(OTL run in Safe Mode)
OTL logfile created on: 11/28/2010 9:48:30 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = F:\
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 544.00 Mb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.96 Gb Total Space | 74.68 Gb Free Space | 53.74% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.96 Gb Free Space | 59.59% Space Free | Partition Type: NTFS
Drive E: | 670.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 1.88 Gb Total Space | 1.86 Gb Free Space | 99.35% Space Free | Partition Type: FAT
Computer Name: ELYSE-PC | User Name: Elyse | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (All) ==========
PRC - F:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Windows\System32\lsass.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Windows\System32\winlogon.exe (Microsoft Corporation)
PRC - C:\Windows\System32\smss.exe (Microsoft Corporation)
PRC - C:\Windows\System32\services.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wininit.exe (Microsoft Corporation)
PRC - C:\Windows\System32\svchost.exe [comLaunch] (Microsoft Corporation)
PRC - C:\Windows\System32\svchost.exe [comLaunch] (Microsoft Corporation)
PRC - C:\Windows\System32\svchost.exe [comLaunch] (Microsoft Corporation)
PRC - C:\Windows\System32\svchost.exe [comLaunch] (Microsoft Corporation)
PRC - C:\Windows\System32\svchost.exe [comLaunch] (Microsoft Corporation)
PRC - C:\Windows\System32\svchost.exe [comLaunch] (Microsoft Corporation)
PRC - C:\Windows\System32\notepad.exe (Microsoft Corporation)
PRC - C:\Windows\System32\lsm.exe (Microsoft Corporation)
PRC - C:\Windows\System32\csrss.exe (Microsoft Corporation)
PRC - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (GRISOFT s.r.o.)
========== Modules (All) ==========
MOD - F:\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\wininet.dll (Microsoft Corporation)
MOD - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
MOD - C:\Windows\System32\iertutil.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\shell32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\ole32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\usp10.dll (Microsoft Corporation)
MOD - C:\Windows\System32\vbscript.dll (Microsoft Corporation)
MOD - C:\Windows\System32\jscript.dll (Microsoft Corporation)
MOD - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
MOD - C:\Windows\System32\WindowsCodecs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\winspool.drv (Microsoft Corporation)
MOD - C:\Windows\System32\atl.dll (Microsoft Corporation)
MOD - C:\Windows\System32\secur32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\lpk.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rpcrt4.dll (Microsoft Corporation)
MOD - C:\Windows\System32\vssapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\user32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\Wldap32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\userenv.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wmiutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wbemsvc.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wbemprox.dll (Microsoft Corporation)
MOD - C:\Windows\System32\version.dll (Microsoft Corporation)
MOD - C:\Windows\System32\setupapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\shdocvw.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\System32\shlwapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\spp.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samlib.dll (Microsoft Corporation)
MOD - C:\Windows\System32\propsys.dll (Microsoft Corporation)
MOD - C:\Windows\System32\oleaut32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netapi32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\odbc32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\ntmarta.dll (Microsoft Corporation)
MOD - C:\Windows\System32\olepro32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msvcrt.dll (Microsoft Corporation)
MOD - C:\Program Files\Windows Journal\NBMapTIP.dll (Microsoft Corporation)
MOD - C:\Windows\System32\mfc42u.dll (Microsoft Corporation)
MOD - C:\Windows\System32\kernel32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msctf.dll (Microsoft Corporation)
MOD - C:\Windows\System32\imm32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\mpr.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\fastprox.dll (Microsoft Corporation)
MOD - C:\Windows\System32\gdi32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\EhStorShell.dll (Microsoft Corporation)
