O1 HOSTS File: ([2012/03/25 18:39:16 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareBlock Class) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (Tenebril Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (McAfee Phishing Filter) - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll ()
O2 - BHO: (MyPoints Toolbar) - {4E7BD74F-2B8D-469E-C1EA-F165BB85A330} - C:\Program Files\mypoints\mypoints.dll ( )
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Freecause Toolbar BHO) - {614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A} - C:\Program Files\MyPoints Toolbar 2.0\Toolbar.dll ()
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MyPoints Toolbar) - {4E7BD74F-2B8D-469E-C1EA-F165BB85A330} - C:\Program Files\mypoints\mypoints.dll ( )
O3 - HKLM\..\Toolbar: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Toolbar 2.0\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..\Toolbar\WebBrowser: (MyPoints Toolbar) - {4E7BD74F-2B8D-469E-C1EA-F165BB85A330} - C:\Program Files\mypoints\mypoints.dll ( )
O3 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..\Toolbar\WebBrowser: (MyPoints Point Finder) - {89A2510A-B4B6-4683-BEC9-1B96700BC7F1} - C:\Program Files\MyPoints Toolbar 2.0\Toolbar.dll ()
O3 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005..\Run: [CTSyncU.exe] C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
O4 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKU\S-1-5-18..\RunOnce: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher\Protector.exe (Tenebril Inc.)
O4 - Startup: C:\Documents and Settings\Robert Moulton\Start Menu\Programs\Startup\Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe (Tenebril Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A}
http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab (DjVuCtl Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4505-8fb8-d0d2d160e512/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://www.srtest.com/srl_bin/sysreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}
http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722}
http://download.games.yahoo.com/games/web_games/sony/davinci/DVCDownloadControl.cab (DVCDownloadControl)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9}
http://download.games.yahoo.com/games/web_games/sony/bewitched/main.cab (BewitchedGameClass Control)
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E}
http://www.systemrequirementslab.com/sysreqlab.cab (System Requirements Lab Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab (SysInfo Class)
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260}
http://download.games.yahoo.com/games/web_games/playtime/mahjongescape/PTGameLauncher.cab (Playtime Games Launcher)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15108/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{65BD8956-3DDB-41D2-BE0F-E377D64DF6B1}: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Filter\application/octet-stream - No CLSID value found
O18 - Protocol\Filter\application/x-complus - No CLSID value found
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-msdownload - No CLSID value found
O20 - AppInit_DLLs: (secuload.dll) - C:\WINDOWS\System32\SecuLoad.dll (Tenebril Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\e4ff1b2b548: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\WB: DllName - (C:\Program Files\Stardock\MyColors\fastload.dll) - C:\Program Files\Stardock\MyColors\fastload.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Robert Moulton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Robert Moulton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/26 17:29:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2012/03/26 17:22:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/03/26 17:13:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/03/25 20:47:22 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Robert Moulton\Desktop\OTL.exe
[2012/03/25 20:15:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/03/25 16:33:13 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/03/25 16:29:28 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/03/25 16:29:28 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/03/25 16:29:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/03/25 16:29:28 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/03/25 16:29:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/03/25 16:28:48 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/25 16:22:47 | 004,443,082 | R--- | C] (Swearware) -- C:\Documents and Settings\Robert Moulton\Desktop\ComboFix.exe
[2012/03/24 16:09:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Moulton\Desktop\tdsskiller
[2012/03/22 20:37:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Moulton\Desktop\GETxPUD
[2012/03/22 16:56:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Moulton\Desktop\bootkit_remover
[2012/03/21 21:31:26 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Robert Moulton\Desktop\aswMBR.exe
[2012/03/20 21:17:04 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Robert Moulton\Desktop\dds.scr
[2012/03/19 17:44:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2012/03/19 17:44:07 | 000,337,112 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/03/19 17:44:07 | 000,020,696 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/03/19 17:44:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/03/19 17:44:05 | 000,035,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/03/19 17:44:04 | 000,610,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/03/19 17:44:04 | 000,053,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/03/19 17:44:03 | 000,095,704 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/03/19 17:44:03 | 000,089,048 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/03/19 17:44:02 | 000,024,920 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/03/19 17:43:23 | 000,041,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/03/19 17:43:22 | 000,201,352 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/03/19 17:43:03 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/03/19 17:43:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/03/19 16:32:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Robert Moulton\Recent
[2012/03/03 16:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Moulton\Application Data\GRETECH
[2012/03/03 16:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Moulton\My Documents\GomPlayer
[2012/03/03 16:06:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\GOM Player
[2012/03/03 16:06:36 | 000,000,000 | ---D | C] -- C:\Program Files\GRETECH
[2012/03/03 15:59:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2012/02/26 19:47:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Moulton\Start Menu\Programs\Google Chrome
