shahmce
Topic Starter
here is the OTL
OTL logfile created on: 9/22/2010 5:46:58 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Wati\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.32 Gb Total Space | 162.41 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 270.44 Gb Total Space | 267.10 Gb Free Space | 98.76% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 239.53 Mb Total Space | 25.98 Mb Free Space | 10.85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: UBS
Current User Name: Wati
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Wati\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Wati\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - D:\OpenDrive\shah\OpenDrive_Tray.exe ()
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\ParetoLogic\FileCure\FileCure.exe (ParetoLogic)
PRC - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAV.exe (PC Tools Research Pty Ltd)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - D:\UBSACC90\NETWORK\Serialkey\UBSLicenseService.exe (home)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Wati\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (USBLAN_Ldr) – E:\Ubs\Network\V92\Service\USBLAN_Ldr.EXE File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PCTAVSvc) – C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (UBSLicense) – D:\UBSACC90\NETWORK\Serialkey\UBSLicenseService.exe (home)
========== Driver Services (SafeList) ==========
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AVRec) – C:\WINDOWS\system32\drivers\AVRec.sys (PC Tools Research Pty Ltd )
DRV - (AVHook) – C:\WINDOWS\system32\drivers\AVHook.sys (PC Tools Research Pty Ltd.)
DRV - (AVFilter) – C:\WINDOWS\system32\drivers\AVFilter.sys (PC Tools Research Pty Ltd)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "data:text/plain,browser.startup.homepage=http://malaysia.search.yahoo.com/firefox/?fr=yff35k-sfp"
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://my.search.yahoo.com/search?ei=UTF-8&fr=yff35kawe&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "ToggleEN Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://malaysia.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://malaysia.search.yahoo.com/firefox/?fr=yff35k-sfp"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {210779b6-fbf4-42ea-97f2-570782d136a3}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {038cb5c7-48ea-4af9-94e0-a1646542e62b}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:[removed]
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/30 12:14:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/14 03:49:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/06 13:54:34 | 000,000,000 | —D | M]
[2010/07/14 03:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Extensions
[2010/08/28 12:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions
[2010/08/03 13:10:18 | 000,000,000 | —D | M] (ToggleEN Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
[2010/08/03 13:05:35 | 000,000,000 | —D | M] (Overget Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{210779b6-fbf4-42ea-97f2-570782d136a3}
[2010/08/24 16:48:21 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/03 13:25:11 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/08/18 13:44:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/08/03 13:16:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\[removed]
[2010/06/30 19:22:32 | 000,000,919 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\searchplugins\conduit.xml
[2010/08/23 14:13:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/14 03:49:10 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
O1 HOSTS File: ([2010/06/22 03:43:01 | 000,012,407 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: '>http://www.w3.org/TR/html4/strict.dtd">
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Yahoo! GeoCities: Get a web site with easy-to-use site building tools.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: 90 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ToggleEN Toolbar) - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OpenDrive Tray] D:\OpenDrive\shah\OpenDrive_Tray.exe ()
O4 - HKLM..\Run: [PCTAVApp] C:\Program Files\PC Tools AntiVirus\PCTAV.exe (PC Tools Research Pty Ltd)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Wati\Start Menu\Programs\Startup\1E0D1C.lnk = C:\WINDOWS\System32\414227\1E0D1C.EXE File not found
O4 - Startup: C:\Documents and Settings\Wati\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Wati\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/18 09:00:05 | 000,000,007 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{722cd71c-a681-11df-8db0-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{722cd71c-a681-11df-8db0-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{788fe03b-9def-11df-8d9f-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{788fe03b-9def-11df-8d9f-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\1\Command - "" = G:\Recycle.exe – File not found
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\2\Command - "" = G:\Recycle.exe – File not found
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\AutoRun\command - "" = qevfra.exe
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\explore\Command - "" = qevfra.exe
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\open\Command - "" = qevfra.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: hoffwr - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: lyixs - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: smkckp - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: yobykmkdf - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: vkxohf - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: ycppmaor - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: dzgooky - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: yjerilywj - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: zlxylksc - C:\WINDOWS\System32\crwrw.dll File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - xvidvfw.dll File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/22 17:38:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/09/22 17:38:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/09/18 13:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2010/09/15 08:50:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Wati\Recent
[2010/09/09 11:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\New Folder
[2010/09/08 09:34:08 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\IECompatCache
[2010/09/04 10:35:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\OpenDrive
[2010/09/04 10:13:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\Gygan Downloads
[2010/09/04 10:13:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Application Data\Gygan
[2010/09/04 10:13:43 | 000,000,000 | —D | C] – C:\Program Files\Xenocode
[2010/09/04 10:13:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Xenocode
[2010/09/04 10:13:41 | 000,000,000 | —D | C] – C:\Program Files\Gygan BETA
[2010/09/01 12:00:59 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\PrivacIE
[2010/09/01 11:53:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\IETldCache
[2010/09/01 11:45:20 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2010/09/01 11:44:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/09/01 11:44:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/08/30 14:57:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Deployment
[2010/08/27 15:16:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Conduit
[2010/08/27 15:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ParetoLogic
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/08/26 13:36:06 | 000,000,000 | —D | C] – C:\Program Files\ParetoLogic
[2010/08/26 11:13:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\shah
[2010/08/26 10:39:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\audex
[2010/08/26 09:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\acc
[2010/08/24 17:03:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Yahoo
[2010/08/24 16:48:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2010/08/24 16:48:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Application Data\Yahoo!
