Tom,
Here are the reports as requested:
2011-02-18 02:14:59 . 2011-02-18 02:15:19 3,793 —-a-w-
C:\Qoobox\Quarantine\catchme.txt
2011-02-18 01:34:29 . 2010-08-17 13:17:06 58,880 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\spoolsv.exe.vir
2011-02-18 01:34:26 . 2011-02-18 01:45:41 23,523 —-a-w- C:\Qoobox\Quarantine\[4]-Submit_2011-02-17_19.33.52.zip
2011-02-15 18:29:23 . 2011-02-15 18:29:23 173 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Toolbar-Locked.reg.dat
2011-02-15 18:24:16 . 2011-02-18 02:20:00 11,562 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-02-15 18:10:48 . 2011-02-18 02:13:17 255 —-a-w- C:\Qoobox\Quarantine\catchme.log
2011-02-14 05:11:50 . 2011-02-14 05:11:50 189 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\1475.bat.vir
2011-02-14 04:11:59 . 2011-02-14 04:11:59 185 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\28.bat.vir
2011-02-14 03:11:48 . 2011-02-14 03:11:48 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\9938.bat.vir
2011-02-14 02:11:44 . 2011-02-14 02:11:44 181 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\8027.bat.vir
2011-02-13 20:11:51 . 2011-02-13 20:11:51 181 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\8429.bat.vir
2011-02-13 19:11:42 . 2011-02-13 19:11:42 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\8063.bat.vir
2011-02-13 18:12:04 . 2011-02-13 18:12:04 189 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\2358.bat.vir
2011-02-13 16:11:52 . 2011-02-13 16:11:52 189 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\3326.bat.vir
2011-02-11 19:11:40 . 2011-02-11 19:11:40 185 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\9035.bat.vir
2011-02-11 18:11:39 . 2011-02-11 18:11:39 187 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\3581.bat.vir
2011-02-11 04:11:55 . 2011-02-11 04:11:55 189 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\2916.bat.vir
2011-02-11 03:11:38 . 2011-02-11 03:11:38 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\5677.bat.vir
2011-02-11 02:11:45 . 2011-02-11 02:11:45 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\7089.bat.vir
2011-02-10 18:11:38 . 2011-02-10 18:11:38 185 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\5143.bat.vir
2011-02-10 04:11:55 . 2011-02-10 04:11:55 187 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\906.bat.vir
2011-02-10 03:11:54 . 2011-02-10 03:11:54 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\5315.bat.vir
2011-02-10 02:11:40 . 2011-02-10 02:11:40 179 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\4673.bat.vir
2011-02-10 01:11:50 . 2011-02-10 01:11:50 179 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\2632.bat.vir
2011-02-10 00:11:43 . 2011-02-10 00:11:43 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\83.bat.vir
2011-02-09 23:11:46 . 2011-02-09 23:11:46 189 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\1965.bat.vir
2011-02-09 22:11:59 . 2011-02-09 22:11:59 187 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\7643.bat.vir
2011-02-09 03:12:03 . 2011-02-09 03:12:03 179 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\9445.bat.vir
2011-02-09 02:11:45 . 2011-02-09 02:11:45 187 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\6305.bat.vir
2011-02-09 01:11:48 . 2011-02-09 01:11:48 185 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\9957.bat.vir
2011-02-09 00:11:43 . 2011-02-09 00:11:43 179 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\4006.bat.vir
2011-02-08 22:11:40 . 2011-02-08 22:11:40 187 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\1521.bat.vir
2011-02-08 04:11:43 . 2011-02-08 04:11:43 183 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\3441.bat.vir
2011-02-08 03:11:41 . 2011-02-08 03:11:41 185 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\7906.bat.vir
2011-02-07 20:12:07 . 2011-02-07 20:12:07 179 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\8902.bat.vir
2011-01-31 02:14:40 . 2011-02-14 05:11:27 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At14.job.vir
2011-01-31 02:14:39 . 2011-02-14 04:11:34 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At13.job.vir
2011-01-31 02:14:39 . 2011-02-15 17:06:27 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At12.job.vir
2011-01-31 02:14:38 . 2011-02-14 16:08:14 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At11.job.vir
2011-01-31 02:14:37 . 2011-02-15 17:06:27 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At10.job.vir
2011-01-27 17:58:04 . 2011-02-15 17:06:28 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At9.job.vir
2011-01-27 17:58:03 . 2011-02-15 00:11:01 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At8.job.vir
2011-01-27 17:58:03 . 2011-01-31 02:14:35 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At7.job.vir
2011-01-27 17:58:02 . 2011-02-15 18:12:07 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At6.job.vir
2011-01-27 17:58:01 . 2011-02-09 22:11:27 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At5.job.vir
2011-01-27 17:58:01 . 2011-02-15 17:17:52 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At4.job.vir
2011-01-27 17:58:01 . 2011-02-13 20:11:20 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At3.job.vir
