Okay in addition to the three logs I've included the entry from Malwarebytes. As for computer and browser status, my OS is Windows XP and the only noticeable problem is that my browser keeps getting redirected.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.orgDatabase version: v2012.07.16.12
Windows XP Service Pack 2 x86 FAT32 (Safe Mode/Networking)
Internet Explorer 6.0.2900.2180
cfjasdhfhsdjklsdnhvk :: ACER [administrator]
7/17/2012 8:36:42 AM
mbam-log-2012-07-17 (08-36-42).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 386080
Time elapsed: 21 minute(s), 36 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Avenger\jBqthUnXGgKIJF.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
(end)
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 07/18/2012 at 18:01:44.
Operating System: Microsoft Windows XP
Processes terminated by Rkill or while it was running:
C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
c:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
Rkill completed on 07/18/2012 at 18:03:00.
OTL logfile created on: 7/18/2012 6:15:49 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.48 Mb Total Physical Memory | 675.35 Mb Available Physical Memory | 66.05% Memory free
2.31 Gb Paging File | 2.13 Gb Available in Paging File | 92.15% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 61.31 Gb Total Space | 27.25 Gb Free Space | 44.44% Space Free | Partition Type: NTFS
Drive D: | 120.09 Gb Total Space | 97.85 Gb Free Space | 81.48% Space Free | Partition Type: FAT32
Drive F: | 27.84 Gb Total Space | 12.42 Gb Free Space | 44.62% Space Free | Partition Type: FAT32
Computer Name: ACER | User Name: cfjasdhfhsdjklsdnhvk | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/07/18 18:04:32 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\google.exe.exe
PRC - [2007/06/13 04:23:07 | 001,033,216 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (sprtlisten)
SRV - File not found [Auto | Stopped] -- -- (nmservice)
SRV - File not found [Auto | Stopped] -- -- (LinksysUpdater)
SRV - File not found [Auto | Stopped] -- -- (JavaQuickStarterService)
SRV - File not found [On_Demand | Stopped] -- -- (CDVDService)
SRV - [2012/02/29 17:58:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011/05/18 12:24:30 | 000,641,464 | ---- | M] (Cisco Systems, Inc.) [Disabled | Stopped] -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe -- (vpnagent)
SRV - [2010/11/30 11:08:30 | 002,222,376 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010/02/25 16:52:08 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe -- (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2)
SRV - [2004/10/29 02:20:54 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2004/10/29 02:18:24 | 000,069,718 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
========== Driver Services (SafeList) ========== DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\SynasUSB.sys -- (SynasUSB)
DRV - File not found [Kernel | Boot | Stopped] -- System32\drivers\dysplr.sys -- (rlqra)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsNcAdpt.sys -- (dsNcAdpt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\CFJASD~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2011/05/18 12:12:07 | 000,019,192 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vpnva.sys -- (vpnva)
DRV - [2008/12/12 19:05:20 | 000,025,264 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\purendis.sys -- (purendis)
DRV - [2008/12/12 19:05:18 | 000,023,984 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp)
DRV - [2005/10/27 16:06:30 | 000,356,096 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61) Linksys Wireless-G PCI Adapter Driver(RT61)
DRV - [2005/09/22 10:34:00 | 003,727,680 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/07/29 11:11:04 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/07/29 11:11:02 | 000,034,048 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/07/13 12:08:20 | 000,033,890 | ---- | M] (Service & Quality Technology.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Capt905c.sys -- (SQTECH905C)
DRV - [2005/03/09 17:53:00 | 000,036,352 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005/02/01 19:18:38 | 000,017,992 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\bcm42rly.sys -- (BCM42RLY)
DRV - [2004/09/29 13:00:00 | 000,247,296 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZD1211U.sys -- (ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS)
DRV - [2004/01/14 13:30:00 | 000,017,151 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ZDPNDIS5.sys -- (ZDPNDIS5)
DRV - [2003/09/25 23:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\GTNDIS5.sys -- (GTNDIS5)
DRV - [2001/08/17 07:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.ask.com/?o=14196&l=disIE - HKCU\..\SearchScopes,DefaultScope = {3D1C0D1B-BB80-4BE1-ACC8-10F266830714}
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://tbsearch.ask.com/redirect?client=ie&tb=FWV5&o=14193&src=crm&q={searchTerms}&locale=en_USIE - HKCU\..\SearchScopes\{3D1C0D1B-BB80-4BE1-ACC8-10F266830714}: "URL" =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz=1I7ADSA_enIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;<local>
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
www.msn.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Tunes install\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.2.72: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.2.72: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.2.72: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.2.72: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.2.72: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\RobloxVersions\version-eecd9135a67340ab\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/02/20 08:52:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/20 08:51:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/20 08:52:28 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{4F85A728-C86F-11E1-8270-B8AC6F996F26}: C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\{4F85A728-C86F-11E1-8270-B8AC6F996F26}\ [2012/07/07 14:07:05 | 000,000,000 | ---D | M]
[2010/11/04 18:22:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Mozilla\Extensions
[2012/07/04 09:55:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Mozilla\Firefox\Profiles\9u9jd9x4.default\extensions
[2010/11/04 18:24:21 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Mozilla\Firefox\Profiles\9u9jd9x4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/01/28 12:09:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/28 12:09:40 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/07 14:07:05 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\DOCUMENTS AND SETTINGS\CFJASDHFHSDJKLSDNHVK\LOCAL SETTINGS\APPLICATION DATA\{4F85A728-C86F-11E1-8270-B8AC6F996F26}
[2011/11/05 00:53:18 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/06/25 07:40:34 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 21:21:03 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/04 21:21:03 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/02/05 10:34:03 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - No CLSID value found.
