This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows XP running slow after infection

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix log

ComboFix 10-07-15.05 - Duncan 17/07/2010 8:48.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.894.382 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Duncan\Desktop\CFscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\Installer\28b51bf.msi
.

((((((((((((((((((((((((( Files Created from 2010-06-17 to 2010-07-17 )))))))))))))))))))))))))))))))
.

2010-07-17 07:29 . 2010-07-17 07:29 242896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-07-17 07:29 . 2010-07-17 07:29 216200 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-07-17 07:25 . 2010-07-17 07:25 1690464 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-07-17 07:25 . 2010-07-17 07:25 1038688 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-07-17 07:25 . 2010-07-17 07:25 813336 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-07-17 07:25 . 2010-07-17 07:25 624920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-07-16 17:29 . 2010-07-16 17:29 503808 —-a-w- c:\documents and settings\Duncan\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-4567eb52-n\msvcp71.dll
2010-07-16 17:29 . 2010-07-16 17:29 499712 —-a-w- c:\documents and settings\Duncan\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-4567eb52-n\jmc.dll
2010-07-16 17:29 . 2010-07-16 17:29 348160 —-a-w- c:\documents and settings\Duncan\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-4567eb52-n\msvcr71.dll
2010-07-15 21:58 . 2010-07-17 07:47 ——– d—–w- c:\windows\system32\CatRoot2
2010-07-15 21:47 . 2010-07-15 21:47 ——– d—–w- C:\_OTL
2010-07-13 06:31 . 2010-07-13 06:31 ——– d—–w- c:\documents and settings\Duncan\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-07-13 06:26 . 2010-07-13 06:26 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Vodafone
2010-07-06 20:39 . 2010-07-06 21:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-06 20:39 . 2010-07-06 20:51 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-06 20:25 . 2010-07-06 20:25 ——– d—–w- c:\program files\Safer Networking
2010-07-06 20:20 . 2010-07-06 20:20 ——– d—–w- c:\documents and settings\Administrator\Application Data\Sony Ericsson
2010-07-06 18:22 . 2010-07-06 18:22 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Conduit
2010-07-06 18:21 . 2010-07-06 18:21 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-07-03 08:22 . 2010-07-03 08:22 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-07-01 11:07 . 2010-07-01 11:07 434176 —-a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
2010-06-21 17:57 . 2010-06-21 17:57 50354 —-a-w- c:\documents and settings\Duncan\Application Data\Facebook\uninstall.exe
2010-06-21 17:56 . 2010-06-21 17:57 ——– d—–w- c:\documents and settings\Duncan\Application Data\Facebook
2010-06-20 07:47 . 2004-08-04 10:00 24576 —-a-w- c:\windows\system32\stu2.exe
2010-06-19 23:12 . 2010-06-19 23:12 ——– d—–w- c:\program files\iPod
2010-06-19 23:12 . 2010-06-19 23:13 ——– d—–w- c:\program files\iTunes
2010-06-19 23:04 . 2010-06-19 23:04 ——– d—–w- c:\program files\Bonjour
2010-06-19 22:57 . 2010-06-19 22:57 72504 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-17 21:01 . 2010-06-17 21:01 ——– d—–w- c:\documents and settings\Susan\Local Settings\Application Data\Conduit
2010-06-17 21:01 . 2010-06-17 21:01 ——– d—–w- c:\documents and settings\Susan\Local Settings\Application Data\Vuze_Remote
2010-06-17 21:01 . 2010-06-17 21:01 ——– d—–w- c:\documents and settings\Susan\Local Settings\Application Data\Google
2010-06-17 20:50 . 2010-06-17 20:50 ——– d—–w- c:\documents and settings\Susan\Local Settings\Application Data\Eastman Kodak Company
2010-06-17 20:45 . 2010-06-18 01:40 ——– d—–w- c:\documents and settings\Susan\Application Data\Apple Computer
2010-06-17 20:45 . 2010-06-17 20:45 ——– d—–w- c:\documents and settings\Susan\Local Settings\Application Data\Apple Computer
2010-06-17 20:45 . 2010-06-17 20:45 ——– d—–w- c:\documents and settings\Susan\Application Data\Vodafone
2010-06-17 20:44 . 2010-06-17 20:44 ——– d—–w- c:\documents and settings\Susan\Application Data\Fighters

