Broni. As requested.
All processes killed
========== OTL ==========
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\Bonham\LOCALS~1\Temp\catchme.sys File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9AA2F14F-E956-44B8-8694-A5B615CDF341}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9AA2F14F-E956-44B8-8694-A5B615CDF341}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ipTray.exe deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\dvd\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12D51199-0DB5-46FE-A120-47A3D7D937CC}\ deleted successfully.
File {12D51199-0DB5-46FE-A120-47A3D7D937CC} - Reg Error: Value error. File not found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\tv\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}\ deleted successfully.
File {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - Reg Error: Value error. File not found not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{4F07DA45-8170-4859-9B5F-037EF2970034} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F07DA45-8170-4859-9B5F-037EF2970034}\ not found.
C:\Qoobox\TestC folder moved successfully.
C:\Qoobox\Test folder moved successfully.
C:\Qoobox\Quarantine\Registry_backups folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32 folder moved successfully.
C:\Qoobox\Quarantine\C\WINDOWS folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Bonham\Local Settings folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Bonham folder moved successfully.
C:\Qoobox\Quarantine\C\Documents and Settings folder moved successfully.
C:\Qoobox\Quarantine\C folder moved successfully.
C:\Qoobox\Quarantine folder moved successfully.
C:\Qoobox\LastRun folder moved successfully.
C:\Qoobox\BackEnv folder moved successfully.
C:\Qoobox folder moved successfully.
C:\WINDOWS\inf\SET4B3.tmp deleted successfully.
C:\WINDOWS\inf\SET4EE.tmp deleted successfully.
C:\WINDOWS\inf\SET8C2.tmp deleted successfully.
C:\Program Files\Messenger\SET295.tmp deleted successfully.
C:\Program Files\Messenger\SET43.tmp deleted successfully.
C:\Program Files\Messenger\uninst0.tmp deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:71173EF9 deleted successfully.
ADS C:\Program Files\autoruns.chm:SummaryInformation deleted successfully.
ADS C:\Documents and Settings\Bonham\Desktop\The Shopping Channel - Official Site.mht:SummaryInformation deleted successfully.
ADS C:\Documents and Settings\Bonham\Desktop\LG Manual.pdf:SummaryInformation deleted successfully.
ADS C:\Documents and Settings\Bonham\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf:SummaryInformation deleted successfully.
ADS C:\Documents and Settings\Bonham\My Documents\Word Files:Roxio EMC Stream deleted successfully.
ADS C:\Documents and Settings\Bonham\My Documents\Excel Files:Roxio EMC Stream deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:B879A65B deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:0656FCD2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:B63300D1 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DA18FD1D deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:211ED887 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:D68FBF6D deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:C31F31E6 deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Bonham
->Temp folder emptied: 22561786 bytes
->Temporary Internet Files folder emptied: 18763154 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 70984 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 40.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Bonham
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: LocalService
->Flash cache emptied: 0 bytes
User: NetworkService
Total Flash Files Cleaned = 0.00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.12.0 log created on 09112010_163556
Files\Folders moved on Reboot...
C:\Documents and Settings\Bonham\Local Settings\Temporary Internet Files\Content.IE5\RLB0N3HL\board,9.0[1].html moved successfully.
C:\Documents and Settings\Bonham\Local Settings\Temporary Internet Files\Content.IE5\GJPO5G5T\index[5].htm moved successfully.
C:\Documents and Settings\Bonham\Local Settings\Temporary Internet Files\Content.IE5\GJPO5G5T\topic,109562.30[1].html moved successfully.
File\Folder C:\Documents and Settings\Bonham\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat not found!
File\Folder C:\WINDOWS\temp\_avast5_\Webshlock.txt not found!
Registry entries deleted on Reboot...
