Bobbye,
Ran Avira - nothing was found.
Logs from OTL below.
OTL logfile created on: 12/18/2011 4:14:04 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Rich\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.52 Gb Available Physical Memory | 84.01% Memory free
4.35 Gb Paging File | 3.99 Gb Available in Paging File | 91.92% Paging File free
Paging file location(s): C:\pagefile.sys 1536 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.49 Gb Total Space | 126.65 Gb Free Space | 87.05% Space Free | Partition Type: NTFS
Computer Name: DHZ5YM51 | User Name: Rich | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Rich\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Windows SteadyState\Bubble.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows SteadyState\SCTSvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\ssoftsrv.exe (Cypherix)
PRC - C:\Program Files\Intel\Intel Application Accelerator\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe (Intel Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\NVIDIA Corporation\nView\nvShell.dll ()
MOD - C:\WINDOWS\SYSTEM32\pdf995mon.dll ()
========== Win32 Services (SafeList) ==========
SRV - (WMDM PMSP Service) -- File not found
SRV - (iPCAgent) -- File not found
SRV - (iPassConnectEngine) -- File not found
SRV - (AppMgmt) -- File not found
SRV - (ACDaemon) -- File not found
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (getPlusHelper) getPlus(R) -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (STSService) -- C:\Program Files\SoundTaxi Media Suite\STSService.exe ()
SRV - (Windows SteadyState) -- C:\Program Files\Windows SteadyState\SCTSvc.exe (Microsoft Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (nTuneService) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (ssoftservice) -- C:\WINDOWS\System32\ssoftsrv.exe (Cypherix)
SRV - (IAANTMon) -- C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (avipbb) -- C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\WINDOWS\SYSTEM32\DRIVERS\avgntflt.sys (Avira GmbH)
DRV - (avkmgr) -- C:\WINDOWS\SYSTEM32\DRIVERS\avkmgr.sys (Avira GmbH)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ssmdrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (cpudrv) -- C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (nm) -- C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
DRV - (NPF) -- C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies)
DRV - (NVR0Dev) -- C:\WINDOWS\nvoclock.sys (NVidia Corp.)
DRV - (Alpham1) -- C:\WINDOWS\SYSTEM32\DRIVERS\Alpham1.sys (Ideazon Corporation)
DRV - (kbdcap) -- C:\WINDOWS\System32\drivers\KbdCap.sys ()
DRV - (Alpham2) -- C:\WINDOWS\SYSTEM32\DRIVERS\Alpham2.sys (Ideazon Corporation)
DRV - (APLMp50) -- C:\WINDOWS\SYSTEM32\DRIVERS\APLMp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MDC80211) iPass Protocol (IEEE 802.1x) -- C:\WINDOWS\SYSTEM32\DRIVERS\mdc80211.sys (Meetinghouse Data Communications)
DRV - (iAimFP4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel(R) Corporation)
DRV - (iAimFP3) -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel(R) Corporation)
DRV - (iAimTV4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel(R) Corporation)
DRV - (iAimTV3) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel(R) Corporation)
DRV - (iAimTV1) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel(R) Corporation)
DRV - (iAimTV0) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel(R) Corporation)
DRV - (iAimFP0) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel(R) Corporation)
DRV - (iAimFP1) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel(R) Corporation)
DRV - (iAimFP2) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel(R) Corporation)
DRV - (i81x) -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel(R) Corporation)
DRV - (b57w2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (ati2mtag) -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ssoftnt4) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssoftnt4.sys ()
DRV - (IntelC52) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (IntelC53) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (mohfilt) -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (CVirtA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (ctdvda2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ha10kx2k.sys (Creative Technology Ltd)
DRV - (WmFilter) -- C:\WINDOWS\SYSTEM32\DRIVERS\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) -- C:\WINDOWS\SYSTEM32\DRIVERS\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) -- C:\WINDOWS\SYSTEM32\DRIVERS\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore) -- C:\WINDOWS\SYSTEM32\DRIVERS\WmXlCore.sys (Logitech Inc.)
DRV - (PfModNT) -- C:\WINDOWS\SYSTEM32\DRIVERS\pfmodnt.sys (Creative Technology Ltd.)
