OTL logfile created on: 5/24/2010 5:52:59 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
702.00 Mb Total Physical Memory | 259.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 48.00% Paging File free
Paging file location(s): C:\pagefile.sys 1056 2112 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 3.76 Gb Free Space | 3.36% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 955.72 Mb Total Space | 230.06 Mb Free Space | 24.07% Space Free | Partition Type: FAT
Drive G: | 931.28 Gb Total Space | 297.09 Gb Free Space | 31.90% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: M-4D5D36C781724
Current User Name: M.O.B ENTERTAINMENT
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe (BitDefender S.R.L.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe (BitDefender S.R.L.)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender S.R.L.)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe (Systweak Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions )
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\plugin_extra.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\plugin_nt.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\plugin_net.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\plugin_fragments.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\plugin_registry.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\plugin_base.m32 (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\BitDefender\BitDefender 2010\Active Virus Control\midas32-v2_000\midas32.dll (BitDefender S.R.L. Bucharest, ROMANIA)
MOD - C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.dll (SourceTec Software Co., LTD)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (CaCCProvSP) -- File not found
SRV - (VSSERV) -- C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe (BitDefender S.R.L.)
SRV - (scan) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll (S.C. BitDefender S.R.L)
SRV - (ThreatFire) -- C:\Program Files\Spyware Doctor\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (Rx2Engine) -- C:\Program Files\Raxco\PerfectSpeed20\Rx2Engine.exe (Raxco Software, Inc.)
SRV - (Rx2Agent) -- C:\Program Files\Raxco\PerfectSpeed20\Rx2Agent.exe (Raxco Software, Inc.)
SRV - (sdCoreService) -- C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (LIVESRV) -- C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe (BitDefender S.R.L.)
SRV - (sdAuxService) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (getPlusHelper) getPlus® -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ASO3DiskOptimizer) -- C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe (Systweak Inc.)
SRV - (WebrootSpySweeperService) -- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (Arrakis3) -- C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender S.R.L.
http://www.bitdefender.com)SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (XobniService) -- C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ========== DRV - (Trufos) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys (BitDefender S.R.L.)
DRV - (Profos) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys (BitDefender S.R.L.)
DRV - (bdftdif) -- C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC)
DRV - (Bdfndisf) -- C:\WINDOWS\system32\drivers\bdfndisf.sys (BitDefender LLC)
DRV - (BDSelfPr) -- C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys (BitDefender)
DRV - (bdfsfltr) -- C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (pctplsg) -- C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (pctgntdi) -- C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (bdfm) -- C:\WINDOWS\system32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (TfSysMon) -- C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) -- C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) -- C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (BDVEDISK) -- C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys (BitDefender)
DRV - (AnyDVD) -- C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ssidrv) -- C:\WINDOWS\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd) -- C:\WINDOWS\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssfs0bbc) -- C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ElbyCDIO) -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (PCTCore) -- C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (DefragFS) -- C:\WINDOWS\system32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (ADASPROT) -- C:\Program Files\Advanced System Optimizer 3\adasprot32.sys ()
DRV - (nvgts) -- C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (EL90XBC) -- C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2E 72 97 57 D6 FA CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKCU\..\URLSearchHook: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "Ask"
FF - prefs.js..browser.startup.homepage: "http://www.ask.com?o=14196&l=dis"
FF - prefs.js..extensions.enabledItems: anttoolbar@ant.com:2.0
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.4.4.118
FF - prefs.js..extensions.enabledItems: {d5eeb813-935a-435d-b01e-b3a02f2cb408}:0.8.7.2
FF - prefs.js..extensions.enabledItems: FFToolbar@bitdefender.com:2.0
FF - prefs.js..extensions.enabledItems: capturefoxmovie@advancity.net:0.7.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}:6.0.19
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.45
FF - prefs.js..extensions.enabledItems: {d47a9f51-8281-43fa-f450-f28ef8735e9a}:2.0.2
FF - prefs.js..extensions.enabledItems: {62ED169D-7F2E-449a-A88D-F4E6F153051F}:1.52
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.4.3.s
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.9
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/12/15 21:41:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010/04/07 20:19:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\FFToolbar@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\ [2010/05/15 15:49:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/20 05:03:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/20 05:03:15 | 000,000,000 | ---D | M]
[2010/03/15 00:12:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Extensions