[2010/08/24 16:47:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2010/08/24 15:43:47 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/22 17:50:40 | 000,000,374 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/22 17:40:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/09/22 17:40:01 | 000,000,378 | —- | M] () – C:\WINDOWS\tasks\FileCure Startup.job
[2010/09/22 17:40:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/22 17:39:59 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/22 17:39:26 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Wati\NTUSER.DAT
[2010/09/22 17:39:04 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Wati\ntuser.ini
[2010/09/22 17:38:44 | 000,000,826 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/22 17:38:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/22 17:36:10 | 000,157,074 | —- | M] () – C:\WINDOWS\System32\x
[2010/09/22 17:08:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/09/22 17:02:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003UA.job
[2010/09/22 17:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/09/22 15:02:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003Core.job
[2010/09/21 15:41:29 | 000,059,904 | —- | M] () – C:\Documents and Settings\Wati\My Documents\BANK RECON AUG 2010.xls
[2010/09/21 15:28:39 | 001,712,720 | —- | M] () – C:\Documents and Settings\Wati\My Documents\How%20To%20Register%20a%20Business%20Online%20Using%20SSM%20ebook.pdf
[2010/09/18 14:02:20 | 000,002,283 | —- | M] () – C:\Documents and Settings\Wati\Desktop\Google Chrome.lnk
[2010/09/18 14:02:20 | 000,002,261 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/09/17 16:31:59 | 000,016,896 | —- | M] () – C:\Documents and Settings\Wati\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 16:31:59 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/09/17 13:50:15 | 000,202,240 | —- | M] () – C:\Documents and Settings\Wati\Desktop\PPE2010.xls
[2010/09/13 18:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2010/09/13 02:04:00 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\FileCure Default.job
[2010/09/11 05:42:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2010/09/09 16:57:04 | 000,067,584 | —- | M] () – C:\Documents and Settings\Wati\My Documents\draft FS - aug 2010.xls
[2010/09/09 11:32:01 | 000,000,123 | —- | M] () – C:\Documents and Settings\Wati\Application Data\default.rss
[2010/09/08 15:57:24 | 000,025,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JVJUL.xls
[2010/09/08 15:57:12 | 000,027,136 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JVAUG.xls
[2010/09/08 15:56:50 | 000,025,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JV.xls
[2010/09/07 18:22:05 | 004,813,446 | -H– | M] () – C:\Documents and Settings\Wati\Local Settings\Application Data\IconCache.db
[2010/09/07 12:44:02 | 000,156,250 | —- | M] () – C:\Documents and Settings\Wati\Desktop\newcf.xlsx
[2010/09/06 16:46:29 | 000,013,513 | —- | M] () – C:\Documents and Settings\Wati\Desktop\Purchase Order Form.docx
[2010/09/05 15:39:01 | 000,000,810 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/09/04 12:10:11 | 000,001,448 | —- | M] () – C:\Documents and Settings\All Users\Desktop\UBS Accounting System 9.2 (SR2).lnk
[2010/09/04 10:13:41 | 000,000,627 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Gygan.lnk
[2010/09/03 15:04:13 | 000,192,000 | —- | M] () – C:\Documents and Settings\Wati\My Documents\Presentation1.ppt
[2010/09/03 14:42:23 | 000,437,346 | —- | M] () – C:\Documents and Settings\Wati\My Documents\The%20letters%20of%20the%20Prophet%20Muhammad%20to%20the%20Kings%20beyond%20Arabia.pdf
[2010/09/02 14:02:08 | 000,000,160 | —- | M] () – C:\Documents and Settings\Wati\default.pls
[2010/09/02 10:10:39 | 000,009,485 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MCELEMAILDIRECTORY.xlsx
[2010/09/01 11:53:58 | 000,000,821 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/01 11:45:33 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/30 14:56:59 | 000,021,163 | —- | M] () – C:\Documents and Settings\Wati\My Documents\Contoh%20Kertas%20Kerja.pdf
[2010/08/30 09:42:49 | 000,173,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MULTI PHONE DIRECTORY.TIF
[2010/08/28 15:40:48 | 001,683,456 | —- | M] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls
[2010/08/28 15:40:39 | 000,192,000 | —- | M] () – C:\Documents and Settings\Wati\Desktop\7Excel Format- Tables(latest).xls
[2010/08/28 15:25:20 | 001,738,752 | —- | M] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls1.xls
[2010/08/27 14:33:22 | 001,680,896 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MCELOG_Budget_201112 (3).xls
[2010/08/27 14:32:02 | 000,187,392 | —- | M] () – C:\Documents and Settings\Wati\My Documents\7Excel Format- Tables(latest).xls
[2010/08/26 13:36:07 | 000,000,918 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,900 | —- | M] () – C:\Documents and Settings\Wati\My Documents\ParetoLogic FileCure.lnk
[2010/08/24 16:48:24 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/08/24 16:47:55 | 000,000,826 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/22 17:47:23 | 000,000,374 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/22 17:38:44 | 000,000,826 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/22 17:36:10 | 000,157,074 | —- | C] () – C:\WINDOWS\System32\x
[2010/09/21 15:41:29 | 000,059,904 | —- | C] () – C:\Documents and Settings\Wati\My Documents\BANK RECON AUG 2010.xls
[2010/09/21 15:28:39 | 001,712,720 | —- | C] () – C:\Documents and Settings\Wati\My Documents\How%20To%20Register%20a%20Business%20Online%20Using%20SSM%20ebook.pdf
[2010/09/17 10:41:13 | 000,202,240 | —- | C] () – C:\Documents and Settings\Wati\Desktop\PPE2010.xls
[2010/09/09 16:57:04 | 000,067,584 | —- | C] () – C:\Documents and Settings\Wati\My Documents\draft FS - aug 2010.xls
[2010/09/08 15:57:12 | 000,027,136 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JVAUG.xls
[2010/09/08 15:56:49 | 000,025,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JV.xls
[2010/09/08 15:56:25 | 000,025,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JVJUL.xls
[2010/09/04 10:13:41 | 000,000,627 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Gygan.lnk
[2010/09/03 15:04:11 | 000,192,000 | —- | C] () – C:\Documents and Settings\Wati\My Documents\Presentation1.ppt
[2010/09/03 14:42:23 | 000,437,346 | —- | C] () – C:\Documents and Settings\Wati\My Documents\The%20letters%20of%20the%20Prophet%20Muhammad%20to%20the%20Kings%20beyond%20Arabia.pdf
[2010/09/02 10:10:39 | 000,009,485 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MCELEMAILDIRECTORY.xlsx
[2010/08/30 15:04:25 | 000,002,283 | —- | C] () – C:\Documents and Settings\Wati\Desktop\Google Chrome.lnk
[2010/08/30 15:04:25 | 000,002,261 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/30 14:57:56 | 000,000,974 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003UA.job