DRV - (emupia) -- C:\WINDOWS\SYSTEM32\DRIVERS\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\WINDOWS\SYSTEM32\DRIVERS\ctac32k.sys (Creative Technology Ltd)
DRV - (omci) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (SDSTOR2K) -- C:\WINDOWS\SYSTEM32\DRIVERS\SDSTOR2K.SYS (SanDisk Corporation)
DRV - (EL90XBC) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\flashcatch@flashcatch.com: C:\Program Files\FlashCatch\firefox [2010/04/11 16:11:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/04 21:00:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/17 08:57:38 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\VideoBar@meep.com: C:\Program Files\Meep\FF\
[2008/06/22 18:25:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rich\Application Data\Mozilla\Extensions
[2011/11/13 09:58:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rich\Application Data\Mozilla\Firefox\Profiles\4gb4jobp.default\extensions
[2011/09/04 07:24:01 | 000,000,000 | ---D | M] (Old Location Bar) -- C:\Documents and Settings\Rich\Application Data\Mozilla\Firefox\Profiles\4gb4jobp.default\extensions\{3205B348-523A-4fac-9BC4-9939CBF583B0}
[2005/12/18 18:46:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rich\Application Data\Mozilla\Firefox\Profiles\4gb4jobp.default\extensions\temp
[2011/03/23 19:42:20 | 000,000,939 | ---- | M] () -- C:\Documents and Settings\Rich\Application Data\Mozilla\Firefox\Profiles\4gb4jobp.default\searchplugins\conduit.xml
[2011/06/11 17:47:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/13 09:37:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/12 09:40:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/05/13 16:09:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/11 17:47:57 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
() (No name found) -- C:\DOCUMENTS AND SETTINGS\RICH\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\4GB4JOBP.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\RICH\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\4GB4JOBP.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\RICH\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\4GB4JOBP.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
[2009/01/01 23:17:05 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/04 21:00:34 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/04 21:00:31 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/12/11 14:21:08 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (FlashCatchBHO Class) - {88618A96-6D8A-42E7-B932-9073D5B2080F} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O2 - BHO: (IeCatch2 Class) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\Jccatch.dll (Amaze Soft)
O3 - HKLM\..\Toolbar: (FlashCatch) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
O3 - HKLM\..\Toolbar: (FlashGet Bar) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll (Amaze Soft)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (FlashCatch) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - C:\Program Files\FlashCatch\flashcatch.dll (Level 9 Technology, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Bubble] C:\Program Files\Windows SteadyState\Bubble.exe (Microsoft Corporation)
O4 - HKLM..\Run: [gcasServ] C:\Program Files\Microsoft AntiSpyware\gcasServ.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Logoff] C:\Program Files\Windows SteadyState\SCTUINotify.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [Tweak UI] C:\WINDOWS\System32\TWEAKUI.CPL (Microsoft Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm ()
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm ()
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (Amaze Soft)
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (Amaze Soft)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71}
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1302816107968 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1306104091687 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-000000000000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{594FB6E3-AFDE-4E88-BF61-4DA9C1952C2A}: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {9EF34FF2-3396-4527-9D27-04C8C1C67806} - C:\Program Files\Microsoft AntiSpyware\shellextension.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/18 16:12:14 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rich\Desktop\OTL.exe
[2011/12/18 15:14:56 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/12/18 15:11:43 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Rich\Recent
[2011/12/11 14:25:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/12/11 14:12:51 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/12/11 14:12:51 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/12/11 14:12:51 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/12/11 14:12:51 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/12/11 14:12:36 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/11 14:12:08 | 004,334,705 | R--- | C] (Swearware) -- C:\Documents and Settings\Rich\Desktop\ComboFix.exe
[2011/12/03 11:53:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/11/22 09:57:22 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/11/22 09:56:24 | 000,523,264 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rich\Desktop\OTM.exe
[2011/11/21 21:06:56 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/11/21 21:06:41 | 002,322,184 | ---- | C] (ESET) -- C:\Documents and Settings\Rich\Desktop\esetsmartinstaller_enu.exe
[2011/11/21 20:16:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/11/21 19:13:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Rich\My Documents\My Videos
