Hi oldman960 - I'm kinda one too (956).
First, thanks for the very prompt response. I too noted the two hjt entries you identified and was 99% sure they were part of the culprits, bu thought it was time to call in the big guns.
Took the actions you prescribed in sequence. Rebooted only after hjt, and not after gmer and otl, since that was not directed.
Computer behavior now seems nominal EXCEPT that the inability to access Microsoft Update remains. Browsing seems normal and quick on all random sites attempted.
For Microsoft Update, behavior is as follows: Launching from Start-All Programs-Windows Update (which has a target of "%SystemRoot%\system32\wupdmgr.exe" and a Start in of "%HOMEDRIVE%%HOMEPATH%") opens IE and calls the url http://windowsupdate.microsoft.com, but results in the message "Internet Explorer cannot display the webpage." Navigating from there to microsoft.com to try drilling down to 'updates' on their site resulted in a redirect to
http://pcspeedmaximizer.s3.amazonaws.com/index.html and the pop-up message "Errors have been found in your operating system registry! Click to download free registry cleaner software." X'd the pop-up to close it and got a web page showing typical bs 'registry errors' supposedly on my system. Closed IE.
Doing a clean IE launch I can navigate to microsoft.com and successfully select Support-Microsoft Update, which goes to update.microsoft.com/…, where I selected Start Now, which goes to the license page, then selected Continue, which tried to 'check for the latest version of update', but that quickly resulted in a page stating "the website has encountered a problem and cannot display the page yuo are trying to view, blah, blah, blah…"
Attempting the same with Firefox and going to Microsoft.com gives a connection reset as soon as It try to go to update.microsoft.com.
I'm ready for the next steps. Here are the requested logs:
GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2011-01-09 09:57:21
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 ST380817AS rev.3.42
Running: pnpzdyo8.exe; Driver: C:\DOCUME~1\Becki\LOCALS~1\Temp\awliikob.sys
—- System - GMER 1.0.15 —-
SSDT F7A7D8B6 ZwCreateKey
SSDT F7A7D8AC ZwCreateThread
SSDT F7A7D8BB ZwDeleteKey
SSDT F7A7D8C5 ZwDeleteValueKey
SSDT F7A7D8CA ZwLoadKey
SSDT F7A7D898 ZwOpenProcess
SSDT F7A7D89D ZwOpenThread
SSDT F7A7D8D4 ZwReplaceKey
SSDT F7A7D8CF ZwRestoreKey
SSDT F7A7D8C0 ZwSetValueKey
—- Kernel code sections - GMER 1.0.15 —-
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section
[0xBA41F510]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B5000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 007B000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[660] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B7000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1140] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E1000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00E2000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00BC000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1520] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01BD000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 01BE000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 01BC000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2072] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B7000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2784] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F
C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[2948] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D1000A
.text C:\WINDOWS\Explorer.EXE[2948] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00D2000A
.text C:\WINDOWS\Explorer.EXE[2948] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00D0000C
.text C:\WINDOWS\System32\svchost.exe[3972] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DE000A
.text C:\WINDOWS\System32\svchost.exe[3972] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DF000A
.text C:\WINDOWS\System32\svchost.exe[3972] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00DD000C
.text C:\WINDOWS\System32\svchost.exe[3972] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 008F000A
.text C:\WINDOWS\System32\svchost.exe[3972] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00E3000A
—- Devices - GMER 1.0.15 —-
Device Ntfs.sys (NT File System
Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System
Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T1L0-1b 8A8F8292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-13 8A8F8292
Device mrxsmb.sys (Windows NT SMB
Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem
Filter Manager/Microsoft Corporation)