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-17 08:01 . 2010-05-02 15:04 ——– d—–w- c:\program files\Common Files\Common Toolkit Suite
2010-07-17 07:28 . 2009-11-01 13:09 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-17 07:27 . 2009-11-01 13:08 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-16 22:40 . 2009-11-03 10:27 1 —-a-w- c:\documents and settings\Duncan\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-16 18:41 . 2010-02-09 14:27 63488 —-a-w- c:\documents and settings\All Users\Application Data\Activ Software\ActivApplications\ActivFocusHook.dll
2010-07-16 18:40 . 2010-02-10 18:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Kodak
2010-07-13 22:46 . 2010-02-10 17:59 ——– d—–w- c:\documents and settings\Duncan\Application Data\Temp
2010-07-02 18:51 . 2009-12-02 08:48 ——– d—–w- c:\documents and settings\Duncan\Application Data\FileZilla
2010-06-19 23:12 . 2010-04-05 08:50 ——– d—–w- c:\program files\Common Files\Apple
2010-06-17 20:45 . 2009-12-24 18:07 49104 —-a-w- c:\documents and settings\Susan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-14 14:30 . 2009-11-01 00:17 743936 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 10:45 . 2010-06-09 10:45 5591040 —-a-w- c:\documents and settings\Duncan\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-02 16:17 . 2009-11-01 13:08 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-19 11:03 . 2010-05-19 11:03 ——– d—–w- c:\documents and settings\Duncan\Application Data\Vodafone
2010-05-19 11:03 . 2010-05-19 11:03 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2010-05-19 11:02 . 2010-05-19 11:02 ——– d—–w- c:\documents and settings\LocalService\Application Data\Vodafone
2010-05-19 11:00 . 2010-05-19 11:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Vodafone
2010-05-19 11:00 . 2010-05-19 11:00 ——– d—–w- c:\program files\Vodafone
2010-05-19 11:00 . 2009-11-01 08:20 ——– d—–w- c:\program files\Common Files\InstallShield
2010-05-18 15:35 . 2010-05-18 15:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 15:35 . 2010-05-18 15:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-18 13:43 . 2010-01-25 17:48 ——– d—–w- c:\program files\Vuze_Remote
2010-05-02 05:56 . 2004-08-04 10:00 1850880 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 10:36 . 2010-05-02 15:04 217736 -c–a-w- c:\documents and settings\All Users\Application Data\{69F69AB0-8485-4B45-A118-148977C1651A}\common\C7B20867\2F8E83F8\prep.exe
2010-04-20 05:51 . 2004-08-04 10:00 285696 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-07-15_07.30.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-17 08:01 . 2010-07-17 08:01 16384 c:\windows\Temp\Perflib_Perfdata_25b0.dat
+ 2010-07-16 18:40 . 2010-07-16 18:40 16384 c:\windows\Temp\Perflib_Perfdata_158.dat
+ 2004-08-04 10:00 . 2004-08-04 10:00 24576 c:\windows\system32\userinit.exe
+ 2010-06-20 16:15 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
+ 2009-11-01 00:17 . 2010-06-14 14:30 743936 c:\windows\system32\dllcache\helpsvc.exe
- 2009-11-01 00:17 . 2004-08-04 10:00 743936 c:\windows\system32\dllcache\helpsvc.exe
+ 2010-03-11 07:54 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-05-18 2515552]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 09:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-05-18 13:43 2515552 —-a-w- c:\program files\Vuze_Remote\tbVuz1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-05-18 2515552]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-05-18 2515552]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-01 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-07-11 537896]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 2065248]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-03 149280]
"ActivControl"="c:\program files\Activ Software\ActivDriver\ActivControl2.exe" [2009-10-22 1088800]
"Conime"="c:\windows\system32\conime.exe" [2004-08-04 27648]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-08-03 1626112]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2010-04-20 386696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\Duncan\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2010-4-12 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-15 08:26 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect]
2008-10-09 14:33 2086912 —-a-w- c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2007-06-13 08:16 528384 —-a-r- c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\AiOHomeCenter.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\Kodak.Statistics.exe"=
"c:\\Program Files\\Kodak\\AiO\\Center\\NetworkPrinterDiscovery.exe"=
"c:\\Program Files\\Kodak\\AiO\\Firmware\\KodakAiOUpdater.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kodak\\Installer\\Setup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"9323:TCP"= 9323:TCP:EKDiscovery

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [01/11/2009 14:08 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [01/11/2009 14:09 243024]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [24/02/2010 23:07 390528]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [01/07/2010 12:07 59240]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [01/07/2010 12:07 166632]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\drivers\activhidsermini.sys [05/05/2009 18:25 55936]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\drivers\activmouse.sys [05/10/2009 18:56 6144]
.
Contents of the 'Scheduled Tasks' folder

2010-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride =
DPF: AuGen - hxxp://www.cecdoc.co.uk/alchemyweb/Components/AuGen.cab
FF - ProfilePath - c:\documents and settings\Duncan\Application Data\Mozilla\Firefox\Profiles\b5kdvc4s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\Duncan\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-17 09:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(18368)
c:\documents and settings\All Users\Application Data\ACTIV Software\ActivApplications\ActivFocusHook.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\program files\Sony Ericsson\Mobile2\File Manager\FM.dll
c:\windows\system32\MSVCR71.dll
c:\program files\Common Files\Teleca Shared\tlib_log.dll
c:\program files\Common Files\Teleca Shared\boost_log-vc71-mt-1_33.dll
c:\windows\system32\msi.dll
c:\program files\Common Files\Teleca Shared\TC Device Mgmt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-17 09:12:31
ComboFix-quarantined-files.txt 2010-07-17 08:12
ComboFix2.txt 2010-07-15 22:27
ComboFix3.txt 2010-07-15 20:10
ComboFix4.txt 2010-07-15 07:34

Pre-Run: 209,554,542,592 bytes free
Post-Run: 209,592,139,776 bytes free

- - End Of File - - 6268939BC9AABFDEA114509094EA7FA5
Upload was successful
================================================================================
===========================

MBAM log

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4321

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

17/07/2010 09:22:30
mbam-log-2010-07-17 (09-22-30).txt

Scan type: Quick scan
Objects scanned: 140400
Time elapsed: 6 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
================================================================================
=============================================