[2010/08/30 14:57:56 | 000,000,922 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003Core.job
[2010/08/30 14:56:59 | 000,021,163 | —- | C] () – C:\Documents and Settings\Wati\My Documents\Contoh%20Kertas%20Kerja.pdf
[2010/08/30 09:42:48 | 000,173,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MULTI PHONE DIRECTORY.TIF
[2010/08/28 14:05:05 | 001,738,752 | —- | C] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls1.xls
[2010/08/28 09:08:26 | 001,683,456 | —- | C] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls
[2010/08/28 09:08:26 | 000,192,000 | —- | C] () – C:\Documents and Settings\Wati\Desktop\7Excel Format- Tables(latest).xls
[2010/08/27 14:33:21 | 001,680,896 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MCELOG_Budget_201112 (3).xls
[2010/08/27 14:32:02 | 000,187,392 | —- | C] () – C:\Documents and Settings\Wati\My Documents\7Excel Format- Tables(latest).xls
[2010/08/26 13:36:12 | 000,000,442 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2010/08/26 13:36:09 | 000,000,378 | —- | C] () – C:\WINDOWS\tasks\FileCure Startup.job
[2010/08/26 13:36:09 | 000,000,362 | —- | C] () – C:\WINDOWS\tasks\FileCure Default.job
[2010/08/26 13:36:07 | 000,000,918 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,900 | —- | C] () – C:\Documents and Settings\Wati\My Documents\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2010/08/24 16:48:24 | 000,262,144 | —- | C] () – C:\ntuser.dat
[2010/08/24 16:47:55 | 000,000,826 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/08/18 09:27:20 | 000,012,407 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\Bron.tok.A12.em.bin
[2010/08/16 17:28:07 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.12.Bron.Tok.bin
[2010/08/16 17:22:03 | 000,000,349 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\BronFoldNetDomList.txt
[2010/08/16 17:18:18 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A12.em.bin
[2010/08/11 11:29:38 | 000,000,123 | —- | C] () – C:\Documents and Settings\Wati\Application Data\default.rss
[2010/08/11 11:03:41 | 000,169,608 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/03 13:12:03 | 000,000,085 | —- | C] () – C:\Documents and Settings\Wati\Application Data\toolbar_log.txt
[2010/07/30 11:31:30 | 000,014,022 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/07/23 08:14:06 | 000,000,051 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
[2010/07/23 08:08:31 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ListHost12.txt
[2010/07/23 03:11:01 | 000,016,896 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/15 03:57:34 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/07/10 06:42:35 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/07/10 06:36:49 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2010/06/22 05:03:58 | 000,000,552 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\NetMailTmp.bin
[2010/06/22 03:43:01 | 000,012,407 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\ListHost12.txt
[2007/11/20 06:42:56 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\XYNetComClient.dll
[2007/07/27 20:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/01/11 21:02:03 | 000,026,190 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\NetMailTmp.bin
========== LOP Check ==========
[2010/08/03 13:40:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/09/05 15:38:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/08/26 13:36:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/09/22 17:40:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/03 14:47:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\AskToolbar
[2010/09/21 17:55:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\BitTorrent
[2010/08/03 13:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\DVDVideoSoftIEHelpers
[2010/08/13 09:12:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\FreeFileViewer
[2010/09/04 10:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Gygan
[2010/09/22 12:21:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\PriceGong
[2010/07/29 16:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\RadioBar
[2010/09/22 17:08:00 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010/09/13 02:04:00 | 000,000,362 | —- | M] () – C:\WINDOWS\Tasks\FileCure Default.job
[2010/09/22 17:40:01 | 000,000,378 | —- | M] () – C:\WINDOWS\Tasks\FileCure Startup.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/22 17:50:40 | 000,000,374 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2010/09/13 18:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2010/09/11 05:42:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2010/09/22 17:40:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job
[2010/09/22 17:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/08/18 09:00:05 | 000,000,007 | -HS- | M] () – C:\AUTOEXEC.BAT
[2010/07/10 06:23:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/07/10 06:28:16 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/10 06:28:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/10 06:28:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/27 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2007/07/27 20:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/08/24 16:48:24 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/08/24 16:48:24 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2010/09/22 17:39:57 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/19 20:21:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/07/02 22:37:10 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/19 20:21:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/07/02 22:37:12 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/07/10 06:28:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/14 16:43:18 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2006/10/27 10:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2006/10/14 16:44:44 | 000,671,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/07/09 23:17:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/07/09 23:17:02 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/07/09 23:17:02 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/10 06:28:20 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/10 06:31:32 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/10 06:31:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >
OTL Extras logfile created on: 9/22/2010 5:46:58 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Wati\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.32 Gb Total Space | 162.41 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 270.44 Gb Total Space | 267.10 Gb Free Space | 98.76% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 239.53 Mb Total Space | 25.98 Mb Free Space | 10.85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: UBS
