___________________________________________________________
OTL LOG
OTL logfile created on: 1/5/2011 8:19:52 PM - Run 3
OTL by OldTimer - Version 3.2.20.1 Folder = J:\Documents and Settings\Mucko\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): J:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = J: | %SystemRoot% = J:\WINDOWS | %ProgramFiles% = J:\Program Files
Drive J: | 195.31 Gb Total Space | 167.63 Gb Free Space | 85.83% Space Free | Partition Type: NTFS
Computer Name: UIOF3455GYP6345 | User Name: Mucko | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
PRC - J:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - j:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - J:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
MOD - J:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – J:\WINDOWS\System32\hidserv.dll File not found
SRV - (0131221293242455mcinstcleanup) McAfee Application Installer Cleanup (0131221293242455) – J:\WINDOWS\TEMP\013122~1.EXE File not found
SRV - (FlipShare Service) – J:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (FlipShareServer) – J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
SRV - (mfefire) – J:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (mfevtp) – J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – J:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – J:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (IntuitUpdateService) – J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (MOBKbackup) – J:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (aspnet_state) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (dlcq_device) – J:\WINDOWS\System32\dlcqcoms.exe ( )
SRV - (APC UPS Service) – J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Driver Services (SafeList) ==========
DRV - (mfehidk) – J:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – J:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – J:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – J:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – J:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – J:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – J:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – J:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (MOBKFilter) – J:\WINDOWS\system32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (HDAudBus) – J:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – J:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Btcsrusb) – J:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (BlueletSCOAudio) – J:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) – J:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (BTHidMgr) – J:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) – J:\WINDOWS\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) – J:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (VComm) – J:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (BlueletAudio) – J:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (athena) – J:\WINDOWS\system32\drivers\athena.sys (AGEIA Technologies, Inc.)
DRV - (nvatabus) – J:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (STHDA) – J:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – J:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (DLACDBHM) – J:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – J:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ctaud2k) Creative Audio Driver (WDM) – J:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – J:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ha20x2k) – J:\WINDOWS\system32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (ossrv) – J:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – J:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – J:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – J:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (DLAUDFAM) – J:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – J:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – J:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – J:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – J:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – J:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – J:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DRVMCDB) – J:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (HSF_DPV) – J:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – J:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – J:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (DRVNDDM) – J:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (ctdvda2k) – J:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (WmXlCore) – J:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmFilter) – J:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – J:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – J:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: J:\Program Files\McAfee\SiteAdvisor [2010/12/14 18:52:49 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DWABrowserHlprObj Class) - {2709D830-B643-4e72-9A1E-701CFFFCF30C} - J:\WINDOWS\system32\dwabho.dll (IBM Corporation)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - j:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - J:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - J:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101104223529.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] J:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] J:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CTDVDDET] J:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] J:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] J:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] J:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCQCATS] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.DLL ()
O4 - HKLM..\Run: [dlcqmon.exe] J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe ()
O4 - HKLM..\Run: [DMXLauncher] J:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [FaxCenterServer] J:\Program Files\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] J:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] J:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [mcui_exe] J:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MemoryCardManager] J:\Program Files\Dell Photo AIO Printer 966\memcard.exe ()
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] J:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UpdReg] J:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] J:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Privacy Suite RiskMonitor] J:\Program Files\CyberScrub Privacy Suite\Launch.exe ()
O4 - HKCU..\RunOnce: [dAaDk00000] J:\Documents and Settings\All Users\Application Data\dAaDk00000\dAaDk00000.exe ()
O4 - Startup: J:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = J:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1287279992296 (WUWebControl Class)
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} https://nhxmail1.nu.com/dwa85W.cab (IBM Lotus iNotes 8.5 Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\AutoRun\command - "" = M:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\Setup FlipShare\command - "" = M:\Setup_FlipShare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/05 20:03:46 | 000,602,112 | —- | C] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/01/05 19:32:48 | 000,000,000 | —D | C] – J:\WINDOWS\CSC
[2011/01/05 17:57:19 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Start Menu\Programs\System Tool
[2011/01/05 17:46:52 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/30 22:23:03 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\My Documents\TurboTax
[2010/12/30 22:20:35 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Intuit
[2010/12/30 22:20:07 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:18:57 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2010/12/30 22:17:30 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:16:28 | 000,000,000 | —D | C] – J:\Program Files\TurboTax
[2010/12/29 20:42:54 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\chops christmas
[2010/12/28 09:56:41 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Flip Video
[2010/12/24 20:29:16 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\Christmas For Rich
[2010/12/23 20:29:27 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison 2
[2010/12/18 22:54:59 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/12/18 22:49:20 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison
[2010/12/18 19:13:06 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Application Data\Flip Video
[2010/12/18 18:35:22 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\CHOPS
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\WINDOWS\System32\QuickTime
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\3ivx
[2010/12/18 18:23:34 | 000,000,000 | —D | C] – J:\Program Files\3ivx
[2010/12/18 18:23:30 | 000,000,000 | —D | C] – J:\Program Files\Flip Video
[2010/12/18 18:23:29 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2010/12/14 14:27:23 | 000,040,960 | —- | C] (Microsoft Corporation) – J:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/08 00:04:39 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\silly cats
[2010/10/16 20:20:41 | 001,224,704 | —- | C] ( ) – J:\WINDOWS\System32\dlcqserv.dll
[2010/10/16 20:20:41 | 000,991,232 | —- | C] ( ) – J:\WINDOWS\System32\dlcqusb1.dll
[2010/10/16 20:20:41 | 000,413,696 | —- | C] ( ) – J:\WINDOWS\System32\dlcqinpa.dll
[2010/10/16 20:20:41 | 000,397,312 | —- | C] ( ) – J:\WINDOWS\System32\dlcqiesc.dll
[2010/10/16 20:20:41 | 000,323,584 | —- | C] ( ) – J:\WINDOWS\System32\DLCQhcp.dll
[2010/10/16 20:20:40 | 000,696,320 | —- | C] ( ) – J:\WINDOWS\System32\dlcqhbn3.dll
[2010/10/16 20:20:40 | 000,643,072 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpmui.dll
[2010/10/16 20:20:40 | 000,585,728 | —- | C] ( ) – J:\WINDOWS\System32\dlcqlmpm.dll
[2010/10/16 20:20:40 | 000,163,840 | —- | C] ( ) – J:\WINDOWS\System32\dlcqprox.dll
[2010/10/16 20:20:40 | 000,094,208 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpplc.dll
[2010/10/16 20:20:39 | 000,684,032 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomc.dll
[2010/10/16 20:20:39 | 000,421,888 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomm.dll
[2005/11/08 07:38:38 | 000,033,792 | R— | C] ( ) – J:\WINDOWS\System32\a3d.dll
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/05 20:08:28 | 000,002,206 | —- | M] () – J:\WINDOWS\System32\wpa.dbl
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,001,595 | —- | M] () – J:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/01/05 19:32:45 | 000,002,048 | –S- | M] () – J:\WINDOWS\bootstat.dat
[2011/01/05 19:30:49 | 000,000,278 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2011/01/05 19:29:25 | 000,064,984 | —- | M] () – J:\WINDOWS\System32\DVCState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settingsbkup.sfm
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settings.sfm
[2011/01/05 17:57:19 | 000,001,054 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 17:53:31 | 000,051,712 | —- | M] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/05 15:37:10 | 000,013,927 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/05 14:13:17 | 000,002,515 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Microsoft Office Word 2007.lnk
[2011/01/04 21:06:57 | 000,032,768 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 20:09:04 | 000,032,256 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:54:19 | 000,177,856 | —- | M] () – J:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/30 22:18:57 | 000,001,882 | —- | M] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | M] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2010/12/17 09:01:01 | 000,074,240 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/12/14 16:45:40 | 000,001,393 | —- | M] () – J:\WINDOWS\imsins.BAK
[2010/12/14 09:44:00 | 000,000,286 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2010/12/08 00:23:40 | 000,001,560 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Disk Defragmenter.lnk
[2010/12/06 21:12:23 | 000,000,000 | -H– | M] () – J:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/05 17:57:19 | 000,001,054 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 14:56:07 | 000,013,927 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/04 21:06:57 | 000,032,768 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 19:55:18 | 000,032,256 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:53:14 | 000,219,416 | —- | C] () – J:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/30 22:18:57 | 000,001,882 | —- | C] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | C] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | C] () – J:\logFile.xsl
[2010/12/17 09:01:00 | 000,074,240 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/10/16 23:48:28 | 000,000,084 | —- | C] () – J:\WINDOWS\csact.ini
[2010/10/16 23:43:08 | 000,000,165 | —- | C] () – J:\WINDOWS\QUICKEN.INI
[2010/10/16 23:31:24 | 000,051,712 | —- | C] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/16 20:34:44 | 000,000,264 | —- | C] () – J:\WINDOWS\wininit.ini
[2010/10/16 20:23:32 | 000,040,960 | —- | C] () – J:\WINDOWS\System32\dlcqvs.dll
[2010/10/16 20:23:30 | 000,344,064 | —- | C] () – J:\WINDOWS\System32\dlcqcoin.dll
[2010/10/16 20:23:20 | 000,692,224 | —- | C] () – J:\WINDOWS\System32\dlcqdrs.dll
[2010/10/16 20:23:20 | 000,065,536 | —- | C] () – J:\WINDOWS\System32\dlcqcaps.dll
[2010/10/16 20:23:20 | 000,061,440 | —- | C] () – J:\WINDOWS\System32\dlcqcnv4.dll
[2010/10/16 20:21:10 | 000,045,056 | —- | C] () – J:\WINDOWS\System32\DLPRMON.DLL
[2010/10/16 20:21:10 | 000,032,768 | —- | C] () – J:\WINDOWS\System32\DLPMONUI.DLL
[2010/10/16 20:20:41 | 000,454,656 | —- | C] () – J:\WINDOWS\System32\dlcqutil.dll
[2010/10/16 20:20:41 | 000,274,432 | —- | C] () – J:\WINDOWS\System32\DLCQinst.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqinsb.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqins.dll