MOD - C:\Windows\System32\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dnsapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\authz.dll (Microsoft Corporation)
MOD - C:\Windows\System32\advapi32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\apphelp.dll (Microsoft Corporation)
MOD - C:\Windows\System32\ntdll.dll (Microsoft Corporation)
MOD - C:\Windows\System32\rsaenh.dll (Microsoft Corporation)
MOD - C:\Windows\System32\xmllite.dll (Microsoft Corporation)
MOD - C:\Windows\System32\ws2_32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbem\wbemdisp.dll (Microsoft Corporation)
MOD - C:\Windows\System32\wbemcomn.dll (Microsoft Corporation)
MOD - C:\Windows\System32\vsstrace.dll (Microsoft Corporation)
MOD - C:\Windows\System32\uxtheme.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sxs.dll (Microsoft Corporation)
MOD - C:\Windows\System32\srclient.dll (Microsoft Corporation)
MOD - C:\Windows\System32\ntdsapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\nsi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\clbcatq.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\System32\linkinfo.dll (Microsoft Corporation)
MOD - C:\Windows\System32\psapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\odbcint.dll (Microsoft Corporation)
MOD - C:\Windows\System32\normaliz.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (MSCamSvc) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (MBackMonitor) – C:\Program Files\McAfee\MBK\MBackMonitor.exe (McAfee)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (GameConsoleService) – C:\Program Files\Dell Games\Dell Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AVG Anti-Spyware Guard) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (GRISOFT s.r.o.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (MPFP) – C:\Windows\System32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (VX1000) – C:\Windows\System32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RTL8187) – C:\Windows\System32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (AVG Anti-Spyware Driver) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ()
DRV - (AvgAsCln) – C:\Windows\System32\drivers\AvgAsCln.sys (GRISOFT, s.r.o.)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (DRVNDDM) – C:\Windows\System32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLARTL_M) – C:\Windows\System32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\Windows\System32\drivers\DLACDBHM.SYS (Roxio)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (SCMNdisP) – C:\Windows\system32\DRIVERS\scmndisp.sys (Windows ® Codename Longhorn DDK provider)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (bcm4sbxp) – C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (DLADResM) – C:\Windows\System32\DLA\DLADResM.SYS (Roxio)
DRV - (DLAUDFAM) – C:\Windows\System32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLABMFSM) – C:\Windows\System32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\Windows\System32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAOPIOM) – C:\Windows\System32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\Windows\System32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\Windows\System32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\Windows\System32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv) – C:\Program Files\DellSupport\Drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (DRVMCDB) – C:\Windows\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaulturl: "
http://aim.search.aol.com/search/search?query={searchTerms}&invocationType;=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/03 14:06:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/11/22 16:42:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/28 23:06:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/28 19:04:07 | 000,000,000 | —D | M]
[2009/07/27 16:15:59 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Mozilla\Extensions
[2009/07/27 16:15:59 | 000,000,000 | —D | M] (No name found) – C:\Users\Elyse\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/11/28 13:50:03 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Mozilla\Firefox\Profiles\cc1744uo.default\extensions
[2009/07/18 14:14:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Elyse\AppData\Roaming\Mozilla\Firefox\Profiles\cc1744uo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/29 17:33:53 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Elyse\AppData\Roaming\Mozilla\Firefox\Profiles\cc1744uo.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2009/12/29 17:34:00 | 000,004,554 | —- | M] () – C:\Users\Elyse\AppData\Roaming\Mozilla\Firefox\Profiles\cc1744uo.default\searchplugins\aim-search.xml