Quick Scan
OTL logfile created on: 9/11/2010 4:43:49 PM - Run 11
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Bonham\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 230.42 Gb Total Space | 202.89 Gb Free Space | 88.05% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: WINXP_MCE
Current User Name: Bonham
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Bonham\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\SpeedFan\speedfan.exe (Almico Software (
www.almico.com))
PRC - C:\Program Files\Common Files\EPSON\eEBAPI\eEBSvc.exe ()
PRC - C:\Program Files\Common Files\EPSON\eEBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Intel\Intel Desktop Utilities\iduServ.exe (Intel(R) Corporation)
PRC - C:\Program Files\Folding@home\Folding@home-x86\FahCore_78.exe ()
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe (Motorola)
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
PRC - C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\WhatPulse\WhatPulse.exe (WhatPulse.org)
PRC - C:\Program Files\Windows Live\Toolbar\wltuser.exe (Microsoft Corporation)
PRC - C:\Program Files\Folding@home\Folding@home-x86\
[email protected] ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe ()
PRC - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe (Sonic Solutions)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Bonham\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
========== Win32 Services (SafeList) ========== SRV - (AWService) -- C:\Program Files\Intel\IDU\awServ.exe File not found
SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (EpsonBidirectionalService) -- C:\Program Files\Common Files\EPSON\eEBAPI\eEBSvc.exe ()
SRV - (EPSONStatusAgent2) -- C:\Program Files\Common Files\EPSON\eEBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
SRV - (IduService) Intel(R) -- C:\Program Files\Intel\Intel Desktop Utilities\iduServ.exe (Intel(R) Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (MotoConnect Service) -- C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
SRV - (RoxLiveShare) -- C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe (Sonic Solutions)
SRV - (RoxMediaDB) -- C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe (Sonic Solutions)
SRV - (RoxWatch) -- C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe (Sonic Solutions)
SRV - (RoxUPnPRenderer) -- C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe (Sonic Solutions)
SRV - (RoxUpnpServer) -- C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe (Sonic Solutions)
========== Driver Services (SafeList) ========== DRV - (SABProcEnum) -- C:\Program Files\Internet Explorer\SABProcEnum.sys File not found
DRV - (PCASp50) -- C:\WINDOWS\System32\Drivers\PCASp50.sys File not found
DRV - (NVIDIAHWAccess) -- C:\Documents and Settings\Bonham\Application Data\NVIDIA\HWAccess.sys File not found
DRV - (Lbd) -- C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
DRV - (osaio) -- C:\WINDOWS\system32\drivers\osaio.sys (OSA Technologies, An Avocent Company)
DRV - (aswTdi) -- C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) -- C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) -- C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) -- C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) -- C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (cpuidlep) -- C:\WINDOWS\System32\drivers\cpuidlep.sys ()
DRV - (smbusp) Intel(R) -- C:\WINDOWS\system32\drivers\intelsmb.sys (Intel Corporation)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (NVHDA) -- C:\WINDOWS\system32\drivers\nvhda32.sys (NVIDIA Corporation)
DRV - (cpudrv) -- C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (motmodem) -- C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (PSI) -- C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (NCHSSVAD) -- C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
DRV - (speedfan) -- C:\WINDOWS\system32\speedfan.sys (Windows (R) 2000 DDK provider)
DRV - (NTIDrvr) -- C:\WINDOWS\system32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (e1express) Intel(R) -- C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (NAL) -- C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (sfng32) -- C:\WINDOWS\system32\drivers\sfng32.sys (Sonic Focus, Inc)
DRV - (IAMTXP) Driver for Intel(R) -- C:\WINDOWS\system32\drivers\IAMTXP.sys (Intel Corporation)
DRV - (RxFilter) -- C:\WINDOWS\system32\drivers\RxFilter.sys (Sonic Solutions)
DRV - (OsaFsLoc) -- C:\WINDOWS\system32\drivers\OsaFsLoc.sys (OSA Technologies)
DRV - (cdudf_xp) -- C:\WINDOWS\System32\drivers\Cdudf_xp.sys (Sonic Solutions)
DRV - (pwd_2k) -- C:\WINDOWS\System32\drivers\Pwd_2k.sys (Sonic Solutions)
DRV - (dvd_2K) -- C:\WINDOWS\System32\drivers\dvd_2k.sys (Sonic Solutions)
DRV - (mmc_2K) -- C:\WINDOWS\System32\drivers\mmc_2k.sys (Sonic Solutions)
DRV - (iaStor) -- C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (drvmcdb) -- C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (FVDSCSI) -- C:\WINDOWS\system32\drivers\fvdscsi.sys (FarStone Inc.)
