My friend's computer was recently infected with the fake Microsoft Security Check malware/mess. I have been trying to help them get it back to normal. Thanks to the terrific assistance of someone on their anti-malware site's forum, I have gotten it clean and mostly recovered but we are having trouble recovering the shortcuts in All Programs. Most of them are empty. The All Programs Accessories and All Programs Administrative Tools were the few shortcuts left intact.
Unfortunately the smtmp folders are empty so we cannot recover the items from there. And to further cause aggravation, despite having Sysyem Restore points galore, System Restore always come up incomplete whether in Safe or Normal mode.
I had seen in another forum on this site (http://www.geekstogo...us/page__st__10) the repair.vbs program and was hoping someone could advise me:
1. If it was ok to run based upon this computers situation prior to my downloading and running it.
2. They only have the Administrator and "owner" as users on this computer. Would I paste the links to C:\Documents and Settings\ Administrator.YOUR-5E03CF73DE\Start Menu or the Owner's start Menu? Does it make a difference?
3. Just paste the links to Start Menu or open it and paste it to programs?
4. Do MBAM and Avira need to be disabled prior to running repair.vbs and pasting the shortcuts?
I cannot open the programs from the C:\Program Files folder either as they are all file folders and if I open a program's folder i.e. Microsoft Works or Works Suite, I see several .exe files and I have no idea which one is the one that opens the program...
This program appears to be their last resort prior to a repair install so I would be really grateful for your help. (I didn't post the link to the other site with the whole history of what we did as I thought the posting rules asked not to).
Here is the OTL log:
OTL logfile created on: 3/16/2012 1:17:34 PM - Run 3
OTL by OldTimer - Version 3.2.37.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 70.81% Memory free
2.29 Gb Paging File | 1.77 Gb Available in Paging File | 77.38% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.28 Gb Total Space | 125.64 Gb Free Space | 84.73% Space Free | Partition Type: NTFS
Drive D: | 5.08 Gb Total Space | 2.70 Gb Free Space | 53.11% Space Free | Partition Type: FAT32
Computer Name: YOUR-5E03CF73DE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/15 13:58:16 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.com
PRC - [2011/12/12 12:03:40 | 000,290,832 | ---- | M] (Verizon) -- C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
PRC - [2011/10/11 15:00:32 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/10/11 15:00:20 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/10/11 15:00:08 | 000,258,512 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/10/11 15:00:08 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/01/23 19:47:42 | 000,770,728 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\lxecmon.exe
PRC - [2010/04/14 16:08:12 | 000,598,696 | ---- | M] ( ) -- C:\WINDOWS\system32\lxeccoms.exe
PRC - [2010/03/17 16:55:42 | 001,565,696 | ---- | M] (Alcatel-Lucent) -- C:\Program Files\Verizon\McciTrayApp.exe
PRC - [2010/01/18 12:27:10 | 000,139,944 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\ezprint.exe
PRC - [2009/11/18 10:50:40 | 000,668,912 | ---- | M] (Radialpoint Inc.) -- C:\Program Files\Verizon\VSP\ServicepointService.exe
PRC - [2009/11/18 10:50:32 | 000,468,208 | ---- | M] (Radialpoint Inc.) -- C:\Program Files\Verizon\VSP\VerizonServicepointComHandler.exe
PRC - [2009/11/18 10:50:30 | 004,269,296 | ---- | M] (Verizon) -- C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
PRC - [2008/09/29 20:49:00 | 000,054,776 | ---- | M] (Abacast, Inc.) -- C:\Documents and Settings\Owner\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/06/28 14:17:25 | 000,196,608 | ---- | M] (New Boundary Technologies, Inc.) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2006/05/16 23:15:10 | 000,071,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
PRC - [2004/04/06 15:04:38 | 000,053,248 | ---- | M] (Netscape Communications Corporation) -- C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
========== Modules (No Company Name) ==========
MOD - [2012/03/15 15:42:56 | 000,220,672 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e6deccf191ab943d3a0812a38ab5c97\CustomMarshalers.ni.dll
MOD - [2012/03/15 15:42:47 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
MOD - [2012/03/15 15:27:09 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
MOD - [2012/03/15 15:23:57 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
MOD - [2012/03/15 15:23:42 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2012/02/16 21:24:58 | 000,372,736 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
MOD - [2012/02/16 21:24:45 | 000,114,688 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
MOD - [2012/02/16 21:24:40 | 000,069,120 | ---- | M] () -- C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2011/10/11 15:00:22 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2011/01/23 19:47:42 | 000,770,728 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\lxecmon.exe