[2010/03/15 00:12:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2009/12/12 17:56:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/01/26 21:37:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/05/24 16:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions
[2009/12/16 05:33:01 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/14 23:37:50 | 000,000,000 | ---D | M] (Screenshot Pimp) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\{62ED169D-7F2E-449a-A88D-F4E6F153051F}
[2010/02/03 23:56:01 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/02/03 23:56:02 | 000,000,000 | ---D | M] (Pixlr Grabber) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2009/12/14 23:37:50 | 000,000,000 | ---D | M] (Aviary) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\{d5eeb813-935a-435d-b01e-b3a02f2cb408}
[2009/12/20 21:01:39 | 000,000,000 | ---D | M] (Sothink Web Video Downloader for Firefox) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
[2010/02/01 01:41:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\anttoolbar@ant.com
[2009/12/14 23:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\capturefoxmovie@advancity.net
[2010/02/01 01:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\SkipScreen@SkipScreen
[2009/12/14 20:56:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\extensions\toolbar@ask.com
[2010/01/10 23:32:33 | 000,001,747 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\searchplugins\ask.uk.xml
[2009/12/14 23:38:27 | 000,002,391 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Mozilla\Firefox\Profiles\lr1iu0lo.default\searchplugins\aviary.xml
[2010/05/24 16:52:30 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/20 05:03:14 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/05/19 19:05:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/04/07 20:19:44 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
[2010/05/20 05:03:09 | 000,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/05/20 05:03:09 | 000,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/04/07 20:19:23 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2010/02/20 16:44:11 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/05/20 05:03:10 | 000,064,984 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2010/04/07 03:54:46 | 000,140,864 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/12/13 01:11:22 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2010/04/07 03:55:21 | 000,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
[2010/04/07 03:54:36 | 000,098,304 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
[2009/11/02 18:16:17 | 000,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2009/11/02 18:16:17 | 000,002,193 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/03/25 16:55:34 | 000,002,191 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2009/11/02 18:16:17 | 000,001,534 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2009/11/02 18:16:17 | 000,002,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2009/11/02 18:16:17 | 000,002,371 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009/11/02 18:16:17 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2009/11/02 18:16:17 | 000,000,792 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2010/05/15 15:32:58 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (TBSB00982 Class) - {DA3D342F-FF20-4E31-9E82-22334155730C} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (BitDefender Toolbar) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ant.com Toolbar) - {6CD56C02-CB4D-41B5-A0FE-B479061CCB41} - C:\Program Files\Antbar\Ant.com Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [FreeRAM XP] C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe (YourWare Solutions )
O4 - HKCU..\Run: [Pando] C:\Program Files\Pando Networks\Pando\pando.exe (Pando Networks)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Web Video Downloader] C:\Program Files\SourceTec\Sothink Web Video Downloader Stand-alone\VideoDownloader.exe (SourceTec Software Co., LTD)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BackupNoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Translate this web page with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Translate with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/...b?1260329231812 (WUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A}
http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 65.32.5.111 65.32.5.112
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/08 19:12:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (sasnative32) - C:\WINDOWS\System32\sasnative32.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/12/08 19:12:16 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (81641353997451264)
========== Files/Folders - Created Within 30 Days ========== [2010/05/24 17:40:19 | 000,571,904 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\OTL.exe
[2010/05/20 18:28:10 | 000,000,000 | ---D | C] -- C:\!KillBox
[2010/05/20 18:25:40 | 000,000,000 | ---D | C] -- C:\Program Files\CleanUp!
[2010/05/20 05:02:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Identities
[2010/05/17 21:14:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/05/16 01:23:44 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Recent
[2010/05/15 22:39:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\bd102047
[2010/05/15 15:49:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\BitDefender
[2010/05/15 15:48:37 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender
[2010/05/15 15:48:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2010/05/15 15:46:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP
[2010/05/15 15:44:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender
[2010/05/15 15:34:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Webroot
[2010/05/14 18:21:48 | 000,000,000 | ---D | C] -- C:\Program Files\MSSOAP
[2010/05/14 18:21:04 | 000,000,000 | ---D | C] -- C:\Program Files\Webroot
[2010/05/14 03:16:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Filseclab
[2010/05/14 02:48:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\ESET Smart Security Business Edition 4.2.35 Retail (32-Bit)
[2010/05/12 22:08:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/12 21:38:25 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/05/12 20:51:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\STOPzilla!