DRV - (cdrbsdrv) -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (SMBios) Intel (R) -- C:\WINDOWS\system32\drivers\SMBios.sys (Intel Corporation)
DRV - (fcdabus) -- C:\WINDOWS\system32\drivers\fcdabus.sys (FarStone Inc.)
DRV - (MODEMCSA) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (giveio) -- C:\WINDOWS\system32\giveio.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.mymanitoba.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[2010/04/17 21:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Mozilla\Extensions
[2010/04/11 16:44:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Bonham\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/04/17 21:02:29 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/15 11:04:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/15 11:04:22 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2002/01/09 00:26:42 | 000,319,488 | ---- | M] (Macromedia, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2010/09/11 16:36:14 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Foxit Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OCDLMgr] C:\Program Files\IZArc\OpenCandy\OCSetupHlp.dll (OpenCandy, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe (WhatPulse.org)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LaunchU3.exe.lnk = C:\WINDOWS\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe ()
O4 - Startup: C:\Documents and Settings\Bonham\Start Menu\Programs\Startup\
[email protected] = C:\Program Files\Folding@home\Folding@home-x86\
[email protected] ()
O4 - Startup: C:\Documents and Settings\Bonham\Start Menu\Programs\Startup\speedfan.lnk = C:\Program Files\SpeedFan\speedfan.exe (Almico Software (
www.almico.com))
O4 - Startup: C:\Documents and Settings\Bonham\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108799
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108799
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Mah%20Jong%20Medley/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189528423203 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189528318687 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD}
http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab (Shockwave Flash Object)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 72.2.10.2 72.2.10.4
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Bonham/LOCALS~1/Temp/msoclip1/01/clip_image002.gif
O24 - Desktop Components:1 () -
O24 - Desktop Components:2 () - file:///C:/Documents%20and%20Settings/Bonham/Local%20Settings/Application%20Data/IM/Runtime/Message/%7B74C62D20-1BC8-452C-B919-F9FAEBDDC056%7D/Forward/image0323232323232.jpg
O24 - Desktop Components:3 () -
O24 - Desktop Components:4 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Bonham\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Bonham\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/03/17 01:03:13 | 000,000,100 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ========== [2010/09/11 15:50:32 | 000,921,512 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Bonham\Desktop\Norton_Removal_Tool.exe
[2010/09/11 15:03:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bonham\Application Data\Intel
[2010/09/11 15:03:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Intel
[2010/09/11 14:58:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bonham\Desktop\IDU_3.1.1.012
[2010/09/11 13:58:32 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/09/11 13:43:20 | 000,576,000 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Bonham\Desktop\OTL.exe
[2010/09/10 00:57:07 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Bonham\Recent
[2010/09/08 12:41:17 | 000,000,000 | ---D | C] -- C:\Program Files\Intel Corporation
[2010/09/03 18:28:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/09/02 20:26:28 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/09/02 20:00:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/09/01 21:38:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/09/01 21:36:35 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/09/01 21:36:35 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/09/01 21:36:35 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/09/01 21:36:35 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/31 13:37:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/08/31 13:37:05 | 000,000,000 | ---D | C] -- C:\Program Files\Sun
[2010/07/20 21:47:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bonham\Application Data\Foxit Software
[2010/07/18 02:06:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bonham\Local Settings\Application Data\OpenCandy
[2010/07/18 00:10:21 | 000,000,000 | ---D | C] -- C:\Program Files\Motherboard Monitor 5
[2010/07/17 22:51:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bonham\Application Data\OpenCandy
