PC looks much better, Thanks you, here is the OTL log
OTL logfile created on: 1/11/2012 9:59:41 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Edgar\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 70.12% Memory free
3.04 Gb Paging File | 2.62 Gb Available in Paging File | 86.48% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 29.12 Gb Free Space | 39.07% Space Free | Partition Type: NTFS
Drive E: | 182.03 Gb Total Space | 71.81 Gb Free Space | 39.45% Space Free | Partition Type: NTFS
Drive F: | 4.27 Gb Total Space | 2.38 Gb Free Space | 55.73% Space Free | Partition Type: FAT32
Computer Name: YOUR-EF9D1E1329 | User Name: Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/11 21:57:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Edgar\Desktop\OTL.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | -H-- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/12/16 21:59:50 | 000,150,040 | -H-- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2009/09/04 23:15:06 | 000,067,872 | -H-- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (LVSrvLauncher)
SRV - File not found [Auto | Stopped] -- -- (intelusb3)
SRV - File not found [Auto | Stopped] -- -- (gusvc)
SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | -H-- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2008/12/16 21:59:50 | 000,150,040 | -H-- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009/08/05 22:48:42 | 000,054,752 | -H-- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2008/12/16 21:58:54 | 000,025,624 | -H-- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008/05/04 12:49:01 | 000,008,413 | -H-- | M] (RealNetworks, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\mcstrm.sys -- (MCSTRM)
DRV - [2007/05/23 04:15:00 | 000,547,744 | -H-- | M] (D-Link Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\A3AB.sys -- (A3AB) D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB)
DRV - [2005/09/23 18:56:28 | 003,966,976 | -H-- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/08/12 16:31:12 | 000,098,432 | -H-- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005/07/29 19:11:04 | 000,012,928 | -H-- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/07/29 19:11:02 | 000,034,048 | -H-- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/03/09 15:53:00 | 000,036,352 | -H-- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2001/08/17 07:49:32 | 000,019,968 | -H-- | M] (Macronix International Co., Ltd. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mxnic.sys -- (mxnic)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.searchcanvas.com/?ot=6
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
IE - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.775: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.775: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.775: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/10/10 14:49:00 | 000,000,000 | ---D | M]
[2011/09/26 18:02:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Edgar\Application Data\Mozilla\Extensions
[2012/01/10 22:34:48 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/01/04 19:45:44 | 000,000,000 | -H-D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/01 03:00:41 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
O1 HOSTS File: ([2012/01/11 21:33:15 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll File not found
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O2 - BHO: (Superfiles Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Superfiles Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\..\Toolbar\WebBrowser: (Superfiles Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O4 - HKLM..\Run: [JIHYyTpFFCbPF.exe] C:\Documents and Settings\All Users\Application Data\JIHYyTpFFCbPF.exe File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime Alternative\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Liset\Start Menu\Programs\Startup\Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3487969574-3620517906-821581102-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm File not found
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx File not found
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715}
http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1209877873268 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F}
http://www.ritzpix.com/net/Uploader/LPUploader57.cab (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://www.creative.com/softwareupdate/su/ocx/15035/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2B9D030-A334-4DA8-A0F0-B081652FF158}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D4619AD3-F353-45B2-97A2-DBAFE5A21BC3}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: E:\Documents and Settings\Owner.YOUR-F8C4439DFA\My Documents\bonnet-1024x768.BMP
O24 - Desktop BackupWallPaper: E:\Documents and Settings\Owner.YOUR-F8C4439DFA\My Documents\bonnet-1024x768.BMP
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/09 19:13:09 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2005/01/09 19:13:09 | 000,000,000 | -H-- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.JDCT - jl_jdct.drv File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/11 21:57:41 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Edgar\Desktop\OTL.exe
[2012/01/11 20:48:49 | 004,378,257 | R--- | C] (Swearware) -- C:\Documents and Settings\Edgar\Desktop\ComboFix.exe
[2012/01/11 20:11:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Edgar\Desktop\bootkit_remover
[2012/01/11 18:39:12 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Edgar\Desktop\dds.scr