Current User Name: Wati
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\Wati\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\ParetoLogic\FileCure\FileCure_noapp.exe %1 (ParetoLogic)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"2033:TCP" = 2033:TCP:LocalSubNet:Enabled:UBS Licensing Daemon
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"2033:TCP" = 2033:TCP:LocalSubNet:Enabled:UBS Licensing Daemon
"3145:TCP" = 3145:TCP:*:Enabled:hhrtfdev
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – File not found
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"E:\Ubs\Network\V92\Service\UsbServer2k.exe" = E:\Ubs\Network\V92\Service\UsbServer2k.exe:*:Enabled:UsbLanServer – File not found
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE – (Software 2000 Limited)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – File not found
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{12345678-1234-1234-1234-12345678911C}" = UBS Accounting System 9.2 (SR2)
"{12345678-1234-1234-1234-12345678921A}" = UBS Inventory & Billing 9.2 (SR2)
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1AA4E6C7-6ED7-4A0B-BBA0-D7D579CF6793}" = OpenDrive
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision Help
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{714DAA5E-803F-44A2-8512-64F26E681030}_is1" = Gygan
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{A20A58C4-6784-4B4B-86CC-94E2E3671033}" = Nero 7 Ultra Edition
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{b86754dd-2ddb-4ac0-9015-cb487277254e}" = InCD Help
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C1C441C4-57FA-4950-BDBA-BABFBAA2AA39}" = ParetoLogic FileCure
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}" = HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{eb2ffb1e-d1d1-4f6a-8e8a-cda5bff40283}" = Nero 9 Essentials
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitTorrent" = BitTorrent
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"PC Tools AntiVirus_is1" = PC Tools AntiVirus 6.0
"SelfAccounts" = SelfAccounts 2.0
"ToggleEN Toolbar" = ToggleEN Toolbar
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/17/2010 4:51:23 AM | Computer Name = UBS | Source = Microsoft Office 12 | ID = 5000
Description = EventType officelifeboathang, P1 outlook.exe, P2 12.0.4518.1014, P3
ntdll.dll, P4 5.1.2600.2180, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:40:21 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:40:41 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:40:42 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:40:45 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:40:56 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:41:00 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:41:01 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:41:03 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:51:31 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
[ OSession Events ]
Error - 7/30/2010 12:06:11 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10052
seconds with 1080 seconds of active time. This session ended with a crash.
Error - 7/31/2010 2:02:25 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7404
seconds with 0 seconds of active time. This session ended with a crash.
Error - 8/11/2010 11:31:52 PM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6006
seconds with 1800 seconds of active time. This session ended with a crash.
Error - 8/30/2010 2:54:12 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 848
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Support Center service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Shell Security service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7000
Description = The USBLAN_Ldr service failed to start due to the following error:
%%21
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Helper Universal service terminated with the following error:
%%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Driver Shell service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Helper Boot service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Monitor Network service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Monitor Config service terminated with the following error: %%126
Error - 9/22/2010 5:51:29 AM | Computer Name = UBS | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147618124
User:
UBS\Wati Name: Worm:Win32/Conficker.B ID: 2147618124 Severity: Severe Category: Worm
Path:
Action: %%808 Error Code: 0x80070032 Error description: The request is not supported.
Status: Signature Version: AV: 1.91.343.0, AS: 1.91.343.0 Engine Version: 1.1.6201.0
Error - 9/22/2010 5:51:29 AM | Computer Name = UBS | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147618124
User:
UBS\Wati Name: Worm:Win32/Conficker.B ID: 2147618124 Severity: Severe Category: Worm
Path:
Action: %%809 Error Code: 0x80070032 Error description: The request is not supported.
Status: Signature Version: AV: 1.91.343.0, AS: 1.91.343.0 Engine Version: 1.1.6201.0
< End of report >
OTL logfile created on: 9/22/2010 5:46:58 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Wati\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.32 Gb Total Space | 162.41 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 270.44 Gb Total Space | 267.10 Gb Free Space | 98.76% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 239.53 Mb Total Space | 25.98 Mb Free Space | 10.85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: UBS
Current User Name: Wati
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Wati\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Wati\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - D:\OpenDrive\shah\OpenDrive_Tray.exe ()
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\ParetoLogic\FileCure\FileCure.exe (ParetoLogic)
PRC - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\PC Tools AntiVirus\PCTAV.exe (PC Tools Research Pty Ltd)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - D:\UBSACC90\NETWORK\Serialkey\UBSLicenseService.exe (home)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Wati\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (USBLAN_Ldr) – E:\Ubs\Network\V92\Service\USBLAN_Ldr.EXE File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PCTAVSvc) – C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (PC Tools Research Pty Ltd)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (UBSLicense) – D:\UBSACC90\NETWORK\Serialkey\UBSLicenseService.exe (home)
========== Driver Services (SafeList) ==========
DRV - (MpFilter) – C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AVRec) – C:\WINDOWS\system32\drivers\AVRec.sys (PC Tools Research Pty Ltd )
DRV - (AVHook) – C:\WINDOWS\system32\drivers\AVHook.sys (PC Tools Research Pty Ltd.)