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [gretsy] rundll32.exe "C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\gretsy.dll",CleanupGlobalTempFiles File not found
O4 - HKLM..\Run: [iTunesHelper] D:\Tunes install\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [kisird] C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\kisird.dll (C-Media Electronics Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [Download] C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\SupportSoft\ddoctorv2\cfjasdhfhsdjklsdnhvk\ssGet.exe ()
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKLM..\RunOnce: [WIAWizardMenu] C:\WINDOWS\System32\sti_ci.dll (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261606953187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261608140578 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/15 21:58:20 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - C:\WINDOWS\System32\LCodcCMP.dll (LEAD Technologies, Inc.)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 0
========== Files/Folders - Created Within 30 Days ========== [2012/07/18 18:04:28 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\google.exe.exe
[2012/07/18 14:42:12 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\dds.com
[2012/07/17 19:48:04 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/07/17 11:22:31 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/07/17 11:22:31 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/07/17 11:22:31 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/07/17 11:22:31 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/07/17 11:05:13 | 004,579,127 | R--- | C] (Swearware) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\ComboFix.exe
[2012/07/16 17:26:17 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/07/16 17:15:58 | 000,000,000 | R--D | C] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Recent
[2012/07/16 17:14:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Start Menu\Programs\File Recovery
[2012/07/09 14:37:04 | 000,000,000 | ---D | C] -- C:\Program Files\Intelore
[2012/07/09 14:33:12 | 000,000,000 | ---D | C] -- C:\Program Files\ZIP Password Recovery
[2012/07/07 14:07:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\{4F85A728-C86F-11E1-8270-B8AC6F996F26}
[2012/07/07 14:07:02 | 000,401,408 | ---- | C] (C-Media Electronics Inc.) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\kisird.dll
[2012/06/07 22:02:33 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\pcouffin.sys
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/07/18 18:04:32 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\google.exe.exe
[2012/07/18 17:58:06 | 001,012,656 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\rkill.com
[2012/07/18 17:52:57 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2012/07/18 17:52:06 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/07/18 17:51:55 | 000,000,308 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3405786225-280757992-2748749879-1005.job
[2012/07/18 17:51:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/07/18 17:51:33 | 1072,222,208 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/18 14:44:00 | 000,001,058 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3405786225-280757992-2748749879-1005UA.job
[2012/07/18 14:43:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3405786225-280757992-2748749879-1005Core.job
[2012/07/18 14:42:14 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\dds.com
[2012/07/17 11:03:36 | 004,579,127 | R--- | M] (Swearware) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\ComboFix.exe
[2012/07/17 09:27:52 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\Default.rdp
[2012/07/16 19:07:12 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/07/16 17:57:26 | 000,000,072 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\-jBqthUnXGgKIJFr
[2012/07/16 17:57:26 | 000,000,072 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\-jBqthUnXGgKIJF
[2012/07/16 17:57:23 | 000,000,368 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\jBqthUnXGgKIJF
[2012/07/16 14:05:05 | 000,055,182 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Desktop\alternator diagram.jpg
[2012/07/16 10:08:04 | 000,100,204 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Desktop\alternatorWiring.jpg
[2012/07/15 14:58:13 | 000,000,316 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3405786225-280757992-2748749879-1005.job
[2012/07/12 18:46:14 | 000,001,040 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to fba.lnk
[2012/07/11 16:32:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/11 14:04:52 | 000,000,025 | ---- | M] () -- C:\WINDOWS\popcinfot.dat
[2012/07/07 14:07:04 | 000,401,408 | ---- | M] (C-Media Electronics Inc.) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\kisird.dll
[2012/07/05 19:27:13 | 000,294,868 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012/07/05 19:27:13 | 000,000,029 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2012/07/05 19:27:13 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012/07/05 18:27:59 | 000,294,868 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012/07/04 19:46:23 | 000,087,608 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\inst.exe
[2012/07/04 19:46:23 | 000,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\pcouffin.sys
[2012/07/04 19:46:23 | 000,007,887 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\pcouffin.cat
[2012/07/04 19:46:23 | 000,001,144 | ---- | M] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\pcouffin.inf
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/07/18 17:58:02 | 001,012,656 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\rkill.com
[2012/07/18 17:52:23 | 000,000,868 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2012/07/18 15:11:34 | 1072,222,208 | -HS- | C] () -- C:\hiberfil.sys
[2012/07/17 11:22:31 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/07/17 11:22:31 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/07/17 11:22:31 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/07/17 11:22:31 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/07/17 11:22:31 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/07/17 09:27:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\My Documents\Default.rdp
[2012/07/16 17:14:39 | 000,000,072 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\-jBqthUnXGgKIJFr
[2012/07/16 17:14:39 | 000,000,072 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\-jBqthUnXGgKIJF
[2012/07/16 17:14:36 | 000,000,368 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\jBqthUnXGgKIJF