MOD - [2010/04/05 06:56:17 | 002,203,803 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\epwizres.dll
MOD - [2010/04/01 13:24:28 | 001,159,168 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\lxecdrs.dll
MOD - [2010/04/01 13:23:27 | 000,389,120 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\lxecscw.dll
MOD - [2010/01/18 12:27:10 | 000,139,944 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\ezprint.exe
MOD - [2009/12/16 13:07:29 | 001,159,168 | ---- | M] () -- C:\Program Files\Lexmark\Pro800-Pro900 Series\lxecdrs.dll
MOD - [2009/12/16 07:42:12 | 000,167,936 | ---- | M] () -- C:\Program Files\Lexmark\Pro800-Pro900 Series\lxecmicro.dll
MOD - [2009/11/26 02:08:23 | 000,049,152 | ---- | M] () -- C:\WINDOWS\system32\LXECPMON.DLL
MOD - [2009/11/18 10:42:38 | 000,158,208 | ---- | M] () -- C:\Program Files\Verizon\VSP\Windows7Features.dll
MOD - [2009/11/04 09:14:19 | 000,157,696 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\lxecdrpp.dll
MOD - [2009/05/27 08:16:50 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\lxecdatr.dll
MOD - [2009/04/07 15:25:27 | 000,409,600 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\iptk.dll
MOD - [2009/03/30 08:37:47 | 000,094,208 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\epoemdll.dll
MOD - [2009/03/30 08:37:46 | 000,045,056 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\epstring.dll
MOD - [2009/03/30 08:37:28 | 000,708,608 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\epwizard.dll
MOD - [2009/03/30 08:35:40 | 000,159,744 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\customui.dll
MOD - [2009/03/30 08:35:22 | 000,061,440 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\epfunct.dll
MOD - [2009/03/30 08:35:17 | 000,118,784 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\eputil.dll
MOD - [2009/03/30 08:35:05 | 000,139,264 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\imagutil.dll
MOD - [2009/03/10 01:43:49 | 000,155,648 | ---- | M] () -- C:\Program Files\Lexmark\Pro800-Pro900 Series\lxeccaps.dll
MOD - [2009/03/10 01:43:49 | 000,155,648 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\lxeccaps.dll
MOD - [2009/03/02 10:25:47 | 000,151,552 | ---- | M] () -- C:\Program Files\Lexmark Pro800-Pro900 Series\lxecptp.dll
MOD - [2009/02/20 04:48:43 | 000,023,552 | ---- | M] () -- C:\WINDOWS\system32\LXECsmr.dll
MOD - [2009/02/20 04:48:03 | 000,299,008 | ---- | M] () -- C:\WINDOWS\system32\LXECsm.dll
MOD - [2009/01/13 09:15:12 | 004,485,120 | ---- | M] () -- C:\WINDOWS\system32\LXECoem.dll
MOD - [2004/03/11 19:56:30 | 000,081,920 | ---- | M] () -- C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/12/12 12:03:40 | 000,290,832 | ---- | M] (Verizon) [Auto | Running] -- C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe -- (IHA_MessageCenter)
SRV - [2011/10/11 15:00:20 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/10/11 15:00:08 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/04/14 16:08:12 | 000,598,696 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\system32\lxeccoms.exe -- (lxec_device)
SRV - [2010/04/14 16:08:05 | 000,193,192 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxecserv.exe -- (lxecCATSCustConnectService)
SRV - [2009/11/18 10:50:40 | 000,668,912 | ---- | M] (Radialpoint Inc.) [Auto | Running] -- C:\Program Files\Verizon\VSP\ServicepointService.exe -- (ServicepointService)
SRV - [2006/06/28 14:17:25 | 000,196,608 | ---- | M] (New Boundary Technologies, Inc.) [Auto | Running] -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- (PrismXL)
SRV - [2004/04/06 15:04:38 | 000,053,248 | ---- | M] (Netscape Communications Corporation) [Auto | Running] -- C:\Program Files\Netscape Internet Service\ncupdatesvc.exe -- (NCUpdateSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS -- (MRENDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS -- (MREMPR5)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012/02/15 12:15:03 | 000,137,416 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/10/11 15:00:32 | 000,074,640 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/10/11 15:00:32 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/03/17 16:53:38 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2010/03/17 16:53:22 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008/02/25 12:54:56 | 000,105,088 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2007/02/04 20:26:59 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2006/06/28 14:14:32 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2006/01/25 15:52:32 | 001,478,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/01/13 21:13:18 | 004,137,984 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/07/28 12:18:40 | 000,685,056 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2005/07/22 11:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 11:01:10 | 000,231,168 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2005/07/22 11:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/07/20 22:08:28 | 000,100,096 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb)
DRV - [2005/07/20 22:08:26 | 000,327,808 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp)