[2007/12/22 15:25:13 | 000,001,877 | —- | M] () – C:\Users\Elyse\AppData\Roaming\Mozilla\Firefox\Profiles\cc1744uo.default\searchplugins\aolsearch.xml
[2007/03/14 18:04:44 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/10/28 23:06:23 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/27 16:15:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/10/28 23:06:17 | 000,025,048 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/10/28 23:06:17 | 000,140,248 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009/07/07 16:20:42 | 000,061,440 | —- | M] (AOL LLC) – C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
[2009/07/07 16:20:42 | 000,065,536 | —- | M] (AOL LLC) – C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
[2010/10/28 23:06:20 | 000,066,520 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2006/10/26 19:12:16 | 000,016,192 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
[2009/01/13 15:16:14 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/01/13 15:16:14 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/01/13 15:16:15 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/01/13 15:16:15 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/01/13 15:16:15 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/01/13 15:16:15 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/01/13 15:16:15 | 000,143,360 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2005/08/09 13:42:53 | 000,057,344 | —- | M] (America Online, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
[2010/10/02 22:11:23 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/10/02 22:11:23 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2007/12/22 14:30:13 | 000,001,948 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\AOL Search.xml
[2010/10/02 22:11:23 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/10/02 22:11:23 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/10/02 22:11:23 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/06/07 19:36:03 | 000,002,024 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml
[2010/10/02 22:11:23 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/10/02 22:11:24 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [!AVG Anti-Spyware] C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe (GRISOFT s.r.o.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\PhotoDownloader.exe File not found
O4 - HKLM..\Run: [ECenter] c:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe (McAfee)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [VX1000] C:\Windows\vVX1000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [471138] C:\Users\Elyse\AppData\Local\Temp\471138.exe ()
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EqCAlppKDp.exe] C:\Users\Elyse\AppData\Local\Temp\EqCAlppKDp.exe ()
O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe File not found
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Elyse\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (RtlGina2.dll) - File not found
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\Windows\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\Windows\System32\sysdm.cpl (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\Windows\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Elyse\Documents\Pictures\Vermont 2010\DSCF3852.JPG
O24 - Desktop BackupWallPaper: C:\Users\Elyse\Documents\Pictures\Vermont 2010\DSCF3852.JPG
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/02/24 03:30:45 | 000,000,053 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{56b81cf2-f12d-11dc-96f9-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{56b81cf2-f12d-11dc-96f9-806e6f6e6963}\Shell\AutoRun\command - "" = E:\StartHere.exe – [2000/05/24 12:27:26 | 000,105,532 | R— | M] ()
O33 - MountPoints2\{5b2f6ba2-a124-11dc-9b19-00188b8f8d55}\Shell\AutoRun\command - "" = F:\WirelessSecurity\install.exe – File not found
O33 - MountPoints2\{6ec7323f-b979-11dc-b4dc-00188b8f8d55}\Shell\AutoRun\command - "" = F:\WirelessSecurity\install.exe – File not found
O33 - MountPoints2\{9aa8e311-d27f-11db-a9c1-00188b8f8d55}\Shell\AutoRun\command - "" = WirelessSecurity\install.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/11/28 20:41:15 | 000,000,000 | —D | C] – C:\Users\Elyse\AppData\Roaming\Malwarebytes
[2010/11/28 20:41:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/28 20:41:05 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/28 20:41:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/28 20:41:05 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
