Hello all-thanks in advance for your help.
Over the last two or three days, I've had an issue while clicking on links found in google searches I run in Firefox. I get randomly redirected to other search engines or Yahoo Hot jobs. If I go back to the google search results and re-click the link for the page I wanted to view, it ususally goes to the proper page.
I've run all the programs on the before you post page and still have this issue.
Here are the logs:
Malwarebytes' Anti-Malware 1.41
Database version: 2939
Windows 5.1.2600 Service Pack 3
10/10/2009 9:18:32 PM
mbam-log-2009-10-10 (21-18-32).txt
Scan type: Quick Scan
Objects scanned: 120572
Time elapsed: 6 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\SoftwareRevenue.org (Adware.ActiveSearch) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\SoftwareRevenue.org\Activeshopper_trim.bmp (Adware.ActiveSearch) -> Quarantined and deleted successfully.
C:\Program Files\SoftwareRevenue.org\googlepage.bmp (Adware.ActiveSearch) -> Quarantined and deleted successfully.
Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 6 Model 14 Stepping 8, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Disabled !
.
Internet Explorer 6.0.2900.5512
Mozilla Firefox 3.5.3 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:92 Go - Free:17 Go )
D:\ [CD_Rom]
.
Scan : 11:54.51
Path : C:\Documents and Settings\Randall J Blash\Desktop\Rooter.exe
User : Randall J Blash ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (592)
______ \??\C:\WINDOWS\system32\csrss.exe (648)
______ \??\C:\WINDOWS\system32\winlogon.exe (672)
______ C:\WINDOWS\system32\services.exe (716)
______ C:\WINDOWS\system32\lsass.exe (728)
______ C:\WINDOWS\system32\svchost.exe (916)
______ C:\WINDOWS\system32\svchost.exe (988)
______ C:\WINDOWS\System32\svchost.exe (1064)
______ C:\WINDOWS\system32\svchost.exe (1096)
______ C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (1204)
______ C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (1240)
______ C:\WINDOWS\system32\svchost.exe (1368)
______ C:\WINDOWS\system32\svchost.exe (1400)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (1616)
______ C:\WINDOWS\system32\LEXBCES.EXE (1720)
______ C:\WINDOWS\system32\spoolsv.exe (1792)
______ C:\WINDOWS\system32\LEXPPS.EXE (1796)
______ C:\WINDOWS\system32\svchost.exe (1964)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (2000)
______ C:\Program Files\Bonjour\mDNSResponder.exe (2012)
______ C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (2044)
______ C:\WINDOWS\system32\DVDRAMSV.exe (180)
______ C:\WINDOWS\eHome\ehRecvr.exe (440)
______ C:\WINDOWS\eHome\ehSched.exe (452)
______ C:\WINDOWS\System32\svchost.exe (640)
______ C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (952)
______ C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (1644)
______ c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (396)
______ c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (1636)
______ C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (2092)
______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2440)
______ C:\Program Files\McAfee\MPF\MPFSrv.exe (2724)
______ C:\WINDOWS\Explorer.EXE (2740)
______ C:\Program Files\McAfee\MSK\MskSrver.exe (2784)
______ C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (2920)
______ c:\PROGRA~1\mcafee.com\agent\mcagent.exe (3008)
______ C:\WINDOWS\System32\snmp.exe (3056)
______ C:\WINDOWS\system32\svchost.exe (3116)
______ C:\WINDOWS\system32\svchost.exe (3276)
______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (3424)
______ C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (3468)
______ C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (3484)
______ C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (3500)
______ C:\Program Files\Brother\ControlCenter2\brctrcen.exe (3516)
______ C:\WINDOWS\system32\igfxtray.exe (3524)
______ C:\WINDOWS\system32\hkcmd.exe (3532)
______ C:\WINDOWS\system32\igfxpers.exe (3540)
______ C:\Program Files\Toshiba\Tvs\TvsTray.exe (3548)
______ C:\WINDOWS\system32\TPSMain.exe (3556)
______ C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe (3564)
______ C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe (3592)
______ C:\WINDOWS\system32\TDispVol.exe (3624)
______ C:\WINDOWS\RTHDCPL.EXE (3632)
______ C:\Program Files\Java\jre6\bin\jusched.exe (3672)
______ C:\Program Files\iTunes\iTunesHelper.exe (3728)
______ C:\WINDOWS\system32\ctfmon.exe (3764)
______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (3780)
______ C:\Program Files\Windows Media Player\WMPNSCFG.exe (3824)
______ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (3832)
______ C:\Program Files\FacetCorp\FacetWin\fwagent.exe (3868)
______ C:\WINDOWS\system32\RAMASST.exe (3880)
______ C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe (3896)
______ C:\Program Files\Synaptics\SynTP\Toshiba.exe (4084)
______ C:\WINDOWS\system32\igfxsrvc.exe (516)
______ C:\WINDOWS\system32\TPSBattM.exe (2072)
______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (2640)
______ C:\Program Files\Windows Media Player\WMPNetwk.exe (1040)
______ C:\WINDOWS\ehome\mcrdsvc.exe (3368)
______ C:\WINDOWS\system32\dllhost.exe (884)
______ C:\WINDOWS\system32\wbem\unsecapp.exe (204)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (2252)
______ C:\Program Files\iPod\bin\iPodService.exe (2224)
______ C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe (3096)
______ C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (4664)
______ C:\WINDOWS\System32\alg.exe (4128)
______ C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (6056)
______ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (4560)
______ C:\WINDOWS\system32\wuauclt.exe (6012)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2264)
______ C:\Documents and Settings\Randall J Blash\Desktop\Rooter.exe (2336)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:99764388864)
\Device\Harddisk0\Partition2 (Start_Offset:99764421120 | Length:263208960)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\McDefragTask.job
