Yes… back so soon. Unfortunately.
Here are the OTL logs…
OTL logfile created on: 12/4/2010 6:34:13 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jill Hadley\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 523.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 24.29 Gb Free Space | 16.83% Space Free | Partition Type: NTFS
Drive W: | 111.73 Gb Total Space | 35.35 Gb Free Space | 31.64% Space Free | Partition Type: NTFS
Drive X: | 9.41 Gb Total Space | 2.71 Gb Free Space | 28.84% Space Free | Partition Type: FAT
Computer Name: MOM | User Name: Jill Hadley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Outlook on the Desktop\OutlookDesktop.exe (SMR Computer Services)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WINDOWS\ipawaruy.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (XDva201) – C:\WINDOWS\System32\XDva201.sys File not found
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (SABProcEnum) – C:\Program Files\Internet Explorer\SABProcEnum.sys File not found
DRV - (PalmUSBD) – C:\WINDOWS\System32\drivers\PalmUSBD.sys File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (Ad-Watch Connect Filter) – C:\WINDOWS\System32\drivers\NSDriver.sys File not found
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (JL2005C) – C:\WINDOWS\system32\drivers\jl2005c.sys (Windows ® 2000 DDK provider)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (SocketLock) – C:\WINDOWS\system32\socketlock.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (iastor) – C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.myspace.com/"
FF - prefs.js..network.proxy.no_proxies_on: "local,*.local"
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/10/31 16:34:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{DA13D27F-371F-4A39-A5F6-453BBE384945}: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945} [2010/12/04 14:22:17 | 000,000,000 | —D | M]
[2009/05/20 10:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Mozilla\Firefox\Profiles\3g8lv8zo.default\extensions
[2010/05/03 10:11:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/06/18 00:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/06 18:12:11 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
O1 HOSTS File: ([2010/10/14 11:03:50 | 000,000,934 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.runescape.com
O1 - Hosts: 127.0.0.1 www.halo3.com
O1 - Hosts: 127.0.0.1 www.galaxiesablaze.com
O1 - Hosts: 127.0.0.1 www.mortalkombat.com
O1 - Hosts: 127.0.0.1 www.mortalkombatdeception.com
O1 - Hosts: 127.0.0.1
http://simpsonizeme.com/#
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (no name) - {C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - No CLSID value found.
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Sjokorecewekif] C:\WINDOWS\ipawaruy.DLL ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [OutlookOnDesktop] C:\Outlook on the Desktop\OutlookDesktop.exe (SMR Computer Services)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD}
http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7}
http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - Reg Error: Key error. File not found
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{8506fe83-105e-11dd-9942-00137211e15b}\Shell - "" = AutoRun
O33 - MountPoints2\{8506fe83-105e-11dd-9942-00137211e15b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8506fe83-105e-11dd-9942-00137211e15b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe – File not found
O33 - MountPoints2\{afb2743b-c69b-11db-9879-00137211e15b}\Shell - "" = AutoRun
O33 - MountPoints2\{afb2743b-c69b-11db-9879-00137211e15b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{afb2743b-c69b-11db-9879-00137211e15b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe – File not found
O33 - MountPoints2\{bf1206f8-2b44-11de-9a62-00137211e15b}\Shell - "" = AutoRun
O33 - MountPoints2\{bf1206f8-2b44-11de-9a62-00137211e15b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{bf1206f8-2b44-11de-9a62-00137211e15b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.dll (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.JDCT - C:\WINDOWS\System32\jl_jdct.drv (JEILIN Tech.)
CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.