[2012/01/11 17:25:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Edgar\Application Data\Malwarebytes
[2012/01/11 17:25:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/11 17:25:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/01/11 17:25:03 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/01/11 17:25:03 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/11 17:24:15 | 010,847,608 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Edgar\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/10 22:15:10 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/10 22:11:36 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/10 22:11:36 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/10 22:11:36 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/10 22:11:36 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/10 22:10:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/10 22:09:57 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/10 21:46:44 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Edgar\Desktop\aswMBR.exe
[2012/01/10 20:47:23 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Edgar\Recent
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/11 21:59:02 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3487969574-3620517906-821581102-1006.job
[2012/01/11 21:59:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3487969574-3620517906-821581102-1006.job
[2012/01/11 21:57:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Edgar\Desktop\OTL.exe
[2012/01/11 21:37:34 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/01/11 21:37:00 | 000,000,998 | -H-- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3487969574-3620517906-821581102-1007UA.job
[2012/01/11 21:37:00 | 000,000,976 | -H-- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3487969574-3620517906-821581102-1007Core.job
[2012/01/11 21:33:15 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/11 21:32:53 | 000,000,374 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2012/01/11 21:32:42 | 000,000,278 | -H-- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3487969574-3620517906-821581102-1007.job
[2012/01/11 21:32:42 | 000,000,276 | -H-- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3487969574-3620517906-821581102-1009.job
[2012/01/11 21:32:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/11 21:32:18 | 2011,680,768 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/11 21:24:37 | 004,378,257 | R--- | M] (Swearware) -- C:\Documents and Settings\Edgar\Desktop\ComboFix.exe
[2012/01/11 21:07:00 | 000,000,286 | -H-- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3487969574-3620517906-821581102-1007.job
[2012/01/11 20:10:45 | 000,044,607 | ---- | M] () -- C:\Documents and Settings\Edgar\Desktop\bootkit_remover.zip
[2012/01/11 20:07:40 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Edgar\Desktop\MBR.dat
[2012/01/11 19:06:38 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Edgar\Desktop\aswMBR.exe
[2012/01/11 18:39:18 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Edgar\Desktop\dds.scr
[2012/01/11 18:00:04 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Edgar\Desktop\w7mbfktv.exe
[2012/01/11 17:25:09 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/11 17:24:20 | 010,847,608 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Edgar\Desktop\mbam-setup-1.60.0.1800.exe
[2012/01/10 22:15:16 | 000,000,314 | RHS- | M] () -- C:\boot.ini
[2012/01/10 13:19:05 | 000,030,277 | -H-- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/01/07 19:12:58 | 000,000,284 | -H-- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3487969574-3620517906-821581102-1009.job
[2012/01/05 09:27:00 | 000,000,284 | -H-- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/03 08:58:44 | 000,472,738 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/03 08:58:44 | 000,084,692 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/03 08:45:11 | 000,001,170 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/12/21 09:58:10 | 000,103,733 | -H-- | M] () -- C:\WINDOWS\System32\itusbcore.dat
[2011/12/21 09:58:10 | 000,000,197 | -H-- | M] () -- C:\WINDOWS\System32\itlsvc.dat
[2011/12/15 03:22:16 | 000,162,728 | -H-- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 03:05:04 | 000,001,393 | -H-- | M] () -- C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/11 20:10:44 | 000,044,607 | ---- | C] () -- C:\Documents and Settings\Edgar\Desktop\bootkit_remover.zip
[2012/01/11 17:59:49 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Edgar\Desktop\w7mbfktv.exe
[2012/01/11 17:25:09 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/10 22:21:54 | 2011,680,768 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/10 22:15:16 | 000,000,199 | ---- | C] () -- C:\Boot.bak
[2012/01/10 22:15:11 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/01/10 22:11:36 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/10 22:11:36 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/10 22:11:36 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/10 22:11:36 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/10 22:11:36 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/10 22:06:19 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Edgar\Desktop\MBR.dat
[2011/11/21 10:34:43 | 000,103,733 | -H-- | C] () -- C:\WINDOWS\System32\itusbcore.dat
[2011/11/21 10:34:43 | 000,000,197 | -H-- | C] () -- C:\WINDOWS\System32\itlsvc.dat
[2010/11/27 13:10:57 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\PTWebCam.INI
[2010/10/16 08:48:29 | 000,118,784 | -H-- | C] () -- C:\WINDOWS\System32\PTTreeIcons.dll
[2010/02/05 20:44:02 | 000,000,292 | -H-- | C] () -- C:\WINDOWS\cdplayer.ini