Security check log

Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 6 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
AVG Free 9.0
ESET Online Scanner v3
Antivirus up to date! (On Access scanning disabled!)
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 16
Out of date Java installed!
Adobe Flash Player 10.0.32.18
Adobe Reader 9.2
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.6)
```````````````````````````````` http://forums.whatthetech.com/index.php?ac…27&t;=113162
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

================================================================================
=================================
ESET log

C:\Documents and Settings\Duncan\Local Settings\Application Data\Identities\{49795307-3F93-49D8-9B68-7DD53DE3DA5E}\Microsoft\Outlook Express\Deleted Items.dbx multiple threats
C:\Documents and Settings\Duncan\Local Settings\Application Data\Identities\{49795307-3F93-49D8-9B68-7DD53DE3DA5E}\Microsoft\Outlook Express\Inbox.dbx Win32/Oficla.FO trojan

================================================================================
=======================================

OTL log

OTL logfile created on: 17/07/2010 10:08:11 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Duncan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

894.00 Mb Total Physical Memory | 175.00 Mb Available Physical Memory | 20.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 195.11 Gb Free Space | 83.78% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DUNCANLAPTOP
Current User Name: Duncan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/07/15 22:45:21 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Duncan\Desktop\OTL.exe
PRC - [2010/07/01 12:07:20 | 001,361,128 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2010/07/01 12:07:18 | 000,840,936 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/06/28 17:21:48 | 000,014,808 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/06/28 17:21:47 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/06/02 17:18:04 | 004,093,792 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgui.exe
PRC - [2010/06/02 17:18:00 | 002,065,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/06/02 17:17:56 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/02 17:17:55 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/02 17:16:41 | 000,722,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/02 17:16:39 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/04/20 11:37:17 | 000,684,680 | —- | M] (SPAMfighter) – C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe
PRC - [2010/04/20 11:37:02 | 000,189,064 | —- | M] (SPAMfighter ApS) – C:\Program Files\Fighters\SPAMfighter\sfus.exe
PRC - [2010/04/20 11:37:00 | 000,386,696 | —- | M] (SPAMfighter ApS) – C:\Program Files\Fighters\SPAMfighter\sfagent.exe
PRC - [2010/03/15 09:25:56 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/15 09:25:01 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/02/24 18:30:09 | 000,029,416 | —- | M] (Apache Software Foundation) – C:\xampplite\apache\bin\httpd.exe
PRC - [2009/10/22 17:44:18 | 000,453,400 | —- | M] () – C:\Program Files\Activ Software\ActivDriver\ActivMgr.exe
PRC - [2009/10/22 17:44:14 | 001,088,800 | —- | M] (Promethean Technologies Group Ltd) – C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe
PRC - [2009/10/03 00:34:42 | 000,015,216 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
PRC - [2009/08/05 13:49:44 | 000,284,016 | —- | M] (Eastman Kodak Company) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
PRC - [2009/08/03 10:33:06 | 001,626,112 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
PRC - [2008/10/09 15:32:56 | 000,014,336 | —- | M] (Vodafone) – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2008/07/11 12:15:46 | 000,537,896 | —- | M] (Dell) – C:\Program Files\Battery Meter\BTMeter.exe
PRC - [2007/05/10 11:22:32 | 000,405,504 | —- | M] (SigmaTel, Inc.) – C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
PRC - [2007/03/16 04:23:20 | 000,983,040 | R— | M] (Teleca AB) – C:\Program Files\Common Files\Teleca Shared\Generic.exe
PRC - [2006/01/02 18:41:22 | 000,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/04/05 18:01:36 | 000,282,624 | —- | M] (FUJI PHOTO FILM CO., LTD.) – C:\Program Files\FinePixViewer\QuickDCF.exe
PRC - [2004/08/04 11:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/07/16 19:41:59 | 000,063,488 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Activ Software\ActivApplications\ActivFocusHook.dll
MOD - [2010/07/15 22:45:21 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Duncan\Desktop\OTL.exe
MOD - [2010/06/07 18:07:08 | 000,541,928 | —- | M] (Trusteer Ltd.) – C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll
MOD - [2004/08/04 11:00:00 | 001,050,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004/08/04 11:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - [2010/07/01 12:07:18 | 000,840,936 | —- | M] (Trusteer Ltd.) [Auto | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe – (RapportMgmtService)
SRV - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/04/20 11:37:17 | 000,684,680 | —- | M] (SPAMfighter) [Auto | Running] – C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe – (Common Toolkit Service)
SRV - [2010/04/20 11:37:02 | 000,189,064 | —- | M] (SPAMfighter ApS) [Auto | Running] – C:\Program Files\Fighters\SPAMfighter\sfus.exe – (SPAMfighter Update Service)
SRV - [2010/04/04 23:34:04 | 000,085,096 | —- | M] (Autodesk) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2010/03/15 09:25:56 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/15 09:25:01 | 000,916,760 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/02/24 18:30:09 | 000,029,416 | —- | M] (Apache Software Foundation) [Auto | Running] – C:\xampplite\apache\bin\httpd.exe – (Apache2.2)
SRV - [2009/08/05 13:49:44 | 000,284,016 | —- | M] (Eastman Kodak Company) [Auto | Running] – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe – (Kodak AiO Network Discovery Service)
SRV - [2008/10/09 15:32:56 | 000,014,336 | —- | M] (Vodafone) [Auto | Running] – C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe – (VMCService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\System32\DRIVERS\OMCI.SYS – (OMCI)