DRV - [2001/08/17 16:49:32 | 000,019,968 | ---- | M] (Macronix International Co., Ltd. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mxnic.sys -- (mxnic)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon...P&CMP=DMC-MVZ00
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7GWYF_enUS314
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Verizon\VSP\nprpspa.dll (Verizon)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
O1 HOSTS File: ([2012/03/02 15:14:11 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (PBlockHelper Class) - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\pbhelper.dll (planetscott.ca)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\system32\bae.dll (Gateway Inc.)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark Pro800-Pro900 Series\ezprint.exe ()
O4 - HKLM..\Run: [Gateway Extended Warranty] C:\Program Files\Gateway\GWCares\GWCares.exe (BillP Studios)
O4 - HKLM..\Run: [Lexmark Pro800-Pro900 Series Fax Server] C:\Program Files\Lexmark Pro800-Pro900 Series\fm3032.exe ()
O4 - HKLM..\Run: [lxecmon.exe] C:\Program Files\Lexmark Pro800-Pro900 Series\lxecmon.exe ()
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\VSP\VerizonServicepoint.exe (Verizon)
O4 - HKCU..\Run: [AbacastDistributedOnDemand:11] C:\Documents and Settings\Owner\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe (Abacast, Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ()
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyds...t Installer.cab (Support.com Configuration Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1285267317328 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C6A64E4-1CC7-4A77-AEAF-23DEA62485B8}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 14:04:39 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/15 15:28:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2012/03/15 15:27:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/03/15 13:58:12 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.com
[2012/03/14 14:52:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Audible
[2012/03/14 13:20:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory
[2012/03/14 13:19:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2012/03/14 13:19:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm
[2012/03/14 13:19:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/03/14 13:19:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/03/12 14:26:19 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$
[2012/03/12 14:08:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/03/12 14:08:14 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/03/06 14:28:39 | 002,063,920 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Owner\Desktop\tdsskiller.exe
[2012/03/05 16:02:56 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/03/05 15:53:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\GrantPerms
[2012/03/02 15:03:55 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/03/02 14:58:34 | 004,424,615 | R--- | C] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/02/28 14:11:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2012/02/28 14:08:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2012/02/27 18:51:36 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2012/02/27 18:50:32 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2012/02/27 14:57:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/02/27 14:47:22 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/27 14:47:22 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/27 14:47:22 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/27 14:47:22 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/27 14:36:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/27 14:20:48 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/27 11:42:07 | 000,583,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/02/27 11:39:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\RK_Quarantine
[2012/02/25 18:46:30 | 000,607,260 | R--- | C] (Swearware) -- C:\Program Files\dds.scr
[2012/02/25 14:07:19 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/02/25 12:52:15 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Owner\Recent
[2012/02/22 10:14:33 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Owner\PrivacIE
[2012/02/21 21:38:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Owner\IETldCache
[2012/02/21 21:18:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2012/02/21 21:11:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8
[2011/08/23 11:31:36 | 001,284,232 | ---- | C] (Coupons.com Incorporated) -- C:\Program Files\couponprinter.exe
[2011/06/27 18:20:25 | 000,900,384 | ---- | C] (Sun Microsystems, Inc.) -- C:\Program Files\JavaSetup6u26.exe
[2011/06/24 13:19:42 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Program Files\ATF_Cleaner.exe
========== Files - Modified Within 30 Days ==========
[2012/03/16 13:16:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/16 11:16:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/15 17:11:55 | 000,000,000 | ---- | M] () -- C:\WINDOWS\TempFile