[2010/07/17 12:33:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bonham\Application Data\SUPERAntiSpyware.com
[2010/07/03 13:06:36 | 004,388,296 | ---- | C] (Foxit Software) -- C:\Documents and Settings\Bonham\Desktop\FoxitPDFEditor220.0205_enu_Setup.exe
[2010/06/28 22:41:30 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010/06/26 23:48:30 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan
[2009/03/27 09:24:12 | 000,648,064 | ---- | C] (Sysinternals -
www.sysinternals.com) -- C:\Program Files\autoruns.exe
[2009/03/27 09:24:12 | 000,540,544 | ---- | C] (Sysinternals -
www.sysinternals.com) -- C:\Program Files\autorunsc.exe
========== Files - Modified Within 90 Days ========== [2010/09/11 16:40:41 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/11 16:39:22 | 000,276,202 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/09/11 16:39:22 | 000,002,539 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LaunchU3.exe.lnk
[2010/09/11 16:38:34 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/11 16:38:25 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/11 16:38:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/11 16:37:24 | 013,070,336 | ---- | M] () -- C:\Documents and Settings\Bonham\NTUSER.DAT
[2010/09/11 16:36:14 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010/09/11 16:12:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/11 15:50:54 | 000,921,512 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Bonham\Desktop\Norton_Removal_Tool.exe
[2010/09/11 15:33:55 | 000,162,182 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\topic,109580.0.html
[2010/09/11 15:13:29 | 000,001,057 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/11 15:13:29 | 000,000,325 | RHS- | M] () -- C:\boot.ini
[2010/09/11 15:13:29 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/09/11 15:05:40 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Bonham\ntuser.ini
[2010/09/11 15:02:51 | 000,255,864 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/11 15:01:21 | 000,001,790 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Intel(R) Desktop Utilities.lnk
[2010/09/11 15:00:48 | 000,008,413 | ---- | M] (OSA Technologies, An Avocent Company) -- C:\WINDOWS\System32\drivers\osaio.sys
[2010/09/11 14:56:23 | 012,713,957 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\IDU_3.1.1.012.zip
[2010/09/11 13:43:35 | 000,576,000 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Bonham\Desktop\OTL.exe
[2010/09/11 13:14:04 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Microsoft Word.lnk
[2010/09/11 12:24:37 | 006,228,992 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\911 photos - Never Forget !.pps
[2010/09/11 09:44:51 | 000,000,218 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Jumble, That Scrambled Word Game!.url
[2010/09/09 09:05:29 | 000,070,734 | ---- | M] () -- C:\Program Files\Storage Drives.JPG
[2010/09/09 08:48:11 | 000,049,244 | ---- | M] () -- C:\Program Files\autoruns.chm
[2010/09/08 23:57:40 | 002,643,698 | -H-- | M] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\IconCache.db
[2010/09/07 23:12:06 | 000,000,386 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag.job
[2010/09/07 17:28:55 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/09/07 10:12:17 | 000,038,848 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010/09/07 10:11:54 | 000,167,592 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010/09/07 09:52:25 | 000,046,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/09/07 09:52:03 | 000,165,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010/09/07 09:47:46 | 000,023,376 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/09/07 09:47:19 | 000,100,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/09/07 09:47:16 | 000,094,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010/09/07 09:47:07 | 000,017,744 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/09/07 09:46:51 | 000,028,880 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/08/30 15:13:57 | 000,001,700 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/08/24 23:35:30 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\SpeedFan.lnk
[2010/08/24 23:35:29 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2010/08/24 23:27:59 | 000,070,696 | ---- | M] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/08/24 23:25:26 | 001,029,907 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\The Shopping Channel - Official Site.mht
[2010/08/24 09:27:15 | 000,016,603 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Nesco.jpg
[2010/08/23 19:21:31 | 000,002,459 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Microsoft PowerPoint.lnk
[2010/08/22 20:06:01 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[2010/08/17 21:53:40 | 000,000,180 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Computer Hope.url
