Jcatsmom
Topic Starter
Same song, second verse. My friend was hit with a double whammy. An infected e-mail disabled McAfee and about a week later she was hit with a rogue antivirus program. Malware Bytes cleaned up one set in Safe Mode and the second in Regular Mode. We are unable to access the internet with IE or Mozilla.
The computer has Windows XP, SP3. My previous topic was [external image: Posted Image] Trojan_Zlob and other infection leftovers, computer slow, but improvin
I am attaching Malware Bytes logs and Otl reports. I would appreciate your help digging this one out again. Thank you!- Jcatsmom
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgDatabase version: 4532Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.187029/12/2010 4:20:34 PM
mbam-log-2010-09-12 (16-20-34).txtScan type: Quick scan
Objects scanned: 151502
Time elapsed: 10 minute(s), 4 second(s)Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2Memory Processes Infected:
(No malicious items detected)Memory Modules Infected:
(No malicious items detected)Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rsoqalds (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rsoqalds (Rogue.SecuritySuite) -> Quarantined and deleted successfully.Registry Data Items Infected:
(No malicious items detected)Folders Infected:
(No malicious items detected)Files Infected:
C:\Documents and Settings\Dee\Local Settings\Application Data\uyrbbgjwr\fpqwvyyuqiw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dee\Local Settings\Application Data\26630516.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgDatabase version: 4602Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.187029/12/2010 4:45:34 PM
mbam-log-2010-09-12 (16-45-34).txtScan type: Quick scan
Objects scanned: 154212
Time elapsed: 17 minute(s), 34 second(s)Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2Memory Processes Infected:
(No malicious items detected)Memory Modules Infected:
C:\WINDOWS\wuint12.dll (Trojan.Hiloti) -> Delete on reboot.Registry Keys Infected:
(No malicious items detected)Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tragevusukasev (Trojan.Hiloti) -> Quarantined and deleted successfully.Registry Data Items Infected:
(No malicious items detected)Folders Infected:
(No malicious items detected)Files Infected:
C:\WINDOWS\wuint12.dll (Trojan.Hiloti) -> Delete on reboot.
C:\Documents and Settings\Dee\Local Settings\Application Data\26630515.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
OTL logfile created on: 9/14/2010 9:14:11 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Dee\Desktop\computer tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 800 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.28 Gb Total Space | 58.44 Gb Free Space | 81.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 488.60 Mb Total Space | 76.61 Mb Free Space | 15.68% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RECTORY
Current User Name: Dee
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dee\Desktop\computer tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
PRC - C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Dee\Desktop\computer tools\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\McAfee\SiteAdvisor\sahook.dll ()
MOD - C:\WINDOWS\unoravucuya.dll ()
MOD - C:\WINDOWS\SYSTEM32\opengl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\glu32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\dciman32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (SAUSBHW) – C:\WINDOWS\System32\Drivers\sausb.sys File not found
DRV - (RPSKT) Security Services Driver (x86) – C:\WINDOWS\System32\DRIVERS\rp_skt32.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Dee\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (WUSB54GV4SRV) – C:\WINDOWS\SYSTEM32\DRIVERS\rt2500usb.sys (Ralink Technology Inc.)
DRV - (GTNDIS5) – C:\WINDOWS\SYSTEM32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (hp4200c) – C:\WINDOWS\SYSTEM32\DRIVERS\hp4200c.sys (Hewlett-Packard)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {60799329-5010-4EEA-B216-C7A87C230110}:1.9.1
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/23 12:24:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/09/12 08:55:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{60799329-5010-4EEA-B216-C7A87C230110}: C:\Documents and Settings\Dee\Local Settings\Application Data\{60799329-5010-4EEA-B216-C7A87C230110} [2010/09/11 16:17:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 23:04:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 23:04:24 | 000,000,000 | —D | M]
[2008/12/02 20:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Mozilla\Extensions
[2010/09/11 17:20:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions
[2010/09/04 12:44:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/11 17:20:18 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/09/03 23:41:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/09/03 23:41:34 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/09/01 19:45:52 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Lgirovaruyuq] C:\WINDOWS\unoravucuya.DLL ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: kaspersky.com ([www] http in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1151174868143 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx (Hotmail Attachments Control)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Dee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/08/14 11:43:06 | 000,000,000 | RHSD | M] - E:\autorun.inf – [ FAT ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Unable to start service SrService!