========== Files/Folders - Created Within 30 Days ==========
[2010/12/04 18:31:54 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/12/04 17:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Desktop\backups
[2010/12/04 17:39:58 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 14:22:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}
[2010/12/04 14:06:21 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Documents\Server
[2010/11/09 22:18:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Application Data\Arkadium
[2010/11/09 22:17:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2010/11/09 22:17:19 | 000,000,000 | —D | C] – C:\Program Files\Mahjongg Dimensions Deluxe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/04 18:31:54 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/12/04 18:07:24 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/04 18:01:41 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/04 18:01:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/04 18:01:18 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2010/12/04 17:39:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 17:15:19 | 000,039,472 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/12/04 12:04:14 | 000,002,501 | —- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2010/12/02 21:35:05 | 000,000,072 | —- | M] () – C:\WINDOWS\MSPConv.INI
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/23 12:29:09 | 000,000,162 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/11/22 10:43:41 | 000,153,600 | —- | M] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/19 13:52:34 | 000,028,160 | —- | M] () – C:\10 Rules for Dating.doc
[2010/11/19 13:34:39 | 000,057,856 | —- | M] () – C:\10 BAND REPORT.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | M] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | M] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/11/12 00:01:19 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jill Hadley\My Documents\CnC AACStyle Gift Cards.doc
[2010/11/10 22:37:22 | 006,604,800 | —- | M] () – C:\CrawlersnCruisers Invitation.doc
[2010/11/09 22:17:41 | 000,001,871 | —- | M] () – C:\Documents and Settings\Jill Hadley\Desktop\Mahjongg Dimensions Deluxe.lnk
[2010/11/07 15:37:07 | 000,001,901 | —- | M] () – C:\WINDOWS\panose.bin
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/02 21:35:05 | 000,000,072 | —- | C] () – C:\WINDOWS\MSPConv.INI
[2010/11/18 20:26:42 | 000,028,160 | —- | C] () – C:\10 Rules for Dating.doc
[2010/11/16 18:42:42 | 000,057,856 | —- | C] () – C:\10 BAND REPORT.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | C] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | C] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/11/12 00:01:18 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jill Hadley\My Documents\CnC AACStyle Gift Cards.doc
[2010/11/09 22:17:41 | 000,001,871 | —- | C] () – C:\Documents and Settings\Jill Hadley\Desktop\Mahjongg Dimensions Deluxe.lnk
[2007/08/27 12:09:53 | 000,000,475 | —- | C] () – C:\WINDOWS\KA.ini
[2007/07/19 15:30:33 | 000,000,217 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/03/30 13:31:20 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\dec_jl6.dll
[2007/02/06 12:14:16 | 000,000,968 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/01/25 14:09:01 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/01/25 13:57:50 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\PRTSERV.dll
[2006/12/03 09:46:38 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/10/07 12:11:48 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/09/09 18:06:07 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2006/09/09 18:05:55 | 000,000,122 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2006/08/03 19:11:28 | 000,003,712 | —- | C] () – C:\WINDOWS\System32\socketlock.sys
[2006/08/03 17:27:25 | 000,000,187 | —- | C] () – C:\Documents and Settings\Jill Hadley\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2006/05/18 08:10:28 | 000,003,072 | —- | C] () – C:\Documents and Settings\Jill Hadley\Application Data\dvd.bmk
[2006/04/30 19:22:53 | 000,153,600 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/30 18:27:43 | 000,000,162 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/04/16 21:14:07 | 000,001,296 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\FASTWiz.html
[2006/04/16 21:13:37 | 000,029,167 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\FASTWiz.log
[2006/04/16 00:52:03 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\6F1BB25984.sys