C:\WINDOWS\Tasks\McQcTask.job
C:\WINDOWS\Tasks\SA.DAT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 11:54.59
.
C:\Rooter$\Rooter_2.txt - (11/10/2009 | 11:54.59)
CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\randall j blash\desktop\itunes.backup\itunes music\compilations\hard to earn\10 words from the nutcracker.m4a
c:\documents and settings\randall j blash\desktop\itunes.backup\itunes music\stone temple pilots\core\11 crackerman.m4a
c:\documents and settings\randall j blash\my documents\iphone stuff\cameraflash-v1.2-cracked.ipa
c:\documents and settings\randall j blash\my documents\iphone stuff\eucalyptus-v1.2.cracked.corepda.ipa
c:\documents and settings\randall j blash\my documents\itunes\itunes music\compilations\hard to earn\10 words from the nutcracker.m4a
c:\documents and settings\randall j blash\my documents\itunes\itunes music\stone temple pilots\core\11 crackerman.m4a
c:\documents and settings\randall j blash\my documents\my music\itunes\itunes music\compilations\hard to earn\10 words from the nutcracker.m4a
c:\documents and settings\randall j blash\my documents\my music\itunes\itunes music\stone temple pilots\core\11 crackerman.m4a
c:\documents and settings\randall j blash\my documents\my music\itunes\mobile applications\cameraflash-v1.2-cracked.ipa
c:\documents and settings\randall j blash\my documents\my music\itunes\mobile applications\eucalyptus-v1.2.cracked.corepda.ipa
c:\program files\toshiba games\bejeweled 2 deluxe\sounds\firecrackle.ogg
c:\program files\toshiba games\mah jong quest\images\tile_firecracker-1.pnge
c:\program files\toshiba games\mah jong quest\images\tile_firecracker-2.pnge
c:\program files\toshiba games\mah jong quest\images\tile_firecracker-3.pnge
c:\program files\toshiba games\mah jong quest\images\tile_firecracker1.pnge
c:\program files\toshiba games\mah jong quest\images\kwazi3\level5-1cracktop.jpge
c:\program files\toshiba games\mah jong quest\images\kwazi5\5_lvl_5a_postcrack1.jpge
c:\program files\toshiba games\mah jong quest\images\kwazi5\5_lvl_5a_postcrack2.jpge
scanner sequence 3.ZZ.11
----- EOF -----
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/11 11:56
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA827D000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7993000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA66CA000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "Lbd.sys" at address 0xf766787e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "Lbd.sys" at address 0xf7667bfe
==EOF==
OTL logfile created on: 10/11/2009 12:04:54 PM - Run 3
OTL by OldTimer - Version 3.0.19.0 Folder = C:\Documents and Settings\Randall J Blash\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 3073 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 92.91 Gb Total Space | 17.18 Gb Free Space | 18.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RANDALL
Current User Name: Randall J Blash
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/10/11 11:35:01 | 00,520,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Randall J Blash\Desktop\OTL.exe
PRC - [2009/10/09 00:18:57 | 01,028,432 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/10/09 00:18:57 | 00,520,024 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/09/13 16:32:04 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/09/08 21:09:42 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/08/13 22:06:25 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/03/25 17:25:20 | 00,797,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2009/03/25 17:25:20 | 00,645,328 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/03/25 11:05:48 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2009/03/24 00:03:18 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/03/19 11:42:02 | 00,884,360 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/02/11 11:06:36 | 00,210,216 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/02/06 06:10:02 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\wmiprvse.exe
PRC - [2009/01/09 11:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/01/09 09:22:10 | 00,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\MskSrver.exe
PRC - [2009/01/09 08:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/04/13 20:12:36 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008/02/19 11:01:46 | 00,278,528 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe
PRC - [2007/12/19 12:08:12 | 00,159,744 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe
PRC - [2007/12/19 12:08:08 | 00,135,168 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxtray.exe
PRC - [2007/12/19 12:07:42 | 00,131,072 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxpers.exe
PRC - [2007/12/19 12:07:30 | 00,249,856 | R--- | M] (Intel Corporation) -- C:\WINDOWS\System32\igfxsrvc.exe
PRC - [2007/07/11 23:27:44 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/01/04 17:38:18 | 00,112,336 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