[2012/07/16 14:05:03 | 000,055,182 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Desktop\alternator diagram.jpg
[2012/07/16 10:08:03 | 000,100,204 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Desktop\alternatorWiring.jpg
[2012/07/12 18:46:14 | 000,001,040 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to fba.lnk
[2012/06/07 22:02:33 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\inst.exe
[2012/06/07 22:02:33 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\pcouffin.cat
[2012/06/07 22:02:33 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\pcouffin.inf
[2012/05/25 22:26:59 | 006,446,080 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\mame.exe
[2012/05/25 22:26:59 | 000,119,296 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\xml2info.exe
[2012/05/25 22:26:59 | 000,104,448 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\chdman.exe
[2012/05/25 22:26:59 | 000,045,568 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\romcmp.exe
[2012/05/25 11:57:57 | 006,547,980 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\mame088b.zip
[2012/04/28 23:16:31 | 000,000,029 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2012/04/28 20:12:58 | 000,294,868 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012/04/28 20:12:58 | 000,294,868 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012/04/28 20:12:58 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012/04/28 20:12:44 | 002,784,050 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2012/04/28 19:50:31 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/23 22:40:48 | 000,111,829 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Start Menu.rar
[2011/10/06 17:45:31 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini
[2011/10/06 17:45:21 | 000,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2011/05/10 13:03:29 | 000,000,406 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2011/03/12 22:23:40 | 000,430,152 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/18 17:08:16 | 000,139,679 | ---- | C] () -- C:\WINDOWS\hpoins15.dat
[2011/02/18 17:08:16 | 000,001,039 | ---- | C] () -- C:\WINDOWS\hpomdl15.dat
[2010/11/04 18:22:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/03/06 13:36:48 | 000,013,120 | -HS- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\d1NJm3Vp784
[2007/08/23 22:35:17 | 000,000,233 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\HMAGIC.CFG
[2007/08/20 21:05:47 | 000,013,195 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\ZGUICFG.DAT
[2007/08/20 21:05:01 | 000,013,195 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\ZGUICFGW.DAT
[2007/04/01 14:38:51 | 000,000,134 | R--- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Valid.Ext
[2007/02/10 12:47:58 | 000,531,446 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\com.kennettnet.MusicRescueProfiles.plist
[2007/02/10 12:47:58 | 000,003,201 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\com.kennettnet.MusicRescue.plist
[2007/01/15 17:27:58 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/08/15 22:55:05 | 000,000,251 | ---- | C] () -- C:\Program Files\wt3d.ini
[2006/03/26 19:47:46 | 000,059,904 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/02/24 19:51:42 | 000,000,143 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Local Settings\Application Data\fusioncache.dat
[2005/08/26 16:53:42 | 000,004,686 | ---- | C] () -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\cfjasdhfhsdjklsdnhvklog.dat
========== LOP Check ========== [2009/07/08 14:50:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2011/08/09 21:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\5Spice Analysis
[2010/04/01 18:04:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2012/02/04 18:22:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco
[2011/10/18 15:49:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IconTweaker
[2012/02/05 10:20:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011/03/12 11:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Linksys
[2006/08/26 04:23:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
[2006/08/15 23:35:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Otto
[2010/05/14 20:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2011/03/08 17:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/06/14 21:11:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Syncrosoft
[2011/07/25 21:36:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/23 09:39:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2011/03/12 11:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/02/13 19:32:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/22 17:20:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2012/05/03 15:57:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\.minecraft
[2010/03/01 16:24:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Autodesk
[2011/05/30 14:27:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\FrostWire
[2009/08/06 15:05:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\GetRightToGo
[2011/10/18 15:49:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\IconTweaker
[2012/02/05 10:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Juniper Networks
[2012/04/30 18:11:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Mupen64Plus
[2011/07/13 12:38:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\OpenOffice.org
[2006/08/15 23:35:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Otto
[2012/03/10 19:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Qesair
[2012/02/29 12:01:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Saqai
[2011/02/07 18:43:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Synthesia
[2010/12/07 19:05:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\TeamViewer
[2012/07/04 19:46:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Vso
[2012/03/09 12:56:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\cfjasdhfhsdjklsdnhvk\Application Data\Xiryvi
[2012/07/18 14:43:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-3405786225-280757992-2748749879-1005Core.job
[2012/07/18 14:44:00 | 000,001,058 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-3405786225-280757992-2748749879-1005UA.job
========== Purity Check ========== ========== Custom Scans ========== < %systemroot%\*. /rp /s > ========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[C:\WINDOWS\$hf_mig$\{29F8DDC1-9487-49b8-B27E-3E0C3C1298FF}] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
========== Alternate Data Streams ========== @Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7BB5E748
< End of report >