[2010/05/12 19:48:51 | 000,000,000 | ---D | C] -- C:\Program Files\STOPzilla!
[2010/05/12 17:48:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/10 20:27:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\Norton.Removal.Tool.2010.0.0.92
[2010/05/10 20:17:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\McAfee Total Protection 2010 FULL
[2010/05/08 22:22:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\Driver_Genius_Pro_9.0.0.186
[2010/05/07 18:41:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/05/07 18:39:43 | 000,000,000 | ---D | C] -- C:\Program Files\Research In Motion
[2010/05/07 17:27:23 | 000,032,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys
[2010/05/07 17:20:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Research In Motion
[2010/05/07 17:19:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Research In Motion
[2010/05/07 09:46:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\eset
[2010/05/06 20:38:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\ESET Smart Security Business Edition 4.2.35 Retail (32-Bit)
[2010/05/03 20:12:12 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2010/05/03 19:58:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\Ideees.Com-Eset
[2010/05/03 00:53:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\other pics
[2010/05/02 20:11:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\SKFsoft.Lotto.Creo.Professional.v5.0.0.3.www.sharestation.com
[2010/04/29 16:42:18 | 000,014,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[2010/04/29 16:42:14 | 000,012,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mouhid.sys
[2010/04/29 16:42:10 | 000,010,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidusb.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/05/24 18:33:18 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/24 17:40:21 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\OTL.exe
[2010/05/24 17:28:29 | 106,784,675 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\AVG.AV.Pro.9.0.800.2779_ITkraze_www.xatz.ws.rar
[2010/05/24 16:41:32 | 000,000,406 | ---- | M] () -- C:\WINDOWS\tasks\Registry Reviver-M.O.B ENTERTAINMENT-Startup.job
[2010/05/24 16:41:19 | 000,000,376 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Dataprivacy.xml
[2010/05/24 16:40:48 | 000,272,291 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/05/24 16:40:12 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/24 16:40:12 | 000,000,306 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-583907252-1383384898-1801674531-1003.job
[2010/05/24 16:40:04 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/05/24 16:39:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/05/22 18:07:22 | 000,000,052 | ---- | M] () -- C:\WINDOWS\System32\ashttpstats.csv
[2010/05/22 18:07:20 | 006,467,584 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\ntuser.dat
[2010/05/22 17:47:49 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/05/20 19:54:42 | 000,163,840 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/20 18:57:42 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\ntuser.ini
[2010/05/19 22:12:43 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/05/19 04:00:05 | 000,000,314 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-583907252-1383384898-1801674531-1003.job
[2010/05/18 17:09:14 | 002,153,014 | -H-- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Local Settings\Application Data\IconCache.db
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\wsbl.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\phar_unmip.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\phar_histprot.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\ph_white.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\ph_summ.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\ph_spoof.sig
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\ph_sign.slf
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\ph_fuzzy.sig
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\ph_black.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pcwords2.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pcwords.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_webproxy.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_video.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_tabloids.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_sign.slf
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_searchengines.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_pornography.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_onlineshop.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_onlinepay.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_onlinedating.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_news.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_im.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_illegal.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_hate.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_games.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_gambling.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\pc_drugs.dat
[2010/05/16 08:43:13 | 000,000,025 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\bdfvconp.ini
[2010/05/16 06:10:28 | 000,000,016 | ---- | M] () -- C:\WINDOWS\System32\asdict.dat
[2010/05/16 06:10:28 | 000,000,004 | ---- | M] () -- C:\WINDOWS\System32\aspdict-en.dat
[2010/05/16 02:31:27 | 000,001,041 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\vso_ts_preview.xml