2011-01-27 17:58:00 . 2011-02-14 16:08:14 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At2.job.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 23,296 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\1.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 125,672 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\a.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 165,160 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\b.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 172,176 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\c.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 105,704 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\d.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 108,920 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\e.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 60,048 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\f.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 70,624 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\g.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 52,920 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\h.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 48,336 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\i.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 28,000 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\J.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 28,080 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\k.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 69,168 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\l.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 104,888 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\m.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 36,808 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\n.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 41,072 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\o.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 96,480 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\p.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 4,440 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\q.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 36,768 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\r.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 159,760 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\s.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 95,664 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\t.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 20,960 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\u.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 30,528 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\v.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 43,520 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\w.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 2,888 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\x.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 10,744 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\y.xml.vir
2011-01-05 12:02:22 . 2011-01-05 12:02:22 11,648 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\Application Data\PriceGong\Data\z.xml.vir
2010-12-08 00:17:51 . 2010-12-08 00:17:53 103,784 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\GoToAssistDownloadHelper.exe.vir
2010-12-02 20:08:25 . 2010-12-02 20:08:25 10 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\install.vir
2010-12-02 19:50:12 . 2010-12-02 19:50:12 5,954 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Local Settings\Application Data\{792A2574-58CF-462A-A7ED-C7C0F19094DD}\chrome\content\overlay.xul.vir
2010-12-02 19:50:12 . 2010-12-02 19:50:13 2,128 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Local Settings\Application Data\{792A2574-58CF-462A-A7ED-C7C0F19094DD}\chrome\content\_cfg.js.vir
2010-12-02 19:50:12 . 2010-12-02 19:50:13 764 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Local Settings\Application Data\{792A2574-58CF-462A-A7ED-C7C0F19094DD}\install.rdf.vir
2010-12-02 19:50:12 . 2010-12-02 19:50:12 122 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Local Settings\Application Data\{792A2574-58CF-462A-A7ED-C7C0F19094DD}\chrome.manifest.vir
2010-12-02 19:47:51 . 2011-02-13 19:11:28 394 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\Tasks\At1.job.vir
2010-12-02 19:45:59 . 2007-08-13 23:32:30 45,568 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\Adobe\AdobeUpdate .exe.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 19,448 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\1.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 85,816 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\a.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 115,856 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\b.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 128,448 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\c.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 81,848 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\d.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 89,256 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\e.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 51,304 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\f.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 59,960 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\g.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 45,264 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\h.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 39,928 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\i.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 25,112 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\J.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 21,896 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\k.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 65,760 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\l.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 86,136 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\m.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 27,608 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\n.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 33,904 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\o.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 77,264 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\p.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 3,512 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\q.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 30,824 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\r.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 128,336 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\s.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 63,440 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\t.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 14,432 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\u.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 18,480 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\v.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 27,696 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\w.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 2,176 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\x.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 6,448 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\y.xml.vir