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/26 17:50:02 | 000,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/03/26 17:47:49 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/03/26 17:20:30 | 000,000,176 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2012/03/26 17:18:18 | 000,000,902 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/26 17:18:11 | 000,000,898 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/26 17:02:51 | 000,054,156 | ---- | M] () -- C:\WINDOWS\QTFont.qfn
[2012/03/26 17:01:05 | 000,025,589 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012/03/26 17:00:31 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/26 17:00:29 | 1071,812,608 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/25 20:47:26 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Moulton\Desktop\OTL.exe
[2012/03/25 18:39:16 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/25 18:14:22 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/25 17:59:00 | 000,001,014 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1103233014-2229641168-2263940352-1005UA.job
[2012/03/25 17:34:42 | 000,064,980 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000005-10031102}.rfx
[2012/03/25 17:34:42 | 000,055,700 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000004-00001102-00000005-10031102}.rfx
[2012/03/25 17:34:42 | 000,055,700 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000005-00000000-00000004-00001102-00000005-10031102}.rfx
[2012/03/25 17:34:42 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2012/03/25 17:34:42 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2012/03/25 16:33:22 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2012/03/25 16:24:19 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\rkill.exe
[2012/03/25 16:22:47 | 004,443,082 | R--- | M] (Swearware) -- C:\Documents and Settings\Robert Moulton\Desktop\ComboFix.exe
[2012/03/25 15:21:41 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\MBR.dat
[2012/03/24 16:08:36 | 002,047,211 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\tdsskiller.zip
[2012/03/24 12:32:40 | 000,095,232 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/23 19:59:02 | 000,000,962 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1103233014-2229641168-2263940352-1005Core.job
[2012/03/23 18:12:20 | 000,000,209 | ---- | M] () -- C:\Boot.bak
[2012/03/22 20:37:00 | 000,497,272 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\GETxPUD.exe
[2012/03/22 20:17:24 | 000,801,997 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\ListParts64.exe
[2012/03/22 20:17:13 | 000,304,845 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\ListParts.exe
[2012/03/22 20:06:45 | 000,002,329 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/03/22 20:06:44 | 000,002,351 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\Google Chrome.lnk
[2012/03/22 16:47:07 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Robert Moulton\Desktop\aswMBR.exe
[2012/03/21 21:31:36 | 000,044,607 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\bootkit_remover.zip
[2012/03/21 20:35:16 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/03/20 21:17:05 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Robert Moulton\Desktop\dds.scr
[2012/03/20 21:16:16 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\4qi37m06.exe
[2012/03/19 17:44:07 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/03/19 17:44:03 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/03/18 22:01:53 | 000,000,853 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/03/17 11:10:00 | 000,000,282 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy.job
[2012/03/16 17:55:24 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2012/03/16 17:48:38 | 000,000,728 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\DVDFab Profile Editor.lnk
[2012/03/16 17:48:38 | 000,000,709 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8 Qt.lnk
[2012/03/16 17:48:38 | 000,000,691 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\DVDFab 8 Qt.lnk
[2012/03/16 17:44:42 | 000,015,766 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\1293_0001[1].pdf
[2012/03/11 20:16:17 | 000,443,202 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/11 20:16:16 | 000,072,276 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/03 18:07:53 | 000,002,378 | ---- | M] () -- C:\Documents and Settings\Robert Moulton\Desktop\Christmas list 2007.rtf
[2012/03/03 16:06:59 | 000,000,826 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GOM Player.lnk
[2012/03/03 15:59:53 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/03/03 15:52:59 | 000,001,755 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2012/03/03 13:37:29 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/26 17:20:30 | 000,000,176 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2012/03/26 16:24:44 | 1071,812,608 | -HS- | C] () -- C:\hiberfil.sys
[2012/03/25 17:42:41 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/03/25 17:42:41 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/03/25 17:01:27 | 000,001,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2012/03/25 17:01:27 | 000,000,769 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpyCatcher Protector.lnk
[2012/03/25 16:33:22 | 000,000,209 | ---- | C] () -- C:\Boot.bak
[2012/03/25 16:33:16 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/03/25 16:29:28 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/03/25 16:29:28 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/03/25 16:29:28 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/03/25 16:29:28 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/03/25 16:29:28 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/03/25 16:24:56 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\rkill.exe
[2012/03/25 15:21:41 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\MBR.dat
[2012/03/22 20:36:59 | 000,497,272 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\GETxPUD.exe
[2012/03/22 20:17:23 | 000,801,997 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\ListParts64.exe
[2012/03/22 20:17:12 | 000,304,845 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\ListParts.exe
[2012/03/22 19:38:37 | 002,047,211 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\tdsskiller.zip
[2012/03/21 21:31:40 | 000,044,607 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\bootkit_remover.zip
[2012/03/20 21:16:15 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\4qi37m06.exe
[2012/03/19 17:44:07 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012/03/19 17:37:54 | 000,002,317 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\OverDrive Media Console.lnk
[2012/03/19 17:37:54 | 000,001,962 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk
[2012/03/19 17:37:54 | 000,001,871 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Barbarian Invasion.lnk
[2012/03/19 17:37:54 | 000,001,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Medieval II Total War Britannia.lnk
[2012/03/19 17:37:54 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Medieval II Total War Teutonic.lnk
[2012/03/19 17:37:54 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Medieval II Total War Crusades.lnk
[2012/03/19 17:37:54 | 000,001,810 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Medieval II Total War Americas.lnk
[2012/03/19 17:37:54 | 000,001,752 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Medieval II Total War.lnk
[2012/03/19 17:37:54 | 000,001,747 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZENcast Organizer.lnk
[2012/03/19 17:37:54 | 000,001,711 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\World in Conflict.lnk
[2012/03/19 17:37:54 | 000,001,698 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PictureProject.lnk
[2012/03/19 17:37:54 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CDBurnerXP.lnk
[2012/03/19 17:37:54 | 000,001,595 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2012/03/19 17:37:54 | 000,001,061 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EASEUS Partition Master 7.0.1 Home Edition.lnk
[2012/03/19 17:37:54 | 000,000,859 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Company of Heroes.lnk
[2012/03/19 17:37:54 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\GOM Player.lnk
[2012/03/19 17:37:54 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2012/03/19 17:37:54 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Watch.lnk
[2012/03/19 17:37:54 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2012/03/19 17:37:54 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/19 17:37:54 | 000,000,747 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2012/03/19 17:37:54 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/03/19 17:37:54 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/03/19 17:37:54 | 000,000,714 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MediaJoin.lnk
[2012/03/19 17:37:54 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2012/03/19 17:37:54 | 000,000,578 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VyperVPN.lnk
[2012/03/19 17:37:54 | 000,000,491 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\OtsAV Free.lnk
[2012/03/19 17:37:54 | 000,000,484 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ots Studio.lnk
[2012/03/19 17:37:54 | 000,000,124 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZEN Media Explorer.lnk
[2012/03/19 17:37:53 | 000,002,489 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live Messenger.lnk
[2012/03/19 17:37:53 | 000,002,329 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/03/19 17:37:53 | 000,002,007 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Games.lnk
[2012/03/19 17:37:53 | 000,001,802 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2012/03/19 17:37:53 | 000,001,769 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Musicmatch Jukebox.lnk
[2012/03/19 17:37:53 | 000,001,746 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Multimedia Sync by doubleTwist.lnk
[2012/03/19 17:37:53 | 000,001,655 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\WeatherBug.lnk
[2012/03/19 17:37:53 | 000,001,478 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk
[2012/03/19 17:37:53 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/19 17:37:53 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/19 17:37:53 | 000,000,709 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8 Qt.lnk
[2012/03/19 17:37:53 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012/03/19 17:37:53 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 8.lnk
[2012/03/19 17:37:53 | 000,000,672 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\GrabIt.lnk
[2012/03/19 17:37:53 | 000,000,669 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 9.0.lnk
[2012/03/19 17:37:53 | 000,000,636 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 7.lnk
[2012/03/19 17:37:53 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/03/19 17:37:53 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/03/19 17:37:52 | 000,000,986 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/03/19 17:37:52 | 000,000,493 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2012/03/19 17:37:49 | 000,002,489 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
[2012/03/19 17:37:49 | 000,002,487 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2012/03/19 17:37:49 | 000,002,046 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Outlook.lnk
[2012/03/19 17:37:49 | 000,002,002 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft PowerPoint.lnk
[2012/03/19 17:37:49 | 000,001,980 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Excel Viewer 2003.lnk
[2012/03/19 17:37:49 | 000,001,934 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Plus! Photo Story 2 LE.lnk
[2012/03/19 17:37:49 | 000,001,907 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Musicmatch Jukebox.lnk
[2012/03/19 17:37:49 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2012/03/19 17:37:49 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/19 17:37:48 | 000,001,990 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Access.lnk
[2012/03/19 17:37:48 | 000,001,794 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\InterVideo Information Service.lnk
[2012/03/19 17:37:48 | 000,001,466 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Media Center.lnk
[2012/03/19 17:37:45 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2012/03/19 17:37:44 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/03/19 17:37:44 | 000,000,819 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2012/03/19 17:37:44 | 000,000,814 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2012/03/19 17:37:44 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Acrobat.com.lnk
[2012/03/18 22:10:17 | 000,000,853 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/03/16 17:48:38 | 000,000,728 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\DVDFab Profile Editor.lnk
[2012/03/16 17:44:42 | 000,015,766 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\1293_0001[1].pdf
[2012/02/26 19:48:22 | 000,002,351 | ---- | C] () -- C:\Documents and Settings\Robert Moulton\Desktop\Google Chrome.lnk
[2012/02/26 19:46:27 | 000,001,014 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1103233014-2229641168-2263940352-1005UA.job
[2012/02/26 19:46:26 | 000,000,962 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1103233014-2229641168-2263940352-1005Core.job
[2011/02/02 09:18:16 | 002,336,384 | ---- | C] () -- C:\WINDOWS\System32\BootMan.exe
[2011/02/02 09:18:16 | 000,086,408 | ---- | C] () -- C:\WINDOWS\System32\setupempdrv03.exe