[2011/11/21 18:18:02 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Rich\Desktop\dds.scr
[2011/11/21 17:17:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Rich\Application Data\Avira
[2011/11/21 17:12:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/11/21 17:11:56 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/11/21 17:11:54 | 000,134,344 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/11/21 17:11:54 | 000,074,640 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/11/21 17:11:54 | 000,036,000 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avkmgr.sys
[2011/11/21 17:11:53 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/11/21 17:11:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2011/11/21 14:10:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/11/21 14:10:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/21 13:57:53 | 002,856,448 | ---- | C] (Корпорация Майкрософт) -- C:\Documents and Settings\Rich\My Documents\qkmz.exe
========== Files - Modified Within 30 Days ==========
[2011/12/18 16:11:38 | 000,000,322 | ---- | M] () -- C:\WINDOWS\MATLAB.INI
[2011/12/18 15:42:24 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rich\Desktop\OTL.exe
[2011/12/18 15:12:45 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2011/12/18 15:11:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2011/12/18 15:11:21 | 3219,296,256 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/11 14:41:11 | 000,030,036 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/12/11 14:41:11 | 000,030,036 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/12/11 14:41:11 | 000,029,760 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/12/11 14:41:11 | 000,029,760 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2011/12/11 14:41:11 | 000,002,064 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2011/12/11 14:41:11 | 000,002,064 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2011/12/11 14:41:11 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
[2011/12/11 14:41:11 | 000,000,288 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
[2011/12/11 14:21:08 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2011/12/11 14:09:36 | 004,334,705 | R--- | M] (Swearware) -- C:\Documents and Settings\Rich\Desktop\ComboFix.exe
[2011/11/22 09:53:00 | 000,523,264 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rich\Desktop\OTM.exe
[2011/11/21 21:06:42 | 002,322,184 | ---- | M] (ESET) -- C:\Documents and Settings\Rich\Desktop\esetsmartinstaller_enu.exe
[2011/11/21 20:27:23 | 000,000,746 | ---- | M] () -- C:\Documents and Settings\Rich\Desktop\Shortcut to WINWORD.EXE.lnk
[2011/11/21 20:23:28 | 000,010,514 | ---- | M] () -- C:\Documents and Settings\Rich\Application Data\wklnhst.dat
[2011/11/21 18:18:02 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Rich\Desktop\dds.scr
[2011/11/21 18:17:03 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Rich\Desktop\gmer.exe
[2011/11/21 17:12:18 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2011/11/21 13:58:04 | 002,856,448 | ---- | M] (Корпорация Майкрософт) -- C:\Documents and Settings\Rich\My Documents\qkmz.exe
[2011/11/20 08:53:39 | 000,000,211 | -HS- | M] () -- C:\BOOT.INI
[2011/11/19 19:22:45 | 000,144,896 | ---- | M] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2011/12/11 14:12:51 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/12/11 14:12:51 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/12/11 14:12:51 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/12/11 14:12:51 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/12/11 14:12:51 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/11/21 20:27:23 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\Rich\Desktop\Shortcut to WINWORD.EXE.lnk
[2011/11/21 18:17:03 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Rich\Desktop\gmer.exe
[2011/11/21 17:12:18 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira Control Center.lnk
[2011/08/20 21:56:07 | 000,000,408 | ---- | C] () -- C:\Documents and Settings\Rich\Application Data\CamShapes.ini
[2011/08/20 21:56:07 | 000,000,408 | ---- | C] () -- C:\Documents and Settings\Rich\Application Data\CamLayout.ini
[2011/08/20 21:56:07 | 000,000,050 | ---- | C] () -- C:\Documents and Settings\Rich\Application Data\Camdata.ini
[2011/05/09 21:39:43 | 000,003,998 | -HS- | C] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\g32nm6cb32555cu00h4dus5w3d30033
[2011/05/09 21:39:43 | 000,003,998 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\g32nm6cb32555cu00h4dus5w3d30033
[2011/04/18 21:30:38 | 000,017,252 | -HS- | C] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\q45f63b3111o63c2hk0htmd5p3j4poe
[2011/04/18 21:30:38 | 000,017,252 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\q45f63b3111o63c2hk0htmd5p3j4poe
[2011/04/13 19:03:19 | 000,019,402 | -HS- | C] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\2874343434
[2011/04/13 19:03:19 | 000,019,402 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\2874343434
[2011/01/23 14:05:32 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/23 14:05:29 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/23 14:05:29 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2010/09/02 13:48:54 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/11 16:25:02 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/04/11 16:25:01 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009/12/31 17:30:28 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2009/11/15 19:44:13 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\rmc_rtspdl.dll