[2006/04/15 18:19:06 | 000,005,852 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/15 18:04:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/15 17:54:36 | 000,000,161 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/04/15 17:53:33 | 000,000,706 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2006/04/15 17:50:45 | 000,000,342 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/04/15 17:15:04 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/04/15 16:50:39 | 000,000,134 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\fusioncache.dat
[2006/04/05 17:02:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/04/05 16:56:15 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/04/05 16:27:18 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/04/05 16:26:48 | 000,000,387 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 03:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:18:42 | 000,378,368 | —- | C] () – C:\WINDOWS\ipawaruy.dll
[2005/08/05 13:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/03/28 08:14:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/03/21 19:00:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2010/10/31 16:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/10/31 16:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/31 15:53:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/31 16:36:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2006/07/27 12:50:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2010/10/31 15:52:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2007/02/17 22:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2007/07/10 11:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/26 16:47:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/06 10:40:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/11/09 22:18:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Arkadium
[2010/10/31 16:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\AVG10
[2008/12/10 00:37:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\CVS
[2010/02/27 12:38:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Facebook
[2006/07/27 12:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\HotSync
[2006/05/18 22:59:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Leadertech
[2006/08/09 07:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Morpheus
[2007/03/20 16:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Netscape
[2010/02/08 13:29:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Opera
[2006/07/11 13:44:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\PgcEdit
[2010/07/14 18:58:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\SiteHound
[2006/04/25 12:52:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Snapfish
[2007/05/17 16:31:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Viewpoint
[2006/07/13 16:28:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\WildTangent
[2009/05/30 08:27:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\WinPatrol
[2010/08/19 16:20:29 | 000,000,516 | —- | M] () – C:\WINDOWS\Tasks\Install.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/05/27 12:24:00 | 000,049,642 | —- | M] () – C:\0544Smudge.JPG
[2010/11/19 13:34:39 | 000,057,856 | —- | M] () – C:\10 BAND REPORT.doc
[2010/11/19 13:52:34 | 000,028,160 | —- | M] () – C:\10 Rules for Dating.doc
[2006/07/26 23:32:48 | 014,899,994 | —- | M] () – C:\3[1].20_full_release_troubleshooter.exe
[2007/12/26 12:35:44 | 000,000,035 | —- | M] () – C:\aa.txt
[2006/07/27 12:52:59 | 000,006,407 | —- | M] () – C:\additdiag.txt
[2009/01/07 14:21:56 | 000,085,999 | —- | M] () – C:\Assessing.JPG
[2009/01/07 15:22:11 | 000,024,161 | —- | M] () – C:\Assessing30.JPG
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/03/23 07:22:27 | 035,960,792 | —- | M] () – C:\avg75free_519a1276.exe
[2008/05/29 09:08:22 | 047,787,248 | —- | M] () – C:\avg_free_stf_en_8_100a1295.exe
[2007/05/13 19:50:07 | 386,508,799 | —- | M] () – C:\BARNYARD_DOMESTIC_WS.ISO
[2010/05/03 11:20:03 | 000,000,237 | RHS- | M] () – C:\boot.ini
[2009/01/06 06:47:30 | 000,591,988 | —- | M] (Michael Scrivo ) – C:\CalendarSetup.exe
[2007/07/06 14:50:27 | 000,055,840 | —- | M] () – C:\cd5b9f47eb3d41ef430ed81d82ef9830.jpg
[2009/04/17 06:13:21 | 000,005,522 | —- | M] () – C:\Christina'sWedding.nra
[2009/05/27 18:59:23 | 075,755,808 | —- | M] (COMODO) – C:\CIS_Setup_3.9.95478.509_XP_Vista_x32.exe
[2007/10/09 14:52:44 | 007,667,225 | —- | M] () – C:\Clean Truck.psd
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/10/13 08:04:26 | 006,603,776 | —- | M] () – C:\CrawlersnCruisers Donation Request Form.doc
[2010/11/10 22:37:22 | 006,604,800 | —- | M] () – C:\CrawlersnCruisers Invitation.doc