2010-11-01 12:32:42 . 2010-11-01 12:32:42 7,712 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\z.xml.vir
2007-05-26 01:52:52 . 2008-06-17 23:52:18 54,908 —-a-w- C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir
2003-01-12 04:10:13 . 2010-12-02 11:51:40 5,016 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Inez Miller\Application Data\PriceGong\Data\mru.xml.vir
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=64cffc1a3787344d8a9ad235c13eee30
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-02-11 05:01:37
# local_time=2011-02-10 11:01:37 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 257303109 257303109 0 0
# compatibility_mode=1024 16777215 100 0 0 0 0 0
# compatibility_mode=5891 16776869 42 87 0 8496345 0 0
# compatibility_mode=8192 67108863 100 0 205426 205426 0 0
# scanned=70007
# found=4
# cleaned=4
# scan_time=5416
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K0QE0I7N\dfsgsfthsrthgargdhxjx[1].jar multiple threats (deleted - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\lyvxk5v.exe Win32/Delf.PWW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\079M9K11\sd[1].exe Win32/Delf.PWW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6WZKEE9Z\7230704585[1] a variant of Java/TrojanDownloader.OpenStream.NBF trojan (deleted - quarantined) 00000000000000000000000000000000 C
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=64cffc1a3787344d8a9ad235c13eee30
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-02-14 05:29:40
# local_time=2011-02-13 11:29:40 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 257568457 257568457 0 0
# compatibility_mode=1024 16777215 100 0 0 0 0 0
# compatibility_mode=5891 16776869 42 87 0 8761693 0 0
# compatibility_mode=8192 67108863 100 0 470774 470774 0 0
# scanned=20669
# found=35
# cleaned=35
# scan_time=950
C:\Documents and Settings\NetworkService\Application Data\ADtCZ.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\D4LFljr5.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\DbGLv1c.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\DHmsO.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\FZwuLv6x.exe Win32/Delf.PWW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\GaHxo.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\h3Cde.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\h5TyXt.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\hvEBSy.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\JryHFO0.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\jS3cyZwKd.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\K9F83ymu.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\KPV5ir.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\kVxk8DG.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\laevRt.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\lCdApoO0.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\LERJEp.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\lNiQU37.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\LqZGchglK.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\mG1JCWr.exe Win32/Delf.PWW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\PcThhO.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\PuDCX.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\Q1puiN.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\rKjBRUaZAd.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\smMyege.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\TRoXyPxtXE.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\VEIy8.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\VGsZp4kdyh.exe Win32/Delf.PWW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\W1yJTBtixQ.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\wsoUm7zLG.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\XlmrOL2Wxw.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\zJimn2Gwp.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Application Data\ZOl8p.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\9Y2ATV06\idebil[1].htm JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UV7TVN7M\sd[1].exe Win32/Delf.PWW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=64cffc1a3787344d8a9ad235c13eee30
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-02-14 07:52:33
# local_time=2011-02-14 01:52:33 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 257569603 257569603 0 0
# compatibility_mode=1024 16777215 100 0 0 0 0 0
# compatibility_mode=5891 16776533 42 87 0 8762839 0 0
# compatibility_mode=8192 67108863 100 0 471920 471920 0 0
# scanned=69899
# found=1
# cleaned=1
# scan_time=8379
C:\WINDOWS\system32\345.js JS/TrojanDownloader.Agent.NWG trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=64cffc1a3787344d8a9ad235c13eee30
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-02-19 10:22:42
# local_time=2011-02-19 04:22:42 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 258058505 258058505 0 0
# compatibility_mode=5891 16776533 42 87 0 9251741 0 0
# compatibility_mode=8192 67108863 100 0 960822 960822 0 0
# scanned=59452
# found=0
# cleaned=0
# scan_time=3687
OTL logfile created on: 2/19/2011 4:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Inez Miller\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
703.00 Mb Total Physical Memory | 390.00 Mb Available Physical Memory | 55.00% Memory free