[2010/10/16 20:20:40 | 000,139,264 | —- | C] () – J:\WINDOWS\System32\dlcqjswr.dll
[2010/10/16 20:20:40 | 000,106,496 | —- | C] () – J:\WINDOWS\System32\dlcqinsr.dll
[2010/10/16 20:20:39 | 000,188,416 | —- | C] () – J:\WINDOWS\System32\dlcqgrd.dll
[2010/10/16 20:20:39 | 000,086,016 | —- | C] () – J:\WINDOWS\System32\dlcqcub.dll
[2010/10/16 20:20:39 | 000,073,728 | —- | C] () – J:\WINDOWS\System32\dlcqcu.dll
[2010/10/16 20:20:39 | 000,036,864 | —- | C] () – J:\WINDOWS\System32\dlcqcur.dll
[2010/10/16 20:20:38 | 000,077,824 | —- | C] () – J:\WINDOWS\System32\DLCQcfg.dll
[2010/10/16 20:14:04 | 000,000,152 | —- | C] () – J:\WINDOWS\CoolPlay.ini
[2010/10/16 20:09:31 | 000,050,432 | R— | C] () – J:\WINDOWS\System32\claptn.ini
[2010/10/16 20:09:31 | 000,003,072 | —- | C] () – J:\WINDOWS\CTXFIRES.DLL
[2010/10/16 20:09:31 | 000,000,190 | R— | C] () – J:\WINDOWS\System32\ctzapxx.ini
[2010/10/16 15:26:34 | 000,004,161 | —- | C] () – J:\WINDOWS\ODBCINST.INI
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – J:\WINDOWS\System32\OGACheckControl.dll
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – J:\WINDOWS\System32\OpenQuicktimeLib.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – J:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – J:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – J:\WINDOWS\System32\gthrctr.ini
[2006/12/06 13:39:49 | 000,000,000 | —- | C] () – J:\WINDOWS\System32\px.ini
[2005/11/08 07:43:30 | 000,038,400 | —- | C] () – J:\WINDOWS\System32\CTBURST.DLL
[2003/03/21 04:56:10 | 000,000,194 | —- | C] () – J:\WINDOWS\System32\KILL.INI
========== LOP Check ==========
[2010/10/20 12:53:05 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Bluetooth
[2011/01/05 17:46:55 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/18 19:12:46 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2011/01/05 19:31:00 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/16 23:49:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\CyberScrub
[2010/12/18 22:54:59 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/10/16 21:03:13 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Desktop Search
[2010/11/28 00:05:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/16 15:24:42 | 000,000,210 | -HS- | M] () – J:\boot.ini
[2011/01/01 21:30:59 | 000,005,496 | —- | M] () – J:\dlcq.log
[2010/10/16 20:38:46 | 000,002,785 | —- | M] () – J:\LGSInst.Log
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – J:\NTDETECT.COM
[2010/10/16 21:27:00 | 000,250,048 | RHS- | M] () – J:\ntldr
[2011/01/05 19:32:08 | 2145,386,496 | -HS- | M] () – J:\pagefile.sys
[2 J:\*.tmp files -> J:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – J:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – J:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – J:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – J:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/10/16 19:37:13 | 000,000,067 | -HS- | M] () – J:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/20 00:34:18 | 000,118,784 | —- | M] () – J:\WINDOWS\system32\spool\prtprocs\w32x86\dlcqdrpp.dll
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/10/16 15:24:42 | 000,094,208 | —- | M] () – J:\WINDOWS\system32\config\default.sav
[2010/10/16 15:24:42 | 000,659,456 | —- | M] () – J:\WINDOWS\system32\config\software.sav
[2010/10/16 15:24:42 | 000,942,080 | —- | M] () – J:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/10/16 21:28:38 | 000,000,272 | -HS- | M] () – J:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/16 21:35:13 | 000,000,119 | -HS- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/16 19:40:40 | 000,000,079 | —- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/10/20 12:00:02 | 000,050,688 | —- | M] (Atribune.org) – J:\Documents and Settings\Mucko\Desktop\ATF-Cleaner.exe
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-05 17:46:25
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 188 bytes -> J:\Documents and Settings\All Users\Application Data\TEMP:B4AF47A7
< End of report >
========== Processes (SafeList) ==========
PRC - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
PRC - J:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - j:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - J:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
MOD - J:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – J:\WINDOWS\System32\hidserv.dll File not found
SRV - (0131221293242455mcinstcleanup) McAfee Application Installer Cleanup (0131221293242455) – J:\WINDOWS\TEMP\013122~1.EXE File not found
SRV - (FlipShare Service) – J:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (FlipShareServer) – J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
SRV - (mfefire) – J:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (mfevtp) – J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – J:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – J:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (IntuitUpdateService) – J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (MOBKbackup) – J:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (aspnet_state) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (dlcq_device) – J:\WINDOWS\System32\dlcqcoms.exe ( )
SRV - (APC UPS Service) – J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Driver Services (SafeList) ==========
DRV - (mfehidk) – J:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – J:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – J:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – J:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – J:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – J:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – J:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – J:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (MOBKFilter) – J:\WINDOWS\system32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (HDAudBus) – J:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – J:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Btcsrusb) – J:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (BlueletSCOAudio) – J:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) – J:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (BTHidMgr) – J:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) – J:\WINDOWS\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) – J:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (VComm) – J:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (BlueletAudio) – J:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (athena) – J:\WINDOWS\system32\drivers\athena.sys (AGEIA Technologies, Inc.)
DRV - (nvatabus) – J:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (STHDA) – J:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – J:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (DLACDBHM) – J:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – J:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ctaud2k) Creative Audio Driver (WDM) – J:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – J:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ha20x2k) – J:\WINDOWS\system32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (ossrv) – J:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – J:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – J:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – J:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (DLAUDFAM) – J:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – J:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – J:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – J:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – J:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – J:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – J:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DRVMCDB) – J:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (HSF_DPV) – J:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – J:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – J:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (DRVNDDM) – J:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (ctdvda2k) – J:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (WmXlCore) – J:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmFilter) – J:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – J:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – J:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: J:\Program Files\McAfee\SiteAdvisor [2010/12/14 18:52:49 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DWABrowserHlprObj Class) - {2709D830-B643-4e72-9A1E-701CFFFCF30C} - J:\WINDOWS\system32\dwabho.dll (IBM Corporation)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - j:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - J:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - J:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101104223529.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] J:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] J:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CTDVDDET] J:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] J:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] J:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] J:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCQCATS] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.DLL ()
O4 - HKLM..\Run: [dlcqmon.exe] J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe ()
O4 - HKLM..\Run: [DMXLauncher] J:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [FaxCenterServer] J:\Program Files\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] J:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] J:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [mcui_exe] J:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MemoryCardManager] J:\Program Files\Dell Photo AIO Printer 966\memcard.exe ()
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] J:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UpdReg] J:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] J:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Privacy Suite RiskMonitor] J:\Program Files\CyberScrub Privacy Suite\Launch.exe ()
O4 - HKCU..\RunOnce: [dAaDk00000] J:\Documents and Settings\All Users\Application Data\dAaDk00000\dAaDk00000.exe ()
O4 - Startup: J:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = J:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1287279992296 (WUWebControl Class)
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} https://nhxmail1.nu.com/dwa85W.cab (IBM Lotus iNotes 8.5 Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\AutoRun\command - "" = M:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\Setup FlipShare\command - "" = M:\Setup_FlipShare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/05 20:03:46 | 000,602,112 | —- | C] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/01/05 19:32:48 | 000,000,000 | —D | C] – J:\WINDOWS\CSC
[2011/01/05 17:57:19 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Start Menu\Programs\System Tool
[2011/01/05 17:46:52 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/30 22:23:03 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\My Documents\TurboTax
[2010/12/30 22:20:35 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Intuit
[2010/12/30 22:20:07 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:18:57 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2010/12/30 22:17:30 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:16:28 | 000,000,000 | —D | C] – J:\Program Files\TurboTax
[2010/12/29 20:42:54 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\chops christmas
[2010/12/28 09:56:41 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Flip Video
[2010/12/24 20:29:16 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\Christmas For Rich
[2010/12/23 20:29:27 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison 2
[2010/12/18 22:54:59 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/12/18 22:49:20 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison
[2010/12/18 19:13:06 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Application Data\Flip Video
[2010/12/18 18:35:22 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\CHOPS
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\WINDOWS\System32\QuickTime
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\3ivx
[2010/12/18 18:23:34 | 000,000,000 | —D | C] – J:\Program Files\3ivx
[2010/12/18 18:23:30 | 000,000,000 | —D | C] – J:\Program Files\Flip Video
[2010/12/18 18:23:29 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2010/12/14 14:27:23 | 000,040,960 | —- | C] (Microsoft Corporation) – J:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/08 00:04:39 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\silly cats
[2010/10/16 20:20:41 | 001,224,704 | —- | C] ( ) – J:\WINDOWS\System32\dlcqserv.dll
[2010/10/16 20:20:41 | 000,991,232 | —- | C] ( ) – J:\WINDOWS\System32\dlcqusb1.dll
[2010/10/16 20:20:41 | 000,413,696 | —- | C] ( ) – J:\WINDOWS\System32\dlcqinpa.dll
[2010/10/16 20:20:41 | 000,397,312 | —- | C] ( ) – J:\WINDOWS\System32\dlcqiesc.dll
[2010/10/16 20:20:41 | 000,323,584 | —- | C] ( ) – J:\WINDOWS\System32\DLCQhcp.dll
[2010/10/16 20:20:40 | 000,696,320 | —- | C] ( ) – J:\WINDOWS\System32\dlcqhbn3.dll
[2010/10/16 20:20:40 | 000,643,072 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpmui.dll
[2010/10/16 20:20:40 | 000,585,728 | —- | C] ( ) – J:\WINDOWS\System32\dlcqlmpm.dll
[2010/10/16 20:20:40 | 000,163,840 | —- | C] ( ) – J:\WINDOWS\System32\dlcqprox.dll
[2010/10/16 20:20:40 | 000,094,208 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpplc.dll
[2010/10/16 20:20:39 | 000,684,032 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomc.dll
[2010/10/16 20:20:39 | 000,421,888 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomm.dll
[2005/11/08 07:38:38 | 000,033,792 | R— | C] ( ) – J:\WINDOWS\System32\a3d.dll
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/05 20:08:28 | 000,002,206 | —- | M] () – J:\WINDOWS\System32\wpa.dbl
