Every time I run a search in Google.com (or other search engines), and I attempt to click on a selection in the results list, I get redirected to a Letstrywithme.com site. An example redirect address would be: http://letstrywithme...2FkaW5nK2dtYWls
Incidentally, it's never an actual site. I get an error message indicating "Server not found. Firefox can't find the server at letstrywithme.com."
I use Firefox exclusively.
Online research indicates it's malware. Spybot and Malwarebyte's Anti-malware have found nothing.
Prior to this particular redirect, I also got lots of others, but usually, if I went back to the search page and clicked on the result a second time, it sent me to the correct page. With this redirect, that's not the case.
I'm attaching the OTL log below, but will mention also two other issues. I only bring them up in case they're related. If they're not, I'm happy to start a new thread later on.Please feel free to disregard if these are unrelated issues. 1) My gmail refuses to load on my laptop only. It freezes on the loading page and blocks any other pages from loading. Nothing works until I restart Firefox. This is ONLY a problem on one computer. the gmail account works perfectly on my desktop and android phone. I've attempted to remove add-ons, clear cache and cookies, etc. to no avail. 2) I downloaded Chrome which did not work properly on my laptop either. I uninstalled it, but I don't know if there are residual issues which are affecting the laptop.
Regarding the Letstrywithme.com redirect: OTL Log
OTL logfile created on: 12/19/2010 7:10:49 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\LILLY\My Documents\Downloads
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 148.80 Gb Total Space | 44.51 Gb Free Space | 29.91% Space Free | Partition Type: NTFS
Computer Name: LEVOFFLAW2 | User Name: LILLY | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/12/19 07:10:09 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\LILLY\My Documents\Downloads\OTL.exe
PRC - [2010/12/11 20:54:36 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/12/11 20:54:34 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/05/07 17:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/05/19 02:19:48 | 000,382,384 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2007/06/13 02:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/03 18:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006/03/02 15:03:24 | 000,082,012 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2006/03/02 14:50:52 | 000,151,552 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\Toshiba.exe
PRC - [2006/01/05 14:02:24 | 000,352,256 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe
PRC - [2005/12/20 11:22:14 | 000,035,328 | ---- | M] (TOSHIBA Corp.) -- C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
PRC - [2005/11/30 12:25:22 | 000,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
PRC - [2005/11/28 10:41:50 | 000,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2005/11/28 10:31:32 | 000,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/11/28 10:29:00 | 000,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/11/28 10:28:14 | 000,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/08/16 11:23:12 | 000,188,416 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
PRC - [2005/07/12 17:14:42 | 000,040,960 | ---- | M] () -- c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
PRC - [2005/05/31 20:59:58 | 000,045,056 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSBattM.exe
PRC - [2005/03/11 15:03:16 | 000,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TDispVol.exe
PRC - [2005/01/17 16:38:38 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2004/08/28 00:33:00 | 000,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\DVDRAMSV.exe
========== Modules (SafeList) ==========
MOD - [2010/12/19 07:10:09 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\LILLY\My Documents\Downloads\OTL.exe
MOD - [2010/05/24 18:35:05 | 000,040,960 | -H-- | M] () -- C:\WINDOWS\system32\caclnsvr.dll
MOD - [2006/08/25 07:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2002/03/03 04:40:00 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\TDispVol.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2010/05/07 17:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2006/11/03 18:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005/12/20 11:22:14 | 000,035,328 | ---- | M] (TOSHIBA Corp.) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe -- (TAPPSRV)
SRV - [2005/11/28 10:31:32 | 000,540,745 | ---- | M] (Intel Corporation ) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2005/11/28 10:29:00 | 000,114,753 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2005/11/28 10:28:14 | 000,217,164 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2005/07/12 17:14:42 | 000,040,960 | ---- | M] () [Auto | Running] -- c:\TOSHIBA\IVP\swupdate\swupdtmr.exe -- (Swupdtmr)
SRV - [2005/01/17 16:38:38 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs)
SRV - [2004/08/28 00:33:00 | 000,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) [Auto | Running] -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\SYSPREP\PEDrv.sys -- (SVRPEDRV)