[2009/11/15 18:52:48 | 000,032,192 | ---- | C] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\Schedule8.dat
[2009/09/06 14:16:32 | 000,139,152 | ---- | C] () -- C:\Documents and Settings\Rich\Application Data\PnkBstrK.sys
[2009/09/06 14:16:32 | 000,139,072 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/09/06 14:16:00 | 000,794,408 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2009/08/09 08:17:14 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/04/04 16:42:02 | 000,000,014 | ---- | C] () -- C:\WINDOWS\popcinfot.dat
[2009/01/12 19:39:50 | 000,000,324 | ---- | C] () -- C:\WINDOWS\game.ini
[2008/09/20 15:30:05 | 000,598,016 | ---- | C] () -- C:\WINDOWS\System32\viscomqtde.dll
[2008/09/20 15:30:05 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2008/08/16 14:26:07 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/08/16 14:26:07 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/07/02 18:30:22 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2008/07/01 20:46:16 | 000,000,010 | ---- | C] () -- C:\WINDOWS\popcinfo.dat
[2007/12/28 15:03:35 | 000,000,288 | ---- | C] () -- C:\WINDOWS\System32\DVCStateBkp-{00000004-00000000-00000001-00001102-00000004-10031102}.dat
[2007/12/28 15:03:35 | 000,000,288 | ---- | C] () -- C:\WINDOWS\System32\DVCState-{00000004-00000000-00000001-00001102-00000004-10031102}.dat
[2007/11/06 20:30:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/06 15:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/10/10 18:47:58 | 000,214,504 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2007/10/10 18:47:52 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2007/04/20 16:15:10 | 000,109,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\KbdCap.sys
[2007/04/20 12:57:29 | 000,046,873 | ---- | C] () -- C:\WINDOWS\System32\unhttp.exe
[2007/04/02 17:23:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2007/04/02 15:14:18 | 000,000,037 | -H-- | C] () -- C:\Documents and Settings\Rich\Application Data\Web Dumper registration.ini
[2007/03/12 12:01:30 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2007/02/11 11:40:02 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2007/02/11 11:16:32 | 000,000,322 | ---- | C] () -- C:\WINDOWS\MATLAB.INI
[2006/09/21 18:40:16 | 000,000,036 | ---- | C] () -- C:\WINDOWS\SlantFin.ini
[2006/07/08 23:59:18 | 000,000,850 | ---- | C] () -- C:\WINDOWS\dispatch.ini
[2006/05/22 19:55:55 | 000,119,165 | ---- | C] () -- C:\WINDOWS\cleanup.exe
[2006/05/22 19:54:31 | 000,091,648 | ---- | C] () -- C:\WINDOWS\System32\xcacls.exe
[2006/04/09 19:33:47 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/11/22 23:00:00 | 000,778,240 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005/09/05 14:25:53 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\DEVLOAD.EXE
[2005/09/05 14:25:53 | 000,004,608 | ---- | C] () -- C:\WINDOWS\DelShell.exe
[2005/09/05 14:25:53 | 000,002,204 | ---- | C] () -- C:\WINDOWS\System32\drivers\UNINST2K.SYS
[2005/09/05 14:25:53 | 000,001,233 | ---- | C] () -- C:\WINDOWS\Sdcache.ini
[2005/09/05 14:25:53 | 000,000,022 | ---- | C] () -- C:\WINDOWS\FLASHKSK.INI
[2005/09/05 14:25:45 | 000,002,974 | ---- | C] () -- C:\WINDOWS\System32\SDUSBPDR.INI
[2005/08/12 16:57:09 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/08/05 21:43:50 | 000,000,645 | ---- | C] () -- C:\WINDOWS\EntPack.ini
[2005/08/05 21:43:50 | 000,000,445 | ---- | C] () -- C:\WINDOWS\EntPack.dat
[2005/08/05 20:20:21 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\fusioncache.dat
[2005/08/01 19:50:48 | 000,002,234 | ---- | C] () -- C:\WINDOWS\Opera.INI
[2005/07/24 11:52:38 | 000,087,040 | ---- | C] () -- C:\WINDOWS\UnGins.exe
[2005/06/23 17:04:01 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/03/25 10:52:46 | 000,000,048 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2005/03/25 10:52:39 | 000,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2005/03/25 10:45:44 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2005/03/25 10:45:44 | 000,050,364 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2005/01/07 13:15:56 | 000,172,056 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2005/01/02 14:37:54 | 000,107,132 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2004/10/25 20:29:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2004/10/25 20:29:18 | 000,005,100 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2004/09/26 18:39:51 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2004/09/25 14:36:18 | 000,001,568 | ---- | C] () -- C:\Documents and Settings\Rich\Application Data\mpauth.dat
[2004/09/18 06:56:47 | 000,000,557 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2004/09/16 16:28:15 | 000,010,514 | ---- | C] () -- C:\Documents and Settings\Rich\Application Data\wklnhst.dat
[2004/09/15 20:33:10 | 000,144,896 | ---- | C] () -- C:\Documents and Settings\Rich\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/09/12 12:55:25 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/09/12 12:52:40 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2004/09/12 12:47:40 | 000,000,288 | ---- | C] () -- C:\WINDOWS\System32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
[2004/09/12 12:47:40 | 000,000,288 | ---- | C] () -- C:\WINDOWS\System32\DVCState-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
[2004/09/12 12:46:00 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/09/12 12:44:56 | 000,000,215 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/09/12 12:41:26 | 001,048,576 | ---- | C] () -- C:\WINDOWS\System32\SFMAN.DAT
[2004/09/12 12:41:26 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2004/09/12 12:41:09 | 000,066,807 | ---- | C] () -- C:\WINDOWS\System32\Aud2_Del.ini