[2010/10/21 11:43:42 | 000,023,040 | —- | M] () – C:\CrawlersnCruisers Show Entry.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | M] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | M] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/10/13 21:03:21 | 000,200,061 | —- | M] () – C:\CrawlersnCruisersFlyer.jpg
[2010/10/25 10:58:38 | 016,563,712 | —- | M] () – C:\CrawlersnCruisersFlyer.p65
[2010/09/14 20:28:27 | 000,232,770 | —- | M] () – C:\CrawlersnCruisersFlyer.pdf
[2010/10/27 12:04:20 | 000,062,022 | —- | M] () – C:\CrawlersnCruisersReg.pdf
[2006/04/05 16:32:26 | 000,006,454 | RH– | M] () – C:\dell.sdr
[2005/10/11 20:03:19 | 049,804,091 | —- | M] () – C:\DreamweaverMX.zip
[2007/09/30 17:55:39 | 004,891,686 | —- | M] () – C:\Engines.psd
[2007/04/07 08:01:15 | 006,006,832 | —- | M] (Mozilla) – C:\Firefox Setup 2.0.0.3.exe
[2008/12/20 17:42:37 | 000,191,495 | —- | M] () – C:\FlamesLeft.jpg
[2008/12/20 17:41:44 | 000,189,105 | —- | M] () – C:\FlamesRight.jpg
[2010/12/04 18:01:18 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2009/05/27 19:21:15 | 000,147,825 | —- | M] () – C:\hosts.zip
[2009/01/09 22:05:48 | 002,116,123 | —- | M] () – C:\IMG_2262.JPG
[2009/01/09 21:03:17 | 000,104,453 | —- | M] () – C:\IMG_2263.JPG
[2009/01/09 22:06:12 | 002,081,506 | —- | M] () – C:\IMG_2264.JPG
[2009/01/09 22:06:20 | 002,104,156 | —- | M] () – C:\IMG_2265.JPG
[2009/01/09 22:07:26 | 002,141,540 | —- | M] () – C:\IMG_2267.JPG
[2009/01/09 22:07:36 | 002,270,194 | —- | M] () – C:\IMG_2268.JPG
[2009/01/09 22:07:56 | 002,175,939 | —- | M] () – C:\IMG_2269.JPG
[2009/01/09 22:08:20 | 002,192,996 | —- | M] () – C:\IMG_2270.JPG
[2009/07/09 16:00:30 | 003,597,248 | —- | M] () – C:\IMG_3932.JPG
[2009/07/09 16:00:32 | 003,903,126 | —- | M] () – C:\IMG_3933.JPG
[2006/06/01 13:02:46 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/05 16:50:09 | 000,000,837 | -H– | M] () – C:\IPH.PH
[2002/04/17 02:55:30 | 000,064,056 | R— | M] () – C:\ITCEdscr.TTF
[2009/08/17 21:46:21 | 000,210,626 | —- | M] () – C:\JillBedZ.JPG
[2008/03/06 20:40:27 | 000,029,696 | —- | M] () – C:\KC Golf Proposal.doc
[2010/08/19 08:28:56 | 000,019,968 | —- | M] () – C:\Kids christmas wishlist.doc
[2008/03/07 16:34:40 | 000,582,000 | —- | M] () – C:\MCPR.exe
[2008/04/14 15:01:20 | 000,061,059 | —- | M] () – C:\MeBed.jpg
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/12/22 16:40:10 | 386,447,359 | —- | M] () – C:\NIMSB169.ISO
[2004/08/10 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/05 14:57:25 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/04 18:01:17 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2007/03/20 16:57:06 | 000,001,809 | —- | M] () – C:\photodex-presenter-install.log
[2002/04/17 02:55:36 | 000,082,680 | —- | M] () – C:\Pristina.TTF
[2009/01/07 12:34:05 | 000,105,082 | —- | M] () – C:\reflection.JPG
[2009/01/07 12:25:52 | 000,131,077 | —- | M] () – C:\reflection1.JPG
[2009/01/07 16:32:32 | 000,276,630 | —- | M] () – C:\ReflectionFlames copy.JPG
[2009/01/07 15:31:46 | 006,465,338 | —- | M] () – C:\ReflectionFlames.psd
[2009/01/07 00:14:33 | 000,112,632 | —- | M] () – C:\reflections.JPG
[2010/09/16 16:31:40 | 000,175,035 | —- | M] () – C:\SSPX6845.jpg
[2010/09/16 12:44:04 | 000,083,652 | —- | M] () – C:\SSPX6846.jpg
[2010/09/16 12:44:02 | 000,091,209 | —- | M] () – C:\SSPX6847.jpg
[2010/05/01 23:21:18 | 000,010,240 | —- | M] () – C:\stewardship program.doc
[2005/10/31 09:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2008/06/27 20:36:19 | 006,467,096 | —- | M] () – C:\SUPERAntiSpyware.exe
[2006/04/05 16:50:15 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2009/01/28 21:36:46 | 000,073,257 | —- | M] () – C:\Template%20left.jpg
[2009/01/28 21:37:00 | 000,074,439 | —- | M] () – C:\Template%20right.jpg
[2009/02/23 12:55:06 | 003,525,632 | —- | M] () – C:\The Life and Times Of Andrew.ppt
[2010/11/18 20:25:10 | 000,145,920 | -HS- | M] () – C:\Thumbs.db
[2009/01/07 12:51:09 | 001,978,204 | —- | M] () – C:\TransSRT.PSD
[2007/10/09 12:58:44 | 000,396,129 | —- | M] () – C:\Truck7855.JPG
[2006/11/29 13:41:42 | 000,030,720 | —- | M] () – C:\TYMMusic.doc
[2008/12/19 20:20:55 | 000,829,494 | —- | M] () – C:\Wolverine.BMP
[2008/12/19 20:37:02 | 000,151,985 | —- | M] () – C:\Wolverine.jpg
[2009/05/27 19:10:09 | 000,887,176 | —- | M] (BillP Studios) – C:\wpsetup.exe
[2010/01/24 10:45:10 | 000,190,730 | —- | M] () – C:\xmen3complete.jpg