953.00 Mb Paging File | 653.00 Mb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.68 Gb Free Space | 58.20% Space Free | Partition Type: NTFS
Computer Name: YOUR-6BVPXYZTOQ | User Name: Inez Miller | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/02/19 15:15:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Inez Miller\Desktop\OTL.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/06/27 16:24:34 | 000,467,028 | —- | M] (Atheros) – C:\WINDOWS\system32\acs.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) – C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2002/08/15 11:11:00 | 000,151,552 | —- | M] (Hewlett-Packard) – C:\WINDOWS\system32\HPConfig.exe
========== Modules (SafeList) ==========
MOD - [2011/02/19 15:15:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Inez Miller\Desktop\OTL.exe
MOD - [2010/08/23 10:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2010/12/07 18:18:59 | 000,013,160 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [Disabled | Stopped] – C:\Program Files\Citrix\GoToAssist\637\g2aservice.exe – (GoToAssist)
SRV - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2008/06/27 16:24:34 | 000,467,028 | —- | M] (Atheros) [Auto | Running] – C:\WINDOWS\system32\acs.exe – (ACS)
SRV - [2008/02/27 11:54:52 | 000,360,547 | —- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] – C:\Program Files\NETGEAR\WN111v2\jswpsapi.exe – (jswpsapi)
SRV - [2007/01/31 14:55:42 | 000,096,370 | —- | M] (Canon Inc.) [Auto | Running] – C:\Program Files\Canon\CAL\CALMAIN.exe – (CCALib8)
SRV - [2003/01/14 15:12:14 | 000,053,248 | —- | M] (Hewlett-Packard Co.) [Disabled | Stopped] – C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe – (HPWirelessMgr)
SRV - [2002/08/15 11:11:00 | 000,151,552 | —- | M] (Hewlett-Packard) [Auto | Running] – C:\WINDOWS\system32\HPConfig.exe – (HPConfig)
========== Driver Services (SafeList) ==========
DRV - [2011/02/19 15:18:26 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{57F92E34-0EA5-4753-8C6E-FAAEF870F882}\MpKsl03669726.sys – (MpKsl03669726)
DRV - [2010/11/09 13:56:12 | 000,098,392 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2008/10/01 16:45:52 | 000,057,440 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\jswscimd.sys – (JSWSCIMD)
DRV - [2008/09/30 03:24:36 | 000,453,120 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\WN111v2.sys – (WN111v2)
DRV - [2007/12/28 14:02:12 | 000,287,232 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\wg111v3.sys – (RTL8187B)
DRV - [2007/12/14 04:31:00 | 000,057,408 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wsimd.sys – (WSIMD)
DRV - [2007/01/19 11:53:43 | 000,018,304 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2007/01/19 11:53:42 | 000,019,712 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2006/10/06 14:49:00 | 000,044,224 | R— | M] (BVRP Software) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS – (BVRPMPR5)
DRV - [2004/11/22 16:36:39 | 000,018,003 | —- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRENDIS5.sys – (MRENDIS5)
DRV - [2004/11/22 16:36:34 | 000,019,345 | —- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMPR5.sys – (MREMPR5)
DRV - [2004/10/07 19:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2004/07/16 11:14:30 | 000,140,416 | —- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt2500usb.sys – (RT2500USB)
DRV - [2004/07/16 11:14:30 | 000,140,416 | —- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt2500usb.sys – (bkn50USB)
DRV - [2004/07/15 16:31:16 | 000,018,432 | —- | M] (National Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DP83815.sys – (DP83815)
DRV - [2003/07/24 12:10:34 | 000,017,149 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\DNINDIS5.sys – (DNINDIS5)
DRV - [2003/07/10 05:16:46 | 000,026,112 | R— | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\aliirda.sys – (ALiIRDA)
DRV - [2003/05/21 14:35:56 | 000,030,592 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\strmdisp.sys – (StreamDispatcher)
DRV - [2003/05/21 14:33:54 | 000,179,712 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWALI.sys – (HSFHWALI)
DRV - [2003/05/21 14:32:32 | 000,631,296 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2003/05/21 14:31:22 | 001,063,040 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2003/03/26 12:20:24 | 000,062,288 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp)
DRV - [2003/03/26 12:20:16 | 000,023,436 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k)
DRV - [2003/03/26 12:17:14 | 000,025,930 | —- | M] (Roxio) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\Dvd_2k.sys – (dvd_2K)
DRV - [2003/03/26 12:17:12 | 000,030,662 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Mmc_2k.sys – (mmc_2K)
DRV - [2003/03/26 12:17:10 | 000,144,250 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\pwd_2K.sys – (pwd_2k)
DRV - [2003/03/26 12:15:28 | 000,206,464 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\udfreadr_xp.sys – (UdfReadr_xp)
DRV - [2003/03/26 12:15:02 | 000,241,280 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\cdudf_xp.sys – (cdudf_xp)
DRV - [2003/03/14 06:48:06 | 000,269,008 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2003/02/06 10:24:16 | 000,164,352 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2002/11/05 09:04:48 | 000,291,328 | R— | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\caliaud.sys – (CALIAUD)
DRV - [2002/11/05 09:04:48 | 000,244,608 | R— | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\calihal.sys – (CALIHALA)
DRV - [2002/10/16 06:15:54 | 000,014,543 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKbFltr.SYS – (DKbFltr)
DRV - [2002/08/15 17:31:00 | 000,471,168 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2002/07/18 07:07:50 | 000,023,602 | —- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\atisgkaf.sys – (caboagp)
DRV - [2002/07/17 13:09:12 | 000,014,504 | —- | M] (Hewlett-Packard) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hpci.sys – (HPCI)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 01:48:56 | 000,289,664 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\atimpab.sys – (atimpab)
