I ran RKILL to stop the process and then ran Malwarebytes to clean out the malwre.
After that all of my desktop shortcuts and files were gone as was my quick launch tool bar Icons. I also noticed that many of the shortcuts were missing from the start menu.
The next thing I did was run Unhide.exe. That brought back most of my desktop shortcuts and files but not all. The shortcuts in the start menu apeared to come back but folders in the menu are still empty.
The quick launch toolbar is there but all shortcuts are missing.
Windows XP Pro V 2002 SP3
Thanks in advance for the help.
OTL log
OTL logfile created on: 5/15/2011 1:24:46 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Michael\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 136.00 Mb Available Physical Memory | 27.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1500 3000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.87 Gb Total Space | 27.56 Gb Free Space | 49.32% Space Free | Partition Type: NTFS
Computer Name: MICHAEL-02YGOYZ | User Name: Michael | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Michael\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Michael\Local Settings\Application Data\Google\Update\1.3.21.53\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Nova Development\Photo Explosion\4.0\ReminderApp.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lexmark 2500 Series\lxddmon.exe ()
PRC - C:\WINDOWS\system32\lxddcoms.exe ( )
PRC - C:\Program Files\Lexmark 2500 Series\lxddamon.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Michael\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) -- File not found
SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (lxddCATSCustConnectService) -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe ()
SRV - (lxdd_device) -- C:\WINDOWS\System32\lxddcoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (OMCI) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
O1 HOSTS File: ([2011/01/25 20:47:37 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AddressBookReminderApp] C:\Program Files\Nova Development\Photo Explosion\4.0\ReminderApp.exe ()
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Lexmark Fax Solutions\fm3032.exe ()
O4 - HKLM..\Run: [lxddamon] C:\Program Files\Lexmark 2500 Series\lxddamon.exe ()
O4 - HKLM..\Run: [lxddmon.exe] C:\Program Files\Lexmark 2500 Series\lxddmon.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([turbotaxweb.turbotaxonline] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell....iler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {3356DB7C-58A7-11D4-AA5C-006097314BF8} http://smartdownload...ew/launcher.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6796.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1254629116874 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1254669903656 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://svwmi.worldm...perSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...inAxControl.CAB (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/27 21:05:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/15 13:14:57 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Michael\Recent
[2011/05/15 12:50:06 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTL.exe
[2011/05/14 00:58:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Start Menu\Programs\HiJackThis
[2011/05/14 00:58:11 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/05/14 00:43:04 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/05/14 00:33:49 | 000,519,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTM.exe
[2011/05/13 23:28:33 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Michael\Desktop\mbam-setup.exe
[2011/05/13 20:58:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Start Menu\Programs\Windows XP Recovery
[2011/05/13 20:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\{B0E51C96-8948-4D7E-B45D-AA755BF63616}
[2011/05/12 20:10:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\FaxCtr
[2011/05/09 14:11:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Start Menu\Programs\BrowserPlus
[2011/05/09 14:11:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Local Settings\Application Data\Yahoo!