========== Files - Modified Within 30 Days ==========
[2010/11/28 21:15:19 | 000,001,356 | —- | M] () – C:\Users\Elyse\AppData\Local\d3d9caps.dat
[2010/11/28 20:42:39 | 000,611,844 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/28 20:42:39 | 000,107,276 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/28 20:41:09 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/28 20:38:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/28 20:37:05 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 20:37:05 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 20:36:48 | 000,016,615 | —- | M] () – C:\Windows\System32\Config.MPF
[2010/11/28 20:36:47 | 000,008,212 | —- | M] () – C:\Windows\mfebcdata
[2010/11/28 18:51:56 | 000,000,755 | —- | M] () – C:\Users\Elyse\Desktop\Win HDD.lnk
[2010/11/27 21:21:45 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{94767EEC-8076-4E0F-A716-8FDBFDAA5786}.job
[2010/11/27 16:51:53 | 000,002,651 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/11/27 15:11:59 | 000,002,255 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes (2).lnk
[2010/11/23 20:16:36 | 000,002,401 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010/11/17 22:15:41 | 000,060,416 | —- | M] () – C:\Users\Elyse\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/15 23:32:35 | 000,001,096 | —- | M] () – C:\Users\Elyse\Desktop\17C-SynthesisOfProtein - Shortcut.lnk
[2010/11/14 15:20:43 | 000,013,746 | —- | M] () – C:\Users\Elyse\Documents\musicianssss.docx
[2010/11/04 21:05:55 | 000,014,300 | —- | M] () – C:\Users\Elyse\Documents\music.docx
[2010/11/02 12:24:59 | 000,002,627 | —- | M] () – C:\Users\Elyse\Desktop\Microsoft Office Word 2007.lnk
========== Files Created - No Company Name ==========
[2010/11/28 20:41:09 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/28 20:36:47 | 000,008,212 | —- | C] () – C:\Windows\mfebcdata
[2010/11/28 18:51:56 | 000,000,755 | —- | C] () – C:\Users\Elyse\Desktop\Win HDD.lnk
[2010/11/15 23:32:35 | 000,001,096 | —- | C] () – C:\Users\Elyse\Desktop\17C-SynthesisOfProtein - Shortcut.lnk
[2010/11/02 18:22:13 | 000,014,300 | —- | C] () – C:\Users\Elyse\Documents\music.docx
[2010/04/22 12:51:20 | 000,000,032 | —- | C] () – C:\ProgramData\ezsid.dat
[2010/04/17 16:57:36 | 000,000,124 | —- | C] () – C:\Windows\POOHRTR.INI
[2010/04/17 16:57:36 | 000,000,124 | —- | C] () – C:\Windows\POOHRFM.INI
[2010/02/07 15:08:15 | 000,000,100 | —- | C] () – C:\Windows\ka.ini
[2009/12/26 11:18:30 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/21 20:21:06 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2008/12/02 19:17:42 | 011,143,213 | —- | C] () – C:\Users\Elyse\AppData\Roaming\UserTile.png
[2008/09/25 19:35:41 | 000,001,356 | —- | C] () – C:\Users\Elyse\AppData\Local\d3d9caps.dat
[2008/07/07 09:42:13 | 000,000,093 | —- | C] () – C:\Users\Elyse\AppData\Local\fusioncache.dat
[2007/04/10 13:46:52 | 000,015,498 | —- | C] () – C:\Windows\VX1000.ini
[2007/03/16 11:43:44 | 000,000,029 | —- | C] () – C:\Windows\atid.ini
[2007/03/15 19:38:15 | 000,056,056 | —- | C] () – C:\Windows\System32\DLAAPI_W.DLL
[2007/03/14 16:15:44 | 000,060,416 | —- | C] () – C:\Users\Elyse\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/12 17:49:45 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2007/03/12 10:12:52 | 000,000,228 | —- | C] () – C:\Windows\wininit.ini
[2007/01/06 06:09:26 | 000,208,896 | —- | C] () – C:\Program Files\Common Files\VistaRunApp.exe
[2006/11/07 14:25:58 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/11/02 07:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/09/16 22:36:50 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/16 22:36:50 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
========== LOP Check ==========
[2007/03/16 11:46:06 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\acccore
[2007/11/18 17:38:13 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Grisoft
[2007/03/17 08:35:13 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\WildTangent
[2010/09/15 00:23:07 | 000,000,340 | —- | M] () – C:\Windows\Tasks\McDefragTask.job
[2010/08/01 00:00:10 | 000,000,318 | —- | M] () – C:\Windows\Tasks\McQcTask.job
[2010/11/28 20:36:51 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/27 21:21:45 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{94767EEC-8076-4E0F-A716-8FDBFDAA5786}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 08:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/03/12 17:49:57 | 000,004,989 | RH– | M] () – C:\dell.sdr