[2004/09/12 12:41:09 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2004/09/12 12:41:08 | 000,232,723 | ---- | C] () -- C:\WINDOWS\System32\ctstatic.dat
[2004/09/12 12:41:08 | 000,190,842 | ---- | C] () -- C:\WINDOWS\System32\ctdlang.dat
[2004/09/12 12:41:08 | 000,184,320 | ---- | C] () -- C:\WINDOWS\PSCONV.EXE
[2004/09/12 12:41:08 | 000,138,716 | ---- | C] () -- C:\WINDOWS\System32\ctbas2w.dat
[2004/09/12 12:41:08 | 000,110,720 | ---- | C] () -- C:\WINDOWS\System32\CTBASICW.DAT
[2004/09/12 12:41:08 | 000,053,674 | ---- | C] () -- C:\WINDOWS\System32\ctdaught.dat
[2004/09/12 12:41:08 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\KILLAPPS.EXE
[2004/09/12 12:41:08 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\REGPLIB.EXE
[2004/09/12 12:41:08 | 000,005,515 | ---- | C] () -- C:\WINDOWS\System32\ENSDEF.INI
[2004/09/12 12:41:08 | 000,000,180 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2004/09/12 12:41:06 | 000,000,184 | ---- | C] () -- C:\WINDOWS\System32\e000001.dat
[2004/09/12 12:41:04 | 000,831,600 | ---- | C] () -- C:\WINDOWS\System32\Ctaa1.dat
[2004/09/12 12:40:44 | 000,000,136 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2004/09/12 12:32:04 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2004/09/12 12:30:30 | 000,442,466 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2004/09/12 12:30:30 | 000,071,732 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2004/09/12 12:12:30 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/09/01 10:49:17 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/07/19 16:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 15:09:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\DSRIRREM.EXE
[2004/05/21 01:30:02 | 000,114,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\ssoftnt4.sys
[2004/05/11 10:03:20 | 000,259,840 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/05/11 10:02:24 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/03/26 16:59:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2003/03/30 07:02:45 | 000,684,032 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2002/09/03 08:59:14 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2002/09/03 08:56:30 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2002/09/03 08:31:46 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2002/09/03 08:31:44 | 000,004,594 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2002/08/29 05:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 05:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 05:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 05:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2002/08/29 05:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 05:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2002/08/29 05:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[1999/01/22 13:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1980/01/01 00:00:00 | 000,397,312 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.exe
[1980/01/01 00:00:00 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
========== LOP Check ==========
[2011/08/04 16:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\!SASCORE
[2010/11/26 10:55:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2009/04/04 16:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/09/14 18:05:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2010/11/17 18:59:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/08/29 16:49:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/01/04 14:01:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\alta
[2008/08/16 14:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\AVSMedia
[2010/07/01 20:57:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\CheckPoint
[2008/01/20 21:09:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\DMCache
[2007/04/15 15:08:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\GetRightToGo
[2009/11/08 13:28:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\GrabPro
[2007/04/17 17:16:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Ideazon
[2007/04/01 13:16:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\iGetter
[2004/09/22 19:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Leadertech
[2007/04/01 13:27:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Maxprog
[2009/11/22 19:11:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Moyea
[2010/12/31 08:50:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Notepad++
[2007/04/04 18:19:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\NOVOSIB Software
[2011/10/26 20:33:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Orbit
[2005/03/25 10:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\pdf995
[2009/09/05 14:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\Skinux
[2010/07/17 12:08:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rich\Application Data\SystemRequirementsLab
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 02:56:49 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: USERINIT.EXE >
[2004/08/04 02:56:57 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\SYSTEM32\userinit.exe
[2002/08/29 05:00:00 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=E931E0A2B8BF0019DB902E98D03662CB -- C:\I386\USERINIT.EXE
< MD5 for: WINLOGON.EXE >
[2004/08/04 02:56:57 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002/08/29 05:00:00 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB -- C:\I386\WINLOGON.EXE
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\SYSTEM32\winlogon.exe
< %systemroot%\*. /mp /s >
< End of report >