[2011/04/23 10:40:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michael\Application Data\Lexmark Productivity Studio
[2011/04/23 10:39:02 | 000,000,000 | ---D | C] -- C:\Program Files\Lx_cats
[2011/04/23 10:36:08 | 000,339,968 | ---- | C] (Data Techniques, Inc.) -- C:\WINDOWS\System32\IMGMAN32.DLL
[2011/04/23 10:36:08 | 000,098,345 | ---- | C] (Data Techniques, Inc.) -- C:\WINDOWS\System32\IMHOST32.DLL
[2011/04/23 10:36:08 | 000,098,304 | ---- | C] (Data Techniques, Inc.) -- C:\WINDOWS\System32\IM31XPNG.DEL
[2011/04/23 10:36:08 | 000,069,632 | ---- | C] (Data Techniques, Inc.) -- C:\WINDOWS\System32\IM31XTIF.DEL
[2011/04/23 10:36:08 | 000,049,152 | ---- | C] (Data Techniques, Inc.) -- C:\WINDOWS\System32\IM31IMG.DIL
[2011/04/23 10:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lexmark Fax Solutions
[2011/04/23 10:36:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FaxCtr
[2009/12/22 22:20:18 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\LXDDhcp.dll
[2009/12/22 22:20:06 | 000,394,160 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddcfg.exe
[2007/05/25 04:41:40 | 000,385,968 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddih.exe
[2007/05/25 04:41:37 | 000,537,520 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddcoms.exe
[2007/05/17 09:19:57 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddpmui.dll
[2007/05/17 09:17:22 | 001,232,896 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddserv.dll
[2007/05/17 09:11:47 | 000,425,984 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddcomm.dll
[2007/05/17 09:10:16 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddlmpm.dll
[2007/05/17 09:08:43 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddiesc.dll
[2007/05/17 09:07:51 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddpplc.dll
[2007/05/17 09:07:02 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddcomc.dll
[2007/05/17 09:06:32 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddprox.dll
[2007/05/17 08:59:50 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddinpa.dll
[2007/05/17 08:58:46 | 000,999,424 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddusb1.dll
[2007/05/17 08:53:19 | 000,700,416 | ---- | C] ( ) -- C:\WINDOWS\System32\lxddhbn3.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/15 13:29:11 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/15 13:27:01 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-484061587-839522115-1003UA.job
[2011/05/15 13:23:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/15 12:50:11 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTL.exe
[2011/05/15 01:38:21 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0EDDE299-1EBA-45EC-84F0-14472A8C02E8}.job
[2011/05/15 01:23:16 | 000,001,394 | -HS- | M] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\rn24wn5mm136m16l4n4fn6k3c0m7h2k77366
[2011/05/15 01:23:16 | 000,001,394 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\rn24wn5mm136m16l4n4fn6k3c0m7h2k77366
[2011/05/15 01:22:56 | 000,212,949 | -HS- | M] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\gnf.exe
[2011/05/15 00:36:14 | 000,502,095 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\unhide.exe
[2011/05/15 00:24:36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/15 00:24:33 | 000,297,256 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/14 22:27:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-484061587-839522115-1003Core.job
[2011/05/14 00:58:26 | 000,002,451 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\HiJackThis.lnk
[2011/05/14 00:57:33 | 001,402,880 | ---- | M] () -- C:\Documents and Settings\Michael\Desktop\HijackThis.msi
[2011/05/14 00:33:35 | 000,519,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michael\Desktop\OTM.exe
[2011/05/13 23:29:27 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/13 23:28:33 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Michael\Desktop\mbam-setup.exe
[2011/05/13 23:02:53 | 000,000,144 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~16703268r
[2011/05/13 23:02:53 | 000,000,128 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\~16703268
[2011/05/13 21:50:02 | 000,000,392 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\16703268
[2011/05/13 20:51:10 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Fxaheba.bin
[2011/05/13 20:51:07 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Srobusuqikuwa.dat
[2011/05/13 20:48:51 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Michael\2gweorjqjutp92vjy9gake
[2011/04/23 10:38:46 | 000,147,905 | ---- | M] () -- C:\WINDOWS\System32\LexFiles.ulf
[2011/04/17 03:13:04 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/04/17 03:09:40 | 000,580,334 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/04/17 03:09:40 | 000,128,020 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/15 13:15:37 | 004,360,032 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/05/15 01:23:03 | 000,001,394 | -HS- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\rn24wn5mm136m16l4n4fn6k3c0m7h2k77366
[2011/05/15 01:23:03 | 000,001,394 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\rn24wn5mm136m16l4n4fn6k3c0m7h2k77366
[2011/05/15 01:22:56 | 000,212,949 | -HS- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\gnf.exe
[2011/05/15 00:36:11 | 000,502,095 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\unhide.exe
[2011/05/14 00:58:12 | 000,002,451 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\HiJackThis.lnk
[2011/05/14 00:57:28 | 001,402,880 | ---- | C] () -- C:\Documents and Settings\Michael\Desktop\HijackThis.msi