DRV - File not found [Kernel | On_Demand | Stopped] -- c:\sysprep\Drivers\ioport.sys -- (IO_Memory)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2010/07/27 00:15:20 | 000,023,904 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2010/07/27 00:14:58 | 006,842,464 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 905(UVC)
DRV - [2010/07/27 00:12:50 | 000,282,336 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2010/05/07 17:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/05/11 09:12:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008/07/06 23:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2006/10/15 22:27:40 | 000,016,694 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - [2006/03/02 14:46:54 | 000,191,968 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2006/02/16 01:56:07 | 000,008,552 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2005/12/09 16:48:40 | 004,123,136 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/12/04 09:55:30 | 001,428,096 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2005/11/30 11:01:02 | 000,043,392 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tvs.sys -- (Tvs)
DRV - [2005/11/30 10:12:00 | 000,162,560 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2005/11/28 11:09:26 | 000,013,568 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2005/11/25 02:38:00 | 000,028,800 | ---- | M] (UPEK Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tcusb.sys -- (TcUsb)
DRV - [2005/11/15 09:00:22 | 001,122,656 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2005/10/20 14:03:42 | 000,006,144 | ---- | M] (Toshiba Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NBSMI.sys -- (TVALD)
DRV - [2005/10/06 05:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/10/06 05:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/10/06 05:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/10/06 05:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/10/06 05:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/10/06 05:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/10/06 05:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/09/14 02:24:08 | 000,179,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\e1e5132.sys -- (e1express) Intel®
DRV - [2005/09/12 03:30:00 | 000,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2005/09/09 14:47:10 | 000,009,344 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2005/08/25 12:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/08/25 12:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/08/24 15:20:28 | 000,009,472 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tbiosdrv.sys -- (tbiosdrv)
DRV - [2005/08/17 19:44:50 | 000,049,867 | R--- | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mardp2k.sys -- (MaRdPnp)
DRV - [2005/08/17 19:44:44 | 000,011,473 | R--- | M] (Mobile Action Technology Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\MaVc2K.sys -- (MaVctrl)
DRV - [2005/08/12 05:20:00 | 000,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2005/06/02 03:33:00 | 000,102,384 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf)
DRV - [2005/01/12 00:05:46 | 000,204,160 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\KR10N.sys -- (KR10N)
DRV - [2005/01/07 17:07:18 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2004/09/16 01:11:02 | 000,025,300 | R--- | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MA8512M.sys -- (MA8512M)
DRV - [2004/09/16 01:11:00 | 000,049,106 | R--- | M] (Mobile Action Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MA8512U.sys -- (MA8512U)
DRV - [2004/08/03 22:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2003/09/19 01:47:00 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (Pfc)
DRV - [2003/09/10 23:36:54 | 000,021,060 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iviaspi.sys -- (Iviaspi)
DRV - [2003/01/29 14:35:00 | 000,012,032 | ---- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio)
DRV - [2003/01/10 12:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google Powered Search"
FF - prefs.js..browser.startup.homepage: "chrome://foxtab/content/homepage.html"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {84529B17-C173-45EE-BA05-412ADCB4D9CD}:1.9.1
FF - prefs.js..extensions.enabledItems: {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}:1.4.1
FF - prefs.js..keyword.URL: "http://search.condui...d=CT2504091&q="
FF - HKLM\software\mozilla\Firefox\extensions\\{84529B17-C173-45EE-BA05-412ADCB4D9CD}: C:\Documents and Settings\LILLY\Local Settings\Application Data\{84529B17-C173-45EE-BA05-412ADCB4D9CD} [2010/05/27 19:36:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/18 19:15:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/19 05:59:11 | 000,000,000 | ---D | M]
[2009/05/19 02:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Extensions
[2009/05/19 02:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Extensions\[email protected]
[2010/12/19 06:17:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\extensions
[2010/12/19 06:10:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/18 02:01:05 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/23 00:19:11 | 000,000,000 | ---D | M] (Vuze Remote Toolbar) -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/12/11 21:36:57 | 000,000,000 | ---D | M] (FoxTab) -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}
[2009/11/12 23:34:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\extensions\[email protected]