[2010/07/26 16:53:22 | 000,000,150 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/08/16 03:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/07/08 19:50:38 | 000,069,120 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp40i.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2004/05/12 13:52:24 | 000,417,792 | —- | M] () – C:\WINDOWS\Nero PhotoShow.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/08/16 03:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 03:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 03:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/05 15:03:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/20 10:48:12 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 03:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/12/04 17:39:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 18:31:54 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/07/26 16:59:08 | 000,204,496 | —- | M] (Malwarebytes) – C:\Documents and Settings\Jill Hadley\Desktop\StartUpLite.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/10 04:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/04/15 16:50:46 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Favorites\Desktop.ini
[1999/07/03 17:38:40 | 000,000,526 | —- | M] () – C:\Documents and Settings\Jill Hadley\Favorites\My Documents.lnk
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
Pool of Radiance remove.exe
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2009/05/18 15:35:24 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Cookies\desktop.ini
[2010/12/04 18:35:28 | 000,098,304 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-10 09:03:58
< >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 171 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2F2F703
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44DAF2F1
< End of report >
OTL Extras logfile created on: 12/4/2010 6:34:13 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jill Hadley\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 523.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 24.29 Gb Free Space | 16.83% Space Free | Partition Type: NTFS
Drive W: | 111.73 Gb Total Space | 35.35 Gb Free Space | 31.64% Space Free | Partition Type: NTFS
Drive X: | 9.41 Gb Total Space | 2.71 Gb Free Space | 28.84% Space Free | Partition Type: FAT
Computer Name: MOM | User Name: Jill Hadley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Disabled:AOL – File not found
"C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe" = C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe:*:Enabled:Toolbox for HP Printing System for Windows – (Hewlett-Packard Company)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – File not found
"C:\Program Files\MySpace\IM\MySpaceIM.exe" = C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM – File not found
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{0323CB96-221A-4042-84A3-93EDE47099FC}" = AVG 2011
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A258E63-8DF5-4ADB-9832-38A0121D65EB}" = AVG 2011
"{1C875160-7E87-45C6-85C5-4FE2A840A3B8}" = Maxtor Quick Start
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 20
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CEA6811-DFAD-4892-828D-49941FE3B779}" = Intel® PROSet for Wired Connections
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6D9785D9-FF53-4C06-9C2A-E4173D41A2FD}_is1" = Outlook on the Desktop 1.5.0
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78EFA95D-3310-4035-815B-A46BA4D0C6FA}" = VOB2MPG 2.3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8C22F265-DE76-44D1-8A79-A71D819137DA}" = Intel® Quick Resume Technology Drivers
"{8E49C988-C8F1-4197-AA6B-94E49751F5D7}" = Microsoft IntelliType Pro 6.3
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{903CE8F7-6C7B-41E6-A1CF-3BF1176264EC}" = Intel® Viiv™
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC60C8C1-855E-45AB-8D95-1D16F8A38E78}" = UGuide
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BA7A3288-228D-4031-A93A-B5F6B3415E15}" = Misc
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{C7DDA8E7-AD3D-4F51-AC1E-B0FF57002192}" = Microsoft IntelliPoint 6.3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F1CD25A0-5401-40B2-BAA9-E267408B16DF}" = Toolbox
"{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner
"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security
"{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"2G_1.2" = JumpStart 2nd Grade v1.2
"989E4C3B-B2C9-4486-9A09-D5A8F953837C" = Bejeweled 2 Deluxe
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe PageMaker 6.5" = Adobe PageMaker 6.5
"Adobe Photoshop 5.0 Limited Edition" = Adobe Photoshop 5.0 Limited Edition
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG" = AVG 2011
"CleanUp!" = CleanUp!