DRV - File not found [Kernel | On_Demand | Running] – C:\DOCUME~1\Duncan\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2010/07/17 08:28:54 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/07/17 08:27:09 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/07/01 12:07:30 | 000,166,632 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys – (RapportPG)
DRV - [2010/07/01 12:07:30 | 000,059,240 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys – (RapportKELL)
DRV - [2010/06/02 17:17:55 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/02/24 23:07:34 | 000,390,528 | —- | M] (Trusteer Ltd.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\RapportBuka.sys – (RapportBuka)
DRV - [2009/10/05 18:56:52 | 000,006,144 | —- | M] (Promethean Technologies Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\activmouse.sys – (prmvmouse)
DRV - [2009/05/05 18:25:12 | 000,055,936 | —- | M] (Promethean Technologies Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\activhidsermini.sys – (ActivHidSerMini)
DRV - [2008/07/04 14:33:40 | 000,101,120 | R— | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ewusbmdm.sys – (hwdatacard)
DRV - [2008/05/02 10:58:28 | 000,008,064 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys – (UsbserFilt)
DRV - [2008/05/02 10:58:14 | 000,020,864 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ccdcmbo.sys – (nmwcdc)
DRV - [2008/05/02 10:58:14 | 000,008,064 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbser_lowerflt.sys – (upperdev)
DRV - [2008/05/02 10:58:12 | 000,017,536 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ccdcmb.sys – (nmwcd)
DRV - [2007/05/10 11:24:34 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/04/24 12:33:46 | 000,100,488 | R— | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s125mgmt.sys – (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/24 12:33:46 | 000,098,696 | R— | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s125obex.sys – (s125obex)
DRV - [2007/04/24 12:33:44 | 000,108,680 | R— | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s125mdm.sys – (s125mdm)
DRV - [2007/04/24 12:33:42 | 000,015,112 | R— | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s125mdfl.sys – (s125mdfl)
DRV - [2007/04/24 12:33:34 | 000,083,336 | R— | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s125bus.sys – (s125bus) Sony Ericsson Device 125 driver (WDM)
DRV - [2007/03/16 19:10:46 | 000,604,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2006/10/11 22:43:56 | 001,777,152 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2006/07/01 23:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/01/07 18:07:18 | 000,138,752 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2004/03/08 12:55:50 | 000,013,567 | —- | M] (B.H.A Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS – (cdrbsdrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.2: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.7.1
FF - prefs.js..extensions.enabledItems: [removed]:3.3.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.16
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.63
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.5.6.0
FF - prefs.js..keyword.URL: "http://www.mirostart.com/s/?src=FF-Address&site;=Yahoo!&cfg;=2-73-0-mTeb\n&q;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/11 08:58:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/28 17:21:52 | 000,000,000 | —D | M]

[2010/03/10 21:18:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Duncan\Application Data\Mozilla\Extensions
[2010/07/16 20:08:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\b5kdvc4s.default\extensions
[2010/03/11 08:01:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\b5kdvc4s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/10 21:00:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\o5ldr2ym.default\extensions
[2010/03/10 21:00:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\o5ldr2ym.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/10 21:00:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\o5ldr2ym.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/03/10 21:00:40 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\o5ldr2ym.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2010/03/10 21:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\o5ldr2ym.default\extensions\[removed]
[2010/03/10 21:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Duncan\Application Data\Mozilla\Firefox\Profiles\o5ldr2ym.default\extensions\[removed]
[2010/03/10 21:14:54 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/06 23:38:46 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/04/06 23:38:46 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/06 23:38:46 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/06 23:38:46 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/07/15 23:20:31 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [ActivControl] C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe (Promethean Technologies Group Ltd)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe (Dell)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [sfagent] C:\Program Files\Fighters\SPAMfighter\sfagent.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
O4 - Startup: C:\Documents and Settings\Duncan\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: AuGen http://www.cecdoc.co.uk/alchemyweb/Components/AuGen.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Duncan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Duncan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/04 23:12:50 | 000,000,000 | —D | M] - C:\AutoCAD LT 2009 32 bit – [ NTFS ]
O32 - AutoRun File - [2009/11/01 01:20:34 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619700398653440)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/17 09:26:51 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/07/17 09:15:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Duncan\Application Data\Malwarebytes
[2010/07/17 09:14:55 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/17 09:14:54 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/17 09:14:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/17 09:14:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/17 08:46:14 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Duncan\Desktop\mbam-setup.exe
[2010/07/17 08:28:50 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll.prepare
[2010/07/15 22:58:01 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot2
[2010/07/15 22:47:19 | 000,000,000 | —D | C] – C:\_OTL
