | 000,000,000 | ---D | M] (ShopAtHome.com Intelligent Shopping Toolbar) -- C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\p36iv0ru.default\extensions\[email protected]
[2011/10/08 06:52:58 | 000,001,945 | ---- | M] () -- C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\p36iv0ru.default\searchplugins\bing-zugo.xml
[2009/09/26 09:13:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/12/01 13:17:35 | 000,000,000 | ---D | M] (Move Media Player) -- C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOVE NETWORKS
[2011/11/09 16:12:10 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/04/14 13:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
[2009/11/19 15:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/19 15:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
O1 HOSTS File: ([2011/12/29 16:18:35 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111002152702.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Outspark Toolbar) - {efa37648-2754-4e3b-ad97-dc088c8805cd} - C:\Program Files\outsparktoolbar\vmntemplateX.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Outspark Toolbar) - {efa37648-2754-4e3b-ad97-dc088c8805cd} - C:\Program Files\outsparktoolbar\vmntemplateX.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\hdashcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MotiveReportAgent] C:\Program Files\Common Files\Motive\McciBootStrapper.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe File not found
O4 - HKLM..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"http://www.cartoonne...all/index.html" File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Documents and Settings\Mike\Desktop\PartyPoker.net.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Documents and Settings\Mike\Desktop\PartyPoker.net.lnk ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll File not found
O15 - HKCU\..Trusted Domains: $talisma_url$ ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: bellsouth.net ([hometab] http in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} http://launch.soe.co...ebInstaller.cab (SOE Web Installer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1240418678484 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1240490776671 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin..../p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.ado...obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B0AFF4B2-6068-4E9F-BB7D-4DB05BEF876A}: DhcpNameServer = 192.168.1.254 192.168.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mike\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/29 16:37:48 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mike\Desktop\OTL.exe
[2011/12/29 16:23:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/12/29 16:18:58 | 000,000,000 | ---D | C] -- C:\ERDNT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/29 16:35:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mike\Desktop\OTL.exe
[2011/12/29 16:23:57 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/29 16:23:24 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/12/29 16:20:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/12/29 16:20:38 | 2146,848,768 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/29 16:18:35 | 000,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/29 16:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At34.job
[2011/12/29 16:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At33.job
[2011/12/29 15:32:28 | 000,648,704 | ---- | M] () -- C:\Documents and Settings\Mike\Desktop\MicrosoftFixit50267.msi
[2011/12/29 15:31:26 | 000,650,240 | ---- | M] () -- C:\Documents and Settings\Mike\Desktop\MicrosoftFixit50203.msi
[2011/12/28 10:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2011/12/28 10:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2011/12/26 13:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At28.job
[2011/12/26 13:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At27.job
[2011/12/26 12:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At26.job
[2011/12/26 12:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At25.job
[2011/12/21 23:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At48.job
[2011/12/21 23:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At47.job
[2011/12/21 22:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At46.job
[2011/12/21 22:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At45.job
[2011/12/10 18:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At38.job
[2011/12/10 18:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At37.job
[2011/12/09 17:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At36.job
[2011/12/09 17:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At35.job
[2011/12/09 15:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At32.job
[2011/12/09 15:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At31.job
[2011/12/09 14:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At30.job
[2011/12/09 14:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At29.job
[2011/12/09 11:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2011/12/09 11:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2011/12/09 09:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2011/12/09 09:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2011/12/09 08:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2011/12/09 08:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2011/12/09 07:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2011/12/09 07:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2011/12/09 06:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2011/12/09 06:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2011/12/09 05:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2011/12/09 05:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2011/12/09 04:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2011/12/09 04:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2011/12/09 03:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2011/12/09 03:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2011/12/09 02:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2011/12/09 02:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2011/12/09 01:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2011/12/09 01:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2011/12/09 00:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2011/12/09 00:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2011/12/08 21:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At44.job
[2011/12/08 21:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At43.job
[2011/12/08 20:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At42.job
[2011/12/08 20:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At41.job
[2011/12/08 19:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\tasks\At40.job
[2011/12/08 19:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\tasks\At39.job
[2011/12/03 16:30:22 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/03 12:02:57 | 025,051,846 | ---- | M] () -- C:\BellSouthIW.re~
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/29 15:35:04 | 000,648,704 | ---- | C] () -- C:\Documents and Settings\Mike\Desktop\MicrosoftFixit50267.msi
[2011/12/29 15:35:01 | 000,650,240 | ---- | C] () -- C:\Documents and Settings\Mike\Desktop\MicrosoftFixit50203.msi
[2011/12/03 12:02:23 | 025,051,846 | ---- | C] () -- C:\BellSouthIW.re~
[2011/11/23 09:57:35 | 000,000,112 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\EqYh3Yq.dat
[2011/10/08 08:47:41 | 000,230,752 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2011/10/08 08:47:41 | 000,118,176 | ---- | C] () -- C:\WINDOWS\patchw.dll
[2011/02/10 00:14:12 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/06/15 09:34:49 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS69.DLL
[2010/01/31 13:00:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcfriend.INI
[2009/11/14 15:13:40 | 000,074,816 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/09/26 14:06:30 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/09/26 09:17:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/09/05 12:50:38 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/05/02 17:29:37 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Mike\Local Settings\Application Data\fusioncache.dat
[2009/05/02 15:26:35 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\BJAXSecurityManager.dll
[2009/05/02 15:26:34 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\BJInstaller.dll
[2009/04/23 06:22:12 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/04/22 11:26:42 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/04/22 11:24:46 | 000,000,222 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/04/22 11:22:13 | 000,001,996 | ---- | C] () -- C:\WINDOWS\System32\drivers\HDACfg.dat
[2009/04/22 11:22:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2009/04/22 11:20:42 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009/04/22 11:10:05 | 000,121,995 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/04/22 11:03:20 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2009/04/22 11:02:52 | 000,004,605 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2009/04/22 11:02:47 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2009/04/22 11:02:43 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2009/04/22 11:01:16 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2009/04/22 10:50:47 | 000,000,785 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008/10/07 08:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/05/26 19:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 19:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2007/09/27 08:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 08:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 08:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2005/12/29 15:47:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/10 11:53:59 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/08/09 14:44:34 | 000,465,838 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/09 14:44:34 | 000,079,598 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/09 14:40:44 | 000,341,832 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/09 14:33:30 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/09 14:28:56 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2003/01/07 13:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/17 14:30:26 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/17 14:30:26 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/17 14:15:40 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/07/21 15:36:50 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/07/21 15:36:06 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[1998/10/11 00:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
========== LOP Check ==========
[2011/11/27 20:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\!SASCORE
[2010/11/06 11:39:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/10/18 17:35:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2011/02/13 20:33:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2011/10/08 06:53:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/12/14 13:26:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Learning Company
[2010/04/27 07:46:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/14 14:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/02 16:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/12/03 12:37:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\74CD5
[2009/10/18 17:36:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\Autodesk
[2011/11/23 09:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\EqqqhYXXwkVrlBx
[2011/11/23 10:12:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\eRL9gTTXqUekBr
[2011/11/23 09:46:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\g99hhTXXwjC
[2010/12/14 13:31:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\InterTrust
[2011/11/23 11:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\jNNyxA0uvS2bFpG
[2011/11/23 19:59:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\JZZ9hYXwkUVlBPy
[2011/11/23 09:46:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\kQQJJ6ddEKf
[2009/09/12 16:29:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\Leadertech
[2009/11/17 18:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\LEGO Company
[2011/11/23 09:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\nQQJJ7dEE8gR
[2011/11/23 10:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\oAA11vvD2bF
[2011/10/08 06:54:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\outsparktoolbar
[2011/11/23 11:46:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\P00ycAA1iD3n4m
[2011/11/23 19:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\p333onGQH6W7f9T
[2011/07/20 09:28:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\Sony Online Entertainment
[2011/11/23 19:48:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\TcSS1ivDonGamsK
[2010/01/01 20:33:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\Unity
[2011/10/08 06:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\vmntemplate
[2009/05/02 17:29:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\Windows Desktop Search
[2009/09/26 13:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\Windows Search
[2011/11/23 19:48:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mike\Application Data\XmmGG5QJ7dE8gZh
[2011/12/09 00:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2011/12/09 04:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2011/12/09 05:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2011/12/09 05:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2011/12/09 06:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2011/12/09 06:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2011/12/09 07:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2011/12/09 07:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2011/12/09 08:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2011/12/09 08:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2011/12/09 09:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2011/12/09 00:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2011/12/09 09:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2011/12/28 10:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2011/12/28 10:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2011/12/09 11:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2011/12/09 11:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2011/12/26 12:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At25.job
[2011/12/26 12:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At26.job
[2011/12/26 13:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At27.job
[2011/12/26 13:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At28.job
[2011/12/09 14:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At29.job
[2011/12/09 01:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2011/12/09 14:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At30.job
[2011/12/09 15:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At31.job
[2011/12/09 15:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At32.job
[2011/12/29 16:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At33.job
[2011/12/29 16:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At34.job
[2011/12/09 17:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At35.job
[2011/12/09 17:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At36.job
[2011/12/10 18:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At37.job
[2011/12/10 18:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At38.job
[2011/12/08 19:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At39.job
[2011/12/09 01:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2011/12/08 19:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At40.job
[2011/12/08 20:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At41.job
[2011/12/08 20:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At42.job
[2011/12/08 21:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At43.job
[2011/12/08 21:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At44.job
[2011/12/21 22:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At45.job
[2011/12/21 22:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At46.job
[2011/12/21 23:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At47.job
[2011/12/21 23:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At48.job
[2011/12/09 02:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2011/12/09 02:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2011/12/09 03:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2011/12/09 03:00:00 | 000,000,354 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2011/12/09 04:00:00 | 000,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
========== Purity Check ==========
< End of report >