[2010/05/15 23:40:36 | 001,992,112 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\videoooooo667.3GP
[2010/05/15 21:51:53 | 000,000,850 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application DataProductTweaks.xml
[2010/05/15 21:51:53 | 000,000,385 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Datauser_gensett.xml
[2010/05/15 21:42:21 | 000,119,505 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\bitdefender log.xml
[2010/05/15 16:28:39 | 000,111,312 | ---- | M] (BitDefender LLC) -- C:\WINDOWS\System32\drivers\bdfndisf.sys
[2010/05/15 15:57:46 | 000,000,385 | ---- | M] () -- C:\WINDOWS\System32\user_gensett.xml
[2010/05/15 15:49:45 | 000,001,869 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BitDefender Total Security 2010.lnk
[2010/05/15 15:46:47 | 000,509,574 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/15 15:46:47 | 000,440,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/05/15 15:46:47 | 000,071,002 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/05/15 15:32:58 | 000,000,734 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/05/14 19:16:31 | 000,305,311 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273928736gucci_chain.jpg
[2010/05/14 19:05:44 | 000,124,027 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\drake at 17.jpg
[2010/05/14 18:22:41 | 000,000,672 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/05/14 18:16:55 | 000,000,164 | ---- | M] () -- C:\WINDOWS\install.dat
[2010/05/14 17:53:29 | 124,525,980 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\aV906631703Wseri.rar
[2010/05/12 21:38:27 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\HijackThis.lnk
[2010/05/12 15:54:52 | 000,082,492 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\image001.jpg
[2010/05/12 15:54:52 | 000,080,121 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\image002.jpg
[2010/05/11 21:32:43 | 000,036,041 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\easter basket in head.2.jpg
[2010/05/11 21:32:43 | 000,029,375 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\easter basket in head.jpg
[2010/05/10 22:25:00 | 000,033,192 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\WhenWill
[2010/05/10 22:24:56 | 000,036,021 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\ggg
[2010/05/10 01:59:02 | 000,422,967 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\pando list of movies.zip
[2010/05/10 01:27:46 | 000,549,963 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\attachments_2010_05_10.zip
[2010/05/10 01:03:15 | 000,044,144 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\securedownloadCACKOVLL.jpg
[2010/05/10 01:03:15 | 000,037,192 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\securedownloadCAPVG21D.jpg
[2010/05/10 01:03:15 | 000,028,297 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\securedownloadCA6IEZHK.jpg
[2010/05/09 19:09:14 | 000,380,742 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\843712257.jpeg
[2010/05/09 19:09:11 | 000,281,303 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\539512490.jpg
[2010/05/09 19:09:09 | 000,412,329 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1933387564.jpg
[2010/05/09 19:09:08 | 000,079,984 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1987076236.jpg
[2010/05/09 19:09:08 | 000,070,005 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1838458604.jpg
[2010/05/09 19:09:07 | 000,118,817 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\610868032.jpg
[2010/05/09 19:09:07 | 000,113,147 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\649539335.jpg
[2010/05/09 19:09:07 | 000,105,937 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1482642828.jpg
[2010/05/09 19:09:05 | 000,068,935 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1963400713.jpg
[2010/05/09 18:45:36 | 000,155,007 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273492993ashanti_body_amaxzing2.jpg
[2010/05/09 18:39:22 | 000,145,377 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\50 inch.jpg
[2010/05/09 18:37:19 | 000,236,295 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273493094nail_ghetto.jpg
[2010/05/09 01:00:02 | 000,163,364 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273237489teairra_bikini1.jpg
[2010/05/09 00:51:35 | 000,274,980 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273237930j_lo_body.jpg
[2010/05/08 23:25:33 | 000,267,967 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410784ghetto_rope.jpg
[2010/05/08 23:25:22 | 000,162,289 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410809eve_thong3.jpg
[2010/05/08 23:25:21 | 000,153,708 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410808eve_thong2.jpg
[2010/05/08 23:25:21 | 000,153,708 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410808eve_thong1.jpg
[2010/05/07 23:58:04 | 000,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2010/05/07 22:36:38 | 000,016,344 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\cincinnatibengals.gif
[2010/05/07 18:46:19 | 002,802,330 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\LoaderBackup-(2010-05-07).ipd
[2010/05/07 18:41:15 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/05/07 18:26:53 | 022,475,264 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\BlackBerry Device Manager_ITA (DM5.0.1b73).msi
[2010/05/06 23:21:15 | 004,109,887 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\Jadakiss - The People (feat. Styles P) - HotNewHipHop.com.mp3
[2010/05/06 00:28:36 | 000,008,000 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\PART_1273205294069.jpeg
[2010/05/05 18:36:44 | 000,013,507 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\MemTest.zip