[2010/07/15 22:45:04 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Duncan\Desktop\OTL.exe
[2010/07/15 08:12:22 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/07/15 07:56:39 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/07/15 07:56:39 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/07/15 07:56:39 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/07/15 07:56:39 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/07/15 07:55:25 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/07/15 07:55:00 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/13 20:46:36 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/07/13 07:31:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Duncan\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/07/13 07:26:52 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Vodafone
[2010/07/11 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Duncan\My Documents\EPDM
[2010/07/06 21:39:43 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/07/06 21:39:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/07/06 21:25:47 | 000,000,000 | —D | C] – C:\Program Files\Safer Networking
[2010/07/06 19:22:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Conduit
[2010/07/06 19:21:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/07/06 19:21:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Google
[2010/07/06 19:08:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/02 23:33:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/02 23:33:10 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/22 11:49:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Duncan\My Documents\Duncan's Party Tibbe Shiels Inn 2010
[2010/06/21 18:56:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Duncan\Application Data\Facebook
[2010/06/20 17:15:14 | 000,017,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2010/06/20 08:47:53 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\stu2.exe
[2010/06/20 00:12:56 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/06/20 00:12:34 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/06/20 00:04:15 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[1 C:\Documents and Settings\Duncan\My Documents\*.tmp files -> C:\Documents and Settings\Duncan\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/17 10:05:13 | 000,867,892 | —- | M] () – C:\Documents and Settings\Duncan\Desktop\SecurityCheck.exe
[2010/07/17 09:25:50 | 002,672,312 | —- | M] () – C:\Documents and Settings\Duncan\Desktop\esetsmartinstaller_enu.exe
[2010/07/17 09:12:47 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/17 09:02:59 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/17 08:46:23 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Duncan\Desktop\mbam-setup.exe
[2010/07/17 08:44:13 | 003,738,072 | R— | M] () – C:\Documents and Settings\Duncan\Desktop\ComboFix.exe
[2010/07/17 08:28:54 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/17 08:28:50 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll.prepare
[2010/07/17 08:28:21 | 062,063,449 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/07/17 08:27:09 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/16 19:41:35 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/16 19:40:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/16 19:40:10 | 937,472,000 | -HS- | M] () – C:\hiberfil.sys
[2010/07/15 23:20:31 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/15 23:19:00 | 004,718,592 | -H– | M] () – C:\Documents and Settings\Duncan\NTUSER.DAT
[2010/07/15 22:45:21 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Duncan\Desktop\OTL.exe
[2010/07/15 20:10:32 | 000,000,406 | —- | M] () – C:\Documents and Settings\Duncan\Application Data\com.adobe.mauby_state.xml
[2010/07/15 20:08:21 | 000,000,732 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Acrobat_com.lnk
[2010/07/15 08:12:28 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/07/13 20:48:48 | 000,000,507 | —- | M] () – C:\WINDOWS\win.ini
[2010/07/13 20:48:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/07/10 14:41:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/10 08:14:37 | 000,433,566 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/10 08:14:37 | 000,068,164 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/10 08:14:34 | 000,508,956 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/08 14:34:13 | 000,015,088 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\alan.odt_0.odt
[2010/07/06 21:40:00 | 000,000,951 | —- | M] () – C:\Documents and Settings\Duncan\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/06 21:40:00 | 000,000,933 | —- | M] () – C:\Documents and Settings\Duncan\Desktop\Spybot - Search & Destroy.lnk
[2010/07/06 21:33:10 | 000,005,019 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\Attach.zip
[2010/06/30 23:26:55 | 000,018,944 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\twohouses.xls
[2010/06/30 23:26:54 | 000,000,147 | -H– | M] () – C:\Documents and Settings\Duncan\My Documents\.~lock.twohouses.xls#
[2010/06/29 07:27:40 | 000,353,276 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\section23FACTSHEET59.pdf
[2010/06/28 23:05:15 | 000,007,168 | —- | M] () – C:\Documents and Settings\Duncan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/27 21:43:12 | 000,050,688 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\SPEC AND PRICE LIST JULY ISLAND COLLECTION 140709-1.doc
[2010/06/27 18:53:34 | 000,010,240 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\Telephone Book.xls
[2010/06/25 18:30:44 | 000,018,432 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\estimate.doc
[2010/06/24 21:12:56 | 000,023,552 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\Kelton Hill Fair 3 Jun 2010.doc
[2010/06/23 21:54:23 | 000,002,475 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ActivInspire.lnk
[2010/06/20 19:25:04 | 000,099,328 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\KEYCOMM_referral_form.doc
[2010/06/20 18:24:57 | 000,000,800 | —- | M] () – C:\Documents and Settings\Duncan\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/06/20 17:14:45 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2010/06/20 17:14:45 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2010/06/20 17:09:21 | 3445,263,417 | —- | M] () – C:\Documents and Settings\Duncan\My Documents\BSL_1.zip