[2011/05/13 22:06:30 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/13 21:02:08 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~16703268r
[2011/05/13 21:02:08 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~16703268
[2011/05/13 20:58:18 | 000,000,392 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16703268
[2011/05/13 20:51:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Fxaheba.bin
[2011/05/13 20:51:07 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Srobusuqikuwa.dat
[2011/05/13 20:48:51 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Michael\2gweorjqjutp92vjy9gake
[2011/04/23 10:36:29 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\LXF3PMON.DLL
[2011/04/23 10:36:29 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXF3FXPU.DLL
[2011/04/23 10:36:08 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\lxf3oem.dll
[2011/04/23 10:36:08 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\LXF3PMRC.DLL
[2011/03/07 22:10:49 | 000,006,958 | -HS- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\934284662
[2011/03/07 22:10:49 | 000,006,958 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\934284662
[2010/09/25 22:08:18 | 000,000,271 | ---- | C] () -- C:\Documents and Settings\Michael\Application Data\hgksfg.bat
[2010/06/20 19:55:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Michael\Application Data\sversion.ini
[2010/06/20 19:49:59 | 000,069,632 | ---- | C] () -- C:\WINDOWS\uinst001.exe
[2010/06/02 19:27:06 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010/06/02 19:26:11 | 000,000,163 | ---- | C] () -- C:\Documents and Settings\Michael\Application Data\default.rss
[2010/06/02 19:26:11 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Michael\Application Data\downloads.m3u
[2010/05/30 19:49:19 | 000,063,828 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/03/06 23:21:54 | 000,000,577 | ---- | C] () -- C:\WINDOWS\System32\gmsblist.dll
[2010/02/18 00:00:28 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\osinfo.dll
[2009/12/22 22:20:54 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\lxddrwrd.ini
[2009/12/22 22:20:18 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\LXDDinst.dll
[2009/12/22 22:17:14 | 000,344,064 | R--- | C] () -- C:\WINDOWS\System32\lxddcoin.dll
[2009/10/04 11:00:25 | 000,156,672 | ---- | C] () -- C:\Documents and Settings\Michael\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/03 23:50:20 | 000,000,033 | ---- | C] () -- C:\WINDOWS\checkip.dat
[2009/10/03 23:20:30 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2009/09/27 21:10:27 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2009/09/27 21:08:24 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/09/27 21:02:46 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/09/27 13:56:17 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/09/27 13:55:24 | 000,297,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2007/05/23 23:04:56 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxddgrd.dll
[2007/01/23 13:40:03 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxddcaps.dll
[2007/01/09 11:13:08 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxdddrs.dll
[2006/10/06 12:08:04 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\lxddcnv4.dll
[2006/05/17 21:47:12 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxddvs.dll
[2003/10/06 16:16:00 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\nvcod.dll
[2001/08/18 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/18 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/18 07:00:00 | 000,580,334 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/18 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/18 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/18 07:00:00 | 000,128,020 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/18 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/18 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/18 07:00:00 | 000,004,594 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/18 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2001/08/18 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/04/24 11:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2010/02/19 23:41:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2010/04/24 11:23:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Network Associates
[2010/04/24 13:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Riverdeep Interactive Learning Limited
[2010/05/30 18:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/06/26 00:45:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\EurekaLog
[2010/02/19 23:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\GARMIN
[2010/08/14 00:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\GianPaoloSaliola
[2010/03/09 21:46:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\gsak
[2010/07/15 20:20:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\Juniper Networks
[2011/04/23 10:40:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\Lexmark Productivity Studio
[2010/05/09 20:44:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\Nova Development
[2011/04/01 22:13:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\OpenOffice.org
[2010/10/30 18:36:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michael\Application Data\WinFF
[2011/05/15 13:29:11 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/05/15 01:38:21 | 000,000,426 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{0EDDE299-1EBA-45EC-84F0-14472A8C02E8}.job
========== Purity Check ==========
< End of report >