[2010/08/16 21:35:31 | 000,002,471 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Microsoft Excel.lnk
[2010/08/16 13:37:29 | 001,585,152 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Invitation2.pps
[2010/08/16 12:43:45 | 000,478,665 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Bernie Vermette - Grand Mamou.wav.wav
[2010/08/15 23:30:37 | 000,000,610 | ---- | M] () -- C:\Documents and Settings\Bonham\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/15 23:30:37 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/08/14 12:14:30 | 001,711,464 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\James Blunt- You Are Beaytiful.wav.wav
[2010/08/11 22:43:28 | 000,494,888 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/11 22:43:28 | 000,436,588 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/08/11 22:43:28 | 000,069,716 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/08/10 00:18:52 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/26 23:21:12 | 000,000,342 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\My eBay.url
[2010/07/21 11:03:39 | 000,045,787 | ---- | M] () -- C:\Documents and Settings\Bonham\My Documents\Proud to be Canadian.gif
[2010/07/21 00:04:20 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\You might be right.doc
[2010/07/17 23:07:03 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\IZArc.lnk
[2010/07/17 20:17:31 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Amazing Half Time Show.doc
[2010/07/17 18:29:18 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Any Video Converter.lnk
[2010/07/17 17:41:41 | 000,000,901 | ---- | M] () -- C:\Documents and Settings\Bonham\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/07/17 17:41:41 | 000,000,883 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Foxit Reader.lnk
[2010/07/11 09:09:23 | 000,000,694 | ---- | M] () -- C:\Documents and Settings\Bonham\Start Menu\Programs\Startup\speedfan.lnk
[2010/07/03 13:06:36 | 004,388,296 | ---- | M] (Foxit Software) -- C:\Documents and Settings\Bonham\Desktop\FoxitPDFEditor220.0205_enu_Setup.exe
[2010/07/02 01:01:31 | 000,112,128 | ---- | M] () -- C:\Documents and Settings\Bonham\Desktop\Folding July 1 2010.xls
[2010/06/27 01:09:05 | 000,004,484 | ---- | M] () -- C:\WINDOWS\System32\drivers\cpuidlep.sys
========== Files Created - No Company Name ========== [2010/09/11 15:33:55 | 000,162,182 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\topic,109580.0.html
[2010/09/11 15:04:35 | 000,000,907 | ---- | C] () -- C:\Documents and Settings\Bonham\Start Menu\Programs\Startup\
[email protected][2010/09/11 15:04:34 | 000,000,694 | ---- | C] () -- C:\Documents and Settings\Bonham\Start Menu\Programs\Startup\speedfan.lnk
[2010/09/11 15:01:21 | 000,001,790 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Intel(R) Desktop Utilities.lnk
[2010/09/11 14:54:43 | 012,713,957 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\IDU_3.1.1.012.zip
[2010/09/11 12:24:37 | 006,228,992 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\911 photos - Never Forget !.pps
[2010/09/09 09:05:29 | 000,070,734 | ---- | C] () -- C:\Program Files\Storage Drives.JPG
[2010/09/07 23:12:06 | 000,000,386 | ---- | C] () -- C:\WINDOWS\tasks\SmartDefrag.job
[2010/09/03 18:18:29 | 000,000,544 | ---- | C] () -- C:\Documents and Settings\Bonham\CFScript.txt
[2010/09/01 21:36:35 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/09/01 21:36:35 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/09/01 21:36:35 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/08/30 15:13:57 | 000,001,700 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/08/24 23:21:23 | 001,029,907 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\The Shopping Channel - Official Site.mht
[2010/08/24 09:28:02 | 000,016,603 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\Nesco.jpg
[2010/08/16 12:43:53 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[2010/08/16 12:43:42 | 000,478,665 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\Bernie Vermette - Grand Mamou.wav.wav
[2010/08/14 12:55:26 | 001,585,152 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\Invitation2.pps
[2010/08/14 12:27:50 | 001,711,464 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\James Blunt- You Are Beaytiful.wav.wav
[2010/07/21 11:06:04 | 000,045,787 | ---- | C] () -- C:\Documents and Settings\Bonham\My Documents\Proud to be Canadian.gif
[2010/07/21 00:04:19 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\You might be right.doc
[2010/07/17 20:35:06 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\Amazing Half Time Show.doc
[2010/07/16 23:04:48 | 000,019,724 | ---- | C] () -- C:\Program Files\FAHlog.txt
[2010/07/03 16:59:39 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/07/02 00:35:02 | 000,112,128 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\Folding July 1 2010.xls