PRC - [2007/01/04 17:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2006/10/18 22:05:26 | 00,204,288 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNSCFG.exe
PRC - [2006/10/18 22:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe
PRC - [2006/10/09 17:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2006/05/05 07:59:16 | 16,206,848 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.EXE
PRC - [2006/01/05 18:02:24 | 00,352,256 | ---- | M] (TOSHIBA) -- C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
PRC - [2005/12/16 04:32:58 | 00,761,945 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/12/16 04:21:00 | 00,151,552 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\Toshiba.exe
PRC - [2005/12/05 16:37:40 | 00,667,718 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
PRC - [2005/11/30 16:25:22 | 00,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Tvs\TvsTray.exe
PRC - [2005/11/28 15:41:50 | 00,602,182 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
PRC - [2005/11/28 15:37:52 | 00,397,381 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2005/11/28 15:31:32 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2005/11/28 15:29:00 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2005/11/28 15:28:14 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2005/11/11 18:30:22 | 00,995,328 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\ControlCenter2\brctrcen.exe
PRC - [2005/08/16 15:23:12 | 00,188,416 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
PRC - [2005/08/05 17:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe
PRC - [2005/08/05 17:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2005/06/01 01:00:12 | 00,282,624 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\System32\TPSMain.exe
PRC - [2005/06/01 00:59:58 | 00,045,056 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\System32\TPSBattM.exe
PRC - [2005/03/17 14:25:54 | 00,057,393 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
PRC - [2005/03/11 19:03:16 | 00,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\System32\TDispVol.exe
PRC - [2005/01/17 20:38:38 | 00,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2004/08/28 04:37:00 | 00,155,648 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\System32\RAMASST.exe
PRC - [2004/08/28 04:33:00 | 00,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\System32\DVDRAMSV.exe
PRC - [2004/08/10 08:00:00 | 00,016,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wbem\unsecapp.exe
PRC - [2003/06/20 01:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2003/05/12 18:02:32 | 00,303,104 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LEXBCES.EXE
PRC - [2003/05/12 18:02:32 | 00,174,592 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LEXPPS.EXE
PRC - [2000/06/15 17:44:36 | 00,102,400 | ---- | M] (FacetCorp) -- C:\Program Files\FacetCorp\FacetWin\fwagent.exe
========== Win32 Services (SafeList) ==========
SRV - [2009/10/09 00:18:57 | 01,028,432 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service [Auto | Running])
SRV - [2009/09/08 21:09:30 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/05/29 13:41:26 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/05/02 19:03:48 | 00,182,768 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
SRV - [2009/04/01 14:21:30 | 00,365,072 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS [On_Demand | Stopped])
SRV - [2009/03/25 17:25:20 | 00,797,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc [Auto | Running])
SRV - [2009/03/25 11:05:48 | 00,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield [Unknown | Running])
SRV - [2009/03/24 00:03:18 | 00,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon [On_Demand | Running])
SRV - [2009/03/19 11:42:02 | 00,884,360 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService [Auto | Running])
SRV - [2009/02/11 11:06:36 | 00,210,216 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service [Auto | Running])
SRV - [2009/01/09 13:05:26 | 00,068,112 | ---- | M] (McAfee) -- C:\Program Files\McAfee\MBK\MBackMonitor.exe -- (MBackMonitor [On_Demand | Stopped])
SRV - [2009/01/09 11:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc [Auto | Running])
SRV - [2009/01/09 09:22:10 | 00,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service [Auto | Running])
SRV - [2009/01/09 08:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/04/13 20:12:36 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe -- (SNMP [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2007/01/19 15:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - [2007/01/04 17:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service [Auto | Running])
SRV - [2006/10/26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/10/18 22:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [Auto | Running])
SRV - [2006/10/09 17:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe -- (ehRecvr [Auto | Running])
SRV - [2005/12/20 15:22:14 | 00,035,328 | ---- | M] (TOSHIBA Corp.) -- C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe -- (TAPPSRV [Auto | Stopped])
SRV - [2005/11/28 15:31:32 | 00,540,745 | ---- | M] (Intel Corporation ) -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
SRV - [2005/11/28 15:29:00 | 00,114,753 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2005/11/28 15:28:14 | 00,217,164 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2005/11/23 00:58:48 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\System32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Stopped])