[2009/11/20 09:14:27 | 000,034,972 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/10/03 10:36:50 | 000,000,111 | -H-- | C] () -- C:\WINDOWS\ka.ini
[2009/09/25 20:28:31 | 000,000,156 | -H-- | C] () -- C:\WINDOWS\QTW.INI
[2009/09/25 20:28:11 | 000,002,552 | -H-- | C] () -- C:\WINDOWS\WAVEMIX.INI
[2009/06/26 20:28:39 | 000,000,376 | -H-- | C] () -- C:\WINDOWS\ODBC.INI
[2009/04/29 12:34:01 | 000,166,304 | -H-- | C] () -- C:\WINDOWS\hpoins28.dat
[2009/04/29 12:34:01 | 000,000,796 | -H-- | C] () -- C:\WINDOWS\hpomdl28.dat
[2009/02/14 12:07:46 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009/02/04 16:15:51 | 000,000,298 | -H-- | C] () -- C:\WINDOWS\EReg077.dat
[2009/02/04 16:15:39 | 000,000,033 | -H-- | C] () -- C:\WINDOWS\TLCAPPS.INI
[2009/01/14 20:16:32 | 000,000,118 | -H-- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/12/16 21:58:54 | 000,025,624 | -H-- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | -H-- | C] () -- C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2008/12/06 09:05:49 | 000,005,950 | -H-- | C] () -- C:\WINDOWS\wininit.ini
[2008/11/30 11:48:16 | 000,000,664 | -H-- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/11/27 19:10:09 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/09 22:14:33 | 000,000,552 | -H-- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2008/07/19 17:04:31 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SETUP32.INI
[2008/05/04 13:18:20 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Edgar\Local Settings\Application Data\fusioncache.dat
[2008/05/04 00:16:53 | 001,662,976 | -H-- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/04 00:16:53 | 001,519,616 | -H-- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/05/04 00:16:53 | 001,019,904 | -H-- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/05/04 00:16:53 | 000,466,944 | -H-- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/05/04 00:16:52 | 001,466,368 | -H-- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/05/04 00:16:52 | 001,339,392 | -H-- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/05/04 00:16:52 | 000,573,440 | -H-- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2008/05/04 00:16:52 | 000,286,720 | -H-- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/05/04 00:16:50 | 000,442,368 | -H-- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/05/04 00:16:50 | 000,393,216 | -H-- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008/05/04 00:16:50 | 000,046,080 | -H-- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2008/05/04 00:08:12 | 000,000,396 | -H-- | C] () -- C:\WINDOWS\lexstat.ini
[2008/05/03 23:38:01 | 000,000,060 | -H-- | C] () -- C:\WINDOWS\System32\SYSDRV.DAT
[2008/05/03 23:34:00 | 000,004,569 | -H-- | C] () -- C:\WINDOWS\System32\secupd.dat
[2008/05/03 23:33:47 | 000,272,128 | -H-- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2008/05/03 23:33:47 | 000,028,626 | -H-- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2008/05/03 23:33:43 | 000,005,151 | -H-- | C] () -- C:\WINDOWS\System32\oembios.dat
[2008/05/03 23:33:39 | 013,107,200 | -H-- | C] () -- C:\WINDOWS\System32\oembios.bin
[2008/05/03 23:33:33 | 000,000,741 | -H-- | C] () -- C:\WINDOWS\System32\noise.dat
[2008/05/03 23:33:08 | 000,673,088 | -H-- | C] () -- C:\WINDOWS\System32\mlang.dat
[2008/05/03 23:33:07 | 000,046,258 | -H-- | C] () -- C:\WINDOWS\System32\mib.bin
[2008/05/03 23:32:06 | 000,218,003 | -H-- | C] () -- C:\WINDOWS\System32\dssec.dat
[2008/05/03 23:31:39 | 000,001,804 | -H-- | C] () -- C:\WINDOWS\System32\dcache.bin
[2008/05/03 22:23:26 | 000,040,960 | -H-- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2008/05/03 22:23:13 | 000,000,164 | -H-- | C] () -- C:\WINDOWS\avrack.ini
[2005/08/05 23:01:54 | 000,235,008 | -H-- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/01/12 11:38:00 | 000,000,061 | -H-- | C] () -- C:\WINDOWS\smscfg.ini
[2005/01/12 10:51:23 | 000,352,256 | -H-- | C] () -- C:\WINDOWS\System32\HotlineClient.exe
[2005/01/09 19:17:55 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/01/09 19:07:25 | 000,021,640 | -H-- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/01/09 17:49:16 | 000,000,461 | -H-- | C] () -- C:\WINDOWS\System32\emver.ini
[2005/01/09 17:49:16 | 000,000,378 | -H-- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/01/09 17:48:21 | 000,472,738 | -H-- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/01/09 17:48:21 | 000,084,692 | -H-- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/01/09 11:00:34 | 000,004,161 | -H-- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/01/09 10:59:39 | 000,162,728 | -H-- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[1999/01/22 12:46:58 | 000,065,536 | -H-- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2011/11/18 21:51:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Abby\Application Data\24C37
[2011/11/18 21:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Abby\Application Data\37EE8
[2011/04/02 18:35:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BlazeVideo
[2008/05/04 00:08:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/05/03 23:22:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2010/09/16 13:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2008/05/13 23:35:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\two setup mode load
[2009/09/13 12:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/03/21 11:59:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/09/13 11:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/16 07:48:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/19 23:58:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2009/05/31 10:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/09/26 21:52:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Edgar\Application Data\GetRightToGo