DRV - [2001/08/17 01:19:48 | 000,174,464 | —- | M] (ESS Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\es198x.sys – (allegro) ESS Allegro Audio Driver (WDM)
DRV - [2001/08/17 01:13:20 | 000,027,164 | —- | M] (Xircom, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CE3N5.SYS – (CE3)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" =
http://autoconfig.cpqcorp.net
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" =
http://autoconfig.cpqcorp.net
IE - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://webmail.blomand.net/src/login.php
IE - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2011/02/17 19:41:39 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - File not found
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - File not found
O3 - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1845834151-916659734-3466184817-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: DirectAnimation Java Classes
file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java
file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Inez Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Inez Miller\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 30 Days ==========
[2011/02/19 15:15:46 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Inez Miller\Desktop\OTL.exe
[2011/02/15 12:17:51 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/02/15 12:12:42 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/02/15 12:12:42 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/02/15 12:12:41 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/02/15 12:12:41 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/02/15 12:10:48 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/02/15 12:03:56 | 000,000,000 | —D | C] – C:\Qoobox
[2011/02/09 20:33:36 | 000,098,392 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/02/09 20:33:36 | 000,027,984 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[2011/02/09 20:33:08 | 000,000,000 | —D | C] – C:\VIPRERESCUE
[2011/02/09 16:09:18 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2011/02/08 20:26:28 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2011/02/08 20:12:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/02/08 20:12:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/02/08 19:36:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Inez Miller\Application Data\AVG10
[2011/02/08 19:25:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/08 19:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/02/08 19:00:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/08 18:19:42 | 001,360,472 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Inez Miller\Desktop\tdsskiller.exe
[2011/02/07 13:27:37 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/02/07 13:04:37 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Easy Assist
[2011/02/07 13:04:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Applications
[2011/02/06 20:15:38 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/02/06 16:58:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2011/01/30 22:27:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Inez Miller\Desktop\computer stuff
[2011/01/30 19:56:37 | 000,000,000 | —D | C] – C:\fd610b2d1a213851d26ee27544a0
[2011/01/26 13:14:57 | 000,000,000 | —D | C] – C:\b9f140afd81130e96b75
[2011/01/26 12:38:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Google
[2011/01/24 17:00:57 | 000,000,000 | —D | C] – C:\f807e8ecfb6f1f0a84
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/19 16:16:05 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/19 15:15:59 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Inez Miller\Desktop\OTL.exe
[2011/02/19 15:11:18 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/02/19 15:10:51 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{9A6FEBFC-2160-4ECE-A8B9-333334E9286C}.job
[2011/02/19 15:05:54 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/19 15:05:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/19 15:05:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/19 15:05:42 | 737,202,176 | -HS- | M] () – C:\hiberfil.sys
[2011/02/17 19:41:39 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/02/17 19:34:27 | 000,001,165 | —- | M] () – C:\CF-Submit.htm
[2011/02/15 12:17:58 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/02/15 11:23:16 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/02/10 20:12:31 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/02/08 20:38:06 | 000,219,248 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/08 20:30:34 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/08 18:20:10 | 001,360,472 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Inez Miller\Desktop\tdsskiller.exe
[2011/02/07 12:58:01 | 000,000,000 | —- | M] () – C:\WINDOWS\Atokakoroxaz.bin
[2011/01/30 21:26:43 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/26 21:04:02 | 000,000,120 | —- | M] () – C:\WINDOWS\Ffolohilofejinur.dat
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/17 19:34:27 | 000,001,165 | —- | C] () – C:\CF-Submit.htm
[2011/02/15 12:17:58 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/02/15 12:17:54 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/02/15 12:12:42 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/02/15 12:12:42 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/02/15 12:12:42 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/02/15 12:12:42 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/02/15 12:12:42 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/02/11 13:06:06 | 737,202,176 | -HS- | C] () – C:\hiberfil.sys
[2011/01/30 21:26:43 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/15 09:12:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2010/12/01 13:51:02 | 000,000,105 | —- | C] () – C:\WINDOWS\ka.ini