[2010/05/05 18:17:02 | 000,225,672 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\CrucialScan.exe
[2010/05/05 17:46:10 | 000,000,745 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\Shortcut to iexplore.lnk
[2010/05/03 20:12:18 | 000,000,685 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\IrfanView.lnk
[2010/05/03 18:27:34 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2010/05/02 20:14:13 | 000,000,002 | -H-- | M] () -- C:\time32.sys
[2010/05/02 20:14:10 | 000,000,442 | -H-- | M] () -- C:\date.sys
[2010/05/02 19:34:06 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/05/02 17:57:17 | 000,014,072 | ---- | M] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\cc_20100502_175706.reg
[2010/05/02 17:39:26 | 000,000,299 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
[2010/05/02 17:39:26 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/01/11 23:02:46 | 003,238,659 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\bb storm.jpg
[2011/01/11 22:52:58 | 003,212,397 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\blackberry storm.jpg
[2010/05/24 17:27:51 | 106,784,675 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\AVG.AV.Pro.9.0.800.2779_ITkraze_www.xatz.ws.rar
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\wsbl.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\phar_unmip.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\phar_histprot.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ph_white.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ph_summ.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ph_spoof.sig
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ph_sign.slf
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ph_fuzzy.sig
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ph_black.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pcwords2.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pcwords.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_webproxy.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_video.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_tabloids.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_socialnetworks.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_sign.slf
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_searchengines.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_regionaltlds.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_pornography.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_onlineshop.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_onlinepay.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_onlinedating.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_news.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_im.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_illegal.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_hate.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_games.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_gambling.dat
[2010/05/16 13:30:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\pc_drugs.dat
[2010/05/16 08:43:13 | 000,000,025 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\bdfvconp.ini
[2010/05/16 06:10:28 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\asdict.dat
[2010/05/16 06:10:28 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\aspdict-en.dat
[2010/05/15 23:40:56 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/05/15 23:40:18 | 001,992,112 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\videoooooo667.3GP
[2010/05/15 21:51:53 | 000,000,850 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application DataProductTweaks.xml
[2010/05/15 21:51:53 | 000,000,385 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Datauser_gensett.xml
[2010/05/15 21:51:45 | 000,000,376 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Dataprivacy.xml
[2010/05/15 21:48:55 | 000,000,052 | ---- | C] () -- C:\WINDOWS\System32\ashttpstats.csv
[2010/05/15 21:42:21 | 000,119,505 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\bitdefender log.xml
[2010/05/15 15:57:46 | 000,000,385 | ---- | C] () -- C:\WINDOWS\System32\user_gensett.xml
[2010/05/15 15:49:45 | 000,001,869 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\BitDefender Total Security 2010.lnk
[2010/05/15 15:49:24 | 000,110,592 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\chrtmp
[2010/05/14 19:19:07 | 000,305,311 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273928736gucci_chain.jpg
[2010/05/14 19:13:12 | 000,124,027 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\drake at 17.jpg
[2010/05/14 17:53:27 | 124,525,980 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\aV906631703Wseri.rar
[2010/05/14 17:43:19 | 000,000,164 | ---- | C] () -- C:\WINDOWS\install.dat
[2010/05/12 21:42:53 | 000,082,492 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\image001.jpg
[2010/05/12 21:42:53 | 000,080,121 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\image002.jpg
[2010/05/12 21:38:27 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\HijackThis.lnk
[2010/05/11 21:33:33 | 000,036,041 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\easter basket in head.2.jpg
[2010/05/11 21:33:23 | 000,029,375 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\easter basket in head.jpg
[2010/05/11 03:21:26 | 006,467,584 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\ntuser.dat
[2010/05/10 19:53:39 | 111,280,128 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\McAfee Total Protection 2009.iso