[2010/05/23 01:11:17 | 000,000,903 | ---- | M] () -- C:\Documents and Settings\LILLY\Application Data\Mozilla\Firefox\Profiles\68mnu47b.default\searchplugins\conduit.xml
[2010/12/19 06:17:41 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/10/22 11:40:45 | 000,000,000 | ---D | M] (Findbasic) -- C:\Program Files\Mozilla Firefox\extensions\{C3F23840-B14B-4B61-AAEF-6BCC3621FA63}
[2010/09/22 00:12:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}
[2010/05/24 00:20:19 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2007/03/09 15:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2009/08/21 03:13:54 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic117.xml
[2009/08/28 13:30:10 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic119.xml
[2009/09/04 16:02:05 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic121.xml
[2009/09/22 06:01:18 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic123.xml
[2009/09/27 18:30:21 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic125.xml
[2009/10/16 23:23:30 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic127.xml
[2009/10/22 11:40:46 | 000,002,392 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\findbasic131.xml
O1 HOSTS File: ([2010/05/24 15:57:25 | 000,393,062 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13576 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe File not found
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Brindys Update - {FFB54554-1545-9908-5010-B4134A1B4101} - C:\Documents and Settings\LILLY\Local Settings\Temp\bsu.html ()
O9 - Extra 'Tools' menuitem : Brindys &Update - {FFB54554-1545-9908-5010-B4134A1B4101} - C:\Documents and Settings\LILLY\Local Settings\Temp\bsu.html ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: efax.com ([www] http in Trusted sites)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://portal.omm.co...ca32/wficat.cab (Citrix ICA Client)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1181342368703 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\LILLY\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\LILLY\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/15 07:38:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{31ba340c-beda-11dd-ad70-86e79704df28}\Shell - "" = AutoRun
O33 - MountPoints2\{31ba340c-beda-11dd-ad70-86e79704df28}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{31ba340c-beda-11dd-ad70-86e79704df28}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{5cc47ec5-e0ee-11db-b6a8-0018de07369d}\Shell - "" = AutoRun
O33 - MountPoints2\{5cc47ec5-e0ee-11db-b6a8-0018de07369d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5cc47ec5-e0ee-11db-b6a8-0018de07369d}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: dplapsrv - (C:\WINDOWS\system32\caclnsvr.dll) - C:\WINDOWS\system32\caclnsvr.dll ()
O36 - AppCertDlls: mrinckup - (C:\WINDOWS\system32\igfxexec.dll) - C:\WINDOWS\system32\igfxexec.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/12/19 05:58:32 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2009/11/20 08:00:59 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\LILLY\Application Data\pcouffin.sys
[2006/12/11 23:34:23 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\IMPLODE.DLL
[2006/02/15 08:25:00 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\DLLVGA.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/19 06:55:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3956782973-2139545190-3139515377-1005UA.job
[2010/12/19 06:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/12/19 05:59:12 | 000,001,740 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/12/19 05:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2010/12/19 04:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2010/12/19 03:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2010/12/19 03:34:01 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/12/19 03:30:58 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/12/19 03:30:38 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/12/19 03:30:37 | 1600,180,224 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/19 02:00:29 | 000,000,306 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/12/19 00:55:00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3956782973-2139545190-3139515377-1005Core.job
[2010/12/18 22:44:13 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2010/12/18 21:44:12 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2010/12/18 17:44:12 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/12/17 23:15:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2010/12/17 23:15:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/12/17 23:15:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2010/12/17 02:00:50 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/12/06 01:40:00 | 000,000,314 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/12/04 09:00:00 | 000,000,386 | ---- | M] () -- C:\WINDOWS\tasks\rpc.job
[2010/11/30 10:15:28 | 000,000,259 | ---- | M] () -- C:\WINDOWS\Lawgic.ini
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/19 05:59:11 | 000,001,740 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/10/28 15:38:20 | 000,052,224 | -H-- | C] () -- C:\WINDOWS\System32\igfxexec.dll
[2010/10/14 05:22:27 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\jsfhjjsd.bat