[2010/06/20 00:14:08 | 000,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[1 C:\Documents and Settings\Duncan\My Documents\*.tmp files -> C:\Documents and Settings\Duncan\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/17 10:05:09 | 000,867,892 | —- | C] () – C:\Documents and Settings\Duncan\Desktop\SecurityCheck.exe
[2010/07/17 09:25:41 | 002,672,312 | —- | C] () – C:\Documents and Settings\Duncan\Desktop\esetsmartinstaller_enu.exe
[2010/07/15 20:10:32 | 000,000,406 | —- | C] () – C:\Documents and Settings\Duncan\Application Data\com.adobe.mauby_state.xml
[2010/07/15 20:08:21 | 000,000,732 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Acrobat_com.lnk
[2010/07/15 08:12:28 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/07/15 08:12:25 | 000,260,272 | —- | C] () – C:\cmldr
[2010/07/15 07:56:39 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/15 07:56:39 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/15 07:56:39 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/15 07:56:39 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/07/15 07:56:39 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/07/14 23:35:48 | 003,738,072 | R— | C] () – C:\Documents and Settings\Duncan\Desktop\ComboFix.exe
[2010/07/09 07:13:20 | 000,015,088 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\alan.odt_0.odt
[2010/07/06 21:40:00 | 000,000,951 | —- | C] () – C:\Documents and Settings\Duncan\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/06 21:40:00 | 000,000,933 | —- | C] () – C:\Documents and Settings\Duncan\Desktop\Spybot - Search & Destroy.lnk
[2010/07/06 21:33:10 | 000,005,019 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\Attach.zip
[2010/07/06 21:28:52 | 937,472,000 | -HS- | C] () – C:\hiberfil.sys
[2010/06/30 23:25:43 | 000,000,147 | -H– | C] () – C:\Documents and Settings\Duncan\My Documents\.~lock.twohouses.xls#
[2010/06/29 07:27:40 | 000,353,276 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\section23FACTSHEET59.pdf
[2010/06/27 21:43:07 | 000,050,688 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\SPEC AND PRICE LIST JULY ISLAND COLLECTION 140709-1.doc
[2010/06/24 21:12:52 | 000,023,552 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\Kelton Hill Fair 3 Jun 2010.doc
[2010/06/24 18:01:38 | 000,018,432 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\estimate.doc
[2010/06/20 19:11:43 | 000,099,328 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\KEYCOMM_referral_form.doc
[2010/06/20 16:53:43 | 3445,263,417 | —- | C] () – C:\Documents and Settings\Duncan\My Documents\BSL_1.zip
[2010/06/20 00:14:08 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/03/16 20:05:01 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/16 20:05:00 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2010/01/05 23:34:47 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/11/01 11:30:11 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2009/11/01 11:30:10 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2009/11/01 11:23:33 | 000,266,240 | —- | C] () – C:\WINDOWS\System32\EMSC.DLL
[2009/11/01 11:23:33 | 000,009,856 | —- | C] () – C:\WINDOWS\System32\drivers\EMSC.sys
[2009/10/22 17:44:36 | 000,223,016 | —- | C] () – C:\WINDOWS\libactivboardex.dll
[2009/10/22 17:44:16 | 000,252,696 | —- | C] () – C:\WINDOWS\ActivDRV.dll
[2004/08/04 11:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/03/24 06:03:00 | 000,279,552 | —- | C] () – C:\WINDOWS\System32\FGWVB32.DLL

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/11/01 01:20:34 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/07/13 20:48:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/07/15 08:12:28 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/07/17 09:13:56 | 000,020,922 | —- | M] () – C:\ComboFix.txt
[2009/11/01 01:20:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/17 10:04:39 | 000,000,352 | —- | M] () – C:\eset_log.txt
[2010/07/16 19:40:10 | 937,472,000 | -HS- | M] () – C:\hiberfil.sys
[2009/11/01 01:20:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/11/01 01:20:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 11:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 11:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/07/16 19:40:09 | 1409,286,144 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/11/01 01:20:03 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2009/08/03 10:33:06 | 000,192,512 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2006/10/11 22:22:06 | 000,303,104 | —- | M] (ATI Technologies Inc.) Unable to obtain MD5 – C:\WINDOWS\system32\ATIDEMGR.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/10/31 23:17:24 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/31 23:17:24 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/31 23:17:24 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2004/08/04 11:00:00 | 000,577,024 | —- | M] (Microsoft Corporation) MD5=C72661F8552ACE7C5C85E16A3CF505C4 – C:\WINDOWS\system32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/04 11:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/04 11:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-16 06:01:49
< End of report >
================================================================================
===========================
OTL Extras

OTL Extras logfile created on: 17/07/2010 10:08:11 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Duncan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

894.00 Mb Total Physical Memory | 175.00 Mb Available Physical Memory | 20.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 59.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 195.11 Gb Free Space | 83.78% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DUNCANLAPTOP
Current User Name: Duncan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files\FinePixViewer\FinePixViewer.exe" "%1" (FUJI PHOTO FILM CO.,LTD.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"9322:TCP" = 9322:TCP:*:Enabled:EKDiscovery
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"9323:TCP" = 9323:TCP:*:Enabled:EKDiscovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze – (Vuze Inc.)
"C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" = C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe:*:Enabled:Kodak.AiO.HomeCenter – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\Kodak.Statistics.exe" = C:\Program Files\Kodak\AiO\Center\Kodak.Statistics.exe:*:Enabled:Kodak.AiO.Statistics – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe" = C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe:*:Enabled:Kodak.AiO.SetupUtility – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Firmware\KodakAiOUpdater.exe" = C:\Program Files\Kodak\AiO\Firmware\KodakAiOUpdater.exe:*:Enabled:Kodak.AiO.FwUpdater – (Eastman Kodak Company)