Device \Device\Ide\IdeDeviceP2T0L0-5 -> \??\IDE#DiskST380817AS______________________________3.42____#5&22652cbd&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
—- Disk sectors - GMER 1.0.15 —-
Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like
behavior; TDL4 <– ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 156301232 (+255): rootkit-like
behavior;
—- EOF - GMER 1.0.15 —-
OTL logfile created on: 1/9/2011 10:04:26 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = F:\Cleanup Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 3750 3750 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.42 Gb Total Space | 4.37 Gb Free Space | 17.88% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.41 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive E: | 40.33 Gb Total Space | 32.91 Gb Free Space | 81.60% Space Free | Partition Type: NTFS
Drive F: | 495.22 Mb Total Space | 346.01 Mb Free Space | 69.87% Space Free | Partition Type: FAT
Computer Name: P4P800E-3GHZE | User Name: Becki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/01/09 09:44:40 | 000,602,112 | —- | M] (OldTimer Tools) – F:\Cleanup Tools\OTL.exe
PRC - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) – D:\Program Files\Secunia\PSI\psia.exe
PRC - [2010/12/21 07:04:30 | 000,399,416 | —- | M] (Secunia) – D:\Program Files\Secunia\PSI\sua.exe
PRC - [2010/12/13 08:40:07 | 000,135,336 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010/12/13 08:39:54 | 000,281,768 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/12/13 08:39:54 | 000,267,944 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/01/14 21:11:00 | 000,076,968 | —- | M] (Avira GmbH) – D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/04 16:38:18 | 000,112,336 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
PRC - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2004/06/12 08:40:42 | 000,594,944 | —- | M] (Alex van Kaam) – D:\Program Files\Motherboard Monitor 5\MBM5.exe
PRC - [2004/02/26 09:52:00 | 000,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2004/02/13 14:12:08 | 000,016,423 | —- | M] () – C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
PRC - [2001/08/23 20:37:39 | 000,167,936 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\point32.exe
========== Modules (SafeList) ==========
MOD - [2011/01/09 09:44:40 | 000,602,112 | —- | M] (OldTimer Tools) – F:\Cleanup Tools\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2004/02/11 16:58:16 | 000,024,613 | —- | M] (BackWeb) – C:\Documents and Settings\Becki\Local Settings\Temp\IadHide5.dll
MOD - [2001/05/09 21:00:28 | 000,045,056 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Hardware\Mouse\Msh_zwf.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\spoolsv.exe – (Spooler)
SRV - File not found [On_Demand | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) [Auto | Running] – D:\Program Files\Secunia\PSI\PSIA.exe – (Secunia PSI Agent)
SRV - [2010/12/21 07:04:30 | 000,399,416 | —- | M] (Secunia) [Auto | Running] – D:\Program Files\Secunia\PSI\sua.exe – (Secunia Update Agent)
SRV - [2010/12/13 08:40:07 | 000,135,336 | —- | M] (Avira GmbH) [Auto | Running] – D:\Program Files\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2010/12/13 08:39:54 | 000,267,944 | —- | M] (Avira GmbH) [Auto | Running] – D:\Program Files\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2010/03/29 07:53:22 | 000,068,000 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper.dll – (getPlusHelper) getPlus®
SRV - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto | Running] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2004/02/26 09:52:00 | 000,049,152 | —- | M] (Ulead Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper)
========== Driver Services (SafeList) ==========
DRV - [2010/12/13 08:40:21 | 000,135,096 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avipbb.sys – (avipbb)
DRV - [2010/12/13 08:40:21 | 000,061,960 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\avgntflt.sys – (avgntflt)
DRV - [2010/09/01 03:30:58 | 000,015,544 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\psi_mf.sys – (PSI)
DRV - [2010/06/17 14:27:22 | 000,028,520 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ssmdrv.sys – (ssmdrv)
DRV - [2010/06/17 14:27:12 | 000,011,608 | —- | M] (Avira GmbH) [Kernel | System | Running] – D:\Program Files\Avira\AntiVir Desktop\avgio.sys – (avgio)
DRV - [2008/04/13 13:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2005/12/19 15:02:36 | 000,060,572 | —- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ftser2k.sys – (FTSER2K)
DRV - [2005/12/19 15:02:36 | 000,028,449 | —- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ftdibus.sys – (FTDIBUS)
DRV - [2005/12/11 22:40:43 | 001,414,656 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/08/03 22:29:56 | 001,897,408 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2004/04/10 08:42:36 | 000,002,944 | —- | M] ([removed]) [Kernel | System | Running] – C:\WINDOWS\system32\mbmiodrvr.sys – (mbmiodrvr)
DRV - [2004/02/18 03:16:14 | 000,091,177 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\P1131Vid.sys – (P1131VID) Creative WebCam NX Pro (WDM)
DRV - [2004/01/09 10:17:02 | 000,601,100 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2003/12/11 10:54:14 | 000,391,424 | —- | M] (Sensaura Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS)
DRV - [2003/10/23 06:28:00 | 000,174,336 | —- | M] (Marvell Semiconductor Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\yukonwxp.sys – (yukonwxp)
DRV - [2002/09/16 17:14:32 | 000,004,228 | —- | M] (PowerQuest Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\PQNTDRV.sys – (PQNTDrv)
DRV - [2001/08/23 02:33:10 | 000,010,192 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ipfilter.sys – (IPFilter)
DRV - [2001/08/17 09:00:04 | 000,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)
DRV - [1997/04/22 09:16:00 | 000,006,272 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ASLM75.SYS – (aslm75)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {3D28ECD4-DCFF-4863-B1EF-93C84A532140}:1.9.1
FF - prefs.js..extensions.enabledItems: {082AF3DD-1069-4377-B0C1-AEA1EFD7B367}:1.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox
FF - HKLM\software\mozilla\Firefox\Extensions\\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}: C:\Documents and Settings\Becki\Local Settings\Application Data\{3D28ECD4-DCFF-4863-B1EF-93C84A532140} [2010/06/01
11:10:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}: C:\Documents and Settings\Stephen\Local Settings\Application Data\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367} [2010/06/06
13:46:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/01/08 19:10:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/01/08 19:11:09 | 000,000,000 | —D | M]
[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions
[2010/02/06 13:59:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Extensions\[removed]
[2011/01/08 22:52:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions
[2009/12/30 09:47:54 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Becki\Application
Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/01 11:28:46 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Becki\Application
Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2008/05/08 15:13:40 | 000,000,000 | —D | M] (Move Media Player) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2009/04/15 10:59:49 | 000,000,000 | —D | M] (Oberon Game Host) – C:\Documents and Settings\Becki\Application Data\Mozilla\Firefox\Profiles\8o8zudx3.default\extensions\[removed]
[2010/06/01 11:10:57 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\BECKI\LOCAL SETTINGS\APPLICATION DATA\{3D28ECD4-DCFF-4863-B1EF-93C84A532140}
[2010/06/06 13:46:09 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\STEPHEN\LOCAL SETTINGS\APPLICATION DATA\{082AF3DD-1069-4377-B0C1-AEA1EFD7B367}
[2009/01/31 11:17:34 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/09 07:34:56 | 000,000,000 | —D | M] (Skype extension for Firefox) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/01/31 11:17:52 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2010/01/12 04:21:51 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
[2010/11/30 11:21:02 | 000,000,000 | —D | M] (Java Console) – D:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
O1 HOSTS File: ([2011/01/08 15:42:46 | 000,001,003 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.8minutedating.com
O1 - Hosts: 127.0.0.1 whysohardx.com
O1 - Hosts: 127.0.0.1 protectyourpc-11.com
O1 - Hosts: 127.0.0.1 checkserverstatux.com
O1 - Hosts: 127.0.0.1 xinmin.cn
O1 - Hosts: 127.0.0.1 xy95.cn
O1 - Hosts: 127.0.0.1 koralda.com
O1 - Hosts: 127.0.0.1 weirden.com
O1 - Hosts: 127.0.0.1 nanocloudcontroller.com
O1 - Hosts: 127.0.0.1 coo0lnet.net
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [ASUS Probe] D:\Program Files\ASUS\Asus Probe\AsusProb.exe ()
O4 - HKLM..\Run: [avgnt] D:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [MBM 5] D:\Program Files\Motherboard Monitor 5\MBM5.EXE (Alex van Kaam)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 3 Forget Me Not Reminders Tray Icon.lnk = D:\Program Files\CreataCard\Gold\FMRemind.exe (Micrografx, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = D:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_22.dll (Sun Microsystems, Inc.)
O9 - Extra Button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Stephen\Start Menu\Programs\UltimateBet\UltimateBet.lnk ()
O9 - Extra 'Tools' menuitem : Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - Reg Error: Value error. File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\aim.exe File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2}
http://download.games.yahoo.com/games/web_…nx.1.0.0.55.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://v5.windowsupdate.microsoft.com/v5co…b?1109450619359 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1294543693234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C}
http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab (cpbrkpie Control)
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876}
http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab (Anonymizer Anti-Spyware Scanner)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697}
http://www.imgag.com/cp/install/AxCtp2.cab (Create & Print ActiveX Plug-in)
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C}
http://di.imgag.com/imgag/cp/install/Crusher.cab (Creative Toolbox Plug-in)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9}
http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} file:///C:/Documents%20and%20Settings/Becki/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41}
http://download.games.yahoo.com/games/web_…r/goldfever.cab (TikGames Online Control)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab (PopCapLoader Object)
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C}
http://games.myspace.com/gameshell/games/c…sh.[removed].cab
(CPlayFirstWeddingDashControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: J:\ireland\ireland 115.jpg
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Becki\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/26 11:03:18 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell - "" = AutoRun
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cd5ee430-c505-11de-bcb9-00112fc9dce4}\Shell\AutoRun\command - "" = K:\MediaManager.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: fastndll - (C:\WINDOWS\system32\ipxrvr32.dll) - C:\WINDOWS\System32\ipxrvr32.dll File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (68412030092050432)
========== Files/Folders - Created Within 30 Days ==========
[2011/01/08 20:29:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/01/08 20:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Application Data\Avira
[2011/01/08 19:22:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/01/08 19:22:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/01/08 19:10:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/01/08 19:09:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/01/08 17:01:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/01/08 17:01:08 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/01/08 17:01:07 | 000,135,096 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2011/01/08 17:01:07 | 000,061,960 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/01/08 17:01:07 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/01/08 17:01:07 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/01/08 17:01:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2011/01/08 16:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Foxit Reader
[2011/01/08 16:46:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2011/01/08 16:42:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/01/08 15:51:00 | 000,000,000 | —D | C] – C:\WINDOWS\Internet Logs
[2011/01/03 04:16:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\eFdDi06300
[2010/12/26 09:12:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/12/21 04:54:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Becki\Start Menu\Programs\FrostWire
[2010/12/19 13:32:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2010/12/19 13:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/12/14 16:42:42 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/12/10 11:35:05 | 000,000,000 | R–D | C] – C:\Documents and Settings\Becki\Start Menu\Programs\Administrative Tools
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At58.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/01/09 10:03:36 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/09 09:43:28 | 033,689,600 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2011/01/09 09:43:26 | 015,939,584 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2011/01/09 09:42:08 | 000,013,736 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/09 08:35:37 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At57.job
[2011/01/09 08:20:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At72.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At71.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At70.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/01/08 20:26:13 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At69.job
[2011/01/08 19:22:51 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/01/08 19:03:47 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2011/01/08 19:03:47 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/01/08 18:50:51 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At65.job
[2011/01/08 17:29:10 | 000,000,637 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:11 | 000,000,166 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:55 | 000,001,094 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:39 | 000,001,138 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:18 | 000,087,228 | —- | M] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2011/01/08 17:05:14 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2011/01/08 17:05:14 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/01/08 16:13:04 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2011/01/08 16:13:03 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/01/08 15:42:46 | 000,001,003 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/08 14:40:21 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At62.job
[2011/01/08 14:11:42 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/01/08 13:57:04 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At61.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/01/08 11:20:26 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At59.job
[2011/01/08 09:12:50 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At64.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At63.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At66.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At60.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/01/07 08:26:15 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At56.job
[2011/01/05 20:16:19 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2011/01/05 20:16:19 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/01/05 08:04:30 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2011/01/05 08:04:30 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/01/04 05:43:57 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At53.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At50.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At55.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/01/04 02:32:01 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At67.job
[2011/01/03 12:42:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/03 08:47:35 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/01/03 06:33:38 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At51.job
[2010/12/30 08:49:42 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At54.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At68.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At52.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At49.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2010/12/30 02:26:21 | 000,000,428 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | M] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/13 10:47:50 | 000,398,744 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/12/13 08:40:21 | 000,135,096 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/12/13 08:40:21 | 000,061,960 | —- | M] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/12/11 11:30:01 | 000,014,739 | —- | M] () – C:\WINDOWS\System32\12543.js
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/08 17:29:10 | 000,000,637 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2011/01/08 17:22:08 | 000,000,166 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172207.reg
[2011/01/08 17:21:54 | 000,001,094 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172153.reg
[2011/01/08 17:21:37 | 000,001,138 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172136.reg
[2011/01/08 17:21:17 | 000,087,228 | —- | C] () – C:\Documents and Settings\Becki\My Documents\cc_20110108_172115.reg
[2011/01/03 05:09:44 | 001,228,854 | —- | C] () – C:\fsqwr.bmp
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Desktop\FrostWire 4.21.3.lnk
[2010/12/21 04:54:48 | 000,000,754 | —- | C] () – C:\Documents and Settings\Becki\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.3.lnk
[2010/12/02 08:08:23 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/11/28 14:16:59 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/11/15 13:18:45 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\start
[2010/11/15 13:18:07 | 000,000,006 | —- | C] () – C:\Documents and Settings\Becki\Application Data\completescan
[2010/11/15 13:11:32 | 000,000,010 | —- | C] () – C:\Documents and Settings\Becki\Application Data\install
[2008/09/14 13:49:35 | 000,000,110 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2007/10/05 18:07:08 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\AsProbe.sys
[2006/06/26 16:58:10 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/04/09 21:21:26 | 000,000,209 | —- | C] () – C:\WINDOWS\KA.INI
[2006/03/22 12:42:09 | 000,000,192 | —- | C] () – C:\WINDOWS\elitemediagroup.ini
[2006/03/21 16:11:25 | 000,000,434 | —- | C] () – C:\WINDOWS\rcycu.dll
[2006/01/24 14:52:40 | 000,006,144 | —- | C] () – C:\Documents and Settings\Becki\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/26 16:12:24 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/10/30 21:24:59 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Stephen.ini
[2005/06/19 17:25:05 | 000,000,327 | —- | C] () – C:\WINDOWS\AudStu.INI
[2005/06/19 11:36:16 | 000,000,000 | —- | C] () – C:\WINDOWS\musiceditor.INI
[2005/06/05 14:10:11 | 000,000,327 | —- | C] () – C:\WINDOWS\beatbox.INI
[2005/06/05 14:10:11 | 000,000,317 | —- | C] () – C:\WINDOWS\sampler.INI
[2005/06/05 14:10:11 | 000,000,028 | —- | C] () – C:\WINDOWS\robota.INI
[2005/06/04 17:46:50 | 000,000,237 | —- | C] () – C:\WINDOWS\musicmaker.INI
[2005/06/04 17:39:52 | 000,000,024 | —- | C] () – C:\WINDOWS\magix.ini
[2005/06/04 17:39:51 | 000,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2005/04/25 13:27:00 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2005/04/08 12:33:05 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/03/21 16:33:05 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Becki.ini
[2005/03/19 15:10:08 | 000,000,244 | —- | C] () – C:\WINDOWS\qwimp.ini
[2005/03/19 15:08:06 | 000,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2005/03/19 14:48:59 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/03/06 13:02:00 | 000,374,784 | —- | C] () – C:\WINDOWS\3dg32.dll
[2005/03/06 13:02:00 | 000,000,250 | —- | C] () – C:\WINDOWS\3dr.ini
[2005/03/04 12:36:50 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/02/27 17:18:15 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2005/02/27 17:18:15 | 000,302,592 | —- | C] () – C:\WINDOWS\System32\pgp.dll
[2005/02/27 17:18:15 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2005/02/27 17:18:15 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\keydb.dll
[2005/02/27 17:18:15 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\simple.dll
[2005/02/27 17:18:15 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\bn.dll
[2005/02/27 15:12:31 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2005/02/27 15:12:31 | 000,006,138 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2005/02/26 13:24:32 | 000,000,227 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2005/02/26 11:37:30 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005/02/26 11:23:35 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2005/02/26 11:17:50 | 000,003,630 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2005/02/26 05:48:23 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2000/09/08 17:53:50 | 000,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
========== LOP Check ==========
[2009/11/03 12:25:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\110
[2009/10/30 10:17:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\122DE
[2009/04/06 00:52:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1230
[2009/03/05 21:19:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\123E
[2009/11/09 12:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\13280
[2009/04/01 18:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\132FD
[2010/01/29 20:49:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\147D
[2009/11/02 09:12:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\16399
[2009/07/17 18:50:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1D3E
[2009/04/13 09:30:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1F119
[2009/03/30 15:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\22119
[2009/11/07 13:39:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\241C5
[2009/05/17 16:56:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2D399
[2009/10/30 07:33:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\33399
[2009/07/19 14:53:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\3437A
[2009/02/25 09:42:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/03/23 09:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\E119
[2011/01/08 21:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eFdDi06300
[2010/01/22 13:43:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/05/24 10:57:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/11/05 21:34:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/04/06 10:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/10/22 11:33:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2005/02/27 16:26:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/11/18 12:13:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/03/09 17:20:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Total 3D Home
[2005/03/04 12:58:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/03/27 19:49:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/05/03 17:10:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2011/01/08 16:16:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2005/03/26 11:13:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Aim
[2010/12/31 03:17:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\FrostWire
[2007/10/05 18:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Grisoft
[2010/11/14 12:00:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\LimeWire
[2007/02/10 23:22:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\OurPictures
[2009/11/05 21:34:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\PlayFirst
[2008/10/22 11:32:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Sandlot Games
[2006/06/09 10:58:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Snapfish
[2005/05/04 11:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\spweng
[2005/04/28 17:40:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Ulead Systems
[2007/06/20 12:29:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Becki\Application Data\Viewpoint
[2010/12/30 02:26:21 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2011/01/08 16:13:03 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2011/01/08 17:05:14 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2011/01/05 08:04:30 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/01/05 20:16:19 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2011/01/08 19:03:47 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2011/01/09 08:12:41 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At25.job
[2011/01/04 05:43:57 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At26.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At27.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At28.job
[2011/01/04 04:20:17 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At29.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/01/05 08:04:30 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At30.job
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At31.job
[2011/01/03 08:07:28 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At32.job
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At33.job
[2011/01/09 10:04:43 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At34.job
[2011/01/08 11:20:26 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At35.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At36.job
[2011/01/08 13:57:04 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At37.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At38.job
[2011/01/08 16:13:04 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At39.job
[2011/01/03 08:07:28 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/01/07 15:01:46 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At40.job
[2011/01/08 17:05:14 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At41.job
[2011/01/08 09:12:50 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At42.job
[2011/01/08 19:03:47 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At43.job
[2011/01/05 20:16:19 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At44.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At45.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At46.job
[2011/01/09 08:12:42 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At47.job
[2010/12/30 02:26:22 | 000,000,430 | —- | M] () – C:\WINDOWS\Tasks\At48.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At49.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At50.job
[2011/01/03 06:33:38 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At51.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At52.job
[2011/01/04 05:43:57 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At53.job
[2010/12/30 08:49:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At54.job
[2011/01/04 04:20:17 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At55.job
[2011/01/07 08:26:15 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At56.job
[2011/01/09 08:35:37 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At57.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At58.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At59.job
[2011/01/09 10:04:43 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At60.job
[2011/01/08 13:57:04 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At61.job
[2011/01/08 14:40:21 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At62.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At63.job
[2011/01/08 09:12:50 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At64.job
[2011/01/08 18:50:51 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At65.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At66.job
[2011/01/04 02:32:01 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At67.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At68.job
[2011/01/08 20:26:13 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At69.job
[2011/01/08 11:20:26 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At70.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At71.job
[2011/01/09 08:12:42 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At72.job
[2010/12/30 02:26:22 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2011/01/07 15:01:46 | 000,000,428 | —- | M] () – C:\WINDOWS\Tasks\At9.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2005/02/26 11:03:18 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/01/08 14:11:42 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2005/02/26 11:03:18 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/02/27 16:03:16 | 000,000,227 | —- | M] () – C:\CtDrvIns.log
[2005/02/27 16:03:16 | 000,013,340 | —- | M] () – C:\CtDrvStp.log
[2005/11/27 22:15:22 | 000,057,868 | —- | M] () – C:\EasyShare.dmp
[2006/01/28 14:26:31 | 000,809,853 | —- | M] () – C:\EasyShareInstall.log
[2011/01/03 08:47:35 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2005/02/26 11:03:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/03/27 19:49:52 | 000,000,732 | -H– | M] () – C:\IPH.PH
[2005/06/19 17:25:20 | 000,000,746 | -HS- | M] () – C:\midi studio 2005.Key
[2005/02/26 11:03:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/25 08:37:31 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/01/09 08:19:54 | 3932,160,000 | -HS- | M] () – C:\pagefile.sys
[2008/11/22 15:26:37 | 000,064,762 | —- | M] () – C:\playground.log
[2011/01/08 14:54:19 | 000,000,359 | —- | M] () – C:\rkill.log
[2011/01/08 12:16:14 | 000,001,257 | —- | M] () – C:\sti.log
[2009/03/29 15:19:08 | 000,000,032 | —- | M] () – C:\wizard.txt
[2005/11/29 15:03:44 | 000,000,000 | —- | M] () – C:\wptUpgrader.log
[2009/02/21 16:01:09 | 000,000,146 | —- | M] () – C:\YServer.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/02/26 11:02:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2004/05/18 16:26:04 | 000,000,208 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo! Mail.url
[2004/05/18 16:13:06 | 000,000,207 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo!.url
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/02/26 05:46:29 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/02/26 05:46:29 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/02/26 05:46:29 | 000,888,832 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2006/09/13 13:34:37 | 000,000,154 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Create & Print Home.url
[2008/09/25 08:45:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2008/09/25 08:45:37 | 000,001,568 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2005/02/26 11:03:24 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2005/02/26 15:36:22 | 000,001,512 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-10 08:31:28
========== Alternate Data Streams ==========
@Alternate Data Stream - 214 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EEB25EAE
@Alternate Data Stream - 202 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:24FECE50
@Alternate Data Stream - 189 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61AF2B29
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9FE30AB2
< End of report >
OTL Extras logfile created on: 1/9/2011 10:04:26 AM - Run 1
OTL by OldTimer - Version 3.2.20.1 Folder = F:\Cleanup Tools
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 3750 3750 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 24.42 Gb Total Space | 4.37 Gb Free Space | 17.88% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.41 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive E: | 40.33 Gb Total Space | 32.91 Gb Free Space | 81.60% Space Free | Partition Type: NTFS
Drive F: | 495.22 Mb Total Space | 346.01 Mb Free Space | 69.87% Space Free | Partition Type: FAT
Computer Name: P4P800E-3GHZE | User Name: Becki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "D:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "D:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"G:\Program Files\aim.exe" = G:\Program Files\aim.exe:*:Enabled:AOL Instant Messenger – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software
Updater – ()
"D:\Program Files\Yahoo!\Messenger\YPager.exe" = D:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – File not found
"D:\Program Files\Yahoo!\Messenger\YServer.exe" = D:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"G:\Program Files\aim.exe" = G:\Program Files\aim.exe:*:Enabled:AOL Instant Messenger – File not found
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – File not found
"D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe" = D:\Program Files\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – ()
"D:\Program Files\Skype\Phone\Skype.exe" = D:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – File not found
"D:\RECYCLER\NPROTECT\00006551.exe" = D:\RECYCLER\NPROTECT\00006551.exe:*:Enabled:Skype – File not found
"C:\Program Files\Grisoft\AVG7\avginet.exe" = C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgamsvr.exe" = C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe – File not found
"C:\Program Files\Grisoft\AVG7\avgcc.exe" = C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe – File not found
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – File not found
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"G:\Program Files\LimeWire\LimeWire.exe" = G:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"G:\Program Files\FrostWire\FrostWire.exe" = G:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – File not found
"D:\Program Files\FrostWire\FrostWire.exe" = D:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{01BDFB08-EE88-4E5E-94A6-AE9EDCFA40C5}" = Microsoft IntelliPoint 4.0
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03B48041-B2CD-476A-87D6-79D0488559A2}" = Desktop Restore
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2405FEDD-9E40-4438-9765-A37A2B389E1A}" = Shoppers' Hotline Control Center
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 22
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4F1DA6BF-3614-48A1-9970-9E90F646789E}" = Ulead VideoStudio 8.0
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{55937F00-A69B-4049-8D3A-1C7729742B6F}" = BUM
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5B18F34B-9620-4702-A051-49832F9860AB}" = Total 3D Home
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{76703039-C98C-4e62-A12C-4D7066BE9985}" = The Sims™ 2 University Life Collection
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9C244239-ED8E-40f1-937F-51C706CD2160}" = The Sims™ 2 Deluxe
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A59BB15D-51B7-F12B-4548-8C0368243441}" = EA Download Manager UI
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1973749-F5E7-40EB-B528-F2B78685B9FF}" = essvcpt
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D39A2674-F79F-410A-00A0-B19F6EA1D054}" = The Sims Carnival BumperBlast
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DF0B1D6F-DEC5-4831-00B7-FC2ACB464C31}" = The Sims Carnival SnapCity
"{DFE94B9F-0AFA-4A97-9F5B-DF2A2608238B}" = Shoppers' Hotline Control Center
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_6" = AIM 6
"AOL Instant Messenger" = AOL Instant Messenger
"ASUS Probe V2.23.04" = ASUS Probe V2.23.04
"ASUS Probe V2.25.02" = ASUS Probe V2.25.02
"AsusUpdate" = AsusUpdate
"ATI Display Driver" = ATI Display Driver
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Bejeweled 2 Deluxe 1.0" = Bejeweled 2 Deluxe 1.0
"BFGC" = Big Fish Games Client
"BFG-Dream Chronicles" = Dream Chronicles
"BFG-Dream Chronicles - The Chosen Child" = Dream Chronicles: The Chosen Child
"BFG-Dream Chronicles 2 - The Eternal Maze" = Dream Chronicles ™ 2: The Eternal Maze
"BFG-Strange Cases - The Tarot Card Mystery" = Strange Cases: The Tarot Card Mystery
"CCleaner" = CCleaner
"CDex" = CDex extraction audio
"CEP - Colour Enable Packages_is1" = CEP (Color Enable Package) v.9.0 (beta)
"Click'N Design 3D" = Click'N Design 3D
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"CreataCard Gold 3" = CreataCard Gold 3
"Creative PC-CAM Center" = Creative PC-CAM Center
"Creative PD1131" = Creative WebCam NX Pro Driver (1.02.03.0218)
"Creative WebCam Monitor" = Creative WebCam Monitor
"Creative WebCam NX Pro User's Guide English" = Creative WebCam NX Pro User's Guide (English)
"EA Download Manager" = EA Download Manager
"Foxit Reader" = Foxit Reader
"FrostWire" = FrostWire 4.21.3
"FTDICOMM" = FTDI USB Serial Converter Drivers
"hp deskjet 940c series" = hp deskjet 940c series (Remove only)
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"JumpStart Artist" = JumpStart Artist
"KeePass Password Safe_is1" = KeePass Password Safe 0.98b
"LimeWire" = LimeWire 5.5.16
"MAGIX Media Manager silver" = MAGIX Media Manager silver
"MAGIX music maker 2005 deLuxe" = MAGIX music maker 2005 deLuxe
"MAGIX music studio 2005 deLuxe" = MAGIX music studio 2005 deLuxe
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Memorex 6142 USB" = Memorex 6142 USB
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Motherboard Monitor 5_is1" = Motherboard Monitor 5
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"My Photo Adventure" = My Photo Adventure
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"Publix Preschool Pals" = Publix Preschool Pals
"RealAlt_is1" = Real Alternative 1.43
"RocketLife" = RocketLife
"Secunia PSI" = Secunia PSI (2.0.0.1003)
"Shareaza" = Shareaza
"The Cat in the Hat" = The Cat in the Hat
"Tweak UI 2.10" = Tweak UI
"UltimateBet" = UltimateBet
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtools3DLifePlayer" = Virtools 3D Life Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/8/2011 5:04:31 PM | Computer Name = P4P800E-3GHZE | Source = Application Hang | ID = 1002
Description = Hanging application Kodak Software Updater.exe, version 0.0.0.0, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/8/2011 5:06:26 PM | Computer Name = P4P800E-3GHZE | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/8/2011 6:04:41 PM | Computer Name = P4P800E-3GHZE | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.
Error - 1/8/2011 6:19:02 PM | Computer Name = P4P800E-3GHZE | Source = MsiInstaller | ID = 11905
Description = Product: Ask Toolbar – Error 1905.Module C:\Program Files\Ask.com\GenericAskToolbar.dll
failed to unregister. HRESULT -2147220472. Contact your support personnel.
Error - 1/8/2011 8:04:24 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 1/8/2011 8:04:25 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 1/8/2011 8:04:40 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 1/8/2011 8:04:40 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.
Error - 1/8/2011 8:04:40 PM | Computer Name = P4P800E-3GHZE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 1/9/2011 9:35:28 AM | Computer Name = P4P800E-3GHZE | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
[ System Events ]
Error - 1/8/2011 9:15:44 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 1/8/2011 9:16:44 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 1/8/2011 9:17:14 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 1/8/2011 9:18:14 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 1/8/2011 9:19:14 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 1/8/2011 9:20:15 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/8/2011 9:20:45 PM | Computer Name = P4P800E-3GHZE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 1/8/2011 9:27:46 PM | Computer Name = P4P800E-3GHZE | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2
Error - 1/9/2011 9:13:26 AM | Computer Name = P4P800E-3GHZE | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2
Error - 1/9/2011 9:20:35 AM | Computer Name = P4P800E-3GHZE | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2
< End of report >