SRV - [2005/08/05 17:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe -- (ehSched [Auto | Running])
SRV - [2005/08/05 17:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe -- (McrdSvc [Auto | Running])
SRV - [2005/07/12 21:14:42 | 00,040,960 | ---- | M] () -- c:\TOSHIBA\IVP\swupdate\swupdtmr.exe -- (Swupdtmr [Auto | Stopped])
SRV - [2005/01/17 20:38:38 | 00,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs [Auto | Running])
SRV - [2004/08/28 04:33:00 | 00,110,592 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\System32\DVDRAMSV.exe -- (DVD-RAM_Service [Auto | Running])
SRV - [2004/08/10 08:11:50 | 00,085,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mhn.dll -- (MHN [On_Demand | Stopped])
SRV - [2003/06/20 01:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2003/05/12 18:02:32 | 00,303,104 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\System32\LEXBCES.EXE -- (LexBceS [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?wa=wsignin...px&id=64855
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com"
FF - prefs.js..browser.search.order.2: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=1296000&lc=1033&_lang=EN"
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:5.0.20090813W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {3205B348-523A-4fac-9BC4-9939CBF583B0}:1.8
FF - prefs.js..extensions.enabledItems: firefox@tvunetworks.com:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 8
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..keyword.URL: "http://www.google.com/search?btnG=Google+Search&q="
FF - HKLM\software\mozilla\Firefox\extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2009/08/31 20:05:11 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/13 21:49:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/04 14:30:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/11 11:53:37 | 00,000,000 | ---D | M]
[2009/01/24 21:12:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Extensions
[2009/01/24 21:12:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/11 08:41:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Firefox\Profiles\ptvmf1rs.default\extensions
[2009/08/13 22:01:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Firefox\Profiles\ptvmf1rs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/19 15:39:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Firefox\Profiles\ptvmf1rs.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/07/17 21:22:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Firefox\Profiles\ptvmf1rs.default\extensions\{3205B348-523A-4fac-9BC4-9939CBF583B0}
[2009/09/15 20:35:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Firefox\Profiles\ptvmf1rs.default\extensions\firefox@tvunetworks.com
[2009/03/07 00:10:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\mozilla\Firefox\Profiles\ptvmf1rs.default\extensions\moveplayer@movenetworks.com
[2009/10/11 08:41:26 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/13 16:32:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/13 22:07:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/09/13 16:32:03 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/13 16:32:03 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 18:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2007/04/30 19:29:22 | 00,049,152 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2008/06/18 02:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/08/13 22:06:25 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2007/07/26 19:03:34 | 00,717,312 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2009/01/07 18:29:18 | 01,447,280 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2003/06/20 15:30:00 | 00,049,152 | ---- | M] (Network Associates Inc) -- C:\Program Files\mozilla firefox\plugins\NPMGWRAP.DLL
[2005/12/05 23:31:00 | 00,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2009/09/13 16:32:06 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2006/12/18 07:18:30 | 00,077,824 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2009/09/09 21:37:58 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/09/09 21:37:58 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/09 21:37:58 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/09 21:37:58 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/09 21:37:58 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/09 21:37:59 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/09 21:37:59 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/07/15 14:10:00 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/15 14:10:00 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/15 14:10:00 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/15 14:10:00 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/15 14:10:00 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/15 14:10:00 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/15 14:10:00 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (344265 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 11803 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {3C7195F6-D788-4D50-BA72-2EE212EDAC78} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe File not found
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] File not found
O4 - HKLM..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FacetWin Agent.lnk = C:\Program Files\FacetCorp\FacetWin\fwagent.exe (FacetCorp)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\System32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe (ArcSoft, Inc.)
O4 - Startup: C:\Documents and Settings\Randall J Blash\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {03A0F84E-3E69-4B3E-B4D3-019CB73B57B3} http://www3.authentium.com/cssrelease/bin/WizMain.exe (Reg Error: Value error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://www.vzwpix.com/activex/VerizonWirel...loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.229.54.212 207.44.96.129 24.229.54.220
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/15 11:38:58 | 00,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: MHN - C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[2009/10/09 00:16:02 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/10/10 20:07:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/10 20:07:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Randall J Blash\Application Data\Malwarebytes
[2009/10/10 20:44:18 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/10/09 00:15:46 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2009/10/10 20:07:39 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/11 11:39:59 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Randall J Blash\Desktop\RootRepeal.exe
[2009/10/11 11:36:40 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/10/11 11:35:00 | 00,520,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Randall J Blash\Desktop\OTL.exe
[2009/10/11 11:34:13 | 00,173,119 | ---- | C] (Eric_71) -- C:\Documents and Settings\Randall J Blash\Desktop\Rooter.exe
[2009/10/11 00:08:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Randall J Blash\Desktop\GooredFix Backups
[2009/10/10 20:44:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/10 20:42:03 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Randall J Blash\Desktop\TFC.exe
[2009/10/10 20:18:09 | 00,069,192 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\Randall J Blash\Desktop\GooredFix.exe
[2009/10/10 20:07:42 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/10 20:07:40 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/10 20:06:55 | 04,045,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Randall J Blash\Desktop\mbam-setup.exe
[2009/10/09 22:02:06 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Randall J Blash\Desktop\spybotsd162.exe
[2009/10/09 00:19:17 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/10/09 00:13:39 | 60,857,536 | ---- | C] (Lavasoft ) -- C:\Documents and Settings\Randall J Blash\Desktop\Ad-AwareAE.exe
========== Files - Modified Within 14 Days ==========
[1 C:\Documents and Settings\Randall J Blash\My Documents\*.tmp files]
[2009/10/11 11:40:16 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\settings.dat
[2009/10/11 11:40:03 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Randall J Blash\Desktop\RootRepeal.exe
[2009/10/11 11:35:01 | 00,520,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Randall J Blash\Desktop\OTL.exe
[2009/10/11 11:34:39 | 00,464,491 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\RootRepeal.zip
[2009/10/11 11:34:25 | 00,440,832 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\CKScanner.exe
[2009/10/11 11:34:17 | 00,173,119 | ---- | M] (Eric_71) -- C:\Documents and Settings\Randall J Blash\Desktop\Rooter.exe
[2009/10/11 08:46:54 | 00,022,295 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2009/10/11 00:14:04 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/11 00:11:20 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/11 00:11:12 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/11 00:11:10 | 32,107,92960 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/10 21:59:09 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/10 20:44:27 | 00,000,778 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/10 20:44:20 | 00,000,622 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\NTREGOPT.lnk
[2009/10/10 20:44:20 | 00,000,603 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\ERUNT.lnk
[2009/10/10 20:42:03 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Randall J Blash\Desktop\TFC.exe
[2009/10/10 20:18:12 | 00,069,192 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\Randall J Blash\Desktop\GooredFix.exe
[2009/10/10 20:07:45 | 00,000,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/10 20:07:08 | 04,045,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Randall J Blash\Desktop\mbam-setup.exe
[2009/10/09 22:21:21 | 00,344,265 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/10/09 22:04:05 | 00,000,944 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\Spybot - Search & Destroy.lnk
[2009/10/09 22:02:06 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Randall J Blash\Desktop\spybotsd162.exe
[2009/10/09 00:19:40 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/09 00:19:10 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/10/09 00:16:00 | 00,000,878 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/10/09 00:13:41 | 60,857,536 | ---- | M] (Lavasoft ) -- C:\Documents and Settings\Randall J Blash\Desktop\Ad-AwareAE.exe
[2009/10/08 21:11:27 | 00,183,808 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\My Documents\budget_rough_draft.xls
[2009/10/04 19:03:13 | 00,033,060 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\ATT_US.ipcc
[2009/10/04 18:46:50 | 00,000,600 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Application Data\winscp.rnd
[2009/10/03 21:12:53 | 00,013,735 | ---- | M] () -- C:\Documents and Settings\Randall J Blash\Desktop\mail_in_copy.png
[2009/09/27 21:07:38 | 00,058,840 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
========== Files - No Company Name ==========
[2009/10/11 11:40:16 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\settings.dat
[2009/10/11 11:34:38 | 00,464,491 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\RootRepeal.zip
[2009/10/11 11:34:24 | 00,440,832 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\CKScanner.exe
[2009/10/10 20:44:27 | 00,000,778 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/10/10 20:44:20 | 00,000,622 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\NTREGOPT.lnk
[2009/10/10 20:44:20 | 00,000,603 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\ERUNT.lnk
[2009/10/10 20:07:45 | 00,000,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/09 22:04:05 | 00,000,944 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\Spybot - Search & Destroy.lnk
[2009/10/09 21:59:44 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/10/09 00:19:40 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/09 00:16:00 | 00,000,878 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/10/03 21:12:52 | 00,013,735 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Desktop\mail_in_copy.png
[2009/09/27 21:07:38 | 00,058,840 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/09/11 17:44:43 | 00,000,600 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Application Data\winscp.rnd
[2009/04/23 18:50:32 | 00,025,224 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Application Data\Comma Separated Values (DOS).ADR
[2009/04/23 18:44:39 | 00,022,648 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Application Data\Comma Separated Values (Windows).ADR
[2009/01/24 19:20:27 | 00,870,128 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Application Data\mcs.rma
[2009/01/24 19:20:27 | 00,000,004 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Application Data\111AD1
[2007/01/01 18:22:18 | 00,001,274 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/11/09 01:10:20 | 00,113,664 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/03 12:01:59 | 00,001,799 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/11/02 21:22:08 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Randall J Blash\Application Data\desktop.ini
[2006/11/02 21:22:07 | 02,106,616 | -H-- | C] () -- C:\Documents and Settings\Randall J Blash\Local Settings\Application Data\IconCache.db
[2006/11/02 21:22:07 | 00,034,288 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2006/11/02 21:22:07 | 00,000,138 | ---- | C] () -- C:\Documents and Settings\Randall J Blash\Local Settings\Application Data\fusioncache.dat
[2006/02/15 03:30:03 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
========== LOP Check ==========
[2009/10/10 20:07:40 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/09/09 21:41:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/22 22:33:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/10/09 00:16:02 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
[2006/12/14 22:37:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Authentium
[2009/05/13 19:19:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2008/06/06 10:04:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Brother
[2006/11/02 21:21:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intel
[2007/11/14 21:21:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2006/02/16 05:55:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pure Networks
[2008/06/06 10:05:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/02/19 21:26:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/02/15 23:17:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/09/14 08:09:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/12/10 23:50:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/09/13 20:14:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/01/25 11:19:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/10/11 11:53:39 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Randall J Blash\Application Data
[2007/03/05 23:34:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Aim
[2009/09/19 15:01:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\ArcSoft
[2007/01/19 09:31:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Azureus
[2008/06/10 16:24:11 | 00,000,000 | R--D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Brother
[2009/08/03 19:45:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\GetRightToGo
[2008/05/30 19:00:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Image Zone Express
[2006/11/02 21:21:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Intel
[2007/05/08 16:49:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\InterVideo
[2008/05/30 22:01:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\LimeWire
[2009/03/07 00:10:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Move Networks
[2006/11/10 01:22:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\OfficeUpdate12
[2009/01/25 11:17:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Paltalk
[2009/01/26 13:46:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Smith Micro
[2006/02/16 05:18:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\toshiba
[2007/08/15 17:38:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\Viewpoint
[2009/06/30 17:47:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\VTExtra
[2006/11/07 18:32:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\WildTangent
[2006/02/16 05:56:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Randall J Blash\Application Data\You've Got Pictures Screensaver
[2009/10/09 00:19:40 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/10/10 21:59:09 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/10 08:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/05/13 19:35:08 | 00,000,360 | ---- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2009/05/13 19:35:07 | 00,000,352 | ---- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2009/10/11 00:11:20 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< End of report >
FYI:When I ran OTL, there was no extras.txt file generaed that I can find.
EDIT:Looking at the logs, I see that there are a couple of iphone cracked apps on my system. I will delete them and repost new logs.