[2010/10/04 19:53:46 | 000,921,624 | —- | M] () – C:\img2-001.raw
[2010/09/12 01:22:00 | 000,921,624 | —- | M] () – C:\img2-002.raw
[2010/04/17 16:57:05 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/10 15:07:00 | 000,002,264 | -H– | M] () – C:\IPH.PH
[2010/04/17 16:57:05 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/28 20:38:10 | 1385,963,520 | -HS- | M] () – C:\pagefile.sys
[2010/11/28 20:40:20 | 000,000,341 | —- | M] () – C:\rkill.log
[2007/03/12 10:21:27 | 000,000,070 | —- | M] () – C:\SystemInfo.ini
< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/23 12:16:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 11:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/11/09 16:25:20 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/11/25 23:34:11 | 000,000,414 | -HS- | M] () – C:\Users\Elyse\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/09/07 10:39:18 | 000,117,126 | —- | M] () – C:\Users\Elyse\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\network.png
< %USERPROFILE%\Desktop\*.exe >
[2009/11/14 12:41:04 | 001,296,288 | —- | M] (McAfee, Inc.) – C:\Users\Elyse\Desktop\DMSetup-Serial.exe
< %PROGRAMFILES%\Common Files\*.* >
[2007/01/06 06:09:26 | 000,208,896 | —- | M] () – C:\Program Files\Common Files\VistaRunApp.exe
< %systemroot%\*.src >
[2007/04/10 13:46:54 | 000,013,023 | —- | M] () – C:\Windows\VX1000.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-26 18:22:43
< End of report >
[2010/11/28 21:47:43 | 003,407,872 | -HS- | M] () – C:\Users\Elyse\NTUSER.DAT
[2010/11/28 21:47:43 | 000,262,144 | -H– | M] () – C:\Users\Elyse\ntuser.dat.LOG1
[2010/11/28 21:42:28 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Local\Temp
[2010/11/28 21:15:19 | 000,001,356 | —- | M] () – C:\Users\Elyse\AppData\Local\d3d9caps.dat
[2010/11/28 20:41:15 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Malwarebytes
[2010/11/28 20:41:09 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/28 20:41:09 | 000,000,000 | —D | M] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/28 20:41:05 | 000,000,000 | —D | M] – C:\ProgramData\Malwarebytes
[2010/11/28 20:38:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/28 20:36:49 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/11/28 20:36:47 | 000,008,212 | —- | M] () – C:\Windows\mfebcdata
[2010/11/28 20:36:39 | 000,524,288 | -HS- | M] () – C:\Users\Elyse\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/11/28 20:36:39 | 000,065,536 | -HS- | M] () – C:\Users\Elyse\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/11/28 20:36:19 | 001,887,894 | -H– | M] () – C:\Users\Elyse\AppData\Local\IconCache.db
[2010/11/28 20:20:39 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Local\ApplicationHistory
[2010/11/28 19:04:05 | 000,000,000 | —D | M] – C:\ProgramData\Viewpoint
[2010/11/28 18:51:56 | 000,000,755 | —- | M] () – C:\Users\Elyse\Desktop\Win HDD.lnk
[2010/11/28 18:51:56 | 000,000,000 | R–D | M] – C:\Users\Elyse\Desktop
[2010/11/27 21:21:45 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{94767EEC-8076-4E0F-A716-8FDBFDAA5786}.job
[2010/11/27 16:52:37 | 000,000,000 | R–D | M] – C:\Users\Elyse\Documents
[2010/11/27 16:51:53 | 000,002,651 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/11/27 15:11:59 | 000,002,255 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes (2).lnk
[2010/11/23 23:33:33 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Skype
[2010/11/23 20:16:36 | 000,002,401 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010/11/23 16:08:36 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\skypePM
[2010/11/23 16:01:49 | 000,000,000 | —D | M] – C:\Program Files\Internet Explorer
[2010/11/17 22:15:41 | 000,060,416 | —- | M] () – C:\Users\Elyse\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/15 23:32:35 | 000,001,096 | —- | M] () – C:\Users\Elyse\Desktop\17C-SynthesisOfProtein - Shortcut.lnk
[2010/11/14 15:20:43 | 000,013,746 | —- | M] () – C:\Users\Elyse\Documents\musicianssss.docx
[2010/11/13 21:02:26 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Corel
[2010/11/13 20:59:46 | 000,000,000 | R–D | M] – C:\Users\Elyse\Downloads
[2010/11/10 16:17:59 | 000,000,000 | —D | M] – C:\ProgramData\Microsoft Help
[2010/11/10 16:17:16 | 000,000,000 | —D | M] – C:\Program Files\Windows Mail
[2010/11/04 21:05:55 | 000,014,300 | —- | M] () – C:\Users\Elyse\Documents\music.docx
[2010/11/02 12:24:59 | 000,002,627 | —- | M] () – C:\Users\Elyse\Desktop\Microsoft Office Word 2007.lnk
[2010/04/22 12:51:20 | 000,000,032 | —- | M] () – C:\ProgramData\ezsid.dat