[2010/07/27 00:03:20 | 010,829,656 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll
[2010/07/27 00:03:18 | 000,290,648 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll
[2010/07/26 23:56:04 | 000,090,411 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2010/05/24 18:35:05 | 000,040,960 | -H-- | C] () -- C:\WINDOWS\System32\caclnsvr.dll
[2010/05/24 18:34:41 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\bpzmnq.dat
[2010/05/24 01:17:45 | 000,030,000 | ---- | C] () -- C:\WINDOWS\System32\bdgtguxvn.dll
[2010/05/07 17:46:36 | 000,014,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2010/05/07 17:43:30 | 000,025,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2010/04/26 10:10:43 | 000,016,346 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\0jf5835bS5a
[2010/04/26 10:10:43 | 000,016,346 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\0jf5835bS5a
[2010/03/03 09:46:52 | 000,013,040 | -HS- | C] () -- C:\Documents and Settings\LILLY\Local Settings\Application Data\osee
[2010/01/15 17:24:29 | 000,001,311 | ---- | C] () -- C:\WINDOWS\hpbvnstp.ini
[2009/11/20 08:01:12 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\pcouffin.log
[2009/11/20 08:00:59 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\inst.exe
[2009/11/20 08:00:59 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\pcouffin.cat
[2009/11/20 08:00:59 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\pcouffin.inf
[2009/07/28 09:27:12 | 000,000,187 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2008/09/15 16:14:24 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/09/15 16:11:10 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/11/02 23:53:13 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\LILLY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/29 19:36:45 | 000,241,664 | R--- | C] () -- C:\WINDOWS\System32\hppapr04.DLL
[2007/07/26 12:07:44 | 000,000,582 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/06/08 15:19:15 | 000,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\addr_file.html
[2006/12/29 14:53:35 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[2006/12/22 01:16:01 | 000,000,384 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2006/12/17 12:51:40 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2006/12/11 23:38:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2006/12/11 23:34:34 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\ExportModeller.dll
[2006/12/11 23:34:31 | 000,049,223 | ---- | C] () -- C:\WINDOWS\System32\crtslv.dll
[2006/12/11 23:34:30 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\u25store.dll
[2006/12/11 23:34:23 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\xhbcommdll.dll
[2006/12/11 23:34:22 | 001,220,096 | ---- | C] () -- C:\WINDOWS\System32\AbacusDB.dll
[2006/12/11 23:34:22 | 000,303,104 | ---- | C] () -- C:\WINDOWS\System32\FreeImage.dll
[2006/12/11 23:34:22 | 000,173,056 | ---- | C] () -- C:\WINDOWS\System32\gteinet.dll
[2006/12/11 23:34:22 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\crheapalloc.dll
[2006/12/03 04:48:48 | 000,000,120 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\FixVTS.ini
[2006/11/29 16:06:13 | 000,000,073 | ---- | C] () -- C:\WINDOWS\webica.ini
[2006/11/28 01:49:41 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2006/11/10 22:37:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EngineExe.INI
[2006/11/05 21:20:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MelodyExe.INI
[2006/11/05 20:57:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\FileMgrExe.INI
[2006/11/05 20:27:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PanelExe.INI
[2006/11/04 22:51:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\AlbumExe.INI
[2006/11/04 22:06:30 | 000,000,098 | ---- | C] () -- C:\WINDOWS\PhoneBkExe.INI
[2006/10/16 15:52:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2006/10/15 22:25:10 | 000,000,259 | ---- | C] () -- C:\WINDOWS\LawgicOLD.ini
[2006/10/15 22:24:18 | 000,000,259 | ---- | C] () -- C:\WINDOWS\Lawgic.ini
[2006/10/15 22:24:18 | 000,000,055 | ---- | C] () -- C:\WINDOWS\BRJ.ini
[2006/10/15 15:43:16 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\PFP120JPR.{PB
[2006/10/15 15:43:16 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\LILLY\Application Data\PFP120JCM.{PB
[2006/10/15 12:57:26 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\LILLY\Local Settings\Application Data\fusioncache.dat
[2006/10/12 16:18:56 | 000,007,936 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll
[2006/09/19 09:33:56 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/31 09:46:13 | 000,000,310 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2006/05/13 14:56:11 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2006/02/24 20:28:54 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\TDispVol.dll
[2006/02/16 07:07:58 | 000,000,012 | ---- | C] () -- C:\WINDOWS\dirsaver.ini
[2006/02/16 01:50:52 | 000,000,383 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/02/16 01:25:21 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/02/16 01:25:21 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/02/16 01:25:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/02/16 01:25:21 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/02/16 01:25:21 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/02/16 01:25:21 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/02/15 08:41:53 | 000,036,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\CSIIDecoder_kern_i386.sys