========== Files/Folders - Created Within 30 Days ==========
[2010/09/11 16:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Local Settings\Application Data\{60799329-5010-4EEA-B216-C7A87C230110}
[2010/09/11 16:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Local Settings\Application Data\uyrbbgjwr
[2010/09/06 17:01:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\My Documents\Dee's photos
[2010/09/03 23:42:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/03 23:41:49 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/03 23:41:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/03 23:41:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/03 23:41:49 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/03 13:51:17 | 000,000,000 | —D | C] – C:\Program Files\Eusing Free Registry Cleaner
[2010/09/02 21:40:05 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2010/09/02 21:06:27 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2010/09/02 21:06:26 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2010/09/02 20:51:29 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010/09/02 18:23:23 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/09/02 18:23:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/02 18:22:54 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/01 19:39:25 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/09/01 19:32:51 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/08/30 08:05:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/30 07:24:11 | 000,000,000 | —D | C] – C:\Program Files\HD Tune
[2010/08/30 07:21:31 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/29 23:12:27 | 000,000,000 | —D | C] – C:\found.001
[2010/08/29 21:21:23 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\PrivacIE
[2010/08/28 22:02:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\IECompatCache
[2010/08/28 21:54:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\IETldCache
[2010/08/28 21:33:30 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/08/28 13:06:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Desktop\computer tools
[2010/08/28 12:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Application Data\Malwarebytes
[2010/08/28 12:41:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/28 12:41:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/28 12:41:26 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/28 12:41:26 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2008/07/24 14:20:40 | 010,420,936 | —- | C] (Microsoft Corporation) – C:\Program Files\xlviewer.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/14 21:11:37 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/14 20:51:10 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/14 20:51:07 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/09/14 20:51:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/09/12 18:05:16 | 004,194,304 | —- | M] () – C:\Documents and Settings\Dee\ntuser.dat
[2010/09/12 18:05:16 | 000,013,189 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/09/12 18:05:16 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Dee\NTUSER.INI
[2010/09/12 18:05:07 | 003,768,536 | -H– | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\IconCache.db
[2010/09/12 17:58:56 | 000,000,724 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/09/12 17:58:56 | 000,000,327 | RHS- | M] () – C:\BOOT.INI
[2010/09/12 17:58:56 | 000,000,256 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/12 16:17:06 | 000,000,444 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/09/12 08:43:51 | 000,002,838 | —- | M] () – C:\WINDOWS\owivanoqiqurih.dll
[2010/09/11 20:21:40 | 000,002,838 | —- | M] () – C:\WINDOWS\osedokezezocoh.dll
[2010/09/06 18:51:31 | 000,000,151 | —- | M] () – C:\WINDOWS\Ulead32.ini
[2010/09/06 17:06:18 | 000,000,071 | —- | M] () – C:\WINDOWS\pex.INI
[2010/09/06 16:57:38 | 000,058,080 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/04 13:09:00 | 000,224,816 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/03 23:41:32 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/03 23:41:32 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/03 23:41:32 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/03 23:41:32 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/03 23:41:31 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/03 18:29:48 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/03 18:28:12 | 000,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/03 18:28:12 | 000,442,466 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/09/03 18:28:12 | 000,071,732 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/09/03 13:51:54 | 077,652,368 | —- | M] () – C:\Documents and Settings\Dee\My Documents\regis bkup1.reg
[2010/09/03 11:29:09 | 000,000,036 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\housecall.guid.cache
[2010/09/02 21:10:40 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/09/02 20:37:39 | 000,219,648 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 19:45:52 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/08/28 21:54:56 | 000,000,815 | —- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/28 12:41:32 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/23 19:18:06 | 000,008,359 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Dee Eichler CV.wpd
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/12 16:17:06 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/09/12 08:43:51 | 000,002,838 | —- | C] () – C:\WINDOWS\owivanoqiqurih.dll
[2010/09/11 20:21:39 | 000,002,838 | —- | C] () – C:\WINDOWS\osedokezezocoh.dll