[2011/02/02 09:18:16 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
[2011/02/02 09:18:15 | 000,013,192 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
[2011/02/02 09:18:15 | 000,008,456 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
[2010/12/30 22:05:15 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/12/21 13:01:08 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Fwodogodinireyi.dat
[2010/12/21 13:01:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Bnozanojo.bin
[2010/06/08 22:03:24 | 000,000,223 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2010/04/29 18:18:24 | 000,313,207 | R--- | C] () -- C:\WINDOWS\System32\ctstatic.dat
[2010/04/29 18:18:24 | 000,053,932 | R--- | C] () -- C:\WINDOWS\System32\ctdaught.dat
[2010/04/12 21:35:15 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/04/12 21:18:01 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
========== LOP Check ==========
[2007/12/25 22:24:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2012/03/19 17:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2009/04/06 19:40:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2005/08/16 20:54:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2008/09/02 21:02:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
[2010/04/12 21:18:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\doubleTwist Corporation
[2012/01/18 19:38:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\dvdfab
[2009/01/20 20:18:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2008/07/09 21:38:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ludia
[2008/11/25 19:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/02/16 19:23:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Otto
[2008/11/25 13:59:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Panasonic
[2006/07/19 20:32:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayTime
[2006/07/19 18:53:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2009/01/20 20:12:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2006/07/19 21:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SonyPicturesGames
[2007/12/11 22:19:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/07/20 10:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril
[2007/06/09 12:04:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/02/05 23:00:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/12/21 21:33:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
[2008/02/06 14:21:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{27ED786F-D773-47F8-93EB-8A249414AD30}
[2009/04/05 15:05:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Canneverbe_Limited
[2008/10/21 17:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2007/03/29 18:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Command & Conquer 3 Tiberium Wars
[2009/04/06 19:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\DAEMON Tools
[2009/04/06 19:55:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\DAEMON Tools Lite
[2009/04/06 19:52:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\DAEMON Tools Pro
[2011/08/26 18:44:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\DVDFab
[2011/02/20 20:57:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\ElevatedDiagnostics
[2009/10/24 20:48:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\FCTB000060497
[2009/08/22 20:34:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Forte
[2009/03/06 20:59:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\FrostWire
[2012/03/10 10:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\GrabIt
[2006/12/03 10:38:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\InterVideo
[2012/02/27 18:35:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Kuoxviv
[2006/08/27 16:10:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Leadertech
[2006/07/31 17:31:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\LucasArts
[2008/07/13 21:18:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Ludia
[2011/07/09 11:35:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Mimo
[2006/12/27 17:35:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\My Battle for Middle-earth Files
[2006/07/11 20:09:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\My Battle for Middle-earth(tm) II Files
[2006/11/30 17:47:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\My The Lord of the Rings, The Rise of the Witch-king Files
[2011/06/11 22:05:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\MYPOINTS
[2008/11/25 19:56:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\NCH Swift Sound
[2007/08/07 18:45:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Nikon
[2007/02/16 19:23:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Otto
[2009/02/24 18:26:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\OverDrive
[2006/10/24 17:27:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Petroglyph
[2008/02/06 14:20:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Seven Zip
[2006/09/22 16:49:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Sierra
[2009/04/26 14:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Snapfish
[2007/07/20 10:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Tenebril
[2009/03/25 17:29:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\The Creative Assembly
[2012/03/03 15:26:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Ulunf
[2010/12/26 22:47:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Unity
[2007/06/09 12:04:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Viewpoint
[2010/11/24 14:22:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\Vso
[2009/04/30 16:42:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Moulton\Application Data\WeatherBug
[2012/03/26 17:50:02 | 000,000,252 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< :OTL >
< O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found. >
< O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) >
< O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found. >
< O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) >
< O3 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) >
< O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) >
< O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.) >
< O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites) >
< O15 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..Trusted Domains: localhost ([]http in Local intranet) >
< O15 - HKU\S-1-5-21-1103233014-2229641168-2263940352-1005\..Trusted Ranges: GD ([http] in Local intranet) >
< O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.) >
Invalid Switch: sysreqlab2.cab (Reg Error: Key error.)
< O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.) >
Invalid Switch: ultrashim.cab (Reg Error: Key error.)