[2012/03/15 17:11:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/15 17:11:39 | 2011,746,304 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/15 15:30:40 | 000,502,794 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/15 15:30:40 | 000,087,134 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/15 15:07:26 | 000,653,000 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-15-2012 03;07;06PM2.JPG
[2012/03/15 15:07:25 | 000,721,628 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-15-2012 03;07;06PM.JPG
[2012/03/15 14:48:53 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/15 13:58:16 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.com
[2012/03/13 16:19:11 | 000,502,586 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM13.JPG
[2012/03/13 16:19:11 | 000,413,208 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM17.JPG
[2012/03/13 16:19:11 | 000,253,895 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM14.JPG
[2012/03/13 16:19:11 | 000,182,688 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM15.JPG
[2012/03/13 16:19:11 | 000,143,904 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM16.JPG
[2012/03/13 16:19:10 | 000,302,577 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM9.JPG
[2012/03/13 16:19:10 | 000,234,317 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM8.JPG
[2012/03/13 16:19:10 | 000,159,407 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM11.JPG
[2012/03/13 16:19:10 | 000,157,861 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM10.JPG
[2012/03/13 16:19:10 | 000,150,266 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM12.JPG
[2012/03/13 16:19:09 | 000,611,502 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM5.JPG
[2012/03/13 16:19:09 | 000,607,520 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM6.JPG
[2012/03/13 16:19:09 | 000,597,173 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM4.JPG
[2012/03/13 16:19:09 | 000,182,271 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM7.JPG
[2012/03/13 16:19:08 | 000,589,904 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM3.JPG
[2012/03/13 16:19:08 | 000,460,022 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM.JPG
[2012/03/13 16:19:08 | 000,360,664 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM2.JPG
[2012/03/13 15:40:35 | 000,246,312 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/13 15:21:09 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/03/12 18:05:44 | 000,308,498 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-12-2012 06;05;33PM.JPG
[2012/03/11 10:13:55 | 000,568,802 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-11-2012 10;07;51AM.JPG
[2012/03/06 14:28:38 | 002,063,920 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Owner\Desktop\tdsskiller.exe
[2012/03/06 12:38:36 | 001,098,419 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-06-2012 11;38;21AM3.JPG
[2012/03/06 12:38:36 | 000,357,698 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-06-2012 11;38;21AM2.JPG
[2012/03/06 12:38:36 | 000,303,173 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-06-2012 11;38;21AM.JPG
[2012/03/05 15:52:55 | 000,450,985 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\GrantPerms.zip
[2012/03/02 15:14:11 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/02 15:03:59 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/03/02 14:58:34 | 004,424,615 | R--- | M] (Swearware) -- C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/03/02 13:12:23 | 000,597,131 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-02-2012 12;10;40PM.JPG
[2012/03/01 17:26:14 | 000,639,933 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\03-01-2012 04;25;45PM.JPG
[2012/03/01 15:42:50 | 000,008,076 | ---- | M] () -- C:\PARADOX.NET
[2012/02/27 18:51:36 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2012/02/27 18:50:37 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2012/02/27 18:28:45 | 001,281,024 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/02/27 14:49:10 | 000,000,327 | ---- | M] () -- C:\Boot.bak
[2012/02/27 11:42:11 | 000,583,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/02/25 18:46:34 | 000,607,260 | R--- | M] (Swearware) -- C:\Program Files\dds.scr
[2012/02/25 18:17:08 | 001,008,141 | ---- | M] () -- C:\Program Files\rkill.exe
[2012/02/24 17:20:12 | 000,551,183 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-24-2012 04;20;04PM.JPG
[2012/02/22 11:52:52 | 000,515,074 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-22-2012 10;52;27AM2.JPG
[2012/02/22 11:52:51 | 000,099,991 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-22-2012 10;52;27AM.JPG
[2012/02/21 18:56:36 | 000,404,138 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 05;56;30PM.JPG
[2012/02/21 18:56:36 | 000,313,687 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 05;56;30PM2.JPG
[2012/02/21 18:54:34 | 000,146,623 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 05;54;28PM.JPG
[2012/02/21 16:16:59 | 000,146,728 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 03;16;55PM.JPG
[2012/02/21 12:53:13 | 000,279,297 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 11;52;47AM.JPG
[2012/02/19 18:52:09 | 000,232,642 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-19-2012 05;52;04PM.JPG