[2010/09/03 13:51:42 | 077,652,368 | —- | C] () – C:\Documents and Settings\Dee\My Documents\regis bkup1.reg
[2010/09/03 11:29:09 | 000,000,036 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\housecall.guid.cache
[2010/09/01 19:39:31 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/09/01 19:39:29 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/09/01 19:33:14 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/09/01 19:33:14 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/08/28 12:41:32 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/04/23 15:42:50 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/04/16 13:39:35 | 000,219,648 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/09 04:01:57 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/04/24 16:06:59 | 000,000,397 | R— | C] () – C:\WINDOWS\hpw9800k.ini
[2006/04/24 16:04:33 | 000,000,478 | —- | C] () – C:\WINDOWS\hpdj9800.ini
[2006/04/24 16:04:21 | 000,001,567 | —- | C] () – C:\WINDOWS\mariner.ini
[2005/10/31 09:04:21 | 000,003,668 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/08/23 11:03:17 | 000,306,688 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[2005/08/23 11:03:17 | 000,095,232 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll
[2005/08/03 11:01:08 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2005/08/03 11:00:54 | 000,001,635 | —- | C] () – C:\WINDOWS\System32\WLAN.INI
[2005/05/10 11:20:38 | 000,093,696 | —- | C] () – C:\WINDOWS\System32\hpgt42.dll
[2005/04/30 12:35:38 | 000,000,071 | —- | C] () – C:\WINDOWS\pex.INI
[2005/04/27 17:17:19 | 000,000,151 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2005/04/27 16:44:22 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/04/26 21:17:56 | 000,061,678 | —- | C] () – C:\Documents and Settings\Dee\Application Data\PFP120JPR.{PB
[2005/04/26 21:17:56 | 000,012,358 | —- | C] () – C:\Documents and Settings\Dee\Application Data\PFP120JCM.{PB
[2005/04/26 19:23:35 | 000,006,602 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/04/25 20:10:41 | 000,000,126 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\fusioncache.dat
[2005/04/23 20:00:53 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2005/04/23 19:55:15 | 000,000,073 | —- | C] () – C:\WINDOWS\ldg.ini
[2005/04/23 19:54:34 | 000,000,776 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/04/23 19:54:34 | 000,000,282 | —- | C] () – C:\WINDOWS\pib.ini
[2005/04/20 14:45:41 | 000,000,070 | —- | C] () – C:\WINDOWS\D96E1E82.ini
[2005/04/20 11:13:15 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2005/04/20 11:11:40 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2005/04/20 11:11:40 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2005/04/18 16:38:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/04/14 00:07:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/14 00:05:58 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/04/13 23:31:02 | 000,000,370 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,882 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 05:00:00 | 000,199,168 | —- | C] () – C:\WINDOWS\unoravucuya.dll
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2009/11/23 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2007/10/27 11:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BellSouth
[2010/05/03 10:54:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2007/12/13 16:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/04/27 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/02/03 17:08:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/04/22 08:51:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2009/11/23 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\AT&T;
[2007/10/27 11:25:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\BellSouth
[2006/10/24 22:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Leadertech
[2010/08/03 13:26:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Sammsoft
[2010/07/24 10:42:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Ulead Systems
[2009/03/20 11:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Viewpoint
[2005/04/18 16:09:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2010/07/15 01:00:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2010/05/11 14:59:29 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2010/09/14 21:11:37 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/11/20 19:01:01 | 019,856,430 | —- | M] () – C:\BellSouthIW.re~
[2008/12/16 19:59:12 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/09/12 17:58:56 | 000,000,327 | RHS- | M] () – C:\BOOT.INI
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/04/13 23:34:32 | 000,004,403 | RH– | M] () – C:\DELL.SDR
[2005/08/23 10:43:27 | 000,547,952 | —- | M] () – C:\HPScanjet4200C.exe
[2004/08/10 13:14:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/04/14 00:03:13 | 000,000,770 | -H– | M] () – C:\IPH.PH
[2010/09/02 19:49:53 | 000,006,794 | —- | M] () – C:\JavaRa.log
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/02 21:10:40 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/09/14 20:51:04 | 838,860,800 | -HS- | M] () – C:\pagefile.sys
[2005/08/23 11:02:28 | 036,422,256 | —- | M] () – C:\sj655en.exe
[2008/02/28 19:28:53 | 000,000,495 | —- | M] () – C:\stub.log