[2008/08/14 15:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Guest\Application Data\iWin
[2011/11/19 02:10:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\24C37
[2008/05/04 14:58:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\DrvMedia
[2010/02/16 21:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\Facebook
[2008/08/14 14:44:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\iWin
[2011/11/18 21:17:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\K88fRRZ9hTXwUVl
[2008/08/07 00:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\MSNInstaller
[2008/07/03 15:54:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\Password Solutions
[2011/11/18 21:17:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\vJJ6dEK8gR
[2011/11/18 21:17:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\WVVeelOOBtP0
[2009/03/04 09:18:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Liset\Application Data\YouSendIt
[2012/01/11 21:37:00 | 000,000,976 | -H-- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-3487969574-3620517906-821581102-1007Core.job
[2012/01/11 21:37:00 | 000,000,998 | -H-- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-3487969574-3620517906-821581102-1007UA.job
[2012/01/11 21:37:34 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/16 08:48:31 | 000,000,035 | -H-- | M] () -- C:\aa.txt
[2005/01/09 19:13:09 | 000,000,000 | -H-- | M] () -- C:\AUTOEXEC.BAT
[2008/05/03 23:37:59 | 000,000,199 | ---- | M] () -- C:\Boot.bak
[2012/01/10 22:15:16 | 000,000,314 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2012/01/11 21:38:19 | 000,020,448 | ---- | M] () -- C:\ComboFix.txt
[2005/01/09 19:13:09 | 000,000,000 | -H-- | M] () -- C:\CONFIG.SYS
[2008/05/09 15:22:35 | 000,000,133 | -H-- | M] () -- C:\DealioAu.log
[2012/01/11 21:32:18 | 2011,680,768 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/20 20:49:23 | 009,060,074 | -H-- | M] () -- C:\immudebug.log
[2005/01/09 19:13:09 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2005/01/09 19:13:09 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/10 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/05/08 20:09:05 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2012/01/11 21:32:15 | 1409,286,144 | -HS- | M] () -- C:\pagefile.sys
[2008/05/04 00:43:04 | 000,000,002 | -H-- | M] () -- C:\REQUEST_OEMRESET_ENDUSER
[2009/02/07 21:59:08 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2009/02/07 21:59:20 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2009/01/15 17:02:53 | 000,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/01/27 18:20:05 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/02/04 19:36:07 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/02/04 20:03:58 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/02/04 20:13:10 | 000,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2009/02/04 20:28:45 | 000,000,232 | -H-- | M] () -- C:\sqmdata07.sqm
[2009/02/07 22:00:37 | 000,000,232 | -H-- | M] () -- C:\sqmdata08.sqm
[2009/02/07 22:02:25 | 000,000,232 | -H-- | M] () -- C:\sqmdata09.sqm
[2009/02/11 20:21:29 | 000,000,232 | -H-- | M] () -- C:\sqmdata10.sqm
[2008/12/24 00:59:06 | 000,000,232 | -H-- | M] () -- C:\sqmdata11.sqm
[2008/12/24 09:20:41 | 000,000,232 | -H-- | M] () -- C:\sqmdata12.sqm
[2008/12/28 01:06:12 | 000,000,232 | -H-- | M] () -- C:\sqmdata13.sqm
[2008/12/29 21:21:26 | 000,000,232 | -H-- | M] () -- C:\sqmdata14.sqm
[2008/12/30 22:24:04 | 000,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2009/01/14 20:11:54 | 000,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2009/01/17 09:24:38 | 000,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2009/01/18 21:04:25 | 000,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2009/02/04 21:38:41 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2009/02/07 21:59:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009/02/07 21:59:20 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2009/01/15 17:02:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/01/27 18:20:05 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/02/04 19:36:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/02/04 20:03:58 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/02/04 20:13:10 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009/02/04 20:28:45 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2009/02/07 22:00:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2009/02/07 22:02:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2009/02/11 20:21:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2008/12/24 00:59:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2008/12/24 09:20:41 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2008/12/28 01:06:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2008/12/29 21:21:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2008/12/30 22:24:04 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2009/01/14 20:11:54 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2009/01/17 09:24:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2009/01/18 21:04:25 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2009/02/04 21:38:41 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2008/07/20 21:37:32 | 000,473,946 | -H-- | M] () -- C:\Uninstall.zip
[2008/05/04 00:43:04 | 000,000,002 | RHS- | M] () -- C:\USER
[2008/07/20 21:49:42 | 006,664,704 | -H-- | M] () -- C:\winzip111es.msi
[2008/07/21 23:30:04 | 000,000,158 | -H-- | M] () -- C:\YServer.txt