[2012/02/15 17:53:55 | 000,641,490 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM5.JPG
[2012/02/15 17:53:54 | 000,561,469 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM3.JPG
[2012/02/15 17:53:54 | 000,294,486 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM4.JPG
[2012/02/15 17:53:53 | 000,543,842 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM.JPG
[2012/02/15 17:53:53 | 000,509,786 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM2.JPG
========== Files Created - No Company Name ==========
[2012/03/15 15:07:26 | 000,653,000 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-15-2012 03;07;06PM2.JPG
[2012/03/15 15:07:25 | 000,721,628 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-15-2012 03;07;06PM.JPG
[2012/03/13 16:19:11 | 000,502,586 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM13.JPG
[2012/03/13 16:19:11 | 000,413,208 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM17.JPG
[2012/03/13 16:19:11 | 000,253,895 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM14.JPG
[2012/03/13 16:19:11 | 000,182,688 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM15.JPG
[2012/03/13 16:19:11 | 000,143,904 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM16.JPG
[2012/03/13 16:19:10 | 000,302,577 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM9.JPG
[2012/03/13 16:19:10 | 000,234,317 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM8.JPG
[2012/03/13 16:19:10 | 000,159,407 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM11.JPG
[2012/03/13 16:19:10 | 000,157,861 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM10.JPG
[2012/03/13 16:19:10 | 000,150,266 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM12.JPG
[2012/03/13 16:19:09 | 000,611,502 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM5.JPG
[2012/03/13 16:19:09 | 000,607,520 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM6.JPG
[2012/03/13 16:19:09 | 000,597,173 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM4.JPG
[2012/03/13 16:19:09 | 000,182,271 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM7.JPG
[2012/03/13 16:19:08 | 000,589,904 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM3.JPG
[2012/03/13 16:19:08 | 000,460,022 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM.JPG
[2012/03/13 16:19:08 | 000,360,664 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-13-2012 04;18;32PM2.JPG
[2012/03/12 18:05:44 | 000,308,498 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-12-2012 06;05;33PM.JPG
[2012/03/12 14:23:39 | 000,225,262 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msimain.sdb
[2012/03/11 10:13:55 | 000,568,802 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-11-2012 10;07;51AM.JPG
[2012/03/08 14:49:26 | 2011,746,304 | -HS- | C] () -- C:\hiberfil.sys
[2012/03/06 12:38:36 | 001,098,419 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-06-2012 11;38;21AM3.JPG
[2012/03/06 12:38:36 | 000,357,698 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-06-2012 11;38;21AM2.JPG
[2012/03/06 12:38:36 | 000,303,173 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-06-2012 11;38;21AM.JPG
[2012/03/05 15:49:54 | 000,450,985 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\GrantPerms.zip
[2012/03/02 13:12:23 | 000,597,131 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-02-2012 12;10;40PM.JPG
[2012/03/01 17:26:14 | 000,639,933 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\03-01-2012 04;25;45PM.JPG
[2012/03/01 15:42:45 | 000,008,076 | ---- | C] () -- C:\PARADOX.NET
[2012/02/27 18:51:36 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2012/02/27 18:24:34 | 000,001,986 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2012/02/27 18:24:34 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012/02/27 18:24:34 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/02/27 14:47:22 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/27 14:47:22 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/27 14:47:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/27 14:47:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/27 14:47:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/27 11:39:01 | 001,281,024 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\RogueKiller.exe
[2012/02/25 18:17:01 | 001,008,141 | ---- | C] () -- C:\Program Files\rkill.exe
[2012/02/24 17:20:12 | 000,551,183 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-24-2012 04;20;04PM.JPG
[2012/02/22 11:52:52 | 000,515,074 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-22-2012 10;52;27AM2.JPG
[2012/02/22 11:52:51 | 000,099,991 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-22-2012 10;52;27AM.JPG
[2012/02/21 18:56:36 | 000,404,138 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 05;56;30PM.JPG
[2012/02/21 18:56:36 | 000,313,687 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 05;56;30PM2.JPG
[2012/02/21 18:54:34 | 000,146,623 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 05;54;28PM.JPG
[2012/02/21 16:16:59 | 000,146,728 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 03;16;55PM.JPG
[2012/02/21 12:53:13 | 000,279,297 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-21-2012 11;52;47AM.JPG