[2005/04/14 00:03:22 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2005/05/10 16:14:32 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\hpzpp3xt.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/07/24 14:21:10 | 010,420,936 | —- | M] (Microsoft Corporation) – C:\Program Files\xlviewer.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/02 21:15:06 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/04/18 20:29:30 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/08/10 13:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-11 01:45:37
========== Alternate Data Streams ==========
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:18B7103A
< End of report >
OTL Extras logfile created on: 9/14/2010 9:14:11 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Dee\Desktop\computer tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 800 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.28 Gb Total Space | 58.44 Gb Free Space | 81.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 488.60 Mb Total Space | 76.61 Mb Free Space | 15.68% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RECTORY
Current User Name: Dee
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP1610\HP Software Update\HPWUCli.exe" = C:\Program Files\HP1610\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox – (Yahoo! Inc.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF}" = Radialpoint Security Services
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"{F24862FD-DDC7-490D-AC02-8797B575D6A9}" = SpaMsiWrapper
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Registry Optimizer_is1" = Advanced Registry Optimizer
"BellsouthHelpCenter4.0b_is1" = FastAccess® DSL Help Center 4.3
"blstoolbar" = AT&T; Toolbar
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"HD Tune_is1" = HD Tune 2.54
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"MSC" = McAfee SecurityCenter
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/5/2010 11:06:04 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/5/2010 11:06:04 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/5/2010 11:06:04 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/5/2010 11:06:05 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 9/11/2010 1:00:30 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 9/11/2010 1:00:30 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/14/2010 9:51:17 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: A connection with the server could not be established
Error - 9/14/2010 9:51:17 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: A connection with the server could not be established
Error - 9/14/2010 9:51:17 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: A connection with the server could not be established
Error - 9/14/2010 10:11:35 PM | Computer Name = RECTORY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 9/12/2010 6:31:29 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor
Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
Error - 9/12/2010 6:31:29 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor
Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
Error - 9/12/2010 6:31:48 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
Error - 9/12/2010 6:31:49 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
Error - 9/12/2010 6:40:42 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/12/2010 6:41:37 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2
Error - 9/12/2010 7:00:00 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2
Error - 9/14/2010 9:51:19 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2
Error - 9/14/2010 10:14:34 PM | Computer Name = RECTORY | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 9/14/2010 10:14:34 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2
< End of report >
The computer has Windows XP, SP3. My previous topic was [external image: Posted Image] Trojan_Zlob and other infection leftovers, computer slow, but improvin
I am attaching Malware Bytes logs and Otl reports. I would appreciate your help digging this one out again. Thank you!- Jcatsmom
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgDatabase version: 4532Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.187029/12/2010 4:20:34 PM
mbam-log-2010-09-12 (16-20-34).txtScan type: Quick scan
Objects scanned: 151502
Time elapsed: 10 minute(s), 4 second(s)Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2Memory Processes Infected:
(No malicious items detected)Memory Modules Infected:
(No malicious items detected)Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rsoqalds (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rsoqalds (Rogue.SecuritySuite) -> Quarantined and deleted successfully.Registry Data Items Infected:
(No malicious items detected)Folders Infected:
(No malicious items detected)Files Infected:
C:\Documents and Settings\Dee\Local Settings\Application Data\uyrbbgjwr\fpqwvyyuqiw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dee\Local Settings\Application Data\26630516.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgDatabase version: 4602Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.187029/12/2010 4:45:34 PM
mbam-log-2010-09-12 (16-45-34).txtScan type: Quick scan
Objects scanned: 154212
Time elapsed: 17 minute(s), 34 second(s)Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2Memory Processes Infected:
(No malicious items detected)Memory Modules Infected:
C:\WINDOWS\wuint12.dll (Trojan.Hiloti) -> Delete on reboot.Registry Keys Infected:
(No malicious items detected)Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tragevusukasev (Trojan.Hiloti) -> Quarantined and deleted successfully.Registry Data Items Infected:
(No malicious items detected)Folders Infected:
(No malicious items detected)Files Infected:
C:\WINDOWS\wuint12.dll (Trojan.Hiloti) -> Delete on reboot.