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,001,595 | —- | M] () – J:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/01/05 19:32:45 | 000,002,048 | –S- | M] () – J:\WINDOWS\bootstat.dat
[2011/01/05 19:30:49 | 000,000,278 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2011/01/05 19:29:25 | 000,064,984 | —- | M] () – J:\WINDOWS\System32\DVCState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settingsbkup.sfm
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settings.sfm
[2011/01/05 17:57:19 | 000,001,054 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 17:53:31 | 000,051,712 | —- | M] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/05 15:37:10 | 000,013,927 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/05 14:13:17 | 000,002,515 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Microsoft Office Word 2007.lnk
[2011/01/04 21:06:57 | 000,032,768 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 20:09:04 | 000,032,256 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:54:19 | 000,177,856 | —- | M] () – J:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/30 22:18:57 | 000,001,882 | —- | M] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | M] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2010/12/17 09:01:01 | 000,074,240 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/12/14 16:45:40 | 000,001,393 | —- | M] () – J:\WINDOWS\imsins.BAK
[2010/12/14 09:44:00 | 000,000,286 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2010/12/08 00:23:40 | 000,001,560 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Disk Defragmenter.lnk
[2010/12/06 21:12:23 | 000,000,000 | -H– | M] () – J:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/05 17:57:19 | 000,001,054 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 14:56:07 | 000,013,927 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/04 21:06:57 | 000,032,768 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 19:55:18 | 000,032,256 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:53:14 | 000,219,416 | —- | C] () – J:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/30 22:18:57 | 000,001,882 | —- | C] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | C] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | C] () – J:\logFile.xsl
[2010/12/17 09:01:00 | 000,074,240 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/10/16 23:48:28 | 000,000,084 | —- | C] () – J:\WINDOWS\csact.ini
[2010/10/16 23:43:08 | 000,000,165 | —- | C] () – J:\WINDOWS\QUICKEN.INI
[2010/10/16 23:31:24 | 000,051,712 | —- | C] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/16 20:34:44 | 000,000,264 | —- | C] () – J:\WINDOWS\wininit.ini
[2010/10/16 20:23:32 | 000,040,960 | —- | C] () – J:\WINDOWS\System32\dlcqvs.dll
[2010/10/16 20:23:30 | 000,344,064 | —- | C] () – J:\WINDOWS\System32\dlcqcoin.dll
[2010/10/16 20:23:20 | 000,692,224 | —- | C] () – J:\WINDOWS\System32\dlcqdrs.dll
[2010/10/16 20:23:20 | 000,065,536 | —- | C] () – J:\WINDOWS\System32\dlcqcaps.dll
[2010/10/16 20:23:20 | 000,061,440 | —- | C] () – J:\WINDOWS\System32\dlcqcnv4.dll
[2010/10/16 20:21:10 | 000,045,056 | —- | C] () – J:\WINDOWS\System32\DLPRMON.DLL
[2010/10/16 20:21:10 | 000,032,768 | —- | C] () – J:\WINDOWS\System32\DLPMONUI.DLL
[2010/10/16 20:20:41 | 000,454,656 | —- | C] () – J:\WINDOWS\System32\dlcqutil.dll
[2010/10/16 20:20:41 | 000,274,432 | —- | C] () – J:\WINDOWS\System32\DLCQinst.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqinsb.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqins.dll
[2010/10/16 20:20:40 | 000,139,264 | —- | C] () – J:\WINDOWS\System32\dlcqjswr.dll
[2010/10/16 20:20:40 | 000,106,496 | —- | C] () – J:\WINDOWS\System32\dlcqinsr.dll
[2010/10/16 20:20:39 | 000,188,416 | —- | C] () – J:\WINDOWS\System32\dlcqgrd.dll
[2010/10/16 20:20:39 | 000,086,016 | —- | C] () – J:\WINDOWS\System32\dlcqcub.dll
[2010/10/16 20:20:39 | 000,073,728 | —- | C] () – J:\WINDOWS\System32\dlcqcu.dll
[2010/10/16 20:20:39 | 000,036,864 | —- | C] () – J:\WINDOWS\System32\dlcqcur.dll
[2010/10/16 20:20:38 | 000,077,824 | —- | C] () – J:\WINDOWS\System32\DLCQcfg.dll
[2010/10/16 20:14:04 | 000,000,152 | —- | C] () – J:\WINDOWS\CoolPlay.ini
[2010/10/16 20:09:31 | 000,050,432 | R— | C] () – J:\WINDOWS\System32\claptn.ini
[2010/10/16 20:09:31 | 000,003,072 | —- | C] () – J:\WINDOWS\CTXFIRES.DLL
[2010/10/16 20:09:31 | 000,000,190 | R— | C] () – J:\WINDOWS\System32\ctzapxx.ini
[2010/10/16 15:26:34 | 000,004,161 | —- | C] () – J:\WINDOWS\ODBCINST.INI
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – J:\WINDOWS\System32\OGACheckControl.dll
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – J:\WINDOWS\System32\OpenQuicktimeLib.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – J:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – J:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – J:\WINDOWS\System32\gthrctr.ini
[2006/12/06 13:39:49 | 000,000,000 | —- | C] () – J:\WINDOWS\System32\px.ini
[2005/11/08 07:43:30 | 000,038,400 | —- | C] () – J:\WINDOWS\System32\CTBURST.DLL
[2003/03/21 04:56:10 | 000,000,194 | —- | C] () – J:\WINDOWS\System32\KILL.INI
========== LOP Check ==========
[2010/10/20 12:53:05 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Bluetooth
[2011/01/05 17:46:55 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/18 19:12:46 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2011/01/05 19:31:00 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/16 23:49:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\CyberScrub
[2010/12/18 22:54:59 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/10/16 21:03:13 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Desktop Search
[2010/11/28 00:05:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/16 15:24:42 | 000,000,210 | -HS- | M] () – J:\boot.ini
[2011/01/01 21:30:59 | 000,005,496 | —- | M] () – J:\dlcq.log
[2010/10/16 20:38:46 | 000,002,785 | —- | M] () – J:\LGSInst.Log
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – J:\NTDETECT.COM
[2010/10/16 21:27:00 | 000,250,048 | RHS- | M] () – J:\ntldr
[2011/01/05 19:32:08 | 2145,386,496 | -HS- | M] () – J:\pagefile.sys
[2 J:\*.tmp files -> J:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – J:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – J:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – J:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – J:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/10/16 19:37:13 | 000,000,067 | -HS- | M] () – J:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/20 00:34:18 | 000,118,784 | —- | M] () – J:\WINDOWS\system32\spool\prtprocs\w32x86\dlcqdrpp.dll
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/10/16 15:24:42 | 000,094,208 | —- | M] () – J:\WINDOWS\system32\config\default.sav
[2010/10/16 15:24:42 | 000,659,456 | —- | M] () – J:\WINDOWS\system32\config\software.sav
[2010/10/16 15:24:42 | 000,942,080 | —- | M] () – J:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/10/16 21:28:38 | 000,000,272 | -HS- | M] () – J:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/16 21:35:13 | 000,000,119 | -HS- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/16 19:40:40 | 000,000,079 | —- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/10/20 12:00:02 | 000,050,688 | —- | M] (Atribune.org) – J:\Documents and Settings\Mucko\Desktop\ATF-Cleaner.exe
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-05 17:46:25
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 188 bytes -> J:\Documents and Settings\All Users\Application Data\TEMP:B4AF47A7
< End of report >
========== Processes (SafeList) ==========
PRC - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
PRC - J:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - j:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - J:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
MOD - J:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – J:\WINDOWS\System32\hidserv.dll File not found
SRV - (0131221293242455mcinstcleanup) McAfee Application Installer Cleanup (0131221293242455) – J:\WINDOWS\TEMP\013122~1.EXE File not found
SRV - (FlipShare Service) – J:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (FlipShareServer) – J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
SRV - (mfefire) – J:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (mfevtp) – J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – J:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – J:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (IntuitUpdateService) – J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (MOBKbackup) – J:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (aspnet_state) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (dlcq_device) – J:\WINDOWS\System32\dlcqcoms.exe ( )
SRV - (APC UPS Service) – J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Driver Services (SafeList) ==========
DRV - (mfehidk) – J:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – J:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – J:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – J:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – J:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – J:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – J:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – J:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (MOBKFilter) – J:\WINDOWS\system32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (HDAudBus) – J:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – J:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Btcsrusb) – J:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (BlueletSCOAudio) – J:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) – J:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (BTHidMgr) – J:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) – J:\WINDOWS\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) – J:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (VComm) – J:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (BlueletAudio) – J:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (athena) – J:\WINDOWS\system32\drivers\athena.sys (AGEIA Technologies, Inc.)
DRV - (nvatabus) – J:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (STHDA) – J:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – J:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (DLACDBHM) – J:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – J:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ctaud2k) Creative Audio Driver (WDM) – J:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – J:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ha20x2k) – J:\WINDOWS\system32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (ossrv) – J:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – J:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – J:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – J:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (DLAUDFAM) – J:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – J:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – J:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – J:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – J:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – J:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – J:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DRVMCDB) – J:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (HSF_DPV) – J:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – J:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – J:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (DRVNDDM) – J:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (ctdvda2k) – J:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (WmXlCore) – J:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmFilter) – J:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – J:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – J:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: J:\Program Files\McAfee\SiteAdvisor [2010/12/14 18:52:49 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DWABrowserHlprObj Class) - {2709D830-B643-4e72-9A1E-701CFFFCF30C} - J:\WINDOWS\system32\dwabho.dll (IBM Corporation)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - j:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - J:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - J:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101104223529.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] J:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] J:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CTDVDDET] J:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] J:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] J:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] J:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCQCATS] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.DLL ()
O4 - HKLM..\Run: [dlcqmon.exe] J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe ()
O4 - HKLM..\Run: [DMXLauncher] J:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [FaxCenterServer] J:\Program Files\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] J:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] J:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [mcui_exe] J:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MemoryCardManager] J:\Program Files\Dell Photo AIO Printer 966\memcard.exe ()
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] J:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UpdReg] J:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] J:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Privacy Suite RiskMonitor] J:\Program Files\CyberScrub Privacy Suite\Launch.exe ()
O4 - HKCU..\RunOnce: [dAaDk00000] J:\Documents and Settings\All Users\Application Data\dAaDk00000\dAaDk00000.exe ()
O4 - Startup: J:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = J:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1287279992296 (WUWebControl Class)