[2006/02/15 08:41:53 | 000,029,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSXT_kern_i386.sys
[2006/02/15 08:40:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NDSTray.INI
[2006/02/15 08:28:50 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2006/02/15 08:28:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2006/02/15 08:28:50 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2006/02/15 08:28:50 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2006/02/15 08:25:00 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\TCtrlIO.dll
[2006/02/15 08:21:53 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2006/02/15 07:44:19 | 000,000,484 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/02/15 07:34:07 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2006/02/15 06:09:00 | 000,000,341 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/02/14 23:30:19 | 000,004,325 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/11/28 20:33:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/09/02 14:44:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\TosBtAcc.dll
[2005/08/24 15:20:28 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\tbiosdrv.sys
[2005/08/05 14:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/07/22 21:30:20 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\TosCommAPI.dll
[2004/07/20 17:04:02 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\TosBtHcrpAPI.dll
[2004/01/15 14:43:28 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\TBTMonUI.dll
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/01/06 19:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2010/04/26 10:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avG
[2010/11/16 22:30:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Brindys
[2006/10/19 15:07:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.1 Setup
[2010/10/13 20:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GEDEX
[2006/10/15 22:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2010/06/10 01:23:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/02 15:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transparent
[2010/03/17 03:04:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VCOM
[2010/10/13 20:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/05/13 15:20:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/08/20 04:41:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/11/02 15:44:38 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
[2010/05/24 16:35:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\00CC0DD11507A96CF638C9496EBF7285
[2008/04/23 23:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\acccore
[2008/04/23 23:10:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Aim
[2010/12/18 19:14:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Azureus
[2010/05/24 23:16:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\CheeseSoft
[2010/11/17 02:33:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\eFax Messenger
[2009/01/22 00:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\GARMIN
[2006/10/15 22:27:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\HotSync
[2006/11/29 16:06:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\ICAClient
[2006/11/10 21:39:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\InterVideo
[2006/10/15 22:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Leadertech
[2009/11/26 04:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\LimeWire
[2006/10/16 16:07:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\OverDrive
[2006/12/03 01:05:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\RipIt4Me
[2006/10/15 19:21:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\toshiba
[2010/06/04 16:29:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\URSoft
[2010/03/17 03:04:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\VCOM
[2009/11/20 08:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LILLY\Application Data\Vso
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2010/12/17 23:15:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2010/12/17 23:15:43 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2010/12/18 17:44:12 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2010/12/18 21:44:12 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2010/12/18 22:44:13 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2010/12/19 03:30:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2010/12/19 03:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2010/12/19 05:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2010/12/19 04:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2010/12/17 23:15:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2010/12/19 06:44:00 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2010/12/17 23:15:42 | 000,000,404 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
[2010/12/19 03:34:01 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/12/04 09:00:00 | 000,000,386 | ---- | M] () -- C:\WINDOWS\Tasks\rpc.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51
< End of report >