C:\Documents and Settings\Dee\Local Settings\Application Data\26630515.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
OTL logfile created on: 9/14/2010 9:14:11 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Dee\Desktop\computer tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 800 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.28 Gb Total Space | 58.44 Gb Free Space | 81.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 488.60 Mb Total Space | 76.61 Mb Free Space | 15.68% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RECTORY
Current User Name: Dee
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dee\Desktop\computer tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
PRC - C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Dee\Desktop\computer tools\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\McAfee\SiteAdvisor\sahook.dll ()
MOD - C:\WINDOWS\unoravucuya.dll ()
MOD - C:\WINDOWS\SYSTEM32\opengl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\glu32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\dciman32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (SAUSBHW) – C:\WINDOWS\System32\Drivers\sausb.sys File not found
DRV - (RPSKT) Security Services Driver (x86) – C:\WINDOWS\System32\DRIVERS\rp_skt32.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Dee\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (WUSB54GV4SRV) – C:\WINDOWS\SYSTEM32\DRIVERS\rt2500usb.sys (Ralink Technology Inc.)
DRV - (GTNDIS5) – C:\WINDOWS\SYSTEM32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (hp4200c) – C:\WINDOWS\SYSTEM32\DRIVERS\hp4200c.sys (Hewlett-Packard)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {60799329-5010-4EEA-B216-C7A87C230110}:1.9.1
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/23 12:24:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/09/12 08:55:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{60799329-5010-4EEA-B216-C7A87C230110}: C:\Documents and Settings\Dee\Local Settings\Application Data\{60799329-5010-4EEA-B216-C7A87C230110} [2010/09/11 16:17:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 23:04:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 23:04:24 | 000,000,000 | —D | M]
[2008/12/02 20:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Mozilla\Extensions
[2010/09/11 17:20:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions
[2010/09/04 12:44:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/11 17:20:18 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/09/03 23:41:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/09/03 23:41:34 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/09/01 19:45:52 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Lgirovaruyuq] C:\WINDOWS\unoravucuya.DLL ()
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: kaspersky.com ([www] http in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1151174868143 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx (Hotmail Attachments Control)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Dee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/08/14 11:43:06 | 000,000,000 | RHSD | M] - E:\autorun.inf – [ FAT ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Unable to start service SrService!
========== Files/Folders - Created Within 30 Days ==========
[2010/09/11 16:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Local Settings\Application Data\{60799329-5010-4EEA-B216-C7A87C230110}
[2010/09/11 16:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Local Settings\Application Data\uyrbbgjwr
[2010/09/06 17:01:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\My Documents\Dee's photos
[2010/09/03 23:42:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/03 23:41:49 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/03 23:41:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/03 23:41:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/03 23:41:49 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/03 13:51:17 | 000,000,000 | —D | C] – C:\Program Files\Eusing Free Registry Cleaner
[2010/09/02 21:40:05 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2010/09/02 21:14:20 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2010/09/02 21:06:27 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[2010/09/02 21:06:26 | 000,000,000 | —D | C] – C:\WINDOWS\EHome
[2010/09/02 20:51:29 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2010/09/02 18:23:23 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/09/02 18:23:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/02 18:22:54 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/01 19:39:25 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/09/01 19:32:51 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/08/30 08:05:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/30 07:24:11 | 000,000,000 | —D | C] – C:\Program Files\HD Tune
[2010/08/30 07:21:31 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/08/29 23:12:27 | 000,000,000 | —D | C] – C:\found.001
[2010/08/29 21:21:23 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\PrivacIE
[2010/08/28 22:02:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\IECompatCache
[2010/08/28 21:54:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\IETldCache
[2010/08/28 21:33:30 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/08/28 13:06:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Desktop\computer tools
[2010/08/28 12:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Application Data\Malwarebytes
[2010/08/28 12:41:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/28 12:41:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/28 12:41:26 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/28 12:41:26 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2008/07/24 14:20:40 | 010,420,936 | —- | C] (Microsoft Corporation) – C:\Program Files\xlviewer.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/14 21:11:37 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/14 20:51:10 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/14 20:51:07 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/09/14 20:51:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/09/12 18:05:16 | 004,194,304 | —- | M] () – C:\Documents and Settings\Dee\ntuser.dat