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} https://nhxmail1.nu.com/dwa85W.cab (IBM Lotus iNotes 8.5 Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\AutoRun\command - "" = M:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\Setup FlipShare\command - "" = M:\Setup_FlipShare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/05 20:03:46 | 000,602,112 | —- | C] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/01/05 19:32:48 | 000,000,000 | —D | C] – J:\WINDOWS\CSC
[2011/01/05 17:57:19 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Start Menu\Programs\System Tool
[2011/01/05 17:46:52 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/30 22:23:03 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\My Documents\TurboTax
[2010/12/30 22:20:35 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Intuit
[2010/12/30 22:20:07 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:18:57 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2010/12/30 22:17:30 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:16:28 | 000,000,000 | —D | C] – J:\Program Files\TurboTax
[2010/12/29 20:42:54 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\chops christmas
[2010/12/28 09:56:41 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Flip Video
[2010/12/24 20:29:16 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\Christmas For Rich
[2010/12/23 20:29:27 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison 2
[2010/12/18 22:54:59 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/12/18 22:49:20 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison
[2010/12/18 19:13:06 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Application Data\Flip Video
[2010/12/18 18:35:22 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\CHOPS
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\WINDOWS\System32\QuickTime
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\3ivx
[2010/12/18 18:23:34 | 000,000,000 | —D | C] – J:\Program Files\3ivx
[2010/12/18 18:23:30 | 000,000,000 | —D | C] – J:\Program Files\Flip Video
[2010/12/18 18:23:29 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2010/12/14 14:27:23 | 000,040,960 | —- | C] (Microsoft Corporation) – J:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/08 00:04:39 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\silly cats
[2010/10/16 20:20:41 | 001,224,704 | —- | C] ( ) – J:\WINDOWS\System32\dlcqserv.dll
[2010/10/16 20:20:41 | 000,991,232 | —- | C] ( ) – J:\WINDOWS\System32\dlcqusb1.dll
[2010/10/16 20:20:41 | 000,413,696 | —- | C] ( ) – J:\WINDOWS\System32\dlcqinpa.dll
[2010/10/16 20:20:41 | 000,397,312 | —- | C] ( ) – J:\WINDOWS\System32\dlcqiesc.dll
[2010/10/16 20:20:41 | 000,323,584 | —- | C] ( ) – J:\WINDOWS\System32\DLCQhcp.dll
[2010/10/16 20:20:40 | 000,696,320 | —- | C] ( ) – J:\WINDOWS\System32\dlcqhbn3.dll
[2010/10/16 20:20:40 | 000,643,072 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpmui.dll
[2010/10/16 20:20:40 | 000,585,728 | —- | C] ( ) – J:\WINDOWS\System32\dlcqlmpm.dll
[2010/10/16 20:20:40 | 000,163,840 | —- | C] ( ) – J:\WINDOWS\System32\dlcqprox.dll
[2010/10/16 20:20:40 | 000,094,208 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpplc.dll
[2010/10/16 20:20:39 | 000,684,032 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomc.dll
[2010/10/16 20:20:39 | 000,421,888 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomm.dll
[2005/11/08 07:38:38 | 000,033,792 | R— | C] ( ) – J:\WINDOWS\System32\a3d.dll
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/05 20:08:28 | 000,002,206 | —- | M] () – J:\WINDOWS\System32\wpa.dbl
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,001,595 | —- | M] () – J:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/01/05 19:32:45 | 000,002,048 | –S- | M] () – J:\WINDOWS\bootstat.dat
[2011/01/05 19:30:49 | 000,000,278 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2011/01/05 19:29:25 | 000,064,984 | —- | M] () – J:\WINDOWS\System32\DVCState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settingsbkup.sfm
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settings.sfm
[2011/01/05 17:57:19 | 000,001,054 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 17:53:31 | 000,051,712 | —- | M] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/05 15:37:10 | 000,013,927 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/05 14:13:17 | 000,002,515 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Microsoft Office Word 2007.lnk
[2011/01/04 21:06:57 | 000,032,768 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 20:09:04 | 000,032,256 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:54:19 | 000,177,856 | —- | M] () – J:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/30 22:18:57 | 000,001,882 | —- | M] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | M] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2010/12/17 09:01:01 | 000,074,240 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/12/14 16:45:40 | 000,001,393 | —- | M] () – J:\WINDOWS\imsins.BAK
[2010/12/14 09:44:00 | 000,000,286 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2010/12/08 00:23:40 | 000,001,560 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Disk Defragmenter.lnk
[2010/12/06 21:12:23 | 000,000,000 | -H– | M] () – J:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/05 17:57:19 | 000,001,054 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 14:56:07 | 000,013,927 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/04 21:06:57 | 000,032,768 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 19:55:18 | 000,032,256 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:53:14 | 000,219,416 | —- | C] () – J:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/30 22:18:57 | 000,001,882 | —- | C] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | C] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | C] () – J:\logFile.xsl
[2010/12/17 09:01:00 | 000,074,240 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/10/16 23:48:28 | 000,000,084 | —- | C] () – J:\WINDOWS\csact.ini
[2010/10/16 23:43:08 | 000,000,165 | —- | C] () – J:\WINDOWS\QUICKEN.INI
[2010/10/16 23:31:24 | 000,051,712 | —- | C] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/16 20:34:44 | 000,000,264 | —- | C] () – J:\WINDOWS\wininit.ini
[2010/10/16 20:23:32 | 000,040,960 | —- | C] () – J:\WINDOWS\System32\dlcqvs.dll
[2010/10/16 20:23:30 | 000,344,064 | —- | C] () – J:\WINDOWS\System32\dlcqcoin.dll
[2010/10/16 20:23:20 | 000,692,224 | —- | C] () – J:\WINDOWS\System32\dlcqdrs.dll
[2010/10/16 20:23:20 | 000,065,536 | —- | C] () – J:\WINDOWS\System32\dlcqcaps.dll
[2010/10/16 20:23:20 | 000,061,440 | —- | C] () – J:\WINDOWS\System32\dlcqcnv4.dll
[2010/10/16 20:21:10 | 000,045,056 | —- | C] () – J:\WINDOWS\System32\DLPRMON.DLL
[2010/10/16 20:21:10 | 000,032,768 | —- | C] () – J:\WINDOWS\System32\DLPMONUI.DLL
[2010/10/16 20:20:41 | 000,454,656 | —- | C] () – J:\WINDOWS\System32\dlcqutil.dll
[2010/10/16 20:20:41 | 000,274,432 | —- | C] () – J:\WINDOWS\System32\DLCQinst.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqinsb.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqins.dll
[2010/10/16 20:20:40 | 000,139,264 | —- | C] () – J:\WINDOWS\System32\dlcqjswr.dll
[2010/10/16 20:20:40 | 000,106,496 | —- | C] () – J:\WINDOWS\System32\dlcqinsr.dll
[2010/10/16 20:20:39 | 000,188,416 | —- | C] () – J:\WINDOWS\System32\dlcqgrd.dll
[2010/10/16 20:20:39 | 000,086,016 | —- | C] () – J:\WINDOWS\System32\dlcqcub.dll
[2010/10/16 20:20:39 | 000,073,728 | —- | C] () – J:\WINDOWS\System32\dlcqcu.dll
[2010/10/16 20:20:39 | 000,036,864 | —- | C] () – J:\WINDOWS\System32\dlcqcur.dll
[2010/10/16 20:20:38 | 000,077,824 | —- | C] () – J:\WINDOWS\System32\DLCQcfg.dll
[2010/10/16 20:14:04 | 000,000,152 | —- | C] () – J:\WINDOWS\CoolPlay.ini
[2010/10/16 20:09:31 | 000,050,432 | R— | C] () – J:\WINDOWS\System32\claptn.ini
[2010/10/16 20:09:31 | 000,003,072 | —- | C] () – J:\WINDOWS\CTXFIRES.DLL
[2010/10/16 20:09:31 | 000,000,190 | R— | C] () – J:\WINDOWS\System32\ctzapxx.ini
[2010/10/16 15:26:34 | 000,004,161 | —- | C] () – J:\WINDOWS\ODBCINST.INI
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – J:\WINDOWS\System32\OGACheckControl.dll
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – J:\WINDOWS\System32\OpenQuicktimeLib.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – J:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – J:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – J:\WINDOWS\System32\gthrctr.ini
[2006/12/06 13:39:49 | 000,000,000 | —- | C] () – J:\WINDOWS\System32\px.ini
[2005/11/08 07:43:30 | 000,038,400 | —- | C] () – J:\WINDOWS\System32\CTBURST.DLL
[2003/03/21 04:56:10 | 000,000,194 | —- | C] () – J:\WINDOWS\System32\KILL.INI
========== LOP Check ==========
[2010/10/20 12:53:05 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Bluetooth
[2011/01/05 17:46:55 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/18 19:12:46 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2011/01/05 19:31:00 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/16 23:49:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\CyberScrub
[2010/12/18 22:54:59 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/10/16 21:03:13 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Desktop Search
[2010/11/28 00:05:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/16 15:24:42 | 000,000,210 | -HS- | M] () – J:\boot.ini
[2011/01/01 21:30:59 | 000,005,496 | —- | M] () – J:\dlcq.log
[2010/10/16 20:38:46 | 000,002,785 | —- | M] () – J:\LGSInst.Log
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – J:\NTDETECT.COM
[2010/10/16 21:27:00 | 000,250,048 | RHS- | M] () – J:\ntldr
[2011/01/05 19:32:08 | 2145,386,496 | -HS- | M] () – J:\pagefile.sys
[2 J:\*.tmp files -> J:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – J:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – J:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – J:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – J:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/10/16 19:37:13 | 000,000,067 | -HS- | M] () – J:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/20 00:34:18 | 000,118,784 | —- | M] () – J:\WINDOWS\system32\spool\prtprocs\w32x86\dlcqdrpp.dll
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/10/16 15:24:42 | 000,094,208 | —- | M] () – J:\WINDOWS\system32\config\default.sav
[2010/10/16 15:24:42 | 000,659,456 | —- | M] () – J:\WINDOWS\system32\config\software.sav
[2010/10/16 15:24:42 | 000,942,080 | —- | M] () – J:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/10/16 21:28:38 | 000,000,272 | -HS- | M] () – J:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/16 21:35:13 | 000,000,119 | -HS- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/16 19:40:40 | 000,000,079 | —- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/10/20 12:00:02 | 000,050,688 | —- | M] (Atribune.org) – J:\Documents and Settings\Mucko\Desktop\ATF-Cleaner.exe
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-05 17:46:25
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 188 bytes -> J:\Documents and Settings\All Users\Application Data\TEMP:B4AF47A7
< End of report >
========== Processes (SafeList) ==========
PRC - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
PRC - J:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - j:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - J:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - J:\Documents and Settings\Mucko\Desktop\OTL.exe (OldTimer Tools)
MOD - J:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – J:\WINDOWS\System32\hidserv.dll File not found
SRV - (0131221293242455mcinstcleanup) McAfee Application Installer Cleanup (0131221293242455) – J:\WINDOWS\TEMP\013122~1.EXE File not found
SRV - (FlipShare Service) – J:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (FlipShareServer) – J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
SRV - (mfefire) – J:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (mfevtp) – J:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – J:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – J:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (IntuitUpdateService) – J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (MOBKbackup) – J:\Program Files\McAfee Online Backup\MOBKbackup.exe (McAfee, Inc.)
SRV - (aspnet_state) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – J:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (MSK80Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (dlcq_device) – J:\WINDOWS\System32\dlcqcoms.exe ( )
SRV - (APC UPS Service) – J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Driver Services (SafeList) ==========
DRV - (mfehidk) – J:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – J:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – J:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – J:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – J:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – J:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – J:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – J:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – J:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (MOBKFilter) – J:\WINDOWS\system32\drivers\MOBK.sys (Mozy, Inc.)
DRV - (HDAudBus) – J:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – J:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Btcsrusb) – J:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation.)
DRV - (BlueletSCOAudio) – J:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation.)
DRV - (BT) – J:\WINDOWS\system32\drivers\btnetdrv.sys (IVT Corporation.)
DRV - (BTHidMgr) – J:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation.)
DRV - (BTHidEnum) – J:\WINDOWS\System32\Drivers\vbtenum.sys (IVT Corporation.)
DRV - (VcommMgr) – J:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation.)
DRV - (VComm) – J:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation.)
DRV - (BlueletAudio) – J:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation.)
DRV - (athena) – J:\WINDOWS\system32\drivers\athena.sys (AGEIA Technologies, Inc.)