[2010/06/27 01:09:05 | 000,004,484 | ---- | C] () -- C:\WINDOWS\System32\drivers\cpuidlep.sys
[2010/06/26 23:48:31 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Bonham\Desktop\SpeedFan.lnk
[2010/06/18 13:47:36 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2010/04/06 22:25:53 | 000,327,002 | ---- | C] () -- C:\Program Files\Jumble.jpg
[2010/04/01 19:49:14 | 000,768,191 | ---- | C] () -- C:\Program Files\scan0001.pdf
[2010/04/01 19:29:53 | 005,613,568 | ---- | C] () -- C:\Program Files\Doc1.doc
[2010/03/11 11:17:20 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2010/02/10 01:09:09 | 000,290,919 | ---- | C] () -- C:\WINDOWS\System32\pythoncom21.dll
[2010/02/10 01:09:09 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes21.dll
[2010/02/10 01:06:58 | 000,096,768 | ---- | C] () -- C:\WINDOWS\SlantAdj.dll
[2010/01/11 19:58:04 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\EEBAPI.dll
[2010/01/11 19:58:04 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\EEBDSCVR.dll
[2010/01/11 19:58:04 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\EBAPI.dll
[2010/01/11 19:19:51 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2010/01/08 13:10:43 | 000,005,212 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/11/26 14:03:47 | 000,000,221 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/08/03 01:21:54 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2009/08/03 01:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2009/08/03 01:21:52 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/12/16 16:46:54 | 000,049,244 | ---- | C] () -- C:\Program Files\autoruns.chm
[2008/03/16 23:51:57 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2008/02/19 19:15:05 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Bonham\Application Data\$_hpcst$.hpc
[2007/11/29 02:03:00 | 000,000,584 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/11/27 01:41:15 | 021,216,112 | ---- | C] () -- C:\Program Files\aaw2007.exe
[2007/11/21 17:41:08 | 000,550,690 | ---- | C] () -- C:\Program Files\sbstar11.exe
[2007/11/17 12:06:23 | 003,458,671 | ---- | C] () -- C:\Program Files\PCTuneUpSetup.exe
[2007/11/14 22:03:20 | 000,160,768 | ---- | C] () -- C:\WINDOWS\System32\midas11.dll
[2007/11/14 22:00:10 | 010,138,931 | ---- | C] () -- C:\Program Files\setupLE.exe
[2007/06/06 16:31:45 | 006,820,520 | ---- | C] () -- C:\Program Files\FirefoxGoogleToolbarSetup.exe
[2007/03/18 16:32:23 | 002,108,000 | ---- | C] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\rx_audio.Cache
[2007/03/15 21:59:33 | 001,529,264 | ---- | C] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\rx_image.Cache
[2007/03/11 22:52:47 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameD.txt
[2007/03/10 22:36:13 | 000,000,247 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2007/03/10 00:13:44 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/05 19:22:24 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2007/03/04 12:31:52 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2007/03/02 20:44:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/03/01 22:40:12 | 000,000,171 | ---- | C] () -- C:\WINDOWS\EPSON CX3200 Installer.ini
[2007/02/27 16:24:19 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Bonham\Local Settings\Application Data\fusioncache.dat
[2006/09/20 11:17:32 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\lpcio.dll
[2006/09/19 20:35:27 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/09/19 20:15:09 | 000,000,436 | R--- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/09/19 20:05:51 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll
[2006/07/28 08:32:44 | 000,007,005 | ---- | C] () -- C:\Program Files\Eula.txt
[2005/12/01 17:05:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/11/14 15:40:28 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/11/10 12:30:04 | 003,596,288 | R--- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/08/05 14:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/07/15 13:35:56 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/07/15 13:35:56 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2004/11/30 05:10:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\besched.dll
[2004/02/05 08:05:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\VDExt800.dll
[2003/10/02 02:00:00 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lockout.dll
[2003/10/02 02:00:00 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\lockres.dll
[2003/09/19 14:03:12 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\GDExt800.dll
[2003/09/04 17:49:42 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\VDExt712.dll
[2003/08/16 07:52:42 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\GDExt712.dll
[2003/07/30 07:19:24 | 000,006,397 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartCd.sys