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Dell Game Console" = Dell Game Console
"Dual Mode Camera_is1" = Uninstall Dual Mode Camera
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab Decrypter_is1" = DVDFab Decrypter 2.9.7.9
"Easy Chef's Million Recipes" = Easy Chef's Million Recipes
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Officejet Pro K550 Series" = HP Officejet Pro K550 Series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1C875160-7E87-45C6-85C5-4FE2A840A3B8}" = Maxtor Quick Start
"InstallShield_{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = Canon Utilities PhotoStitch 3.1
"Intel® Quick Resume Technology" = Intel® Quick Resume Technology Drivers
"LimeWire" = LimeWire 4.16.0
"Mahjongg Dimensions Deluxe" = Mahjongg Dimensions Deluxe (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Morpheus" = Morpheus 5.2 (remove only)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSPUB4" = Microsoft Publisher 97
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"Nero PhotoShow Express" = Nero PhotoShow Express
"NeroVision!UninstallKey" = NeroVision Express 2
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NMIX!UninstallKey" = NeroMIX
"NVIDIA Drivers" = NVIDIA Drivers
"PRC_1.0" = JumpStart Parent Resource Center v1.0
"Print Server Driver" = Print Server Driver
"PROSet" = Intel® PRO Network Connections Drivers
"Putt-Putt Travels Through Time" = Putt-Putt Travels Through Time
"Tetris" = Tetris (remove only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2009
"winusb0100" = Microsoft WinUsb 1.0
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Zune" = Zune
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/4/2010 6:02:56 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.
Error - 12/4/2010 6:02:56 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 12/4/2010 7:15:14 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.
Error - 12/4/2010 7:15:14 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 12/4/2010 7:34:41 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.
Error - 12/4/2010 7:34:41 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 12/4/2010 7:45:59 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.
Error - 12/4/2010 7:46:00 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 12/4/2010 8:01:34 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.
Error - 12/4/2010 8:01:34 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
[ IntelDH Events ]
Error - 11/15/2010 4:17:45 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 11/18/2010 10:29:35 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 11/19/2010 3:22:19 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 11/22/2010 11:43:05 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 12/3/2010 11:30:55 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 12/4/2010 4:19:20 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 12/4/2010 6:02:57 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 12/4/2010 7:15:15 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 12/4/2010 7:34:42 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
Error - 12/4/2010 7:46:01 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.
[ System Events ]
Error - 11/23/2010 3:22:11 AM | Computer Name = MOM | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.5 for the Network Card with network
address 00137211E15B has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).
Error - 11/23/2010 2:29:11 PM | Computer Name = MOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 12/4/2010 4:19:15 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 12/4/2010 4:20:17 PM | Computer Name = MOM | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00000018, parameter2 00000002, parameter3
00000000, parameter4 f73af25f.
Error - 12/4/2010 4:20:52 PM | Computer Name = MOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service ehRecvr with
arguments "-Service" in order to run the server: {F4396DC6-E851-4D3A-8D01-34E6949F3500}
Error - 12/4/2010 6:02:52 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 12/4/2010 7:15:10 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 12/4/2010 7:34:40 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 12/4/2010 7:45:56 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 12/4/2010 8:01:31 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
< End of report >
And the Gmer log
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-12-04 21:51:57
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.10.0
Running: gmer.exe; Driver: C:\DOCUME~1\JILLHA~1\LOCALS~1\Temp\pxtdypow.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xED0EB620] <– ROOTKIT !!!
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF627B360, 0x20FDBD, 0xE8000020]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\iexplore.exe[152] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 0015737C
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0015613F
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00155F43
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00155ACB
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00155CC8
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00155B3E
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00155C19
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1104] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 005017E0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1104] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 005181B0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 0015737C
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0015613F
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00155F43
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00155ACB
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00155CC8
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00155B3E
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00155C19
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 0015737C
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0015613F
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00155F43
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00155ACB
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00155CC8
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00155B3E
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00155C19
.text C:\WINDOWS\Explorer.EXE[3276] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 00B48369
.text C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[3600] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 00719AB0 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Ip socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Tcp socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Avgtdix \Device\AvgTdi socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp socketlock.sys
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat B5AF1D20
Device \FileSystem\Fastfat \Fat B5B01428
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
—- Services - GMER 1.0.15 —-
Service system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys (*** hidden *** ) [SYSTEM] ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@imagepath \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@inst 0
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@ver sni060409
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cid 01
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@bid 3630642939-514355335-4051444915-1532494702
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@aid 998
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@sid 3
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@logoffset 4087
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthsvjupfblextaporxbcbahnriymgargnv.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwpcwvsmitrpkcbvmkejyhekmbquxlgyk.dat
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthnjqpfrxqtswnfkvwfjlxspvynteypelv.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwcrcqmjnkiheoifiivvknytmohgldrrd.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthgmkwrqvurcnlxsvfpaowtsswrtpgasxd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@imagepath \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@inst 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@ver sni060409
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cid 01
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@bid 3630642939-514355335-4051444915-1532494702
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@aid 998
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@sid 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cmddelay 28801
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@logoffset 4087
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthsvjupfblextaporxbcbahnriymgargnv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwpcwvsmitrpkcbvmkejyhekmbquxlgyk.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthnjqpfrxqtswnfkvwfjlxspvynteypelv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwcrcqmjnkiheoifiivvknytmohgldrrd.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthgmkwrqvurcnlxsvfpaowtsswrtpgasxd.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@imagepath \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@inst 0
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@ver sni060409
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cid 01
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@bid 3630642939-514355335-4051444915-1532494702
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@aid 998
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@sid 3
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@logoffset 4087
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthsvjupfblextaporxbcbahnriymgargnv.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwpcwvsmitrpkcbvmkejyhekmbquxlgyk.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthnjqpfrxqtswnfkvwfjlxspvynteypelv.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwcrcqmjnkiheoifiivvknytmohgldrrd.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthgmkwrqvurcnlxsvfpaowtsswrtpgasxd.dat
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@ Wireless
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@ProcessGroupPolicy ProcessWIRELESSPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@ Folder Redirection
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@ProcessGroupPolicyEx ProcessGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@DllName fdeploy.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoMachinePolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@PerUserLocalSettings 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@EventSources (Folder Redirection,Application)?
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ Microsoft Disk Quota
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoBackgroundPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@DllName dskquota.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@ QoS Packet Scheduler
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@ProcessGroupPolicy ProcessPSCHEDPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@ Scripts
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@ProcessGroupPolicy ProcessScriptsGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@ProcessGroupPolicyEx ProcessScriptsGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@GenerateGroupPolicy GenerateScriptsGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@NotifyLinkTransition 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ Internet Explorer Zonemapping
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ProcessGroupPolicy ProcessGroupPolicyForZoneMap
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSucessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ Internet Explorer User Accelerators
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicy ProcessGroupPolicyForActivities
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessSecurityPolicyGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@GenerateGroupPolicy SceGenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionRsopPlanningDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicyEx SceProcessSecurityPolicyGPOEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ Security
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@EnableAsynchronousProcessing 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@MaxNoGPOListChangesInterval 960
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicyEx ProcessGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ Internet Explorer Branding
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoMachinePolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3014
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessEFSRecoveryGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ EFS recovery
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@ 802.3 Group Policy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@DisplayName @dot3gpclnt.dll,-100
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@ProcessGroupPolicyEx ProcessLANPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@GenerateGroupPolicy GenerateLANPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@DllName dot3gpclnt.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ Microsoft Offline Files
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@DllName %SystemRoot%\System32\cscui.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoSlowLink 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ Software Installation
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@DllName appmgmts.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ProcessGroupPolicyEx ProcessGroupPolicyObjectsEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@RequiresSucessfulRegistry 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@PerUserLocalSettings 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@EventSources (Application Management,Application)?(MsiInstaller,Application)?
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ Internet Explorer Machine Accelerators
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicy ProcessGroupPolicyForActivities
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@ IP Security
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@ProcessGroupPolicy ProcessIPSECPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@HelpAssistant 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@TsInternetUser 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@SQLAgentCmdExec 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@NetShowServices 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IWAM_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IUSR_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@VUSR_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@ASPNET 0
—- EOF - GMER 1.0.15 —-