DRV - (nvatabus) – J:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (STHDA) – J:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – J:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (DLACDBHM) – J:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – J:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (ctaud2k) Creative Audio Driver (WDM) – J:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – J:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ha20x2k) – J:\WINDOWS\system32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (ossrv) – J:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – J:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (emupia) – J:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – J:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (DLAUDFAM) – J:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – J:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – J:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – J:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – J:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – J:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – J:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DRVMCDB) – J:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (HSF_DPV) – J:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – J:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – J:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (DRVNDDM) – J:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (ctdvda2k) – J:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (WmXlCore) – J:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmFilter) – J:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – J:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – J:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: J:\Program Files\McAfee\SiteAdvisor [2010/12/14 18:52:49 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - J:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DWABrowserHlprObj Class) - {2709D830-B643-4e72-9A1E-701CFFFCF30C} - J:\WINDOWS\system32\dwabho.dll (IBM Corporation)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - j:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - J:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - J:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101104223529.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] J:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] J:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [CTDVDDET] J:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] J:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] J:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] J:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DLCQCATS] J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.DLL ()
O4 - HKLM..\Run: [dlcqmon.exe] J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe ()
O4 - HKLM..\Run: [DMXLauncher] J:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [FaxCenterServer] J:\Program Files\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [ISUSPM Startup] J:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] J:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [mcui_exe] J:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MemoryCardManager] J:\Program Files\Dell Photo AIO Printer 966\memcard.exe ()
O4 - HKLM..\Run: [NvCplDaemon] J:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] J:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UpdReg] J:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] J:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Privacy Suite RiskMonitor] J:\Program Files\CyberScrub Privacy Suite\Launch.exe ()
O4 - HKCU..\RunOnce: [dAaDk00000] J:\Documents and Settings\All Users\Application Data\dAaDk00000\dAaDk00000.exe ()
O4 - Startup: J:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = J:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1287279992296 (WUWebControl Class)
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} https://nhxmail1.nu.com/dwa85W.cab (IBM Lotus iNotes 8.5 Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - J:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: J:\Documents and Settings\Mucko\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - J:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\AutoRun\command - "" = M:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{435c9701-f096-11df-b281-001b41001739}\Shell\Setup FlipShare\command - "" = M:\Setup_FlipShare.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/05 20:03:46 | 000,602,112 | —- | C] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/01/05 19:32:48 | 000,000,000 | —D | C] – J:\WINDOWS\CSC
[2011/01/05 17:57:19 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Start Menu\Programs\System Tool
[2011/01/05 17:46:52 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/30 22:23:03 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\My Documents\TurboTax
[2010/12/30 22:20:35 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Intuit
[2010/12/30 22:20:07 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:18:57 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\TurboTax 2010
[2010/12/30 22:17:30 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\IsolatedStorage
[2010/12/30 22:16:28 | 000,000,000 | —D | C] – J:\Program Files\TurboTax
[2010/12/29 20:42:54 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\chops christmas
[2010/12/28 09:56:41 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Local Settings\Application Data\Flip Video
[2010/12/24 20:29:16 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\Christmas For Rich
[2010/12/23 20:29:27 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison 2
[2010/12/18 22:54:59 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/12/18 22:49:20 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\For Allison
[2010/12/18 19:13:06 | 000,000,000 | —D | C] – J:\Documents and Settings\LocalService\Application Data\Flip Video
[2010/12/18 18:35:22 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\CHOPS
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\WINDOWS\System32\QuickTime
[2010/12/18 18:23:37 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Start Menu\Programs\3ivx
[2010/12/18 18:23:34 | 000,000,000 | —D | C] – J:\Program Files\3ivx
[2010/12/18 18:23:30 | 000,000,000 | —D | C] – J:\Program Files\Flip Video
[2010/12/18 18:23:29 | 000,000,000 | —D | C] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2010/12/14 14:27:23 | 000,040,960 | —- | C] (Microsoft Corporation) – J:\WINDOWS\System32\dllcache\ndproxy.sys
[2010/12/08 00:04:39 | 000,000,000 | —D | C] – J:\Documents and Settings\Mucko\Desktop\silly cats
[2010/10/16 20:20:41 | 001,224,704 | —- | C] ( ) – J:\WINDOWS\System32\dlcqserv.dll
[2010/10/16 20:20:41 | 000,991,232 | —- | C] ( ) – J:\WINDOWS\System32\dlcqusb1.dll
[2010/10/16 20:20:41 | 000,413,696 | —- | C] ( ) – J:\WINDOWS\System32\dlcqinpa.dll
[2010/10/16 20:20:41 | 000,397,312 | —- | C] ( ) – J:\WINDOWS\System32\dlcqiesc.dll
[2010/10/16 20:20:41 | 000,323,584 | —- | C] ( ) – J:\WINDOWS\System32\DLCQhcp.dll
[2010/10/16 20:20:40 | 000,696,320 | —- | C] ( ) – J:\WINDOWS\System32\dlcqhbn3.dll
[2010/10/16 20:20:40 | 000,643,072 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpmui.dll
[2010/10/16 20:20:40 | 000,585,728 | —- | C] ( ) – J:\WINDOWS\System32\dlcqlmpm.dll
[2010/10/16 20:20:40 | 000,163,840 | —- | C] ( ) – J:\WINDOWS\System32\dlcqprox.dll
[2010/10/16 20:20:40 | 000,094,208 | —- | C] ( ) – J:\WINDOWS\System32\dlcqpplc.dll
[2010/10/16 20:20:39 | 000,684,032 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomc.dll
[2010/10/16 20:20:39 | 000,421,888 | —- | C] ( ) – J:\WINDOWS\System32\dlcqcomm.dll
[2005/11/08 07:38:38 | 000,033,792 | R— | C] ( ) – J:\WINDOWS\System32\a3d.dll
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/05 20:08:28 | 000,002,206 | —- | M] () – J:\WINDOWS\System32\wpa.dbl
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
[2011/01/05 19:33:03 | 000,001,595 | —- | M] () – J:\Documents and Settings\All Users\Desktop\McAfee Internet Security.lnk
[2011/01/05 19:32:45 | 000,002,048 | –S- | M] () – J:\WINDOWS\bootstat.dat
[2011/01/05 19:30:49 | 000,000,278 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2011/01/05 19:29:25 | 000,064,984 | —- | M] () – J:\WINDOWS\System32\DVCState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,055,172 | —- | M] () – J:\WINDOWS\System32\BMXState-{00000004-00000000-00000005-00001102-00000005-10031102}.rfx
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settingsbkup.sfm
[2011/01/05 19:29:25 | 000,001,080 | —- | M] () – J:\WINDOWS\System32\settings.sfm
[2011/01/05 17:57:19 | 000,001,054 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 17:53:31 | 000,051,712 | —- | M] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/05 15:37:10 | 000,013,927 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/05 14:13:17 | 000,002,515 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Microsoft Office Word 2007.lnk
[2011/01/04 21:06:57 | 000,032,768 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 20:09:04 | 000,032,256 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:54:19 | 000,177,856 | —- | M] () – J:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/30 22:18:57 | 000,001,882 | —- | M] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | M] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2010/12/17 09:01:01 | 000,074,240 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/12/14 16:45:40 | 000,001,393 | —- | M] () – J:\WINDOWS\imsins.BAK
[2010/12/14 09:44:00 | 000,000,286 | —- | M] () – J:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1220945662-1682526488-839522115-1003.job
[2010/12/08 00:23:40 | 000,001,560 | —- | M] () – J:\Documents and Settings\Mucko\Desktop\Disk Defragmenter.lnk
[2010/12/06 21:12:23 | 000,000,000 | -H– | M] () – J:\WINDOWS\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[6 J:\WINDOWS\*.tmp files -> J:\WINDOWS\*.tmp -> ]
[5 J:\WINDOWS\System32\dllcache\*.tmp files -> J:\WINDOWS\System32\dllcache\*.tmp -> ]
[42 J:\WINDOWS\System32\*.tmp files -> J:\WINDOWS\System32\*.tmp -> ]
[2 J:\*.tmp files -> J:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/05 17:57:19 | 000,001,054 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\System Tool 2011.lnk
[2011/01/05 14:56:07 | 000,013,927 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\cosigner cancellation.docx
[2011/01/04 21:06:57 | 000,032,768 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\I chose the name raven.doc
[2011/01/04 21:06:50 | 000,154,197 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\NCT_Forbearance.pdf
[2011/01/04 21:06:50 | 000,065,536 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Maine wage garnishment laws.doc
[2011/01/04 21:06:50 | 000,031,744 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Time Off Hours for Stress.doc
[2011/01/04 21:06:50 | 000,031,232 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Johnson letter regarding gun ownership revised 2[1].doc
[2011/01/02 22:14:34 | 000,029,982 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\New Kitty.jpg
[2011/01/01 19:55:18 | 000,032,256 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\Allison's New Years Day Itinerary.doc
[2011/01/01 10:53:14 | 000,219,416 | —- | C] () – J:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/12/30 22:18:57 | 000,001,882 | —- | C] () – J:\Documents and Settings\All Users\Desktop\TurboTax 2010.lnk
[2010/12/18 19:12:41 | 000,000,819 | —- | C] () – J:\Documents and Settings\All Users\Desktop\FlipShare.lnk
[2010/12/18 18:24:45 | 000,001,015 | R— | C] () – J:\logFile.xsl
[2010/12/17 09:01:00 | 000,074,240 | —- | C] () – J:\Documents and Settings\Mucko\Desktop\2011 'A' Shift Schedule.xls
[2010/10/16 23:48:28 | 000,000,084 | —- | C] () – J:\WINDOWS\csact.ini
[2010/10/16 23:43:08 | 000,000,165 | —- | C] () – J:\WINDOWS\QUICKEN.INI
[2010/10/16 23:31:24 | 000,051,712 | —- | C] () – J:\Documents and Settings\Mucko\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/16 20:34:44 | 000,000,264 | —- | C] () – J:\WINDOWS\wininit.ini
[2010/10/16 20:23:32 | 000,040,960 | —- | C] () – J:\WINDOWS\System32\dlcqvs.dll
[2010/10/16 20:23:30 | 000,344,064 | —- | C] () – J:\WINDOWS\System32\dlcqcoin.dll
[2010/10/16 20:23:20 | 000,692,224 | —- | C] () – J:\WINDOWS\System32\dlcqdrs.dll
[2010/10/16 20:23:20 | 000,065,536 | —- | C] () – J:\WINDOWS\System32\dlcqcaps.dll
[2010/10/16 20:23:20 | 000,061,440 | —- | C] () – J:\WINDOWS\System32\dlcqcnv4.dll
[2010/10/16 20:21:10 | 000,045,056 | —- | C] () – J:\WINDOWS\System32\DLPRMON.DLL
[2010/10/16 20:21:10 | 000,032,768 | —- | C] () – J:\WINDOWS\System32\DLPMONUI.DLL
[2010/10/16 20:20:41 | 000,454,656 | —- | C] () – J:\WINDOWS\System32\dlcqutil.dll
[2010/10/16 20:20:41 | 000,274,432 | —- | C] () – J:\WINDOWS\System32\DLCQinst.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqinsb.dll
[2010/10/16 20:20:40 | 000,176,128 | —- | C] () – J:\WINDOWS\System32\dlcqins.dll
[2010/10/16 20:20:40 | 000,139,264 | —- | C] () – J:\WINDOWS\System32\dlcqjswr.dll
[2010/10/16 20:20:40 | 000,106,496 | —- | C] () – J:\WINDOWS\System32\dlcqinsr.dll
[2010/10/16 20:20:39 | 000,188,416 | —- | C] () – J:\WINDOWS\System32\dlcqgrd.dll
[2010/10/16 20:20:39 | 000,086,016 | —- | C] () – J:\WINDOWS\System32\dlcqcub.dll
[2010/10/16 20:20:39 | 000,073,728 | —- | C] () – J:\WINDOWS\System32\dlcqcu.dll
[2010/10/16 20:20:39 | 000,036,864 | —- | C] () – J:\WINDOWS\System32\dlcqcur.dll
[2010/10/16 20:20:38 | 000,077,824 | —- | C] () – J:\WINDOWS\System32\DLCQcfg.dll
[2010/10/16 20:14:04 | 000,000,152 | —- | C] () – J:\WINDOWS\CoolPlay.ini
[2010/10/16 20:09:31 | 000,050,432 | R— | C] () – J:\WINDOWS\System32\claptn.ini
[2010/10/16 20:09:31 | 000,003,072 | —- | C] () – J:\WINDOWS\CTXFIRES.DLL
[2010/10/16 20:09:31 | 000,000,190 | R— | C] () – J:\WINDOWS\System32\ctzapxx.ini
[2010/10/16 15:26:34 | 000,004,161 | —- | C] () – J:\WINDOWS\ODBCINST.INI
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – J:\WINDOWS\System32\OGACheckControl.dll
[2008/02/19 01:33:34 | 000,446,352 | —- | C] () – J:\WINDOWS\System32\OpenQuicktimeLib.dll
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – J:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – J:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – J:\WINDOWS\System32\gthrctr.ini
[2006/12/06 13:39:49 | 000,000,000 | —- | C] () – J:\WINDOWS\System32\px.ini
[2005/11/08 07:43:30 | 000,038,400 | —- | C] () – J:\WINDOWS\System32\CTBURST.DLL
[2003/03/21 04:56:10 | 000,000,194 | —- | C] () – J:\WINDOWS\System32\KILL.INI
========== LOP Check ==========
[2010/10/20 12:53:05 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Bluetooth
[2011/01/05 17:46:55 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\dAaDk00000
[2010/12/18 19:12:46 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\Flip Video
[2011/01/05 19:31:00 | 000,000,000 | —D | M] – J:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/16 23:49:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\CyberScrub
[2010/12/18 22:54:59 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Flip Video
[2010/10/16 21:03:13 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Desktop Search
[2010/11/28 00:05:36 | 000,000,000 | —D | M] – J:\Documents and Settings\Mucko\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/10/16 15:24:42 | 000,000,210 | -HS- | M] () – J:\boot.ini
[2011/01/01 21:30:59 | 000,005,496 | —- | M] () – J:\dlcq.log
[2010/10/16 20:38:46 | 000,002,785 | —- | M] () – J:\LGSInst.Log
[2010/12/18 18:24:45 | 000,001,015 | R— | M] () – J:\logFile.xsl
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – J:\NTDETECT.COM
[2010/10/16 21:27:00 | 000,250,048 | RHS- | M] () – J:\ntldr
[2011/01/05 19:32:08 | 2145,386,496 | -HS- | M] () – J:\pagefile.sys
[2 J:\*.tmp files -> J:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – J:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – J:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – J:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – J:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/10/16 19:37:13 | 000,000,067 | -HS- | M] () – J:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/20 00:34:18 | 000,118,784 | —- | M] () – J:\WINDOWS\system32\spool\prtprocs\w32x86\dlcqdrpp.dll
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – J:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/10/16 15:24:42 | 000,094,208 | —- | M] () – J:\WINDOWS\system32\config\default.sav
[2010/10/16 15:24:42 | 000,659,456 | —- | M] () – J:\WINDOWS\system32\config\software.sav
[2010/10/16 15:24:42 | 000,942,080 | —- | M] () – J:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/10/16 21:28:38 | 000,000,272 | -HS- | M] () – J:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/16 21:35:13 | 000,000,119 | -HS- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/10/16 19:40:40 | 000,000,079 | —- | M] () – J:\Documents and Settings\Mucko\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2008/10/20 12:00:02 | 000,050,688 | —- | M] (Atribune.org) – J:\Documents and Settings\Mucko\Desktop\ATF-Cleaner.exe
[2011/01/05 20:03:48 | 000,602,112 | —- | M] (OldTimer Tools) – J:\Documents and Settings\Mucko\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-01-05 17:46:25
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 188 bytes -> J:\Documents and Settings\All Users\Application Data\TEMP:B4AF47A7
< End of report >
_____________________________________________________________________________
HIJACK THIS LOG
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:26:25 PM, on 1/5/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17093)
Boot mode: Safe mode with network support
Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\system32\svchost.exe
J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
J:\WINDOWS\system32\mfevtps.exe
J:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
J:\WINDOWS\Explorer.EXE
J:\WINDOWS\system32\ctfmon.exe
j:\PROGRA~1\mcafee.com\agent\mcagent.exe
J:\Program Files\Internet Explorer\iexplore.exe
J:\Documents and Settings\Mucko\Local Settings\Temporary Internet Files\Content.IE5\5U6FRAXZ\HiJackThis[1].exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - J:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DWABrowserHlprObj Class - {2709D830-B643-4e72-9A1E-701CFFFCF30C} - J:\WINDOWS\system32\dwabho.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - j:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - J:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - J:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101104223529.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - j:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - j:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTDVDDET] "J:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "J:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "J:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "J:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] J:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [FaxCenterServer] "J:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcqmon.exe] "J:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "J:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "J:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "J:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] J:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DMXLauncher] J:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [mcui_exe] "J:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "J:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "J:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 J:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [ctfmon.exe] J:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "J:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Privacy Suite RiskMonitor] "J:\Program Files\CyberScrub Privacy Suite\Launch.exe" "J:\Program Files\CyberScrub Privacy Suite\CSRiskMon.exe"
O4 - HKCU\..\RunOnce: [dAaDk00000] J:\Documents and Settings\All Users\Application Data\dAaDk00000\dAaDk00000.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://J:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - J:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - J:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - J:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - J:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1287279992296
O16 - DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} (IBM Lotus iNotes 8.5 Control) - https://nhxmail1.nu.com/dwa85W.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - J:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - J:\WINDOWS\system32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0131221293242455) (0131221293242455mcinstcleanup) - Unknown owner - J:\WINDOWS\TEMP\013122~1.EXE (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - J:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - J:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcq_device - - J:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: FlipShare Service - Unknown owner - J:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: FlipShare Server (FlipShareServer) - Unknown owner - J:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - J:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - J:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - J:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - J:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - J:\WINDOWS\system32\mfevtps.exe
O23 - Service: McAfee Online Backup (MOBKbackup) - McAfee, Inc. - J:\Program Files\McAfee Online Backup\MOBKbackup.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINDOWS\system32\nvsvc32.exe
–
End of file - 8934 bytes
____________________________________________________________________________
DDS LOG
DDS (Ver_09-06-26.01) - NTFSx86 NETWORK
Run by [removed] at 20:27:03.42 on Wed 01/05/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3069.2690 [GMT -5:00]
AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
J:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
J:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
J:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
J:\WINDOWS\system32\mfevtps.exe
J:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
J:\WINDOWS\Explorer.EXE
J:\WINDOWS\system32\ctfmon.exe
j:\PROGRA~1\mcafee.com\agent\mcagent.exe
J:\Program Files\Internet Explorer\iexplore.exe
J:\Documents and Settings\Mucko\Local Settings\Temporary Internet Files\Content.IE5\JMFP2CE7\dds[1].scr
============== Pseudo HJT Report ===============
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - j:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - j:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DWABrowserHlprObj Class: {2709d830-b643-4e72-9a1e-701cfffcf30c} - j:\windows\system32\dwabho.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - j:\progra~1\mcafee\msk\mskapbho.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - j:\windows\system32\dla\DLASHX_W.DLL
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - j:\program files\common files\mcafee\systemcore\ScriptSn.20101104223529.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - j:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - j:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [ctfmon.exe] j:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "j:\program files\messenger\msmsgs.exe" /background
uRun: [Privacy Suite RiskMonitor] "j:\program files\cyberscrub privacy suite\launch.exe" "j:\program files\cyberscrub privacy suite\CSRiskMon.exe"
uRunOnce: [dAaDk00000] j:\documents and settings\all users\application data\daadk00000\dAaDk00000.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [NvCplDaemon] RUNDLL32.EXE j:\windows\system32\NvCpl.dll,NvStartup
mRun: [CTDVDDET] "j:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [VolPanel] "j:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r
mRun: [AudioDrvEmulator] "j:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "j:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [UpdReg] j:\windows\UpdReg.EXE
mRun: [FaxCenterServer] "j:\program files\dell pc fax\fm3032.exe" /s
mRun: [dlcqmon.exe] "j:\program files\dell photo aio printer 966\dlcqmon.exe"
mRun: [MemoryCardManager] "j:\program files\dell photo aio printer 966\memcard.exe"
mRun: [ISUSPM Startup] "j:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "j:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DLA] j:\windows\system32\dla\DLACTRLW.EXE
mRun: [DMXLauncher] j:\program files\dell\media experience\DMXLauncher.exe
mRun: [mcui_exe] "j:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Adobe Reader Speed Launcher] "j:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "j:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DLCQCATS] rundll32 j:\windows\system32\spool\drivers\w32x86\3\DLCQtime.dll,_RunDLLEntry@16
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
StartupFolder: j:\docume~1\alluse~1\startm~1\programs\startup\apcups~1.lnk - j:\program files\apc\apc powerchute personal edition\Display.exe
IE: E&xport; to Microsoft Excel - j:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - j:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - j:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - j:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1287279992296
DPF: {75AA409D-05F9-4F27-BD53-C7339D4B1D0A} - hxxps://nhxmail1.nu.com/dwa85W.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - j:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - j:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;j:\windows\system32\drivers\mfehidk.sys [2010-8-24 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;j:\windows\system32\drivers\mfetdi2k.sys [2010-10-16 84072]
R2 McMPFSvc;McAfee Personal Firewall Service;"j:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-16 271480]
R2 mfefire;McAfee Firewall Core Service;j:\program files\common files\mcafee\systemcore\mfefire.exe [2010-10-16 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;j:\windows\system32\mfevtps.exe [2010-10-16 141792]
R3 mfefirek;McAfee Inc. mfefirek;j:\windows\system32\drivers\mfefirek.sys [2010-10-16 313288]
R3 mfendiskmp;mfendiskmp;j:\windows\system32\drivers\mfendisk.sys [2010-10-16 88544]
S1 MOBKFilter;MOBKFilter;j:\windows\system32\drivers\MOBK.sys [2010-10-16 54776]
S2 0131221293242455mcinstcleanup;McAfee Application Installer Cleanup (0131221293242455);j:\windows\temp\013122~1.exe j:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> j:\windows\temp\013122~1.exe j:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;j:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FlipShare Service;FlipShare Service;j:\program files\flip video\flipshare\FlipShareService.exe [2010-12-15 460144]
S2 FlipShareServer;FlipShare Server;j:\program files\flip video\flipshareserver\FlipShareServer.exe [2010-12-15 1085440]
S2 IntuitUpdateService;Intuit Update Service;j:\program files\common files\intuit\update service\IntuitUpdateService.exe [2010-8-23 13672]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"j:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-16 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;"j:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-16 271480]
S2 McProxy;McAfee Proxy Service;"j:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-10-16 271480]
S2 McShield;McShield;j:\program files\common files\mcafee\systemcore\mcshield.exe [2010-10-16 171168]
S2 MOBKbackup;McAfee Online Backup;j:\program files\mcafee online backup\MOBKbackup.exe [2010-4-13 229688]
S3 athena;athena;j:\windows\system32\drivers\athena.sys [2010-10-16 110336]
S3 cfwids;McAfee Inc. cfwids;j:\windows\system32\drivers\cfwids.sys [2010-10-16 55840]
S3 mfeavfk;McAfee Inc. mfeavfk;j:\windows\system32\drivers\mfeavfk.sys [2010-10-16 152960]
S3 mfebopk;McAfee Inc. mfebopk;j:\windows\system32\drivers\mfebopk.sys [2010-10-16 52104]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;j:\windows\system32\drivers\mfendisk.sys [2010-10-16 88544]
S3 mferkdet;McAfee Inc. mferkdet;j:\windows\system32\drivers\mferkdet.sys [2010-10-16 84264]
S3 WinRM;Windows Remote Management (WS-Management);j:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;j:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-01-05 17:46 –d—– j:\docume~1\alluse~1\applic~1\dAaDk00000
2010-12-30 22:16 –d—– j:\program files\TurboTax
2010-12-18 22:54 –d—– j:\docume~1\mucko\applic~1\Flip Video
2010-12-18 18:24 1,015 a—-r– J:\logFile.xsl
2010-12-18 18:23 –d—– j:\windows\system32\QuickTime
2010-12-18 18:23 –d—– j:\program files\3ivx
2010-12-18 18:23 –d—– j:\program files\Flip Video
2010-12-18 18:23 –d—– j:\docume~1\alluse~1\applic~1\Flip Video
2010-12-14 14:27 40,960 -c—— j:\windows\system32\dllcache\ndproxy.sys
==================== Find3M ====================
2010-11-30 09:39 499,712 a——- j:\windows\system32\msvcp71.dll
2010-11-30 09:39 348,160 a——- j:\windows\system32\msvcr71.dll
2010-11-26 21:17 169,416 a——- j:\windows\system32\dwabho.dll
2010-11-20 08:05 3,320 a——- j:\windows\desctemp.dat
2010-11-18 13:12 81,920 a——- j:\windows\system32\isign32.dll
2010-11-05 19:34 832,512 a——- j:\windows\system32\wininet.dll
2010-11-05 19:34 78,336 a——- j:\windows\system32\ieencode.dll
2010-11-05 19:34 17,408 a——- j:\windows\system32\corpol.dll
2010-11-02 14:52 12 a——- j:\windows\fonts\wfonts.key
2010-10-28 08:13 290,048 a——- j:\windows\system32\atmfd.dll
2010-10-26 08:25 1,853,312 a——- j:\windows\system32\win32k.sys
2010-10-16 21:29 87,263 a——- j:\windows\pchealth\helpctr\offlinecache\index.dat
2010-10-16 19:35 21,640 a——- j:\windows\system32\emptyregdb.dat
2010-10-13 21:28 141,792 a——- j:\windows\system32\mfevtps.exe
________________________________________________________________
ATTACH LOG
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/16/2010 8:39:00 PM
System Uptime: 1/5/2011 7:32:03 PM (1 hours ago)
Motherboard: Dell Inc. | | 0UY253
Processor: Intel® Core™2 CPU 6600 @ 2.40GHz | Microprocessor | 2394/1066mhz
==== Disk Partitions =========================
A: is Removable
C: is Removable
D: is Removable
E: is Removable
F: is Removable
G: is Removable
H: is CDROM ()
I: is CDROM ()
J: is FIXED (NTFS) - 195 GiB total, 167.625 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 10/16/2010 8:40:43 PM - System Checkpoint
RP2: 10/16/2010 8:41:40 PM - Installed Dell Resource CD
RP3: 10/16/2010 8:48:29 PM - Installed Broadcom Gigabit Integrated Controller
RP4: 10/16/2010 8:49:46 PM - Installed Modem Helper
RP5: 10/16/2010 8:51:47 PM - Installed Broadcom Management Programs
RP6: 10/16/2010 8:52:58 PM - Installed Windows XP KB835221WXP.
RP7: 10/16/2010 8:53:14 PM - Installed SigmaTel Audio
RP8: 10/16/2010 9:05:32 PM - Installed Engine Installer
RP9: 10/16/2010 9:05:42 PM - Installed Windows Media Format Runtime
RP10: 10/16/2010 9:05:54 PM - Installed Common Audio Driver Interface
RP11: 10/16/2010 9:05:59 PM - Installed Creative Audio Creation Mode console
RP12: 10/16/2010 9:06:10 PM - Installed Creative Console Launcher Component
RP13: 10/16/2010 9:06:27 PM - Installed Creative Audio Device Selection
RP14: 10/16/2010 9:06:32 PM - Installed Creative Entertainment Mode console
RP15: 10/16/2010 9:06:38 PM - Installed Creative Game Mode console
RP16: 10/16/2010 9:06:43 PM - Installed Mode Switcher
RP17: 10/16/2010 9:06:49 PM - Installed Creative Audio Console
RP18: 10/16/2010 9:06:55 PM - Installed Creative 3DMIDI Player
RP19: 10/16/2010 9:07:11 PM - Installed Creative Diagnostics 4
RP20: 10/16/2010 9:07:16 PM - Installed Creative MediaSource DVD-Audio Player
RP21: 10/16/2010 9:07:23 PM - Installed Creative Speaker Connection Wizard
RP22: 10/16/2010 9:07:28 PM - Installed THX Setup Console
RP23: 10/16/2010 9:07:34 PM - Installed SoundFont Bank Manager
RP24: 10/16/2010 9:07:39 PM - Installed Creative Karaoke Player
RP25: 10/16/2010 9:07:47 PM - Installed Creative Smart Recorder
RP26: 10/16/2010 9:07:51 PM - Installed Creative Vienna SoundFont Studio
RP27: 10/16/2010 9:08:00 PM - Installed Creative Volume Panel
RP28: 10/16/2010 9:08:04 PM - Installed Creative WaveStudio
RP29: 10/16/2010 9:08:09 PM - Installed X-Fi Splash
RP30: 10/16/2010 9:08:34 PM - Installed On Screen Display
RP31: 10/16/2010 9:10:19 PM - Installed Sound Blaster X-Fi
RP32: 10/16/2010 9:10:52 PM - Installed Engine Installer
RP33: 10/16/2010 9:10:57 PM - Removed Common Audio Driver Interface
RP34: 10/16/2010 9:11:00 PM - Installed Common Audio Driver Interface
RP35: 10/16/2010 9:11:03 PM - Installed Creative MediaSource
RP36: 10/16/2010 9:11:14 PM - Installed Creative MediaSource Detector
RP37: 10/16/2010 9:11:18 PM - Installed Creative MediaSource Go!
RP38: 10/16/2010 9:11:22 PM - Installed Creative MediaSource Player Skin Pack
RP39: 10/16/2010 9:11:26 PM - Installed Creative MediaSource MiniDisc Plugin
RP40: 10/16/2010 9:11:31 PM - Installed Creative Music Store Plugin
RP41: 10/16/2010 9:11:36 PM - Installed Creative MediaSource
RP42: 10/16/2010 9:11:53 PM - Configured Engine Installer
RP43: 10/16/2010 9:11:55 PM - Installed Creative Music Store Plugin
RP44: 10/16/2010 9:15:43 PM - Installed Dell System Software
RP45: 10/16/2010 9:15:44 PM - Installed Desktop System Software
RP46: 10/16/2010 9:15:51 PM - Installed Windows XP KB908673.
RP47: 10/16/2010 9:18:23 PM - Installed Dell System Software
RP48: 10/16/2010 9:18:25 PM - Installed Desktop System Software
RP49: 10/16/2010 9:18:31 PM - Installed Windows XP KB908673.
RP50: 10/16/2010 9:21:16 PM - Printer Driver Dell Print-2-Fax Printer Installed
RP51: 10/16/2010 9:22:46 PM - Installed Windows Installer KB893803.
RP52: 10/16/2010 9:29:35 PM - Installed Microsoft Office Home and Student 2007
RP53: 10/16/2010 9:31:36 PM - Printer Driver Send To Microsoft OneNote Driver Installed
RP54: 10/16/2010 9:32:43 PM - Installed APC PowerChute Personal Edition
RP55: 10/16/2010 9:38:33 PM - Installed Logitech Gaming Software
RP56: 10/16/2010 9:43:36 PM - Installed Bluesoleil2.6.0.1 Release 070402
RP57: 10/16/2010 9:47:58 PM - Software Distribution Service 3.0
RP58: 10/16/2010 10:00:35 PM - Software Distribution Service 3.0
RP59: 10/16/2010 10:17:44 PM - Printer Driver Microsoft XPS Document Writer Installed
RP60: 10/16/2010 10:24:09 PM - Software Distribution Service 3.0
RP61: 10/16/2010 10:43:03 PM - Software Distribution Service 3.0
RP62: 10/16/2010 11:15:18 PM - Software Distribution Service 3.0
RP63: 10/16/2010 11:26:52 PM - Software Distribution Service 3.0
RP64: 10/16/2010 11:29:01 PM - Software Distribution Service 3.0
RP65: 10/16/2010 11:29:32 PM - Software Distribution Service 3.0
RP66: 10/16/2010 11:40:14 PM - Software Distribution Service 3.0
RP67: 10/16/2010 11:46:16 PM - Installed Dell CinePlayer
RP68: 10/17/2010 12:26:08 AM - Installed Adobe Reader 9.4.0.
RP69: 10/18/2010 12:42:49 AM - System Checkpoint
RP70: 10/18/2010 10:22:48 PM - Software Distribution Service 3.0
RP71: 10/19/2010 6:48:57 PM - Software Distribution Service 3.0
RP72: 10/19/2010 7:03:53 PM - Software Distribution Service 3.0
RP73: 10/20/2010 7:13:40 PM - System Checkpoint
RP74: 10/22/2010 9:59:39 AM - System Checkpoint
RP75: 10/22/2010 4:11:59 PM - Software Distribution Service 3.0
RP76: 10/23/2010 6:00:26 PM - System Checkpoint
RP77: 10/24/2010 7:13:02 PM - System Checkpoint
RP78: 10/25/2010 8:16:18 PM - System Checkpoint
RP79: 10/26/2010 10:01:23 PM - System Checkpoint
RP80: 10/28/2010 8:44:05 PM - System Checkpoint
RP81: 10/29/2010 9:39:01 PM - System Checkpoint
RP82: 10/30/2010 6:59:21 PM - Software Distribution Service 3.0
RP83: 11/1/2010 9:08:47 AM - Software Distribution Service 3.0
RP84: 11/2/2010 11:19:38 AM - System Checkpoint
RP85: 11/3/2010 8:52:17 PM - System Checkpoint
RP86: 11/4/2010 10:33:53 PM - System Checkpoint
RP87: 11/5/2010 2:45:46 PM - Software Distribution Service 3.0
RP88: 11/6/2010 11:16:30 PM - System Checkpoint
RP89: 11/7/2010 2:00:13 AM - Software Distribution Service 3.0
RP90: 11/8/2010 8:52:54 PM - Software Distribution Service 3.0
RP91: 11/9/2010 10:17:14 PM - System Checkpoint
RP92: 11/10/2010 10:34:43 PM - System Checkpoint
RP93: 11/11/2010 9:39:15 PM - Software Distribution Service 3.0
RP94: 11/13/2010 12:23:08 AM - System Checkpoint
RP95: 11/14/2010 8:07:23 PM - System Checkpoint
RP96: 11/15/2010 3:55:57 AM - Software Distribution Service 3.0
RP97: 11/16/2010 10:31:49 AM - System Checkpoint
RP98: 11/18/2010 7:38:03 AM - System Checkpoint
RP99: 11/19/2010 9:11:29 AM - System Checkpoint
RP100: 11/20/2010 9:29:37 AM - System Checkpoint
RP101: 11/21/2010 6:51:39 PM - System Checkpoint
RP102: 11/22/2010 8:33:43 PM - System Checkpoint
RP103: 11/23/2010 9:01:11 PM - System Checkpoint
RP104: 11/25/2010 7:42:40 PM - System Checkpoint
RP105: 11/26/2010 7:53:24 PM - System Checkpoint
RP106: 11/27/2010 8:24:52 PM - System Checkpoint
RP107: 11/29/2010 7:43:25 AM - System Checkpoint
RP108: 11/30/2010 10:42:58 AM - System Checkpoint
RP109: 12/1/2010 2:19:24 PM - System Checkpoint
RP110: 12/2/2010 6:19:07 PM - System Checkpoint
RP111: 12/4/2010 8:58:54 AM - System Checkpoint
RP112: 12/5/2010 12:08:45 PM - System Checkpoint
RP113: 12/6/2010 8:31:27 PM - System Checkpoint
RP114: 12/8/2010 2:21:52 AM - System Checkpoint
RP115: 12/8/2010 5:15:03 PM - Software Distribution Service 3.0
RP116: 12/9/2010 6:31:22 PM - System Checkpoint
RP117: 12/10/2010 2:26:05 PM - Software Distribution Service 3.0
RP118: 12/12/2010 9:18:59 PM - Software Distribution Service 3.0
RP119: 12/13/2010 9:20:15 PM - System Checkpoint
RP120: 12/14/2010 4:43:20 PM - Software Distribution Service 3.0
RP121: 12/14/2010 10:36:27 PM - Software Distribution Service 3.0
RP122: 12/14/2010 11:45:50 PM - Software Distribution Service 3.0
RP123: 12/16/2010 10:34:11 AM - System Checkpoint
RP124: 12/17/2010 10:35:35 AM - System Checkpoint
RP125: 12/17/2010 11:30:23 AM - Software Distribution Service 3.0
RP126: 12/18/2010 4:08:28 PM - System Checkpoint
RP127: 12/19/2010 11:22:21 PM - System Checkpoint
RP128: 12/20/2010 5:06:55 AM - Software Distribution Service 3.0
RP129: 12/21/2010 7:23:44 AM - System Checkpoint
RP130: 12/22/2010 8:56:14 PM - System Checkpoint
RP131: 12/23/2010 9:14:07 PM - System Checkpoint
RP132: 12/24/2010 10:09:20 PM - System Checkpoint
RP133: 12/26/2010 12:21:13 AM - System Checkpoint
RP134: 12/26/2010 5:42:36 AM - Software Distribution Service 3.0
RP135: 12/27/2010 9:30:17 AM - System Checkpoint
RP136: 12/28/2010 10:27:14 AM - System Checkpoint
RP137: 12/29/2010 9:18:25 PM - System Checkpoint
RP138: 12/30/2010 10:17:36 PM - Installed TurboTax 2010 wrapper
RP139: 1/1/2011 9:59:41 AM - System Checkpoint
RP140: 1/1/2011 10:52:28 AM - Software Distribution Service 3.0
RP141: 1/1/2011 6:08:31 PM - Software Distribution Service 3.0
RP142: 1/2/2011 9:37:37 PM - System Checkpoint
RP143: 1/4/2011 9:25:55 PM - System Checkpoint
RP144: 1/4/2011 11:07:01 PM - Software Distribution Service 3.0
RP145: 1/5/2011 12:46:17 PM - Software Distribution Service 3.0
==== Installed Programs ======================
3ivx MPEG-4 5.0.3 (remove only)
ABBYY FineReader 6.0 Sprint
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.4.1
Adobe Shockwave Player 11.5
AnswerWorks 5.0 English Runtime
APC PowerChute Personal Edition
Bluesoleil2.6.0.1 Release 070402
Broadcom Gigabit Integrated Controller
Broadcom Management Programs
Conexant D850 56K V.92 DFVc Modem
Corel Paint Shop Pro X
Corel Photo Album 6
Creative MediaSource
CyberScrub® Privacy Suite™ 5.1
Dell CinePlayer
Dell PC Fax
Dell Photo AIO Printer 966
Dell Resource CD
FlipShare
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
Logitech Gaming Software
McAfee Internet Security
McAfee Online Backup
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Modem Helper
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser
NVIDIA Drivers
OGA Notifier 2.0.0048.0
Quicken 2009
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
SigmaTel Audio
Sonic Update Manager
Sound Blaster X-Fi
Spybot - Search & Destroy
System Tool2011
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Windows (KB971513)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Driver Package - AGEIA Technologies, Inc. (athena) AGEIAHardware (11/09/2006 1.0.6)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
1/5/2011 8:08:45 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
1/5/2011 7:34:03 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm MOBKFilter
1/5/2011 7:28:47 PM, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 2 time(s).
1/5/2011 7:24:07 PM, error: Service Control Manager [7034] - The McAfee Validation Trust Protection Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 7:20:14 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the McAfee Personal Firewall Service service to connect.
1/5/2011 7:20:14 PM, error: Service Control Manager [7000] - The McAfee Personal Firewall Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/5/2011 7:19:21 PM, error: Service Control Manager [7034] - The IMAPI CD-Burning COM Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 7:19:21 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
1/5/2011 7:19:21 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/5/2011 7:19:14 PM, error: Service Control Manager [7034] - The Volume Shadow Copy service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 6:16:48 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
1/5/2011 6:16:01 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec mfehidk mfetdi2k MOBKFilter MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McAfee Validation Trust Protection Service service depends on the McAfee Inc. mfehidk service which failed to start because of the following error: A device attached to the system is not functioning.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McAfee Proxy Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McAfee Personal Firewall Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McAfee Network Agent service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McAfee Firewall Core Service service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The McAfee Anti-Spam Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/5/2011 6:16:01 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
1/5/2011 6:15:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
1/5/2011 6:15:28 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
1/5/2011 6:09:42 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 25 time(s).
1/5/2011 6:09:41 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 24 time(s).
1/5/2011 6:09:41 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 23 time(s).
1/5/2011 6:09:11 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 22 time(s).
1/5/2011 6:08:41 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 21 time(s).
1/5/2011 6:08:41 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 20 time(s).
1/5/2011 6:08:41 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 19 time(s).
1/5/2011 6:08:40 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 18 time(s).
1/5/2011 6:08:31 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 17 time(s).
1/5/2011 6:08:26 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 16 time(s).
1/5/2011 6:08:22 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 15 time(s).
1/5/2011 6:08:18 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 14 time(s).
1/5/2011 6:07:47 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 13 time(s).
1/5/2011 6:07:17 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 12 time(s).
1/5/2011 6:07:12 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 11 time(s).
1/5/2011 6:06:42 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 9 time(s).
1/5/2011 6:06:42 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 10 time(s).
1/5/2011 6:06:12 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 8 time(s).
1/5/2011 6:05:42 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 7 time(s).
1/5/2011 6:05:12 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 6 time(s).
1/5/2011 6:05:12 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 5 time(s).
1/5/2011 6:05:09 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 4 time(s).
1/5/2011 6:05:07 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 6:05:07 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 2 time(s).
1/5/2011 6:05:07 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the McAfee SiteAdvisor Service service to connect.
1/5/2011 6:05:07 PM, error: Service Control Manager [7000] - The McAfee SiteAdvisor Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/5/2011 6:05:07 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
1/5/2011 5:59:20 PM, error: Service Control Manager [7034] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 5:59:20 PM, error: Service Control Manager [7034] - The McAfee Services service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 5:59:20 PM, error: Service Control Manager [7034] - The McAfee Proxy Service service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 5:59:20 PM, error: Service Control Manager [7034] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 5:59:20 PM, error: Service Control Manager [7034] - The McAfee Network Agent service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 5:59:20 PM, error: Service Control Manager [7034] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 3 time(s).
1/5/2011 5:58:20 PM, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:58:20 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:58:20 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:58:20 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:58:20 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:58:20 PM, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:20 PM, error: Service Control Manager [7034] - The Intuit Update Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:20 PM, error: Service Control Manager [7034] - The dlcq_device service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:20 PM, error: Service Control Manager [7031] - The McAfee VirusScan Announcer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7031] - The McAfee Anti-Spam Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
1/5/2011 5:57:20 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the FlipShare Server service to connect.
1/5/2011 5:57:19 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:19 PM, error: Service Control Manager [7034] - The McAfee Online Backup service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:19 PM, error: Service Control Manager [7034] - The FlipShare Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:19 PM, error: Service Control Manager [7034] - The Creative Service for CDROM Access service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:19 PM, error: Service Control Manager [7034] - The APC UPS Service service terminated unexpectedly. It has done this 1 time(s).
1/5/2011 5:57:19 PM, error: Service Control Manager [7031] - The FlipShare Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
1/4/2011 9:03:09 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
==== End Of File ===========================
============= FINISH: 20:27:11.25 ===============
________________________________________________________________________