[1999/01/22 13:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ========== [2010/02/10 00:40:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2008/02/23 11:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2007/03/04 12:01:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2008/06/05 10:06:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/02/28 00:20:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2007/12/23 12:28:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2010/03/29 19:19:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2008/07/12 09:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/03/12 11:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IM
[2008/03/12 11:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail
[2009/04/17 22:00:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2007/10/25 11:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/04/09 16:09:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/05/20 12:15:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Novatel Wireless
[2010/02/24 02:02:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/04/21 22:51:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/12/05 19:25:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlotSoft
[2007/03/16 00:46:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\River Past G5
[2008/01/21 18:01:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/04/24 00:29:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2010/08/09 22:54:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/16 01:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\USBSRService
[2007/12/29 14:26:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/03/27 23:01:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\AnvSoft
[2010/03/25 16:02:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Auslogics
[2008/02/23 11:01:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Babylon
[2007/04/01 16:24:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Backup MyPC
[2007/12/24 14:10:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\eBay
[2010/02/12 20:53:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\EPSON
[2006/09/19 20:04:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\FarStone
[2010/09/09 08:27:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Folding@home-x86
[2009/03/30 16:11:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Foxit
[2010/07/20 21:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Foxit Software
[2010/04/01 21:44:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\FreeMoviesToDVD
[2010/03/27 22:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\GetGo Software
[2009/02/07 00:59:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\GlarySoft
[2010/03/11 18:13:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Image Zone Express
[2010/06/03 23:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\IObit
[2007/04/01 16:25:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Leadertech
[2010/03/25 23:05:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\LockHunter
[2010/04/09 12:22:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\MxBoost
[2009/04/10 01:00:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\NCH Swift Sound
[2010/04/19 09:12:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\NesterSoft
[2009/02/13 21:14:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\NewspaperDirect
[2010/07/17 22:51:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\OpenCandy
[2010/02/10 19:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Opera
[2010/03/22 11:46:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\PC Magazine Utilities
[2010/02/28 20:13:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Printer Info Cache
[2007/03/15 23:58:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\River Past G5
[2007/04/09 16:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\SlipStream
[2009/04/17 21:59:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\SpinTop
[2010/04/11 16:44:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Thunderbird
[2010/04/24 00:27:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Toolbar4
[2010/02/15 22:21:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Uniblue
[2010/04/16 01:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\USBSafelyRemove
[2010/03/11 10:32:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\Video Converter for Any Flv Player
[2010/05/22 21:44:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\WhatPulse
[2010/06/05 00:36:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bonham\Application Data\WinPatrol
[2010/09/07 23:12:06 | 000,000,386 | ---- | M] () -- C:\WINDOWS\Tasks\SmartDefrag.job
[2010/08/22 20:06:01 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\switchShakeIcon.job
========== Purity Check ========== < End of report >