[2010/05/10 01:59:02 | 000,422,967 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\pando list of movies.zip
[2010/05/10 01:32:33 | 000,036,021 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\ggg
[2010/05/10 01:32:24 | 000,033,192 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\WhenWill
[2010/05/10 01:27:46 | 000,549,963 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\attachments_2010_05_10.zip
[2010/05/10 01:05:25 | 000,044,144 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\securedownloadCACKOVLL.jpg
[2010/05/10 01:04:39 | 000,037,192 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\securedownloadCAPVG21D.jpg
[2010/05/10 01:04:33 | 000,028,297 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\securedownloadCA6IEZHK.jpg
[2010/05/09 19:16:03 | 000,113,147 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\649539335.jpg
[2010/05/09 19:15:51 | 000,070,005 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1838458604.jpg
[2010/05/09 19:15:11 | 000,105,937 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1482642828.jpg
[2010/05/09 19:15:00 | 000,118,817 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\610868032.jpg
[2010/05/09 19:14:49 | 000,281,303 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\539512490.jpg
[2010/05/09 19:14:43 | 000,412,329 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1933387564.jpg
[2010/05/09 19:14:17 | 000,068,935 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1963400713.jpg
[2010/05/09 19:14:00 | 000,079,984 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1987076236.jpg
[2010/05/09 19:13:39 | 000,380,742 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\843712257.jpeg
[2010/05/09 18:46:24 | 000,155,007 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273492993ashanti_body_amaxzing2.jpg
[2010/05/09 18:40:14 | 000,145,377 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\50 inch.jpg
[2010/05/09 18:38:49 | 000,236,295 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273493094nail_ghetto.jpg
[2010/05/09 01:04:14 | 000,163,364 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273237489teairra_bikini1.jpg
[2010/05/09 00:57:03 | 000,274,980 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273237930j_lo_body.jpg
[2010/05/08 23:34:09 | 000,267,967 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410784ghetto_rope.jpg
[2010/05/08 23:27:37 | 000,162,289 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410809eve_thong3.jpg
[2010/05/08 23:27:24 | 000,153,708 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410808eve_thong2.jpg
[2010/05/08 23:27:16 | 000,153,708 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\1273410808eve_thong1.jpg
[2010/05/07 22:36:52 | 000,016,344 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\cincinnatibengals.gif
[2010/05/07 18:46:19 | 002,802,330 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\LoaderBackup-(2010-05-07).ipd
[2010/05/07 18:41:15 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Desktop Manager.lnk
[2010/05/07 18:26:52 | 022,475,264 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\BlackBerry Device Manager_ITA (DM5.0.1b73).msi
[2010/05/07 17:20:39 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2010/05/06 23:21:15 | 004,109,887 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\Jadakiss - The People (feat. Styles P) - HotNewHipHop.com.mp3
[2010/05/06 00:28:36 | 000,008,000 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\PART_1273205294069.jpeg
[2010/05/05 18:36:43 | 000,013,507 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\MemTest.zip
[2010/05/05 18:17:01 | 000,225,672 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\CrucialScan.exe
[2010/05/05 17:46:10 | 000,000,745 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Desktop\Shortcut to iexplore.lnk
[2010/05/03 20:12:18 | 000,000,685 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\IrfanView.lnk
[2010/05/02 17:57:12 | 000,014,072 | ---- | C] () -- C:\Documents and Settings\M.O.B ENTERTAINMENT\My Documents\cc_20100502_175706.reg
[2010/03/08 05:54:30 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI
[2010/03/06 01:44:53 | 000,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2010/03/06 01:36:52 | 000,002,261 | ---- | C] () -- C:\WINDOWS\LottoBuster.ini
[2010/02/20 05:10:12 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/02/20 05:09:54 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/02/20 05:09:53 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/02/20 05:09:51 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/02/17 20:23:12 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
[2010/02/14 18:28:58 | 000,000,009 | ---- | C] () -- C:\WINDOWS\lc.ini
[2010/01/29 12:28:04 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\uuddc32.dll
[2009/12/20 20:20:17 | 000,000,063 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/12/19 21:42:17 | 000,074,703 | ---- | C] () -- C:\WINDOWS\System32\mfc45.dll
[2009/11/20 21:32:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\nvmccs.dll
[2009/03/10 23:18:00 | 000,190,976 | ---- | C] () -- C:\WINDOWS\System32\WgaLogon.dll
[2009/02/06 13:35:56 | 001,481,728 | ---- | C] () -- C:\WINDOWS\System32\LegitCheckControl.dll
[2009/01/15 13:45:34 | 000,181,248 | ---- | C] () -- C:\WINDOWS\System32\txmlutil.dll
[2007/08/07 05:52:14 | 000,443,104 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2007/01/31 14:50:32 | 000,913,408 | ---- | C] () -- C:\WINDOWS\System32\xreglib.dll
[2006/06/29 18:19:26 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\id3vx_ocx.dll