DRV - (AVFilter) – C:\WINDOWS\system32\drivers\AVFilter.sys (PC Tools Research Pty Ltd)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "data:text/plain,browser.startup.homepage=http://malaysia.search.yahoo.com/firefox/?fr=yff35k-sfp"
FF - prefs.js..CommunityToolbar.SearchFromAddressBarSavedUrl: "data:text/plain,keyword.URL=http://my.search.yahoo.com/search?ei=UTF-8&fr=yff35kawe&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "ToggleEN Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://malaysia.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://malaysia.search.yahoo.com/firefox/?fr=yff35k-sfp"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {210779b6-fbf4-42ea-97f2-570782d136a3}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {038cb5c7-48ea-4af9-94e0-a1646542e62b}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:[removed]
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/07/30 12:14:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/14 03:49:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/06 13:54:34 | 000,000,000 | —D | M]
[2010/07/14 03:49:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Extensions
[2010/08/28 12:25:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions
[2010/08/03 13:10:18 | 000,000,000 | —D | M] (ToggleEN Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
[2010/08/03 13:05:35 | 000,000,000 | —D | M] (Overget Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{210779b6-fbf4-42ea-97f2-570782d136a3}
[2010/08/24 16:48:21 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/03 13:25:11 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/08/18 13:44:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/08/03 13:16:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\extensions\[removed]
[2010/06/30 19:22:32 | 000,000,919 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Mozilla\Firefox\Profiles\4v2601n8.default\searchplugins\conduit.xml
[2010/08/23 14:13:41 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/14 03:49:10 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
O1 HOSTS File: ([2010/06/22 03:43:01 | 000,012,407 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: '>http://www.w3.org/TR/html4/strict.dtd">
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: Yahoo! GeoCities: Get a web site with easy-to-use site building tools.
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts:
O1 - Hosts: 90 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ToggleEN Toolbar) - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files\DVDVideoSoftTB\tbDVD0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OpenDrive Tray] D:\OpenDrive\shah\OpenDrive_Tray.exe ()
O4 - HKLM..\Run: [PCTAVApp] C:\Program Files\PC Tools AntiVirus\PCTAV.exe (PC Tools Research Pty Ltd)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Wati\Start Menu\Programs\Startup\1E0D1C.lnk = C:\WINDOWS\System32\414227\1E0D1C.EXE File not found
O4 - Startup: C:\Documents and Settings\Wati\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Wati\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/18 09:00:05 | 000,000,007 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{30ee205e-a8d8-11df-8dbd-406186e2533e}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{722cd71c-a681-11df-8db0-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{722cd71c-a681-11df-8db0-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{788fe03b-9def-11df-8d9f-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{788fe03b-9def-11df-8d9f-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell - "" = AutoRun
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\1\Command - "" = G:\Recycle.exe – File not found
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\2\Command - "" = G:\Recycle.exe – File not found
O33 - MountPoints2\{c4821bfe-a446-11df-8da8-406186e2533e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\AutoRun\command - "" = qevfra.exe
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\explore\Command - "" = qevfra.exe
O33 - MountPoints2\{ffb7c588-94e3-11df-8d89-406186e2533e}\Shell\open\Command - "" = qevfra.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: hoffwr - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: lyixs - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: smkckp - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: yobykmkdf - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: vkxohf - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: ycppmaor - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: dzgooky - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: yjerilywj - C:\WINDOWS\System32\crwrw.dll File not found
NetSvcs: zlxylksc - C:\WINDOWS\System32\crwrw.dll File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - xvidvfw.dll File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/22 17:38:43 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/09/22 17:38:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/09/18 13:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\McAfee
[2010/09/15 08:50:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Wati\Recent
[2010/09/09 11:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\New Folder
[2010/09/08 09:34:08 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\IECompatCache
[2010/09/04 10:35:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\OpenDrive
[2010/09/04 10:13:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\Gygan Downloads
[2010/09/04 10:13:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Application Data\Gygan
[2010/09/04 10:13:43 | 000,000,000 | —D | C] – C:\Program Files\Xenocode
[2010/09/04 10:13:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Xenocode
[2010/09/04 10:13:41 | 000,000,000 | —D | C] – C:\Program Files\Gygan BETA
[2010/09/01 12:00:59 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\PrivacIE
[2010/09/01 11:53:56 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Wati\IETldCache
[2010/09/01 11:45:20 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2010/09/01 11:44:28 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/09/01 11:44:20 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/08/30 14:57:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Deployment
[2010/08/27 15:16:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Conduit
[2010/08/27 15:16:21 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ParetoLogic
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/08/26 13:36:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/08/26 13:36:06 | 000,000,000 | —D | C] – C:\Program Files\ParetoLogic
[2010/08/26 11:13:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\shah
[2010/08/26 10:39:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\audex
[2010/08/26 09:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\My Documents\acc
[2010/08/24 17:03:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Local Settings\Application Data\Yahoo
[2010/08/24 16:48:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2010/08/24 16:48:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Wati\Application Data\Yahoo!
[2010/08/24 16:47:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2010/08/24 15:43:47 | 000,000,000 | —D | C] – C:\Program Files\Yahoo!