"C:\Documents and Settings\All Users\Application Data\Kodak\Installer\Setup.exe" = C:\Documents and Settings\All Users\Application Data\Kodak\Installer\Setup.exe:*:Enabled:Kodak.AiO.Installer – (KODAK)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{053B3DA8-91B5-4682-A130-715412A1A252}" = Paint.NET v3.5.4
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D0AB230-E7BC-41CB-A50C-F282273E897B}" = SPAMfighter Client
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.1
"{25BEC3AB-5CD4-481D-9143-215C1BBB189E}" = Sony Ericsson PC Suite
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{450063AA-643B-417C-8CF5-405BA3F4EF40}" = Autodesk Design Review 2009
"{543A4F31-9590-416A-A621-42CEB4C6A694}" = Battery Meter
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{5783F2D7-7009-0409-0002-0060B0CE6BBA}" = AutoCAD LT 2009 - English
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{6F654BB3-95C5-4ACC-962F-D72492514503}" = ActivInspire Help (GBR) v1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7970AA03-F817-4916-AE77-80DC801646CC}" = ActivInspire v1
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7AEBFFF0-15A1-48A9-88F3-06604486C7C9}" = WMPTagSupportExtender
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{8E7A8F89-9A8C-48A5-8A03-BDAE191D7B1A}" = MySQL Server 5.1
"{9899605D-68FE-4457-BA7C-05A1813AB7F1}" = ActivDriver v5.4.6
"{9BD24D14-A5F1-49CA-85CA-90E9A8AEF44A}" = ActivInspire HWR Resources (ENU) v1
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5181519-9F3D-4372-ABC6-C333C2F3A816}_is1" = RunAlyzer
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}" = Sony Ericsson Drivers
"{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}" = Vodafone Mobile Connect Lite
"{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}" = Sony Ericsson Device Data
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D680C913-5955-469D-9D88-C1940F7506D6}" = RAW FILE CONVERTER LE
"{D6BF6477-8369-489F-8DE6-3731F4B88560}" = Sony Ericsson PC Suite
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Centre
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{EF40BAC3-372B-46F4-A32D-B37CF4217CE7}" = ATI Catalyst Control Center
"{EFD0BFEB-980E-491B-833B-A8848E5E0F0F}" = Hyplay
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3418D3A-C2E6-443B-83FD-F80585D96C5E}" = ActivInspire Core Resources v1
"{FB557C20-AF8C-471E-AB56-0EBE5ECD007C}" = MySQL Workbench 5.1 OSS
"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr
"{FEF06E73-A519-4510-8CF3-B66041B91D8A}" = EMSC
"8461-7759-5462-8226" = Vuze
"AbcNavigator 2_is1" = AbcNavigator 2.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.8
"ATI Display Driver" = ATI Display Driver
"AutoCAD LT 2009 - English" = AutoCAD LT 2009 - English
"Autodesk Design Review 2009" = Autodesk Design Review 2009
"AVG9Uninstall" = AVG Free 9.0
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ESET Online Scanner" = ESET Online Scanner v3
"FileZilla Client" = FileZilla Client 3.3.2
"InstallShield_{543A4F31-9590-416A-A621-42CEB4C6A694}" = Battery Meter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Ogg Codecs" = Ogg Codecs 0.81.15562
"Rapport_msi" = Rapport
"SPAMfighter" = SPAMfighter
"Vuze_Remote Toolbar" = Vuze_Remote Toolbar
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
"ypoOrder_is1" = ypoOrder 7.10

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 16/07/2010 20:29:55 | Computer Name = DUNCANLAPTOP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 16/07/2010 20:29:55 | Computer Name = DUNCANLAPTOP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5375

Error - 16/07/2010 20:29:55 | Computer Name = DUNCANLAPTOP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5375

Error - 17/07/2010 03:04:44 | Computer Name = DUNCANLAPTOP | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(KodakESP5200+1602._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 17/07/2010 03:04:44 | Computer Name = DUNCANLAPTOP | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(KodakESP5200+1602._scanner._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 17/07/2010 03:04:44 | Computer Name = DUNCANLAPTOP | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(KodakESP5200+1602._smb._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 17/07/2010 03:39:52 | Computer Name = DUNCANLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application PaintDotNet.exe, version 3.54.3708.31979, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 17/07/2010 03:39:54 | Computer Name = DUNCANLAPTOP | Source = Application Hang | ID = 1002
Description = Hanging application PaintDotNet.exe, version 3.54.3708.31979, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 17/07/2010 04:26:47 | Computer Name = DUNCANLAPTOP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 17/07/2010 04:26:47 | Computer Name = DUNCANLAPTOP | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

[ System Events ]
Error - 15/07/2010 18:05:27 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7034
Description = The Dell Wireless WLAN Tray Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 15/07/2010 18:05:28 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7034
Description = The MySQL service terminated unexpectedly. It has done this 1 time(s).

Error - 15/07/2010 18:10:57 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 15/07/2010 18:20:27 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7034
Description = The Dell Wireless WLAN Tray Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 15/07/2010 18:20:27 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7034
Description = The MySQL service terminated unexpectedly. It has done this 1 time(s).

Error - 16/07/2010 01:56:09 | Computer Name = DUNCANLAPTOP | Source = DCOM | ID = 10010
Description = The server {1F87137D-0E7C-44D5-8C73-4EFFB68962F2} did not register
with DCOM within the required timeout.

Error - 17/07/2010 03:47:20 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 17/07/2010 03:47:47 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7034