[2012/02/19 18:52:09 | 000,232,642 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-19-2012 05;52;04PM.JPG
[2012/02/16 01:33:21 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/16 01:33:21 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/15 17:53:55 | 000,641,490 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM5.JPG
[2012/02/15 17:53:55 | 000,294,486 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM4.JPG
[2012/02/15 17:53:54 | 000,561,469 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM3.JPG
[2012/02/15 17:53:53 | 000,543,842 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM.JPG
[2012/02/15 17:53:53 | 000,509,786 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\02-15-2012 04;53;36PM2.JPG
[2011/10/24 14:47:03 | 000,260,762 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/06/23 13:19:47 | 000,684,297 | ---- | C] () -- C:\Program Files\unhide.exe
[2010/09/08 14:47:17 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxecvs.dll
[2010/09/08 14:47:15 | 000,442,368 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeccoin.dll
[2010/09/08 14:47:08 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\lxecgcfg.dll
[2010/09/08 14:47:07 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\lxeccui.dll
[2010/09/08 14:47:07 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\lxeccuir.dll
[2010/09/08 14:45:19 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\LXECPMON.DLL
[2010/09/08 14:45:19 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXECFXPU.DLL
[2010/09/08 14:44:59 | 004,485,120 | ---- | C] () -- C:\WINDOWS\System32\LXECoem.dll
[2010/09/08 14:43:17 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\lxecrwrd.ini
[2010/09/08 14:43:05 | 000,356,352 | ---- | C] ( ) -- C:\WINDOWS\System32\LXEChcp.dll
[2010/09/08 14:43:05 | 000,331,776 | ---- | C] () -- C:\WINDOWS\System32\LXECinst.dll
[2010/09/08 14:43:04 | 000,364,544 | ---- | C] ( ) -- C:\WINDOWS\System32\lxecinpa.dll
[2010/09/08 14:43:04 | 000,344,064 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeciesc.dll
[2010/09/08 14:43:03 | 001,048,576 | ---- | C] ( ) -- C:\WINDOWS\System32\lxecserv.dll
[2010/09/08 14:43:03 | 000,847,872 | ---- | C] ( ) -- C:\WINDOWS\System32\lxecusb1.dll
[2010/09/08 14:43:03 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxecpmui.dll
[2010/09/08 14:43:03 | 000,577,536 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeclmpm.dll
[2010/09/08 14:43:02 | 000,688,128 | ---- | C] ( ) -- C:\WINDOWS\System32\lxechbn3.dll
[2010/09/08 14:43:02 | 000,324,264 | ---- | C] ( ) -- C:\WINDOWS\System32\lxecih.exe
[2010/09/08 14:43:02 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\lxecins.dll
[2010/09/08 14:43:02 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\lxecinsb.dll
[2010/09/08 14:43:02 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxecgrd.dll
[2010/09/08 14:43:02 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\lxecinsr.dll
[2010/09/08 14:43:02 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\lxecjswr.dll
[2010/09/08 14:43:01 | 000,802,816 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeccomc.dll
[2010/09/08 14:43:01 | 000,598,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeccoms.exe
[2010/09/08 14:43:01 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeccomm.dll
[2010/09/08 14:43:01 | 000,253,952 | ---- | C] () -- C:\WINDOWS\System32\lxeccu.dll
[2010/09/08 14:43:01 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\lxeccub.dll
[2010/09/08 14:43:01 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\lxeccur.dll
[2010/09/08 14:43:00 | 000,373,416 | ---- | C] ( ) -- C:\WINDOWS\System32\lxeccfg.exe
[2010/09/08 14:42:19 | 000,299,008 | ---- | C] () -- C:\WINDOWS\System32\LXECsm.dll
[2010/09/08 14:42:19 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\LXECsmr.dll
========== LOP Check ==========
[2008/02/01 15:16:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2011/08/21 11:31:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lexmark Pro800-Pro900 Series
[2011/05/27 14:26:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2006/06/28 13:57:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Netscape Internet Service
[2010/09/08 14:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pro800-Pro900 Series
[2011/04/28 08:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Radialpoint
[2006/06/28 14:15:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/02/28 14:11:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/09/20 17:38:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Garmin
[2006/06/28 14:17:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Leadertech
[2011/08/22 10:11:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Pro800-Pro900 Series
[2006/06/28 14:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SampleView
[2010/09/16 13:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Template
[2010/07/12 14:27:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
[2010/07/13 14:01:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Windows Search
========== Purity Check ==========
< End of report >Thank you for your patience and help!