[2005/01/20 22:12:08 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
========== LOP Check ========== [2009/12/18 15:21:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avanquest
[2010/03/25 18:56:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2010/05/15 15:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender
[2009/12/19 21:37:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2010/02/09 21:00:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easy Flyer Creator
[2009/12/19 21:42:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iolo
[2010/05/07 18:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/03/28 19:40:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2009/12/23 02:34:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/12/27 00:17:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Systweak
[2009/12/15 00:21:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/05/24 17:51:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/23 04:02:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/12/18 15:22:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Avanquest
[2010/03/25 19:13:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Babylon
[2010/05/15 15:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\BitDefender
[2010/01/02 04:12:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\BitTorrent
[2010/04/09 15:46:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Data Solutions
[2010/03/14 23:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\ESET
[2010/03/28 17:37:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Facebook
[2010/03/15 00:11:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Flock
[2010/02/20 16:44:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Foxit
[2010/05/07 00:05:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\FrostWire
[2009/12/10 21:51:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\GetRightToGo
[2009/12/19 21:42:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\iolo
[2010/03/21 21:58:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Kutchka
[2009/12/20 20:42:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Leadertech
[2010/03/14 19:54:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\LimeWire
[2009/12/08 19:56:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Opera
[2010/05/07 17:20:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Research In Motion
[2010/05/20 17:39:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\SlimBrowser
[2010/05/12 20:51:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\STOPzilla!
[2009/12/26 20:02:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Systweak
[2010/03/05 14:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Thinstall
[2010/05/16 02:31:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\M.O.B ENTERTAINMENT\Application Data\Vso
[2010/05/24 16:41:32 | 000,000,406 | ---- | M] () -- C:\WINDOWS\Tasks\Registry Reviver-M.O.B ENTERTAINMENT-Startup.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2009/12/08 19:12:45 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/05/17 18:04:31 | 000,105,978 | ---- | M] () -- C:\bdlog.txt
[2010/05/02 17:39:26 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2009/12/10 20:55:57 | 000,037,425 | ---- | M] () -- C:\caavsetupLog.txt
[2010/05/15 14:56:05 | 001,264,651 | ---- | M] () -- C:\caisslog.txt
[2009/12/26 04:47:57 | 000,000,412 | ---- | M] () -- C:\CD3rdPartyWrapper.log
[2009/12/08 19:12:45 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/05/02 20:14:10 | 000,000,442 | -H-- | M] () -- C:\date.sys
[2009/12/14 03:18:22 | 000,001,515 | ---- | M] () -- C:\ErrLog.txt
[2009/12/08 19:12:45 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/05/20 18:50:41 | 000,000,813 | ---- | M] () -- C:\log.txt
[2010/05/20 18:50:52 | 000,000,813 | ---- | M] () -- C:\log1.txt
[2010/05/23 19:01:14 | 000,001,684 | ---- | M] () -- C:\michelle cd list.txt
[2009/12/08 19:12:45 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/04/13 10:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 12:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/05/24 16:39:56 | 1107,296,256 | -HS- | M] () -- C:\pagefile.sys
[2009/12/02 14:07:18 | 000,341,504 | -H-- | M] (Media Cope) -- C:\Speak Text.exe
[2010/05/20 18:48:44 | 000,000,000 | ---- | M] () -- C:\start.txt
[2010/05/02 20:14:13 | 000,000,002 | -H-- | M] () -- C:\time32.sys
[2008/11/10 10:50:14 | 000,708,608 | -H-- | M] (NEEMedia) -- C:\USkin.dll
[2009/11/04 19:20:32 | 000,083,456 | -H-- | M] (Media Cope) -- C:\wifv.exe
[2010/05/20 18:48:44 | 000,000,318 | ---- | M] () -- C:\win.txt
[2010/05/20 18:48:45 | 000,000,000 | ---- | M] () -- C:\windows.txt
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2009/03/08 05:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 05:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2009/12/21 12:14:03 | 000,184,320 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\iepeers.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\System32\config\*.sav >[2009/12/07 12:38:00 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/12/07 12:38:00 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/12/07 12:37:59 | 000,913,408 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >[2010/05/15 16:28:39 | 000,111,312 | ---- | M] (BitDefender LLC) -- C:\WINDOWS\system32\drivers\bdfndisf.sys
========== Alternate Data Streams ========== @Alternate Data Stream - 199 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C265C458
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1F8C9007
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >