ken545,
I'm glad to finally be at the point to run the scans and produce logs. A big thanks to you!
Here are the results:
Malware bytes - No malicious items were detected.
aswMBR - downloaded the latest Avast! virus definitions - attached produced txt file.
OTL completed with no issues - logs listed below (Lots of things in log I have no idea what they are or where the came from.)
OTL.txt:
OTL logfile created on: 2/14/2012 10:12:40 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brenda Poland\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.07 Mb Total Physical Memory | 536.63 Mb Available Physical Memory | 52.50% Memory free
30.20 Gb Paging File | 29.89 Gb Available in Paging File | 98.99% Paging File free
Paging file location(s): C:\pagefile.sys 30000 50000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.18 Gb Total Space | 83.72 Gb Free Space | 58.07% Space Free | Partition Type: NTFS
Computer Name: D6KX9PB1 | User Name: Brenda Poland | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Brenda Poland\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\WINDOWS\system32\dlcccoms.exe ( )
PRC - C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\dlccHPEC.DLL ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\dlccFLIB.DLL ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcccfg.dll ()
MOD - C:\WINDOWS\system32\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccfg.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlccdrec.dll ()
MOD - C:\Program Files\Dell Photo AIO Printer 924\dlcccnv4.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) -- File not found
SRV - (MBAMService) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ServiceLayer) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (PcCtlCom) -- C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
SRV - (DSBrokerService) -- C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Tmntsrv) -- C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
SRV - (tmproxy) -- C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
SRV - (TmPfw) -- C:\Program Files\Trend Micro\Internet Security 14\TmPfw.exe (Trend Micro Inc.)
SRV - (dlcc_device) -- C:\WINDOWS\System32\dlcccoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (MBAMProtector) -- C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (UsbserFilt) -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) -- C:\WINDOWS\system32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) -- C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsu) -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (tmxpflt) -- C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) -- C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) -- C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)
DRV - (USB_RNDIS_XP) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (NwlnkIpx) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (dsunidrv) -- C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (tmcfw) -- C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) -- C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (DSproct) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ASCTRM) -- C:\WINDOWS\System32\drivers\asctrm.sys (Windows (R) 2000 DDK provider)
DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (NwlnkNb) -- C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (HSFHWBS2) -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) -- C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2011/07/24 20:08:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/19 10:04:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/16 10:40:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2011/07/24 20:08:03 | 000,000,000 | ---D | M]
[2010/08/19 10:05:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Brenda Poland\Application Data\Mozilla\Extensions
[2010/08/19 10:05:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Brenda Poland\Application Data\Mozilla\Firefox\Profiles\jcs6xakz.default\extensions
[2010/08/19 10:05:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Brenda Poland\Application Data\Mozilla\Firefox\Profiles\jcs6xakz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/11/17 08:49:17 | 000,000,276 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Application Data\Mozilla\Firefox\Profiles\jcs6xakz.default\searchplugins\search.xml
[2010/08/19 10:05:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2007/03/09 18:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
O1 HOSTS File: ([2012/02/10 09:38:18 | 000,442,741 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1
www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1
www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1
www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1
www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 127.0.0.1 171203.com
O1 - Hosts: 127.0.0.1 17-plus.com
O1 - Hosts: 127.0.0.1
www.1800searchonline.com
O1 - Hosts: 127.0.0.1 1800searchonline.com
O1 - Hosts: 127.0.0.1
www.180searchassistant.com
O1 - Hosts: 15219 more lines...
O2 - BHO: (Reg Error: Value error.) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - No CLSID value found.
O3 - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\..\Toolbar\WebBrowser: (no name) - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe File not found
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [pccguide.exe] C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: C:\Documents and Settings\Brenda Poland\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT1\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3120691911-3222514972-401631166-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.0.cab (DLM Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87A9F30A-15CF-4635-8B39-9399F6194D80}: DhcpNameServer = 192.168.1.254 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Brenda Poland\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brenda Poland\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O30 - LSA: Authentication Packages - (nwprovau) -C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/14 09:29:11 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Brenda Poland\Desktop\OTL.exe
[2012/02/13 13:30:17 | 004,733,440 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Brenda Poland\Desktop\aswMBR.exe
[2012/02/10 18:38:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brenda Poland\My Documents\Downloads
[2012/02/09 15:05:30 | 000,000,000 | --SD | C] -- C:\ComboFix
[2012/02/09 10:23:04 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/02/09 10:15:24 | 002,059,824 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Brenda Poland\Desktop\TDSSKiller.exe
[2012/02/09 10:14:56 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/02/09 10:14:56 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/02/09 10:14:56 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/02/09 10:14:56 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/02/09 10:12:04 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/09 08:59:55 | 004,399,011 | R--- | C] (Swearware) -- C:\Documents and Settings\Brenda Poland\Desktop\ComboFix.exe
[2012/02/08 19:55:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brenda Poland\Application Data\Malwarebytes
[2012/02/08 19:54:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/08 19:54:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/02/08 19:54:41 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/02/08 19:54:41 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/08 19:53:51 | 009,502,424 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Brenda Poland\Desktop\mbam-setup-1.60.1.1000.exe
[2012/02/08 19:07:10 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/02/08 13:38:21 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Brenda Poland\Desktop\dds.scr
[2012/02/08 13:36:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/02/08 13:36:14 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT1
[2012/02/08 13:34:45 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Brenda Poland\Desktop\erunt-setup.exe
[2012/02/08 13:05:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Brenda Poland\Recent
[2012/02/08 09:12:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/02/08 09:09:42 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2012/02/07 13:31:38 | 000,000,000 | ---D | C] -- C:\Program Files\Safer Networking
[2012/02/07 13:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Brenda Poland\Desktop\snlTCNTplugins01
[2012/01/23 08:18:04 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2006/08/28 22:19:24 | 001,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccserv.dll
[2006/08/28 22:19:24 | 001,134,592 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccusb1.dll
[2006/08/28 22:19:24 | 000,774,144 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcchbn3.dll
[2006/08/28 22:19:24 | 000,704,512 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccomc.dll
[2006/08/28 22:19:24 | 000,638,976 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccpmui.dll
[2006/08/28 22:19:24 | 000,491,520 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccoms.exe
[2006/08/28 22:19:24 | 000,483,328 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcclmpm.dll
[2006/08/28 22:19:24 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccomm.dll
[2006/08/28 22:19:24 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccih.exe
[2006/08/28 22:19:24 | 000,368,640 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcccfg.exe
[2006/08/28 22:19:24 | 000,155,648 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccprox.dll
[2006/08/28 22:19:24 | 000,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\dlccpplc.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Brenda Poland\*.tmp files -> C:\Documents and Settings\Brenda Poland\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/14 10:02:01 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/14 10:01:58 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\MBR.dat
[2012/02/14 09:29:13 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Brenda Poland\Desktop\OTL.exe
[2012/02/14 09:02:01 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/14 08:01:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/14 08:01:42 | 1071,796,224 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/13 21:53:00 | 000,024,030 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Application Data\wklnhst.dat
[2012/02/13 20:40:27 | 000,057,952 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\DiskMange-del.GIF
[2012/02/13 14:15:36 | 000,058,184 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\DiskMange.GIF
[2012/02/13 14:06:57 | 000,060,416 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/13 13:30:20 | 004,733,440 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Brenda Poland\Desktop\aswMBR.exe
[2012/02/13 13:16:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/10 09:38:18 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/02/09 21:18:09 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-09-fix3.wps
[2012/02/09 18:28:08 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120210-093818.backup
[2012/02/09 18:20:22 | 002,059,824 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Brenda Poland\Desktop\TDSSKiller.exe
[2012/02/09 18:18:50 | 002,041,278 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\tdsskiller.zip
[2012/02/09 17:56:58 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\MBRCheck.exe
[2012/02/09 15:49:35 | 000,014,848 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-09-fix2.wps
[2012/02/09 15:24:40 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120209-182808.backup
[2012/02/09 13:33:02 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-09-fix.wps
[2012/02/09 12:29:52 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120209-152440.backup
[2012/02/09 10:23:23 | 000,000,326 | RHS- | M] () -- C:\boot.ini
[2012/02/09 09:57:51 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120209-122952.backup
[2012/02/09 08:59:55 | 004,399,011 | R--- | M] (Swearware) -- C:\Documents and Settings\Brenda Poland\Desktop\ComboFix.exe
[2012/02/09 08:47:09 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120209-095750.backup
[2012/02/08 21:40:55 | 000,684,297 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\unhide.exe
[2012/02/08 21:30:33 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120209-084709.backup
[2012/02/08 21:10:13 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120208-213033.backup
[2012/02/08 20:51:04 | 000,010,240 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-08-fix.wps
[2012/02/08 19:54:44 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/08 19:53:51 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Brenda Poland\Desktop\mbam-setup-1.60.1.1000.exe
[2012/02/08 19:12:04 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\rkill.exe
[2012/02/08 19:09:22 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120208-211013.backup
[2012/02/08 19:03:32 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-08.wps
[2012/02/08 13:38:24 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Brenda Poland\Desktop\dds.scr
[2012/02/08 13:36:40 | 000,000,774 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/02/08 13:36:16 | 000,000,599 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\ERUNT.lnk
[2012/02/08 13:35:19 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Brenda Poland\Desktop\erunt-setup.exe
[2012/02/08 13:30:20 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120208-190922.backup
[2012/02/08 09:37:50 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120208-133019.backup
[2012/02/07 19:53:01 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120208-093749.backup
[2012/02/07 15:51:32 | 000,043,876 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\requested-files[2012-02-07_15_51].cab
[2012/02/07 14:59:58 | 000,007,145 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\requested-files[2012-02-07_14_59].cab
[2012/02/07 14:49:43 | 001,339,719 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\rootalyz-0.3.4.47.zip
[2012/02/07 07:45:12 | 000,859,992 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\snlTCNTplugins01.zip
[2012/02/06 18:38:34 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120207-195300.backup
[2012/02/06 17:15:05 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120206-183833.backup
[2012/02/06 16:04:30 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120206-171505.backup
[2012/02/06 14:51:15 | 000,442,741 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120206-160430.backup
[2012/02/06 12:14:23 | 000,442,655 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120206-145115.backup
[2012/02/06 10:42:46 | 000,442,655 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120206-121423.backup
[2012/02/04 16:58:55 | 000,442,655 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120206-104246.backup
[2012/01/31 11:02:25 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/30 22:56:20 | 000,210,432 | ---- | M] () -- C:\Documents and Settings\Brenda Poland\Desktop\Silicone Space Station Guide.wps
[2012/01/30 22:08:55 | 000,441,842 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120204-165854.backup
[2012/01/25 20:31:40 | 000,000,848 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2012/01/23 08:18:04 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/01/22 09:45:11 | 000,441,692 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20120130-220854.backup
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Brenda Poland\*.tmp files -> C:\Documents and Settings\Brenda Poland\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/14 10:01:58 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\MBR.dat
[2012/02/13 20:40:22 | 000,057,952 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\DiskMange-del.GIF
[2012/02/13 14:15:27 | 000,058,184 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\DiskMange.GIF
[2012/02/09 19:49:47 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-09-fix3.wps
[2012/02/09 18:18:39 | 002,041,278 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\tdsskiller.zip
[2012/02/09 17:56:57 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\MBRCheck.exe
[2012/02/09 13:59:50 | 000,014,848 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-09-fix2.wps
[2012/02/09 12:26:58 | 1071,796,224 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/09 10:23:21 | 000,000,210 | ---- | C] () -- C:\Boot.bak
[2012/02/09 10:23:08 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/02/09 10:14:56 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/09 10:14:56 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/09 10:14:56 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/09 10:14:56 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/09 10:14:56 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/09 08:58:05 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-09-fix.wps
[2012/02/08 21:40:52 | 000,684,297 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\unhide.exe
[2012/02/08 19:54:44 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/08 19:40:26 | 000,010,240 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-08-fix.wps
[2012/02/08 19:11:58 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\rkill.exe
[2012/02/08 15:32:00 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\spybot-forum-post 2012-02-08.wps
[2012/02/08 13:36:40 | 000,000,774 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/02/08 13:36:16 | 000,000,599 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\ERUNT.lnk
[2012/02/07 15:51:32 | 000,043,876 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\requested-files[2012-02-07_15_51].cab
[2012/02/07 14:59:58 | 000,007,145 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\requested-files[2012-02-07_14_59].cab
[2012/02/07 14:49:30 | 001,339,719 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\rootalyz-0.3.4.47.zip
[2012/02/07 07:45:07 | 000,859,992 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Desktop\snlTCNTplugins01.zip
[2010/08/10 15:59:12 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Local Settings\Application Data\housecall.guid.cache
[2010/03/10 10:47:47 | 000,000,186 | ---- | C] () -- C:\WINDOWS\RealFlight.INI
[2008/07/23 11:50:52 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/07/23 11:46:38 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/05/16 08:56:34 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/02/12 13:13:58 | 000,060,416 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/10 09:21:56 | 000,691,545 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2008/02/10 09:21:56 | 000,003,453 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2007/03/01 15:46:27 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2007/03/01 10:17:24 | 000,006,048 | ---- | C] () -- C:\WINDOWS\System32\MCC16.dll
[2007/03/01 08:01:34 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\BJAXSecurityManager.dll
[2007/03/01 08:01:33 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\BJInstaller.dll
[2006/12/03 08:40:28 | 000,000,848 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2006/12/02 11:56:46 | 000,024,030 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Application Data\wklnhst.dat
[2006/09/04 14:54:48 | 000,000,034 | ---- | C] () -- C:\WINDOWS\AuthMgr.INI
[2006/09/04 14:21:18 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Brenda Poland\Local Settings\Application Data\fusioncache.dat
[2006/08/28 23:05:25 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/08/28 22:59:04 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/28 22:53:47 | 000,000,779 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/08/28 22:50:37 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE
[2006/08/28 22:47:17 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/08/28 22:19:24 | 000,430,080 | ---- | C] () -- C:\WINDOWS\System32\dlccutil.dll
[2006/08/28 22:19:24 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlccinsb.dll
[2006/08/28 22:19:24 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\dlccins.dll
[2006/08/28 22:19:24 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\dlccjswr.dll
[2006/08/28 22:19:24 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\dlccinsr.dll
[2006/08/28 22:19:24 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcccub.dll
[2006/08/28 22:19:24 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcccu.dll
[2006/08/28 22:19:24 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlccvs.dll
[2006/08/28 22:19:24 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcccur.dll
[2006/08/28 22:19:22 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dlcccfg.dll
[2006/08/28 22:19:02 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe
[2006/08/28 22:18:58 | 000,095,617 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2006/08/28 22:18:26 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/08/16 03:48:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/08/16 03:38:45 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 03:37:24 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:27:59 | 000,297,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 03:18:35 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/08/16 03:18:33 | 000,553,836 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2005/08/16 03:18:33 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2005/08/16 03:18:33 | 000,117,452 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2005/08/16 03:18:33 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2005/08/16 03:18:32 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2005/08/16 03:18:30 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005/08/16 03:18:28 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2005/08/16 03:18:23 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2005/08/16 03:18:23 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2005/08/16 03:18:15 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2005/08/16 03:18:08 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2005/08/05 13:01:54 | 000,239,104 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 13:00:16 | 000,000,611 | ---- | C] () -- C:\WINDOWS\System32\dlccplc.ini
[2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/13 15:46:46 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\zlib.dll
========== LOP Check ==========
[2005/08/16 19:54:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2007/08/28 17:57:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2011/08/19 17:19:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2011/09/22 15:03:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2011/07/24 20:12:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2007/04/19 18:41:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Transparent
[2006/08/28 22:48:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/23 16:49:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\Amazon
[2007/03/01 09:01:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\BellSouth
[2006/09/17 15:42:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\Leadertech
[2011/08/19 17:19:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\PC Suite
[2006/09/07 08:35:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\Simple Star
[2007/08/07 17:47:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\Souptoys
[2006/12/02 11:56:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\Template
[2006/11/19 07:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Brenda Poland\Application Data\Walgreens
[2006/10/02 10:55:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\EarthLink Toolbar
[2006/09/08 06:13:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Randy Poland\Application Data\EarthLink Toolbar
========== Purity Check ==========
< End of report >