[2010/02/28 19:18:59 | 000,086,576 | —- | M] () – C:\Users\Elyse\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/12/26 11:18:30 | 000,000,056 | -H– | M] () – C:\ProgramData\ezsidmv.dat
[2008/12/02 19:17:44 | 011,143,213 | —- | M] () – C:\Users\Elyse\AppData\Roaming\UserTile.png
[2008/11/09 16:25:20 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2008/07/07 09:42:13 | 000,000,093 | —- | M] () – C:\Users\Elyse\AppData\Local\fusioncache.dat
[2007/01/06 06:09:26 | 000,208,896 | —- | M] () – C:\Program Files\Common Files\VistaRunApp.exe
========== Files - Modified Within 30 Days ==========
[2010/11/28 21:15:19 | 000,001,356 | —- | M] () – C:\Users\Elyse\AppData\Local\d3d9caps.dat
[2010/11/28 20:42:39 | 000,611,844 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/28 20:42:39 | 000,107,276 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/28 20:41:09 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/28 20:38:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/28 20:37:05 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 20:37:05 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/28 20:36:48 | 000,016,615 | —- | M] () – C:\Windows\System32\Config.MPF
[2010/11/28 20:36:47 | 000,008,212 | —- | M] () – C:\Windows\mfebcdata
[2010/11/28 18:51:56 | 000,000,755 | —- | M] () – C:\Users\Elyse\Desktop\Win HDD.lnk
[2010/11/27 21:21:45 | 000,000,418 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{94767EEC-8076-4E0F-A716-8FDBFDAA5786}.job
[2010/11/27 16:51:53 | 000,002,651 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/11/27 15:11:59 | 000,002,255 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes (2).lnk
[2010/11/23 20:16:36 | 000,002,401 | —- | M] () – C:\Users\Elyse\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010/11/17 22:15:41 | 000,060,416 | —- | M] () – C:\Users\Elyse\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/15 23:32:35 | 000,001,096 | —- | M] () – C:\Users\Elyse\Desktop\17C-SynthesisOfProtein - Shortcut.lnk
[2010/11/14 15:20:43 | 000,013,746 | —- | M] () – C:\Users\Elyse\Documents\musicianssss.docx
[2010/11/04 21:05:55 | 000,014,300 | —- | M] () – C:\Users\Elyse\Documents\music.docx
[2010/11/02 12:24:59 | 000,002,627 | —- | M] () – C:\Users\Elyse\Desktop\Microsoft Office Word 2007.lnk
========== LOP Check ==========
[2007/03/16 11:46:06 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\acccore
[2007/11/18 17:38:13 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\Grisoft
[2007/03/17 08:35:13 | 000,000,000 | —D | M] – C:\Users\Elyse\AppData\Roaming\WildTangent
[2010/09/15 00:23:07 | 000,000,340 | —- | M] () – C:\Windows\Tasks\McDefragTask.job
[2010/08/01 00:00:10 | 000,000,318 | —- | M] () – C:\Windows\Tasks\McQcTask.job
[2010/11/28 20:36:51 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/27 21:21:45 | 000,000,418 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{94767EEC-8076-4E0F-A716-8FDBFDAA5786}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 08:22:24 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/03/12 17:49:57 | 000,004,989 | RH– | M] () – C:\dell.sdr
[2010/10/04 19:53:46 | 000,921,624 | —- | M] () – C:\img2-001.raw
[2010/09/12 01:22:00 | 000,921,624 | —- | M] () – C:\img2-002.raw
[2010/04/17 16:57:05 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/10 15:07:00 | 000,002,264 | -H– | M] () – C:\IPH.PH
[2010/04/17 16:57:05 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/11/28 20:38:10 | 1385,963,520 | -HS- | M] () – C:\pagefile.sys
[2010/11/28 20:40:20 | 000,000,341 | —- | M] () – C:\rkill.log
[2007/03/12 10:21:27 | 000,000,070 | —- | M] () – C:\SystemInfo.ini
< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/23 12:16:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 11:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/11/09 16:25:20 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/11/25 23:34:11 | 000,000,414 | -HS- | M] () – C:\Users\Elyse\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/09/07 10:39:18 | 000,117,126 | —- | M] () – C:\Users\Elyse\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\network.png
< %USERPROFILE%\Desktop\*.exe >
[2009/11/14 12:41:04 | 001,296,288 | —- | M] (McAfee, Inc.) – C:\Users\Elyse\Desktop\DMSetup-Serial.exe
< %PROGRAMFILES%\Common Files\*.* >
[2007/01/06 06:09:26 | 000,208,896 | —- | M] () – C:\Program Files\Common Files\VistaRunApp.exe
< %systemroot%\*.src >
[2007/04/10 13:46:54 | 000,013,023 | —- | M] () – C:\Windows\VX1000.src
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-26 18:22:43
< End of report >