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/22 17:50:40 | 000,000,374 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/22 17:40:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\PCConfidential.job
[2010/09/22 17:40:01 | 000,000,378 | —- | M] () – C:\WINDOWS\tasks\FileCure Startup.job
[2010/09/22 17:40:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/22 17:39:59 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/22 17:39:26 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Wati\NTUSER.DAT
[2010/09/22 17:39:04 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Wati\ntuser.ini
[2010/09/22 17:38:44 | 000,000,826 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/22 17:38:11 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/22 17:36:10 | 000,157,074 | —- | M] () – C:\WINDOWS\System32\x
[2010/09/22 17:08:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/09/22 17:02:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003UA.job
[2010/09/22 17:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/09/22 15:02:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003Core.job
[2010/09/21 15:41:29 | 000,059,904 | —- | M] () – C:\Documents and Settings\Wati\My Documents\BANK RECON AUG 2010.xls
[2010/09/21 15:28:39 | 001,712,720 | —- | M] () – C:\Documents and Settings\Wati\My Documents\How%20To%20Register%20a%20Business%20Online%20Using%20SSM%20ebook.pdf
[2010/09/18 14:02:20 | 000,002,283 | —- | M] () – C:\Documents and Settings\Wati\Desktop\Google Chrome.lnk
[2010/09/18 14:02:20 | 000,002,261 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/09/17 16:31:59 | 000,016,896 | —- | M] () – C:\Documents and Settings\Wati\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 16:31:59 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/09/17 13:50:15 | 000,202,240 | —- | M] () – C:\Documents and Settings\Wati\Desktop\PPE2010.xls
[2010/09/13 18:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2010/09/13 02:04:00 | 000,000,362 | —- | M] () – C:\WINDOWS\tasks\FileCure Default.job
[2010/09/11 05:42:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2010/09/09 16:57:04 | 000,067,584 | —- | M] () – C:\Documents and Settings\Wati\My Documents\draft FS - aug 2010.xls
[2010/09/09 11:32:01 | 000,000,123 | —- | M] () – C:\Documents and Settings\Wati\Application Data\default.rss
[2010/09/08 15:57:24 | 000,025,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JVJUL.xls
[2010/09/08 15:57:12 | 000,027,136 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JVAUG.xls
[2010/09/08 15:56:50 | 000,025,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\JV.xls
[2010/09/07 18:22:05 | 004,813,446 | -H– | M] () – C:\Documents and Settings\Wati\Local Settings\Application Data\IconCache.db
[2010/09/07 12:44:02 | 000,156,250 | —- | M] () – C:\Documents and Settings\Wati\Desktop\newcf.xlsx
[2010/09/06 16:46:29 | 000,013,513 | —- | M] () – C:\Documents and Settings\Wati\Desktop\Purchase Order Form.docx
[2010/09/05 15:39:01 | 000,000,810 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/09/04 12:10:11 | 000,001,448 | —- | M] () – C:\Documents and Settings\All Users\Desktop\UBS Accounting System 9.2 (SR2).lnk
[2010/09/04 10:13:41 | 000,000,627 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Gygan.lnk
[2010/09/03 15:04:13 | 000,192,000 | —- | M] () – C:\Documents and Settings\Wati\My Documents\Presentation1.ppt
[2010/09/03 14:42:23 | 000,437,346 | —- | M] () – C:\Documents and Settings\Wati\My Documents\The%20letters%20of%20the%20Prophet%20Muhammad%20to%20the%20Kings%20beyond%20Arabia.pdf
[2010/09/02 14:02:08 | 000,000,160 | —- | M] () – C:\Documents and Settings\Wati\default.pls
[2010/09/02 10:10:39 | 000,009,485 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MCELEMAILDIRECTORY.xlsx
[2010/09/01 11:53:58 | 000,000,821 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/01 11:45:33 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/30 14:56:59 | 000,021,163 | —- | M] () – C:\Documents and Settings\Wati\My Documents\Contoh%20Kertas%20Kerja.pdf
[2010/08/30 09:42:49 | 000,173,088 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MULTI PHONE DIRECTORY.TIF
[2010/08/28 15:40:48 | 001,683,456 | —- | M] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls
[2010/08/28 15:40:39 | 000,192,000 | —- | M] () – C:\Documents and Settings\Wati\Desktop\7Excel Format- Tables(latest).xls
[2010/08/28 15:25:20 | 001,738,752 | —- | M] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls1.xls
[2010/08/27 14:33:22 | 001,680,896 | —- | M] () – C:\Documents and Settings\Wati\My Documents\MCELOG_Budget_201112 (3).xls
[2010/08/27 14:32:02 | 000,187,392 | —- | M] () – C:\Documents and Settings\Wati\My Documents\7Excel Format- Tables(latest).xls
[2010/08/26 13:36:07 | 000,000,918 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,900 | —- | M] () – C:\Documents and Settings\Wati\My Documents\ParetoLogic FileCure.lnk
[2010/08/24 16:48:24 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/08/24 16:47:55 | 000,000,826 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/22 17:47:23 | 000,000,374 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/22 17:38:44 | 000,000,826 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/22 17:36:10 | 000,157,074 | —- | C] () – C:\WINDOWS\System32\x
[2010/09/21 15:41:29 | 000,059,904 | —- | C] () – C:\Documents and Settings\Wati\My Documents\BANK RECON AUG 2010.xls
[2010/09/21 15:28:39 | 001,712,720 | —- | C] () – C:\Documents and Settings\Wati\My Documents\How%20To%20Register%20a%20Business%20Online%20Using%20SSM%20ebook.pdf
[2010/09/17 10:41:13 | 000,202,240 | —- | C] () – C:\Documents and Settings\Wati\Desktop\PPE2010.xls
[2010/09/09 16:57:04 | 000,067,584 | —- | C] () – C:\Documents and Settings\Wati\My Documents\draft FS - aug 2010.xls
[2010/09/08 15:57:12 | 000,027,136 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JVAUG.xls
[2010/09/08 15:56:49 | 000,025,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JV.xls
[2010/09/08 15:56:25 | 000,025,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\JVJUL.xls
[2010/09/04 10:13:41 | 000,000,627 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Gygan.lnk
[2010/09/03 15:04:11 | 000,192,000 | —- | C] () – C:\Documents and Settings\Wati\My Documents\Presentation1.ppt
[2010/09/03 14:42:23 | 000,437,346 | —- | C] () – C:\Documents and Settings\Wati\My Documents\The%20letters%20of%20the%20Prophet%20Muhammad%20to%20the%20Kings%20beyond%20Arabia.pdf
[2010/09/02 10:10:39 | 000,009,485 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MCELEMAILDIRECTORY.xlsx
[2010/08/30 15:04:25 | 000,002,283 | —- | C] () – C:\Documents and Settings\Wati\Desktop\Google Chrome.lnk
[2010/08/30 15:04:25 | 000,002,261 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/08/30 14:57:56 | 000,000,974 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003UA.job
[2010/08/30 14:57:56 | 000,000,922 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1214440339-839522115-1003Core.job
[2010/08/30 14:56:59 | 000,021,163 | —- | C] () – C:\Documents and Settings\Wati\My Documents\Contoh%20Kertas%20Kerja.pdf
[2010/08/30 09:42:48 | 000,173,088 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MULTI PHONE DIRECTORY.TIF
[2010/08/28 14:05:05 | 001,738,752 | —- | C] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls1.xls
[2010/08/28 09:08:26 | 001,683,456 | —- | C] () – C:\Documents and Settings\Wati\Desktop\MCELOG_Budget_201112 (3).xls
[2010/08/28 09:08:26 | 000,192,000 | —- | C] () – C:\Documents and Settings\Wati\Desktop\7Excel Format- Tables(latest).xls
[2010/08/27 14:33:21 | 001,680,896 | —- | C] () – C:\Documents and Settings\Wati\My Documents\MCELOG_Budget_201112 (3).xls
[2010/08/27 14:32:02 | 000,187,392 | —- | C] () – C:\Documents and Settings\Wati\My Documents\7Excel Format- Tables(latest).xls
[2010/08/26 13:36:12 | 000,000,442 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Registration3.job
[2010/08/26 13:36:09 | 000,000,378 | —- | C] () – C:\WINDOWS\tasks\FileCure Startup.job
[2010/08/26 13:36:09 | 000,000,362 | —- | C] () – C:\WINDOWS\tasks\FileCure Default.job
[2010/08/26 13:36:07 | 000,000,918 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,900 | —- | C] () – C:\Documents and Settings\Wati\My Documents\ParetoLogic FileCure.lnk
[2010/08/26 13:36:07 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\ParetoLogic Update Version3.job
[2010/08/24 16:48:24 | 000,262,144 | —- | C] () – C:\ntuser.dat
[2010/08/24 16:47:55 | 000,000,826 | —- | C] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/08/18 09:27:20 | 000,012,407 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\Bron.tok.A12.em.bin
[2010/08/16 17:28:07 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Update.12.Bron.Tok.bin
[2010/08/16 17:22:03 | 000,000,349 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\BronFoldNetDomList.txt
[2010/08/16 17:18:18 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Bron.tok.A12.em.bin
[2010/08/11 11:29:38 | 000,000,123 | —- | C] () – C:\Documents and Settings\Wati\Application Data\default.rss
[2010/08/11 11:03:41 | 000,169,608 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/03 13:12:03 | 000,000,085 | —- | C] () – C:\Documents and Settings\Wati\Application Data\toolbar_log.txt
[2010/07/30 11:31:30 | 000,014,022 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/07/23 08:14:06 | 000,000,051 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
[2010/07/23 08:08:31 | 000,012,407 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ListHost12.txt
[2010/07/23 03:11:01 | 000,016,896 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/15 03:57:34 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/07/10 06:42:35 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/07/10 06:36:49 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4906.dll
[2010/06/22 05:03:58 | 000,000,552 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\NetMailTmp.bin
[2010/06/22 03:43:01 | 000,012,407 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\ListHost12.txt
[2007/11/20 06:42:56 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\XYNetComClient.dll
[2007/07/27 20:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2004/01/11 21:02:03 | 000,026,190 | —- | C] () – C:\Documents and Settings\Wati\Local Settings\Application Data\NetMailTmp.bin
========== LOP Check ==========
[2010/08/03 13:40:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/09/05 15:38:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FileCure
[2010/08/26 13:36:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/09/22 17:40:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/03 14:47:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\AskToolbar
[2010/09/21 17:55:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\BitTorrent
[2010/08/03 13:25:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\DVDVideoSoftIEHelpers
[2010/08/13 09:12:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\FreeFileViewer
[2010/09/04 10:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\Gygan
[2010/09/22 12:21:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\PriceGong
[2010/07/29 16:45:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Wati\Application Data\RadioBar
[2010/09/22 17:08:00 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010/09/13 02:04:00 | 000,000,362 | —- | M] () – C:\WINDOWS\Tasks\FileCure Default.job
[2010/09/22 17:40:01 | 000,000,378 | —- | M] () – C:\WINDOWS\Tasks\FileCure Startup.job
[2010/09/22 17:45:00 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/09/22 17:50:40 | 000,000,374 | -H– | M] () – C:\WINDOWS\Tasks\MpIdleTask.job
[2010/09/13 18:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Registration3.job
[2010/09/11 05:42:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\ParetoLogic Update Version3.job
[2010/09/22 17:40:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\PCConfidential.job
[2010/09/22 17:01:00 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/08/18 09:00:05 | 000,000,007 | -HS- | M] () – C:\AUTOEXEC.BAT
[2010/07/10 06:23:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/07/10 06:28:16 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/10 06:28:16 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/07/10 06:28:16 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/27 20:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2007/07/27 20:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/08/24 16:48:24 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2010/08/24 16:48:24 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2010/09/22 17:39:57 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/19 20:21:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/07/02 22:37:10 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/19 20:21:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/07/02 22:37:12 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/07/10 06:28:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/14 16:43:18 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/04/16 14:08:20 | 000,312,832 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp70v.dll
[2006/10/27 10:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2006/10/14 16:44:44 | 000,671,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/07/09 23:17:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/07/09 23:17:02 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/07/09 23:17:02 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/10 06:28:20 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/10 06:31:32 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/07/10 06:31:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\Wati\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
< End of report >
OTL Extras logfile created on: 9/22/2010 5:46:58 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Wati\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.32 Gb Total Space | 162.41 Gb Free Space | 83.15% Space Free | Partition Type: NTFS
Drive D: | 270.44 Gb Total Space | 267.10 Gb Free Space | 98.76% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 239.53 Mb Total Space | 25.98 Mb Free Space | 10.85% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Computer Name: UBS
Current User Name: Wati
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\Wati\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\PROGRA~1\MICROS~2\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\ParetoLogic\FileCure\FileCure_noapp.exe %1 (ParetoLogic)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"2033:TCP" = 2033:TCP:LocalSubNet:Enabled:UBS Licensing Daemon
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"2033:TCP" = 2033:TCP:LocalSubNet:Enabled:UBS Licensing Daemon
"3145:TCP" = 3145:TCP:*:Enabled:hhrtfdev
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – File not found
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"E:\Ubs\Network\V92\Service\UsbServer2k.exe" = E:\Ubs\Network\V92\Service\UsbServer2k.exe:*:Enabled:UsbLanServer – File not found
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE – (Software 2000 Limited)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe – File not found
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{12345678-1234-1234-1234-12345678911C}" = UBS Accounting System 9.2 (SR2)
"{12345678-1234-1234-1234-12345678921A}" = UBS Inventory & Billing 9.2 (SR2)
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1AA4E6C7-6ED7-4A0B-BBA0-D7D579CF6793}" = OpenDrive
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool Help
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision Help
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{714DAA5E-803F-44A2-8512-64F26E681030}_is1" = Gygan
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{A20A58C4-6784-4B4B-86CC-94E2E3671033}" = Nero 7 Ultra Edition
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{b86754dd-2ddb-4ac0-9015-cb487277254e}" = InCD Help
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C1C441C4-57FA-4950-BDBA-BABFBAA2AA39}" = ParetoLogic FileCure
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed Help
"{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}" = HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed Help
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{eb2ffb1e-d1d1-4f6a-8e8a-cda5bff40283}" = Nero 9 Essentials
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights Help
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"BitTorrent" = BitTorrent
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"PC Tools AntiVirus_is1" = PC Tools AntiVirus 6.0
"SelfAccounts" = SelfAccounts 2.0
"ToggleEN Toolbar" = ToggleEN Toolbar
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.0.1
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/17/2010 4:51:23 AM | Computer Name = UBS | Source = Microsoft Office 12 | ID = 5000
Description = EventType officelifeboathang, P1 outlook.exe, P2 12.0.4518.1014, P3
ntdll.dll, P4 5.1.2600.2180, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:40:21 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:40:41 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:40:42 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:40:45 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:40:56 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:41:00 AM | Computer Name = UBS | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070422, P2 beginsearch, P3 search, P4
2.1.6805.0, P5 mpsigdwn.dll, P6 2.1.6805.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/22/2010 5:41:01 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:41:03 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/22/2010 5:51:31 AM | Computer Name = UBS | Source = MSSecurityEssentials | ID = 5000
Description =
[ OSession Events ]
Error - 7/30/2010 12:06:11 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10052
seconds with 1080 seconds of active time. This session ended with a crash.
Error - 7/31/2010 2:02:25 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7404
seconds with 0 seconds of active time. This session ended with a crash.
Error - 8/11/2010 11:31:52 PM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6006
seconds with 1800 seconds of active time. This session ended with a crash.
Error - 8/30/2010 2:54:12 AM | Computer Name = UBS | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 848
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Support Center service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Shell Security service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7000
Description = The USBLAN_Ldr service failed to start due to the following error:
%%21
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Helper Universal service terminated with the following error:
%%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Driver Shell service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Helper Boot service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Monitor Network service terminated with the following error: %%126
Error - 9/22/2010 5:41:38 AM | Computer Name = UBS | Source = Service Control Manager | ID = 7023
Description = The Monitor Config service terminated with the following error: %%126
Error - 9/22/2010 5:51:29 AM | Computer Name = UBS | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147618124
User:
UBS\Wati Name: Worm:Win32/Conficker.B ID: 2147618124 Severity: Severe Category: Worm
Path:
Action: %%808 Error Code: 0x80070032 Error description: The request is not supported.
Status: Signature Version: AV: 1.91.343.0, AS: 1.91.343.0 Engine Version: 1.1.6201.0
Error - 9/22/2010 5:51:29 AM | Computer Name = UBS | Source = Microsoft Antimalware | ID = 1008
Description = %%861 has encountered an error when taking action on spyware or other
potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147618124
User:
UBS\Wati Name: Worm:Win32/Conficker.B ID: 2147618124 Severity: Severe Category: Worm
Path:
Action: %%809 Error Code: 0x80070032 Error description: The request is not supported.
Status: Signature Version: AV: 1.91.343.0, AS: 1.91.343.0 Engine Version: 1.1.6201.0
< End of report >