[2010/09/12 18:05:16 | 000,013,189 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/09/12 18:05:16 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Dee\NTUSER.INI
[2010/09/12 18:05:07 | 003,768,536 | -H– | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\IconCache.db
[2010/09/12 17:58:56 | 000,000,724 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/09/12 17:58:56 | 000,000,327 | RHS- | M] () – C:\BOOT.INI
[2010/09/12 17:58:56 | 000,000,256 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/12 16:17:06 | 000,000,444 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/09/12 08:43:51 | 000,002,838 | —- | M] () – C:\WINDOWS\owivanoqiqurih.dll
[2010/09/11 20:21:40 | 000,002,838 | —- | M] () – C:\WINDOWS\osedokezezocoh.dll
[2010/09/06 18:51:31 | 000,000,151 | —- | M] () – C:\WINDOWS\Ulead32.ini
[2010/09/06 17:06:18 | 000,000,071 | —- | M] () – C:\WINDOWS\pex.INI
[2010/09/06 16:57:38 | 000,058,080 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/04 13:09:00 | 000,224,816 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/03 23:41:32 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/03 23:41:32 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/03 23:41:32 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/03 23:41:32 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/03 23:41:31 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/03 18:29:48 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/03 18:28:12 | 000,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/03 18:28:12 | 000,442,466 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/09/03 18:28:12 | 000,071,732 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/09/03 13:51:54 | 077,652,368 | —- | M] () – C:\Documents and Settings\Dee\My Documents\regis bkup1.reg
[2010/09/03 11:29:09 | 000,000,036 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\housecall.guid.cache
[2010/09/02 21:10:40 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/09/02 20:37:39 | 000,219,648 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 19:45:52 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/08/28 21:54:56 | 000,000,815 | —- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/28 12:41:32 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/23 19:18:06 | 000,008,359 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Dee Eichler CV.wpd
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/12 16:17:06 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/09/12 08:43:51 | 000,002,838 | —- | C] () – C:\WINDOWS\owivanoqiqurih.dll
[2010/09/11 20:21:39 | 000,002,838 | —- | C] () – C:\WINDOWS\osedokezezocoh.dll
[2010/09/03 13:51:42 | 077,652,368 | —- | C] () – C:\Documents and Settings\Dee\My Documents\regis bkup1.reg
[2010/09/03 11:29:09 | 000,000,036 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\housecall.guid.cache
[2010/09/01 19:39:31 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/09/01 19:39:29 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/09/01 19:33:14 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/09/01 19:33:14 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/08/28 12:41:32 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/04/23 15:42:50 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/04/16 13:39:35 | 000,219,648 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/09 04:01:57 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/04/24 16:06:59 | 000,000,397 | R— | C] () – C:\WINDOWS\hpw9800k.ini
[2006/04/24 16:04:33 | 000,000,478 | —- | C] () – C:\WINDOWS\hpdj9800.ini
[2006/04/24 16:04:21 | 000,001,567 | —- | C] () – C:\WINDOWS\mariner.ini
[2005/10/31 09:04:21 | 000,003,668 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/08/23 11:03:17 | 000,306,688 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[2005/08/23 11:03:17 | 000,095,232 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll
[2005/08/03 11:01:08 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2005/08/03 11:00:54 | 000,001,635 | —- | C] () – C:\WINDOWS\System32\WLAN.INI
[2005/05/10 11:20:38 | 000,093,696 | —- | C] () – C:\WINDOWS\System32\hpgt42.dll
[2005/04/30 12:35:38 | 000,000,071 | —- | C] () – C:\WINDOWS\pex.INI
[2005/04/27 17:17:19 | 000,000,151 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2005/04/27 16:44:22 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/04/26 21:17:56 | 000,061,678 | —- | C] () – C:\Documents and Settings\Dee\Application Data\PFP120JPR.{PB
[2005/04/26 21:17:56 | 000,012,358 | —- | C] () – C:\Documents and Settings\Dee\Application Data\PFP120JCM.{PB
[2005/04/26 19:23:35 | 000,006,602 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/04/25 20:10:41 | 000,000,126 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\fusioncache.dat
[2005/04/23 20:00:53 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2005/04/23 19:55:15 | 000,000,073 | —- | C] () – C:\WINDOWS\ldg.ini
[2005/04/23 19:54:34 | 000,000,776 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/04/23 19:54:34 | 000,000,282 | —- | C] () – C:\WINDOWS\pib.ini
[2005/04/20 14:45:41 | 000,000,070 | —- | C] () – C:\WINDOWS\D96E1E82.ini
[2005/04/20 11:13:15 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2005/04/20 11:11:40 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2005/04/20 11:11:40 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2005/04/18 16:38:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/04/14 00:07:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/14 00:05:58 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/04/13 23:31:02 | 000,000,370 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,882 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 05:00:00 | 000,199,168 | —- | C] () – C:\WINDOWS\unoravucuya.dll
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2009/11/23 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2007/10/27 11:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BellSouth
[2010/05/03 10:54:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2007/12/13 16:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/04/27 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/02/03 17:08:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/04/22 08:51:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2009/11/23 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\AT&T;
[2007/10/27 11:25:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\BellSouth
[2006/10/24 22:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Leadertech
[2010/08/03 13:26:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Sammsoft
[2010/07/24 10:42:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Ulead Systems
[2009/03/20 11:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Viewpoint
[2005/04/18 16:09:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2010/07/15 01:00:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2010/05/11 14:59:29 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2010/09/14 21:11:37 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/11/20 19:01:01 | 019,856,430 | —- | M] () – C:\BellSouthIW.re~
[2008/12/16 19:59:12 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/09/12 17:58:56 | 000,000,327 | RHS- | M] () – C:\BOOT.INI
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/04/13 23:34:32 | 000,004,403 | RH– | M] () – C:\DELL.SDR
[2005/08/23 10:43:27 | 000,547,952 | —- | M] () – C:\HPScanjet4200C.exe
[2004/08/10 13:14:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/04/14 00:03:13 | 000,000,770 | -H– | M] () – C:\IPH.PH
[2010/09/02 19:49:53 | 000,006,794 | —- | M] () – C:\JavaRa.log
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/02 21:10:40 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2010/09/14 20:51:04 | 838,860,800 | -HS- | M] () – C:\pagefile.sys
[2005/08/23 11:02:28 | 036,422,256 | —- | M] () – C:\sj655en.exe
[2008/02/28 19:28:53 | 000,000,495 | —- | M] () – C:\stub.log
[2005/04/14 00:03:22 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2005/05/10 16:14:32 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\hpzpp3xt.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/07/24 14:21:10 | 010,420,936 | —- | M] (Microsoft Corporation) – C:\Program Files\xlviewer.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/09/02 21:15:06 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/04/18 20:29:30 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/08/10 13:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-11 01:45:37
========== Alternate Data Streams ==========
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:18B7103A
< End of report >
OTL Extras logfile created on: 9/14/2010 9:14:11 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Dee\Desktop\computer tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 800 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.28 Gb Total Space | 58.44 Gb Free Space | 81.99% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 488.60 Mb Total Space | 76.61 Mb Free Space | 15.68% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RECTORY
Current User Name: Dee
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\HP1610\HP Software Update\HPWUCli.exe" = C:\Program Files\HP1610\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox – (Yahoo! Inc.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF}" = Radialpoint Security Services
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"{F24862FD-DDC7-490D-AC02-8797B575D6A9}" = SpaMsiWrapper
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Registry Optimizer_is1" = Advanced Registry Optimizer
"BellsouthHelpCenter4.0b_is1" = FastAccess® DSL Help Center 4.3
"blstoolbar" = AT&T; Toolbar
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"HD Tune_is1" = HD Tune 2.54
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"MSC" = McAfee SecurityCenter
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/5/2010 11:06:04 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/5/2010 11:06:04 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/5/2010 11:06:04 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/5/2010 11:06:05 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 9/11/2010 1:00:30 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 9/11/2010 1:00:30 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 9/14/2010 9:51:17 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: A connection with the server could not be established
Error - 9/14/2010 9:51:17 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: A connection with the server could not be established
Error - 9/14/2010 9:51:17 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: A connection with the server could not be established
Error - 9/14/2010 10:11:35 PM | Computer Name = RECTORY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 9/12/2010 6:31:29 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor
Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
Error - 9/12/2010 6:31:29 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor
Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
Error - 9/12/2010 6:31:48 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
Error - 9/12/2010 6:31:49 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
Error - 9/12/2010 6:40:42 PM | Computer Name = RECTORY | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/12/2010 6:41:37 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2
Error - 9/12/2010 7:00:00 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2
Error - 9/14/2010 9:51:19 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2
Error - 9/14/2010 10:14:34 PM | Computer Name = RECTORY | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 9/14/2010 10:14:34 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2
< End of report >