Description = The Dell Wireless WLAN Tray Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 17/07/2010 03:47:47 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7034
Description = The MySQL service terminated unexpectedly. It has done this 1 time(s).

Error - 17/07/2010 03:53:47 | Computer Name = DUNCANLAPTOP | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.


< End of report >

Away for another 24 hours I'm afraid
Hello,

Thanks for letting me know that you will be away for another 24 hours. I appreciate you letting me know.


Infected Outlook Express
The ESET log indicates that there are infected emails in the Inbox and Deleted Items folder in Outlook Express.

Please delete the emails in your Inbox folder - keep only the emails that are of extreme importance. After you finish deleting the emails, please right click on the Deleted Items folder and click Empty 'Deleted Items' Folder.

Having removed all your unwanted Emails completely it is now wise to Compact all your remaining Emails. Compacting makes the size of the folders smaller by compacting the files contained within them. All the Emails are still readable and still intact just smaller.

To do this click from the top toolbar File / Folder / Compact All Folders



NEXT:



OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    DRV - File not found [Kernel | On_Demand | Running] – C:\DOCUME~1\Duncan\LOCALS~1\Temp\catchme.sys – (catchme)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: AuGen http://www.cecdoc.co.uk/alchemyweb/Components/AuGen.cab (Reg Error: Key error.)
    [2010/07/17 08:46:14 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Duncan\Desktop\mbam-setup.exe
    [2010/07/17 10:05:13 | 000,867,892 | —- | M] () – C:\Documents and Settings\Duncan\Desktop\SecurityCheck.exe
    [2010/07/17 09:25:50 | 002,672,312 | —- | M] () – C:\Documents and Settings\Duncan\Desktop\esetsmartinstaller_enu.exe
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Update Windows XP
Service Pack 3 (SP3)
It would be in your best interest to install this service pack. This update includes all previously released updates for your system.
Microsoft advises that SP1 or SP1a needs to be installed before installing this update.
Attention: The SP3 download is very large! Based on your Internet connection… be prepared, it could take hours to download!!
Alternately, you could see if a friend or family member has the SP3 update on CD or order it from MS for a fee … based on your location.

This will be a 2 step process…
The 1st step in this process is to apply Service Pack 3 (SP3) for Windows XP. This update, includes security fixes, to protect your computer.
The 2nd step is to apply all the critical updates and patches since SP3 was released.
Note: If at any time during these steps, you experience problems with your computer…:stop: …Do not continue with the steps and post a description of the problem.
  • First
  • Obtain Windows XP Service Pack 3 from the Microsoft Download Center
  • Click the Download …button. Choose "Save" at the prompt…and save the file to your desktop.
  • Double click the "WindowsXP-KB936929-SP3-x86-ENU.exe" file on your desktop to install the update.
    When the installation has completed successfully…
  • ! IMPORTANT ! reboot your computer (normally) before proceeding to the next step.
Second
  • Now…Go to: Windows Update and install the Critical Updates.
  • Press the "Express"…button to have all "critical" updates shown.
  • Make sure all critical updates and patches are checked for download and installation.
  • Press the Install Updates … button to begin downloading and installing the updates
    After successfully installing the critical updates and patches…
  • ! IMPORTANT ! reboot your computer normally (again) before proceeding.


NEXT:



Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 21 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT:



Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.
OTIL Log (now at stage of SP3 update) All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Service catchme stopped successfully! Service catchme deleted successfully! File C:\DOCUME~1\Duncan\LOCALS~1\Temp\catchme.sys not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Starting removal of ActiveX control AuGen Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\AuGen\DownloadInformation\\INF . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\AuGen\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\AuGen\ not found. C:\Documents and Settings\Duncan\Desktop\mbam-setup.exe moved successfully. C:\Documents and Settings\Duncan\Desktop\SecurityCheck.exe moved successfully. C:\Documents and Settings\Duncan\Desktop\esetsmartinstaller_enu.exe moved successfully. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Duncan ->Temp folder emptied: 97690 bytes ->Temporary Internet Files folder emptied: 57115403 bytes ->Java cache emptied: 10680337 bytes ->FireFox cache emptied: 82978683 bytes ->Flash cache emptied: 4489 bytes User: LocalService ->Temp folder emptied: 65716 bytes ->Temporary Internet Files folder emptied: 38416 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 0 bytes User: Susan ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 16867 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 2549 bytes Total Files Cleaned = 144.00 mb [EMPTYFLASH] User: Administrator ->Flash cache emptied: 0 bytes User: All Users User: Default User ->Flash cache emptied: 0 bytes User: Duncan ->Flash cache emptied: 0 bytes User: LocalService User: NetworkService ->Flash cache emptied: 0 bytes User: Susan ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.9.0 log created on 07192010_214134 Files\Folders moved on Reboot… C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\SHINSHMZ\15568713140@x50[1] moved successfully. C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\Q0A5OPKO\aceUACping[1].htm moved successfully. C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\O789ATUD\CA0XGP4J.com moved successfully. C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\O789ATUD\CAGL21ZK.com moved successfully. C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\O789ATUD\img[3].htm moved successfully. C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\O789ATUD\ListingsServlet[1].htm moved successfully. C:\Documents and Settings\Duncan\Local Settings\Temporary Internet Files\Content.IE5\DXWKJDY1\optn=64[2] moved successfully. Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI