sgraye
Topic Starter
Spam email is being sent from my email account.
Results of OTL scan. PLEASE REVIEW AND COMMENT!!! Thanks…
OLT.TXT
OTL logfile created on: 2/9/2011 9:39:55 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Home Office\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 67.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 584.17 Gb Total Space | 520.01 Gb Free Space | 89.02% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 2.19 Gb Free Space | 18.40% Space Free | Partition Type: NTFS
Computer Name: HOMEOFFICE-PC | User Name: Home Office | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Home Office\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files (x86)\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
PRC - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\Home Office\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (szserver) – c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (nmservice) – C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (LinksysUpdater) – C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (IntuitUpdateService) – C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (purendis) – C:\Windows\SysNative\drivers\purendis.sys (Cisco Systems, Inc.)
DRV:64bit: - (pnarp) – C:\Windows\SysNative\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (szkg5) – C:\Windows\SySWOW64\DRIVERS\szkg64.sys (iS3 Inc.)
DRV - (is3srv) – C:\Windows\SySWOW64\drivers\is3srv64.sys (iS3 Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ig?referrer=ign_n [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
IE - HKCU\..\URLSearchHook: {23256f20-0d9b-4323-b005-6e5de569c4b7} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "chrome://speeddial/content/speeddial.xul"
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0
FF - prefs.js..extensions.enabledItems: [removed]:1.4.3
FF - prefs.js..extensions.enabledItems: [removed]:11.0.2.556
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/14 08:05:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/01/12 23:24:48 | 000,000,000 | —D | M]
[2010/08/28 14:42:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Home Office\AppData\Roaming\Mozilla\Extensions
[2011/02/07 16:14:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions
[2010/12/11 09:33:23 | 000,000,000 | —D | M] (Speed Dial) – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/08/30 01:27:01 | 000,000,000 | —D | M] ("MultirowBookmarksToolbar") – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/08/30 01:28:12 | 000,000,000 | —D | M] (Smart Bookmarks Bar) – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions\[removed]
[2011/02/07 02:46:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/10/27 06:59:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/05 10:28:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/10/17 23:17:50 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]
[2010/10/09 18:46:21 | 000,466,944 | —- | M] (Catalina Marketing Corp.) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
[2010/10/09 18:46:21 | 000,466,944 | —- | M] (Catalina Marketing Corp.) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol500.dll
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/10/18 21:57:47 | 000,000,860 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll (Google Inc.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - c:\Program Files (x86)\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [nmctxth] C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9:64bit: - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fb2a3727-ae4b-11df-a9a2-90e6ba32f965}\Shell - "" = AutoRun
O33 - MountPoints2\{fb2a3727-ae4b-11df-a9a2-90e6ba32f965}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/02/09 09:33:56 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Home Office\Desktop\OTL.exe
[2011/02/09 09:24:17 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\backups
[2011/02/09 09:14:00 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Home Office\Desktop\HijackThis.exe
[2011/02/08 21:07:29 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/02/08 21:07:28 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/02/08 21:07:28 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/02/08 21:07:28 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/02/08 21:07:28 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/02/08 21:07:28 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/02/08 21:07:28 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/02/08 21:07:28 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/02/08 21:07:28 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/02/08 21:07:28 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/02/08 21:07:27 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/02/08 21:07:27 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/02/08 21:06:52 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/02/08 21:06:52 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/02/08 21:06:51 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/02/08 21:06:51 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/02/08 21:06:51 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/02/08 21:06:51 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/02/08 21:06:51 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/02/08 21:06:51 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/02/08 21:06:48 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/02/08 21:06:48 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/02/08 21:06:48 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/02/08 21:06:46 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/02/08 21:06:46 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/02/08 21:06:46 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/02/08 21:06:44 | 005,510,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/02/08 21:06:44 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/02/08 21:06:44 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/02/08 21:06:44 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/02/08 21:06:43 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/02/08 21:06:43 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/02/08 21:06:43 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/02/08 21:06:43 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/02/08 18:23:21 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-8
[2011/02/07 21:01:02 | 000,000,000 | —D | C] – C:\STOPzilla!
[2011/02/07 20:56:15 | 009,920,304 | —- | C] (Microsoft Corporation) – C:\Users\Home Office\Desktop\mseinstall.exe
[2011/02/07 18:46:50 | 012,832,200 | —- | C] (Microsoft Corporation) – C:\Users\Home Office\Desktop\windows-kb890830-x64-v3.15.exe
[2011/02/07 18:41:00 | 037,403,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MRT.exe
[2011/02/07 14:13:15 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-7
[2011/02/07 02:54:03 | 000,000,000 | —D | C] – C:\Windows\pss
[2011/02/07 02:47:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2011
[2011/02/06 17:05:21 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-6
[2011/02/06 16:55:33 | 115,832,504 | —- | C] (Kaspersky Lab) – C:\Users\Home Office\Desktop\kis11.0.2.556en.exe
[2011/02/05 11:06:04 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-5
[2011/02/04 16:57:24 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-4
[2011/02/02 15:48:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\STOPzilla!
[2011/02/02 15:48:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
[2011/02/01 08:20:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/02/01 08:18:54 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/02/01 08:18:53 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/01/31 18:12:26 | 000,132,560 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/01/31 18:12:24 | 000,546,256 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/01/31 18:12:24 | 000,452,048 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/01/31 18:12:24 | 000,398,800 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/01/31 18:12:24 | 000,028,624 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/01/31 18:12:24 | 000,022,992 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/01/31 18:12:22 | 000,390,608 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/01/31 18:12:22 | 000,067,024 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/01/31 18:12:20 | 000,738,768 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/01/31 18:12:20 | 000,230,864 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/01/30 15:24:18 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Roaming\OverDrive
[2011/01/30 15:24:18 | 000,000,000 | —D | C] – C:\Users\Home Office\Documents\My Media
[2011/01/30 15:24:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OverDrive Media Console
[2011/01/30 15:24:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\OverDrive Media Console
[2011/01/30 00:48:20 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Roaming\TechSmith
[2011/01/29 11:33:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snagit 10
[2011/01/27 19:30:10 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Local\Canon Easy-PhotoPrint EX
[2011/01/27 19:29:54 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX2
[2011/01/27 19:29:54 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonEPP
[2011/01/27 19:29:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2011/01/27 19:29:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2011/01/27 19:29:37 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2011/01/27 19:15:15 | 001,002,008 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igxpun.exe
[2011/01/27 19:15:15 | 000,000,000 | —D | C] – C:\Windows\SysWow64\x64
[2011/01/27 19:10:11 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Local\ElevatedDiagnostics
[2011/01/24 17:15:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Canon
[2011/01/21 12:58:41 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\Music
[2011/01/14 11:20:51 | 000,000,000 | —D | C] – C:\temp
[2011/01/14 11:20:13 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\AT&T
[2011/01/14 11:10:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Media Framework 2.1.1e
[2011/01/14 11:10:31 | 000,000,000 | —D | C] – C:\Program Files\JMF2.1.1e
[2011/01/14 11:10:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\AT&T
[2011/01/14 11:10:08 | 000,306,688 | —- | C] (InstallShield Software Corporation) – C:\Windows\IsUninst.exe
[2011/01/12 12:22:03 | 001,888,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2011/01/12 12:22:03 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/01/12 12:22:03 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/01/12 12:22:03 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/01/12 12:22:03 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/01/12 12:22:03 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/01/12 12:22:02 | 004,068,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/01/12 12:22:02 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/01/12 12:22:02 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/01/12 12:22:02 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/01/12 12:22:02 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/01/12 12:22:02 | 000,470,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/01/12 12:22:02 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/01/12 12:22:02 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/01/12 12:22:01 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2011/01/12 12:22:01 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/01/12 12:22:01 | 000,283,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/01/12 12:22:01 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/01/12 12:22:01 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/01/12 12:22:01 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/01/12 12:22:01 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/01/12 12:22:01 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/01/12 12:22:01 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/01/12 12:22:01 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/01/12 12:22:01 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/01/12 12:21:44 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/01/12 12:21:44 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[4 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/09 09:37:45 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/09 09:33:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Home Office\Desktop\OTL.exe
[2011/02/09 09:16:12 | 000,057,856 | —- | M] () – C:\Users\Home Office\Desktop\hijack notes.doc
[2011/02/09 09:16:12 | 000,000,162 | -H– | M] () – C:\Users\Home Office\Desktop\~$jack notes.doc
[2011/02/09 09:15:05 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/09 09:13:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Home Office\Desktop\HijackThis.exe
[2011/02/09 08:38:42 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 08:38:42 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 08:36:08 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/02/09 08:36:08 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/02/09 08:36:08 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/02/09 08:31:46 | 000,000,480 | —- | M] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/02/09 08:30:59 | 000,454,632 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/02/09 08:30:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/09 08:30:33 | 529,182,719 | -HS- | M] () – C:\hiberfil.sys
[2011/02/09 08:29:28 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2011/02/07 21:07:02 | 000,000,432 | —- | M] () – C:\Users\Home Office\Documents\cc_20110207_210659.reg
[2011/02/07 21:06:53 | 000,000,082 | —- | M] () – C:\Users\Home Office\Documents\cc_20110207_210650.reg
[2011/02/07 20:58:22 | 000,002,052 | —- | M] () – C:\Windows\epplauncher.mif
[2011/02/07 20:57:02 | 009,920,304 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\mseinstall.exe
[2011/02/07 18:44:13 | 012,832,200 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\windows-kb890830-x64-v3.15.exe
[2011/02/07 11:16:20 | 000,002,342 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/02/07 02:53:25 | 000,000,082 | —- | M] () – C:\Users\Home Office\Documents\cc_20110207_025323.reg
[2011/02/07 02:51:23 | 000,150,083 | —- | M] () – C:\Windows\SysNative\drivers\klin.dat
[2011/02/07 02:51:23 | 000,107,075 | —- | M] () – C:\Windows\SysNative\drivers\klick.dat
[2011/02/06 16:55:34 | 115,832,504 | —- | M] (Kaspersky Lab) – C:\Users\Home Office\Desktop\kis11.0.2.556en.exe
[2011/02/06 16:31:44 | 000,007,358 | —- | M] () – C:\Users\Home Office\Documents\cc_20110206_163141.reg
[2011/02/03 13:55:38 | 000,000,356 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForHome Office.job
[2011/02/01 08:20:17 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/31 18:12:26 | 000,132,560 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/01/31 18:12:24 | 000,546,256 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/01/31 18:12:24 | 000,452,048 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/01/31 18:12:24 | 000,398,800 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/01/31 18:12:24 | 000,028,624 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/01/31 18:12:24 | 000,022,992 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/01/31 18:12:22 | 000,390,608 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/01/31 18:12:22 | 000,067,024 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/01/31 18:12:20 | 000,738,768 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/01/31 18:12:20 | 000,230,864 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/01/30 15:24:03 | 000,002,525 | —- | M] () – C:\Users\Public\Desktop\OverDrive Media Console.lnk
[2011/01/30 00:48:12 | 000,001,934 | —- | M] () – C:\Users\Home Office\Documents\cc_20110130_004810.reg
[2011/01/29 15:01:47 | 000,000,313 | —- | M] () – C:\Users\Home Office\.JMAppsCfg
[2011/01/29 11:31:17 | 031,494,960 | —- | M] () – C:\Users\Home Office\Desktop\snagit.exe
[2011/01/27 19:29:48 | 000,001,888 | —- | M] () – C:\Users\Public\Desktop\Canon Easy-PhotoPrint EX.lnk
[2011/01/26 00:53:10 | 000,265,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/01/26 00:31:20 | 000,144,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/01/18 19:05:43 | 011,276,842 | —- | M] () – C:\Users\Home Office\Desktop\bluetabs.zip
[2011/01/18 01:20:48 | 000,000,722 | —- | M] () – C:\Users\Home Office\Documents\cc_20110118_012045.reg
[2011/01/14 11:10:33 | 000,001,795 | —- | M] () – C:\Users\Home Office\Desktop\JMStudio.lnk
[4 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/09 09:16:12 | 000,057,856 | —- | C] () – C:\Users\Home Office\Desktop\hijack notes.doc
[2011/02/09 09:16:12 | 000,000,162 | -H– | C] () – C:\Users\Home Office\Desktop\~$jack notes.doc
[2011/02/09 08:31:38 | 000,000,480 | —- | C] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/02/09 08:29:28 | 000,003,288 | —- | C] () – C:\bootsqm.dat
[2011/02/07 21:07:01 | 000,000,432 | —- | C] () – C:\Users\Home Office\Documents\cc_20110207_210659.reg
[2011/02/07 21:06:53 | 000,000,082 | —- | C] () – C:\Users\Home Office\Documents\cc_20110207_210650.reg
[2011/02/07 20:58:22 | 000,002,052 | —- | C] () – C:\Windows\epplauncher.mif
[2011/02/07 02:53:25 | 000,000,082 | —- | C] () – C:\Users\Home Office\Documents\cc_20110207_025323.reg
[2011/02/06 16:31:43 | 000,007,358 | —- | C] () – C:\Users\Home Office\Documents\cc_20110206_163141.reg
[2011/02/01 08:20:16 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/30 15:24:03 | 000,002,525 | —- | C] () – C:\Users\Public\Desktop\OverDrive Media Console.lnk
[2011/01/30 00:48:11 | 000,001,934 | —- | C] () – C:\Users\Home Office\Documents\cc_20110130_004810.reg
[2011/01/29 11:31:17 | 031,494,960 | —- | C] () – C:\Users\Home Office\Desktop\snagit.exe
[2011/01/27 19:29:48 | 000,001,888 | —- | C] () – C:\Users\Public\Desktop\Canon Easy-PhotoPrint EX.lnk
[2011/01/18 19:05:42 | 011,276,842 | —- | C] () – C:\Users\Home Office\Desktop\bluetabs.zip
[2011/01/18 01:20:47 | 000,000,722 | —- | C] () – C:\Users\Home Office\Documents\cc_20110118_012045.reg
[2011/01/14 11:29:54 | 000,000,313 | —- | C] () – C:\Users\Home Office\.JMAppsCfg
[2011/01/14 11:10:33 | 000,001,795 | —- | C] () – C:\Users\Home Office\Desktop\JMStudio.lnk
[2011/01/14 11:10:32 | 000,413,696 | —- | C] () – C:\Windows\SysWow64\jsound.dll
[2011/01/14 11:10:32 | 000,380,928 | —- | C] () – C:\Windows\SysWow64\jmmpa.dll
[2011/01/14 11:10:32 | 000,282,624 | —- | C] () – C:\Windows\SysWow64\jmh261.dll
[2011/01/14 11:10:32 | 000,184,320 | —- | C] () – C:\Windows\SysWow64\jmvh263.dll
[2011/01/14 11:10:32 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\jmjpeg.dll
[2011/01/14 11:10:32 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\jmh263enc.dll
[2011/01/14 11:10:32 | 000,098,304 | —- | C] () – C:\Windows\SysWow64\jmg723.dll
[2011/01/14 11:10:32 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\jmmpegv.dll
[2011/01/14 11:10:32 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\jmutil.dll
[2011/01/14 11:10:32 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\jmgsm.dll
[2011/01/14 11:10:32 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\jmam.dll
[2011/01/14 11:10:32 | 000,049,152 | —- | C] () – C:\Windows\SysWow64\jmcvid.dll
[2011/01/14 11:10:32 | 000,049,152 | —- | C] () – C:\Windows\SysWow64\jmacm.dll
[2011/01/14 11:10:32 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\jmvfw.dll
[2011/01/14 11:10:32 | 000,040,960 | —- | C] () – C:\Windows\SysWow64\jmdaud.dll
[2011/01/14 11:10:32 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\jmvcm.dll
[2011/01/14 11:10:32 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\jmgdi.dll
[2011/01/14 11:10:32 | 000,032,768 | —- | C] () – C:\Windows\SysWow64\jmfjawt.dll
[2011/01/14 11:10:32 | 000,032,768 | —- | C] () – C:\Windows\SysWow64\jmddraw.dll
[2011/01/14 11:10:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\jmmci.dll
[2011/01/14 11:10:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\jmdaudc.dll
[2010/08/23 10:22:13 | 000,000,199 | —- | C] () – C:\Windows\QUICKEN.INI
[2010/06/29 23:12:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/12/20 19:42:18 | 000,000,326 | —- | C] () – C:\Windows\primopdf.ini
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
========== LOP Check ==========
[2010/11/07 10:17:51 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\Articulate
[2010/09/08 12:32:04 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\BenjaminMoore.Fandeck.USEN.DA6CDF681F87B6FCFCE07B9D05DADF40E81244E5.1
[2010/10/09 18:46:21 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\Catalina Marketing Corp
[2010/08/26 19:44:52 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\Elluminate
[2011/01/30 15:24:18 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\OverDrive
[2010/08/22 18:17:39 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\PictureMover
[2011/02/03 18:08:17 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\PrimoPDF
[2011/01/30 00:48:20 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\TechSmith
[2010/08/27 07:30:11 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\webex
[2010/08/23 23:05:17 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\WinBatch
[2010/11/30 11:28:15 | 000,000,552 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/11/19 07:33:03 | 000,032,626 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/02/09 08:29:28 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2010/08/24 17:45:19 | 000,001,000 | —- | M] () – C:\FINIS_IT.TXT
[2011/02/09 08:30:33 | 529,182,719 | -HS- | M] () – C:\hiberfil.sys
[2010/10/10 21:44:26 | 000,000,000 | —- | M] () – C:\install.rdf
[2011/01/14 11:10:39 | 000,000,163 | —- | M] () – C:\jmf.log
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/02/09 08:30:35 | 2137,235,455 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/22 18:22:57 | 000,000,221 | -HS- | M] () – C:\Users\Home Office\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/09 09:13:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Home Office\Desktop\HijackThis.exe
[2011/02/06 16:55:34 | 115,832,504 | —- | M] (Kaspersky Lab) – C:\Users\Home Office\Desktop\kis11.0.2.556en.exe
[2011/02/07 20:57:02 | 009,920,304 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\mseinstall.exe
[2011/02/09 09:33:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Home Office\Desktop\OTL.exe
[2011/01/29 11:31:17 | 031,494,960 | —- | M] () – C:\Users\Home Office\Desktop\snagit.exe
[2011/02/07 18:44:13 | 012,832,200 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\windows-kb890830-x64-v3.15.exe
[2010/12/28 13:37:00 | 003,070,808 | —- | M] (PKWARE, Inc.) – C:\Users\Home Office\Desktop\ZIPReader.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
EXTRAS.TXT
OTL Extras logfile created on: 2/9/2011 9:39:55 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Home Office\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 67.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 584.17 Gb Total Space | 520.01 Gb Free Space | 89.02% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 2.19 Gb Free Space | 18.40% Space Free | Partition Type: NTFS
Computer Name: HOMEOFFICE-PC | User Name: Home Office | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{26280024-DFB7-4967-90DB-7F9C6660D01E}" = HP MediaSmart SmartMenu
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{77B8B4A5-EE79-4907-A318-2DA86325B8D7}" = iTunes
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0054-0409-1000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00B4-0409-1000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-003B-0000-1000-0000000FF1CE}" = Microsoft Office Project Professional 2010
"{91140000-0057-0000-1000-0000000FF1CE}" = Microsoft Office Visio 2010
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{E5C95CA5-4565-4B9D-97ED-05088D775614}" = Apple Mobile Device Support
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CANONIJINBOXADDON100" = Canon Inkjet Printer Driver Add-On Module
"CCleaner" = CCleaner
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PRJPROR" = Microsoft Project Professional 2010
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Office14.VISIOR" = Microsoft Visio Professional 2010
"PC-Doctor for Windows" = Hardware Diagnostic Tools
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08DB3902-2CE0-474D-BCE3-0177766CE9F1}" = HP Support Assistant
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 23
"{27469CB8-D16D-D807-E86F-3F29691BAC37}" = Virtual Fan Deck
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{37D59F62-2FC7-412D-AA55-3D0E6A9BD9C7}" = Microsoft Live Search Toolbar
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5BCC634A-58AD-42F9-B3C6-2EA52F81CF85}" = Snagit 10
"{5C47C8B6-77FF-4FC7-A388-66FCF9CFC24C}" = Snagit 9.1.3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73CB01A1-A9D0-41CA-B490-348880975F48}" = STOPzilla
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BF2A74BF-8D12-47F1-8B19-22B30AF6B0D1}" = Linksys EasyLink Advisor
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Activate Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}" = OverDrive Media Console
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD6C316A-FE75-4FBB-9D22-4C1920232B72}" = LightScribe System Software
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AT&T Unified Messaging" = AT&T Unified Messaging
"BenjaminMoore.Fandeck.USEN.DA6CDF681F87B6FCFCE07B9D05DADF40E81244E5.1" = Virtual Fan Deck
"Digital Editions" = Adobe Digital Editions
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Google Chrome" = Google Chrome
"Homepage Protection" = Homepage Protection
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011
"Java Media Framework 2.1.1e" = Java Media Framework 2.1.1e
"Linksys EasyLink Advisor" = Linksys EasyLink Advisor
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"TurboTax 2008" = TurboTax 2008
"WildTangent hp Master Uninstall" = HP Games
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/7/2011 6:42:41 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3354
Error - 2/7/2011 6:42:42 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/7/2011 6:42:42 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4368
Error - 2/7/2011 6:42:42 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4368
Error - 2/7/2011 10:58:22 PM | Computer Name = HomeOffice-PC | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation
was canceled. You canceled the Security Essentials installation on your computer.
Error code:0x8004FF0A.
Error - 2/7/2011 10:59:24 PM | Computer Name = HomeOffice-PC | Source = Application Hang | ID = 1002
Description = The program SZOptions.exe version 5.0.84.5 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 3f0 Start
Time: 01cbc73c0e0d3f40 Termination Time: 16 Application Path: c:\Program Files (x86)\STOPzilla!\SZOptions.exe
Report
Id: 5f2376c3-332f-11e0-acea-90e6ba32f965
Error - 2/7/2011 11:05:22 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
Error - 2/7/2011 11:07:23 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
Error - 2/7/2011 11:08:02 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
Error - 2/7/2011 11:11:09 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
[ Hewlett-Packard Events ]
Error - 9/25/2010 11:40:39 PM | Computer Name = HomeOffice-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 1/14/2011 2:29:36 AM | Computer Name = HomeOffice-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 1/20/2011 2:38:47 PM | Computer Name = HomeOffice-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\011120123843.xml
File not created by asset agent
[ System Events ]
Error - 2/8/2011 12:48:34 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:50:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:50:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:50:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:55:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:55:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:55:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:57:48 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:57:48 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:57:48 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
< End of report >
Results of OTL scan. PLEASE REVIEW AND COMMENT!!! Thanks…
OLT.TXT
OTL logfile created on: 2/9/2011 9:39:55 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Home Office\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 67.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 584.17 Gb Total Space | 520.01 Gb Free Space | 89.02% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 2.19 Gb Free Space | 18.40% Space Free | Partition Type: NTFS
Computer Name: HOMEOFFICE-PC | User Name: Home Office | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Home Office\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files (x86)\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Windows\SysWOW64\java.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
PRC - C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
PRC - C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
========== Modules (SafeList) ==========
MOD - C:\Users\Home Office\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (szserver) – c:\Program Files (x86)\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (nmservice) – C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (LinksysUpdater) – C:\Program Files (x86)\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (IntuitUpdateService) – C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (purendis) – C:\Windows\SysNative\drivers\purendis.sys (Cisco Systems, Inc.)
DRV:64bit: - (pnarp) – C:\Windows\SysNative\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (szkg5) – C:\Windows\SySWOW64\DRIVERS\szkg64.sys (iS3 Inc.)
DRV - (is3srv) – C:\Windows\SySWOW64\drivers\is3srv64.sys (iS3 Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ig?referrer=ign_n [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
IE - HKCU\..\URLSearchHook: {23256f20-0d9b-4323-b005-6e5de569c4b7} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "chrome://speeddial/content/speeddial.xul"
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5.8
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0
FF - prefs.js..extensions.enabledItems: [removed]:1.4.3
FF - prefs.js..extensions.enabledItems: [removed]:11.0.2.556
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/14 08:05:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/01/12 23:24:48 | 000,000,000 | —D | M]
[2010/08/28 14:42:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Home Office\AppData\Roaming\Mozilla\Extensions
[2011/02/07 16:14:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions
[2010/12/11 09:33:23 | 000,000,000 | —D | M] (Speed Dial) – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/08/30 01:27:01 | 000,000,000 | —D | M] ("MultirowBookmarksToolbar") – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/08/30 01:28:12 | 000,000,000 | —D | M] (Smart Bookmarks Bar) – C:\Users\Home Office\AppData\Roaming\Mozilla\Firefox\Profiles\ygkzcj8d.default\extensions\[removed]
[2011/02/07 02:46:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/10/27 06:59:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/05 10:28:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/10/17 23:17:50 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]
[2010/10/09 18:46:21 | 000,466,944 | —- | M] (Catalina Marketing Corp.) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
[2010/10/09 18:46:21 | 000,466,944 | —- | M] (Catalina Marketing Corp.) – C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol500.dll
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/10/18 21:57:47 | 000,000,860 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll (Google Inc.)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - c:\Program Files (x86)\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [nmctxth] C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9:64bit: - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\amd64\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fb2a3727-ae4b-11df-a9a2-90e6ba32f965}\Shell - "" = AutoRun
O33 - MountPoints2\{fb2a3727-ae4b-11df-a9a2-90e6ba32f965}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\J\Shell - "" = AutoRun
O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/02/09 09:33:56 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Home Office\Desktop\OTL.exe
[2011/02/09 09:24:17 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\backups
[2011/02/09 09:14:00 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Home Office\Desktop\HijackThis.exe
[2011/02/08 21:07:29 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/02/08 21:07:28 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/02/08 21:07:28 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/02/08 21:07:28 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/02/08 21:07:28 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/02/08 21:07:28 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/02/08 21:07:28 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/02/08 21:07:28 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/02/08 21:07:28 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/02/08 21:07:28 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/02/08 21:07:27 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/02/08 21:07:27 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/02/08 21:06:52 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/02/08 21:06:52 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/02/08 21:06:51 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/02/08 21:06:51 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\davclnt.dll
[2011/02/08 21:06:51 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/02/08 21:06:51 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/02/08 21:06:51 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/02/08 21:06:51 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/02/08 21:06:48 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/02/08 21:06:48 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/02/08 21:06:48 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/02/08 21:06:46 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/02/08 21:06:46 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/02/08 21:06:46 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/02/08 21:06:44 | 005,510,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/02/08 21:06:44 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/02/08 21:06:44 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/02/08 21:06:44 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/02/08 21:06:43 | 000,366,080 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/02/08 21:06:43 | 000,294,400 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/02/08 21:06:43 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/02/08 21:06:43 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/02/08 18:23:21 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-8
[2011/02/07 21:01:02 | 000,000,000 | —D | C] – C:\STOPzilla!
[2011/02/07 20:56:15 | 009,920,304 | —- | C] (Microsoft Corporation) – C:\Users\Home Office\Desktop\mseinstall.exe
[2011/02/07 18:46:50 | 012,832,200 | —- | C] (Microsoft Corporation) – C:\Users\Home Office\Desktop\windows-kb890830-x64-v3.15.exe
[2011/02/07 18:41:00 | 037,403,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MRT.exe
[2011/02/07 14:13:15 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-7
[2011/02/07 02:54:03 | 000,000,000 | —D | C] – C:\Windows\pss
[2011/02/07 02:47:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2011
[2011/02/06 17:05:21 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-6
[2011/02/06 16:55:33 | 115,832,504 | —- | C] (Kaspersky Lab) – C:\Users\Home Office\Desktop\kis11.0.2.556en.exe
[2011/02/05 11:06:04 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-5
[2011/02/04 16:57:24 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\New 2011-2-4
[2011/02/02 15:48:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\STOPzilla!
[2011/02/02 15:48:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STOPzilla
[2011/02/01 08:20:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/02/01 08:18:54 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/02/01 08:18:53 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/01/31 18:12:26 | 000,132,560 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/01/31 18:12:24 | 000,546,256 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/01/31 18:12:24 | 000,452,048 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/01/31 18:12:24 | 000,398,800 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/01/31 18:12:24 | 000,028,624 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/01/31 18:12:24 | 000,022,992 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/01/31 18:12:22 | 000,390,608 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/01/31 18:12:22 | 000,067,024 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/01/31 18:12:20 | 000,738,768 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/01/31 18:12:20 | 000,230,864 | R— | C] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/01/30 15:24:18 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Roaming\OverDrive
[2011/01/30 15:24:18 | 000,000,000 | —D | C] – C:\Users\Home Office\Documents\My Media
[2011/01/30 15:24:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OverDrive Media Console
[2011/01/30 15:24:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\OverDrive Media Console
[2011/01/30 00:48:20 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Roaming\TechSmith
[2011/01/29 11:33:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Snagit 10
[2011/01/27 19:30:10 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Local\Canon Easy-PhotoPrint EX
[2011/01/27 19:29:54 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX2
[2011/01/27 19:29:54 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonEPP
[2011/01/27 19:29:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2011/01/27 19:29:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2011/01/27 19:29:37 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2011/01/27 19:15:15 | 001,002,008 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igxpun.exe
[2011/01/27 19:15:15 | 000,000,000 | —D | C] – C:\Windows\SysWow64\x64
[2011/01/27 19:10:11 | 000,000,000 | —D | C] – C:\Users\Home Office\AppData\Local\ElevatedDiagnostics
[2011/01/24 17:15:03 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Canon
[2011/01/21 12:58:41 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\Music
[2011/01/14 11:20:51 | 000,000,000 | —D | C] – C:\temp
[2011/01/14 11:20:13 | 000,000,000 | —D | C] – C:\Users\Home Office\Desktop\AT&T
[2011/01/14 11:10:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Media Framework 2.1.1e
[2011/01/14 11:10:31 | 000,000,000 | —D | C] – C:\Program Files\JMF2.1.1e
[2011/01/14 11:10:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\AT&T
[2011/01/14 11:10:08 | 000,306,688 | —- | C] (InstallShield Software Corporation) – C:\Windows\IsUninst.exe
[2011/01/12 12:22:03 | 001,888,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2011/01/12 12:22:03 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/01/12 12:22:03 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/01/12 12:22:03 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10warp.dll
[2011/01/12 12:22:03 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/01/12 12:22:03 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d2d1.dll
[2011/01/12 12:22:02 | 004,068,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/01/12 12:22:02 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/01/12 12:22:02 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/01/12 12:22:02 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DWrite.dll
[2011/01/12 12:22:02 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/01/12 12:22:02 | 000,470,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/01/12 12:22:02 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/01/12 12:22:02 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/01/12 12:22:01 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2011/01/12 12:22:01 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/01/12 12:22:01 | 000,283,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/01/12 12:22:01 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/01/12 12:22:01 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/01/12 12:22:01 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1core.dll
[2011/01/12 12:22:01 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/01/12 12:22:01 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/01/12 12:22:01 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/01/12 12:22:01 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
[2011/01/12 12:22:01 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/01/12 12:21:44 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/01/12 12:21:44 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[4 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/09 09:37:45 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/09 09:33:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Home Office\Desktop\OTL.exe
[2011/02/09 09:16:12 | 000,057,856 | —- | M] () – C:\Users\Home Office\Desktop\hijack notes.doc
[2011/02/09 09:16:12 | 000,000,162 | -H– | M] () – C:\Users\Home Office\Desktop\~$jack notes.doc
[2011/02/09 09:15:05 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/09 09:13:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Home Office\Desktop\HijackThis.exe
[2011/02/09 08:38:42 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 08:38:42 | 000,015,984 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 08:36:08 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/02/09 08:36:08 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/02/09 08:36:08 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/02/09 08:31:46 | 000,000,480 | —- | M] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/02/09 08:30:59 | 000,454,632 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/02/09 08:30:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/09 08:30:33 | 529,182,719 | -HS- | M] () – C:\hiberfil.sys
[2011/02/09 08:29:28 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2011/02/07 21:07:02 | 000,000,432 | —- | M] () – C:\Users\Home Office\Documents\cc_20110207_210659.reg
[2011/02/07 21:06:53 | 000,000,082 | —- | M] () – C:\Users\Home Office\Documents\cc_20110207_210650.reg
[2011/02/07 20:58:22 | 000,002,052 | —- | M] () – C:\Windows\epplauncher.mif
[2011/02/07 20:57:02 | 009,920,304 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\mseinstall.exe
[2011/02/07 18:44:13 | 012,832,200 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\windows-kb890830-x64-v3.15.exe
[2011/02/07 11:16:20 | 000,002,342 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/02/07 02:53:25 | 000,000,082 | —- | M] () – C:\Users\Home Office\Documents\cc_20110207_025323.reg
[2011/02/07 02:51:23 | 000,150,083 | —- | M] () – C:\Windows\SysNative\drivers\klin.dat
[2011/02/07 02:51:23 | 000,107,075 | —- | M] () – C:\Windows\SysNative\drivers\klick.dat
[2011/02/06 16:55:34 | 115,832,504 | —- | M] (Kaspersky Lab) – C:\Users\Home Office\Desktop\kis11.0.2.556en.exe
[2011/02/06 16:31:44 | 000,007,358 | —- | M] () – C:\Users\Home Office\Documents\cc_20110206_163141.reg
[2011/02/03 13:55:38 | 000,000,356 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForHome Office.job
[2011/02/01 08:20:17 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/31 18:12:26 | 000,132,560 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3HTUI5.dll
[2011/01/31 18:12:24 | 000,546,256 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZComp5.dll
[2011/01/31 18:12:24 | 000,452,048 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZBase5.dll
[2011/01/31 18:12:24 | 000,398,800 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3DBA5.dll
[2011/01/31 18:12:24 | 000,028,624 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3XDat5.dll
[2011/01/31 18:12:24 | 000,022,992 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\SZIO5.dll
[2011/01/31 18:12:22 | 000,390,608 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3UI5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Svc5.dll
[2011/01/31 18:12:22 | 000,099,792 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Inet5.dll
[2011/01/31 18:12:22 | 000,067,024 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Hks5.dll
[2011/01/31 18:12:20 | 000,738,768 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Base5.dll
[2011/01/31 18:12:20 | 000,230,864 | R— | M] (iS3, Inc.) – C:\Windows\SysWow64\IS3Win325.dll
[2011/01/30 15:24:03 | 000,002,525 | —- | M] () – C:\Users\Public\Desktop\OverDrive Media Console.lnk
[2011/01/30 00:48:12 | 000,001,934 | —- | M] () – C:\Users\Home Office\Documents\cc_20110130_004810.reg
[2011/01/29 15:01:47 | 000,000,313 | —- | M] () – C:\Users\Home Office\.JMAppsCfg
[2011/01/29 11:31:17 | 031,494,960 | —- | M] () – C:\Users\Home Office\Desktop\snagit.exe
[2011/01/27 19:29:48 | 000,001,888 | —- | M] () – C:\Users\Public\Desktop\Canon Easy-PhotoPrint EX.lnk
[2011/01/26 00:53:10 | 000,265,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/01/26 00:31:20 | 000,144,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/01/18 19:05:43 | 011,276,842 | —- | M] () – C:\Users\Home Office\Desktop\bluetabs.zip
[2011/01/18 01:20:48 | 000,000,722 | —- | M] () – C:\Users\Home Office\Documents\cc_20110118_012045.reg
[2011/01/14 11:10:33 | 000,001,795 | —- | M] () – C:\Users\Home Office\Desktop\JMStudio.lnk
[4 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/09 09:16:12 | 000,057,856 | —- | C] () – C:\Users\Home Office\Desktop\hijack notes.doc
[2011/02/09 09:16:12 | 000,000,162 | -H– | C] () – C:\Users\Home Office\Desktop\~$jack notes.doc
[2011/02/09 08:31:38 | 000,000,480 | —- | C] () – C:\Windows\SysNative\drivers\kgpcpy.cfg
[2011/02/09 08:29:28 | 000,003,288 | —- | C] () – C:\bootsqm.dat
[2011/02/07 21:07:01 | 000,000,432 | —- | C] () – C:\Users\Home Office\Documents\cc_20110207_210659.reg
[2011/02/07 21:06:53 | 000,000,082 | —- | C] () – C:\Users\Home Office\Documents\cc_20110207_210650.reg
[2011/02/07 20:58:22 | 000,002,052 | —- | C] () – C:\Windows\epplauncher.mif
[2011/02/07 02:53:25 | 000,000,082 | —- | C] () – C:\Users\Home Office\Documents\cc_20110207_025323.reg
[2011/02/06 16:31:43 | 000,007,358 | —- | C] () – C:\Users\Home Office\Documents\cc_20110206_163141.reg
[2011/02/01 08:20:16 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/01/30 15:24:03 | 000,002,525 | —- | C] () – C:\Users\Public\Desktop\OverDrive Media Console.lnk
[2011/01/30 00:48:11 | 000,001,934 | —- | C] () – C:\Users\Home Office\Documents\cc_20110130_004810.reg
[2011/01/29 11:31:17 | 031,494,960 | —- | C] () – C:\Users\Home Office\Desktop\snagit.exe
[2011/01/27 19:29:48 | 000,001,888 | —- | C] () – C:\Users\Public\Desktop\Canon Easy-PhotoPrint EX.lnk
[2011/01/18 19:05:42 | 011,276,842 | —- | C] () – C:\Users\Home Office\Desktop\bluetabs.zip
[2011/01/18 01:20:47 | 000,000,722 | —- | C] () – C:\Users\Home Office\Documents\cc_20110118_012045.reg
[2011/01/14 11:29:54 | 000,000,313 | —- | C] () – C:\Users\Home Office\.JMAppsCfg
[2011/01/14 11:10:33 | 000,001,795 | —- | C] () – C:\Users\Home Office\Desktop\JMStudio.lnk
[2011/01/14 11:10:32 | 000,413,696 | —- | C] () – C:\Windows\SysWow64\jsound.dll
[2011/01/14 11:10:32 | 000,380,928 | —- | C] () – C:\Windows\SysWow64\jmmpa.dll
[2011/01/14 11:10:32 | 000,282,624 | —- | C] () – C:\Windows\SysWow64\jmh261.dll
[2011/01/14 11:10:32 | 000,184,320 | —- | C] () – C:\Windows\SysWow64\jmvh263.dll
[2011/01/14 11:10:32 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\jmjpeg.dll
[2011/01/14 11:10:32 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\jmh263enc.dll
[2011/01/14 11:10:32 | 000,098,304 | —- | C] () – C:\Windows\SysWow64\jmg723.dll
[2011/01/14 11:10:32 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\jmmpegv.dll
[2011/01/14 11:10:32 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\jmutil.dll
[2011/01/14 11:10:32 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\jmgsm.dll
[2011/01/14 11:10:32 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\jmam.dll
[2011/01/14 11:10:32 | 000,049,152 | —- | C] () – C:\Windows\SysWow64\jmcvid.dll
[2011/01/14 11:10:32 | 000,049,152 | —- | C] () – C:\Windows\SysWow64\jmacm.dll
[2011/01/14 11:10:32 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\jmvfw.dll
[2011/01/14 11:10:32 | 000,040,960 | —- | C] () – C:\Windows\SysWow64\jmdaud.dll
[2011/01/14 11:10:32 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\jmvcm.dll
[2011/01/14 11:10:32 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\jmgdi.dll
[2011/01/14 11:10:32 | 000,032,768 | —- | C] () – C:\Windows\SysWow64\jmfjawt.dll
[2011/01/14 11:10:32 | 000,032,768 | —- | C] () – C:\Windows\SysWow64\jmddraw.dll
[2011/01/14 11:10:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\jmmci.dll
[2011/01/14 11:10:32 | 000,028,672 | —- | C] () – C:\Windows\SysWow64\jmdaudc.dll
[2010/08/23 10:22:13 | 000,000,199 | —- | C] () – C:\Windows\QUICKEN.INI
[2010/06/29 23:12:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/12/20 19:42:18 | 000,000,326 | —- | C] () – C:\Windows\primopdf.ini
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
========== LOP Check ==========
[2010/11/07 10:17:51 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\Articulate
[2010/09/08 12:32:04 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\BenjaminMoore.Fandeck.USEN.DA6CDF681F87B6FCFCE07B9D05DADF40E81244E5.1
[2010/10/09 18:46:21 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\Catalina Marketing Corp
[2010/08/26 19:44:52 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\Elluminate
[2011/01/30 15:24:18 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\OverDrive
[2010/08/22 18:17:39 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\PictureMover
[2011/02/03 18:08:17 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\PrimoPDF
[2011/01/30 00:48:20 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\TechSmith
[2010/08/27 07:30:11 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\webex
[2010/08/23 23:05:17 | 000,000,000 | —D | M] – C:\Users\Home Office\AppData\Roaming\WinBatch
[2010/11/30 11:28:15 | 000,000,552 | —- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2010/11/19 07:33:03 | 000,032,626 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/02/09 08:29:28 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2010/08/24 17:45:19 | 000,001,000 | —- | M] () – C:\FINIS_IT.TXT
[2011/02/09 08:30:33 | 529,182,719 | -HS- | M] () – C:\hiberfil.sys
[2010/10/10 21:44:26 | 000,000,000 | —- | M] () – C:\install.rdf
[2011/01/14 11:10:39 | 000,000,163 | —- | M] () – C:\jmf.log
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/02/09 08:30:35 | 2137,235,455 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/22 18:22:57 | 000,000,221 | -HS- | M] () – C:\Users\Home Office\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/02/09 09:13:43 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Home Office\Desktop\HijackThis.exe
[2011/02/06 16:55:34 | 115,832,504 | —- | M] (Kaspersky Lab) – C:\Users\Home Office\Desktop\kis11.0.2.556en.exe
[2011/02/07 20:57:02 | 009,920,304 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\mseinstall.exe
[2011/02/09 09:33:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Home Office\Desktop\OTL.exe
[2011/01/29 11:31:17 | 031,494,960 | —- | M] () – C:\Users\Home Office\Desktop\snagit.exe
[2011/02/07 18:44:13 | 012,832,200 | —- | M] (Microsoft Corporation) – C:\Users\Home Office\Desktop\windows-kb890830-x64-v3.15.exe
[2010/12/28 13:37:00 | 003,070,808 | —- | M] (PKWARE, Inc.) – C:\Users\Home Office\Desktop\ZIPReader.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
EXTRAS.TXT
OTL Extras logfile created on: 2/9/2011 9:39:55 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Home Office\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 67.00% Memory free
12.00 Gb Paging File | 10.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 584.17 Gb Total Space | 520.01 Gb Free Space | 89.02% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 2.19 Gb Free Space | 18.40% Space Free | Partition Type: NTFS
Computer Name: HOMEOFFICE-PC | User Name: Home Office | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{26280024-DFB7-4967-90DB-7F9C6660D01E}" = HP MediaSmart SmartMenu
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{77B8B4A5-EE79-4907-A318-2DA86325B8D7}" = iTunes
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0054-0409-1000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00B4-0409-1000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-003B-0000-1000-0000000FF1CE}" = Microsoft Office Project Professional 2010
"{91140000-0057-0000-1000-0000000FF1CE}" = Microsoft Office Visio 2010
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{E5C95CA5-4565-4B9D-97ED-05088D775614}" = Apple Mobile Device Support
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CANONIJINBOXADDON100" = Canon Inkjet Printer Driver Add-On Module
"CCleaner" = CCleaner
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PRJPROR" = Microsoft Project Professional 2010
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Office14.VISIOR" = Microsoft Visio Professional 2010
"PC-Doctor for Windows" = Hardware Diagnostic Tools
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08DB3902-2CE0-474D-BCE3-0177766CE9F1}" = HP Support Assistant
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 23
"{27469CB8-D16D-D807-E86F-3F29691BAC37}" = Virtual Fan Deck
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{37D59F62-2FC7-412D-AA55-3D0E6A9BD9C7}" = Microsoft Live Search Toolbar
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5BCC634A-58AD-42F9-B3C6-2EA52F81CF85}" = Snagit 10
"{5C47C8B6-77FF-4FC7-A388-66FCF9CFC24C}" = Snagit 9.1.3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73CB01A1-A9D0-41CA-B490-348880975F48}" = STOPzilla
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BF2A74BF-8D12-47F1-8B19-22B30AF6B0D1}" = Linksys EasyLink Advisor
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Activate Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D4AFC7AD-F637-4EDD-BC76-767E4AF78CE1}" = OverDrive Media Console
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD6C316A-FE75-4FBB-9D22-4C1920232B72}" = LightScribe System Software
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AT&T Unified Messaging" = AT&T Unified Messaging
"BenjaminMoore.Fandeck.USEN.DA6CDF681F87B6FCFCE07B9D05DADF40E81244E5.1" = Virtual Fan Deck
"Digital Editions" = Adobe Digital Editions
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Google Chrome" = Google Chrome
"Homepage Protection" = Homepage Protection
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Anti-Virus 2011
"Java Media Framework 2.1.1e" = Java Media Framework 2.1.1e
"Linksys EasyLink Advisor" = Linksys EasyLink Advisor
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"TurboTax 2008" = TurboTax 2008
"WildTangent hp Master Uninstall" = HP Games
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/7/2011 6:42:41 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3354
Error - 2/7/2011 6:42:42 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/7/2011 6:42:42 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4368
Error - 2/7/2011 6:42:42 PM | Computer Name = HomeOffice-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4368
Error - 2/7/2011 10:58:22 PM | Computer Name = HomeOffice-PC | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF0A Description:Microsoft Security Essentials installation
was canceled. You canceled the Security Essentials installation on your computer.
Error code:0x8004FF0A.
Error - 2/7/2011 10:59:24 PM | Computer Name = HomeOffice-PC | Source = Application Hang | ID = 1002
Description = The program SZOptions.exe version 5.0.84.5 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 3f0 Start
Time: 01cbc73c0e0d3f40 Termination Time: 16 Application Path: c:\Program Files (x86)\STOPzilla!\SZOptions.exe
Report
Id: 5f2376c3-332f-11e0-acea-90e6ba32f965
Error - 2/7/2011 11:05:22 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
Error - 2/7/2011 11:07:23 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
Error - 2/7/2011 11:08:02 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
Error - 2/7/2011 11:11:09 PM | Computer Name = HomeOffice-PC | Source = System Restore | ID = 8193
Description =
[ Hewlett-Packard Events ]
Error - 9/25/2010 11:40:39 PM | Computer Name = HomeOffice-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()
at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Error - 1/14/2011 2:29:36 AM | Computer Name = HomeOffice-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 1/20/2011 2:38:47 PM | Computer Name = HomeOffice-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\011120123843.xml
File not created by asset agent
[ System Events ]
Error - 2/8/2011 12:48:34 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:50:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:50:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:50:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:55:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:55:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:55:42 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:57:48 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:57:48 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 2/8/2011 12:57:48 AM | Computer Name = HomeOffice-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
< End of report >