[2008/09/08 19:33:55 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2008/08/28 12:53:18 | 000,012,358 | —- | C] () – C:\Documents and Settings\Inez Miller\Application Data\PFP100JCM.{PB
[2008/08/26 13:24:19 | 000,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2008/08/26 13:23:52 | 000,000,626 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2008/06/27 16:18:04 | 000,262,216 | —- | C] () – C:\WINDOWS\System32\IPTests.dll
[2007/05/25 19:35:26 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2004/09/29 14:33:45 | 000,000,135 | —- | C] () – C:\Documents and Settings\Inez Miller\Local Settings\Application Data\fusioncache.dat
[2004/06/10 14:11:32 | 000,009,216 | —- | C] () – C:\Documents and Settings\Inez Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/04/18 16:43:46 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/04/18 16:43:44 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2004/03/01 13:46:59 | 000,000,053 | —- | C] () – C:\WINDOWS\WININIT.INI
[2004/03/01 13:46:51 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2003/09/04 12:41:45 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/09/04 12:38:10 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2003/09/04 12:24:35 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\SynTPCoI.dll
[2003/09/04 12:19:17 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/09/04 12:17:14 | 000,000,139 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2002/09/09 09:15:50 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/09/09 08:49:10 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/05/31 06:10:25 | 000,000,000 | —- | C] () – C:\WINDOWS\pcf.INI
[2002/05/12 10:12:16 | 000,000,000 | —- | C] () – C:\WINDOWS\PCFriend.INI
[1998/10/11 00:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll
========== LOP Check ==========
[2003/09/04 12:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\InterTrust
[2011/02/07 13:04:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2007/05/25 20:06:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2011/02/15 12:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2004/03/01 13:51:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2004/03/01 13:52:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2011/02/08 19:25:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/12/01 13:49:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Imaginext™
[2011/02/08 19:22:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/01/15 09:26:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NETGEAR
[2002/12/08 10:08:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2011/01/30 23:10:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ResultBrowse
[2002/12/08 12:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Winferno
[2010/12/26 20:20:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2003/09/04 12:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\InterTrust
[2003/09/04 12:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Guest\Application Data\InterTrust
[2007/05/25 20:06:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Inez Miller\Application Data\AT&T;
[2011/02/08 19:36:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Inez Miller\Application Data\AVG10
[2003/09/04 12:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Inez Miller\Application Data\InterTrust
[2006/01/02 07:22:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Inez Miller\Application Data\InterVideo
[2002/05/31 06:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Inez Miller\Application Data\MysteryStudio
[2002/12/10 23:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Inez Miller\Application Data\RegistryKeys
[2003/09/04 12:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Pam and Jody Scott\Application Data\InterTrust
[2009/01/23 10:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Pam and Jody Scott\Application Data\InterVideo
[2002/08/19 08:15:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Pam and Jody Scott\Application Data\MysteryStudio
[2011/02/19 15:11:18 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/02/19 15:10:51 | 000,000,436 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{9A6FEBFC-2160-4ECE-A8B9-333334E9286C}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2002/09/09 01:32:20 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2002/09/09 01:32:20 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2002/09/09 01:32:20 | 000,385,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemdrive%\*.sys /90 /md5 >
[2011/02/19 15:05:42 | 737,202,176 | -HS- | M] ()
Unable to obtain MD5 – C:\hiberfil.sys
[2011/02/19 15:05:31 | 301,989,888 | -HS- | M] ()
Unable to obtain MD5 – C:\pagefile.sys
< End of report >
OTL Extras logfile created on: 2/19/2011 4:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Inez Miller\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
703.00 Mb Total Physical Memory | 390.00 Mb Available Physical Memory | 55.00% Memory free
953.00 Mb Paging File | 653.00 Mb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 21.68 Gb Free Space | 58.20% Space Free | Partition Type: NTFS
Computer Name: YOUR-6BVPXYZTOQ | User Name: Inez Miller | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000000-3976-4267-9F39-1DC4745090B7}" = Microsoft Learning and Research Plus Support Files
"{092eeeee-9fdd-4895-a568-0818c96beb6c}" = AiO_Scan
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}" = WN111v2
"{1CAD83B0-87A3-4206-BF70-644546808731}" = Overland
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Productivity Pack
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{2F1FD032-67D1-4569-923F-47EAF132BF0F}" = DocProc
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{369B36BE-3D64-4641-9AEA-808D436FE130}" = Microsoft Picture It! Express 7.0
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1
"{54e854d5-d5d4-452d-9c75-b39f5625b5fb}" = Readme
"{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{829698DE-9EAC-475E-9A05-B7BA807CA1EF}" = Director
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{939227BD-19D8-4684-8A04-31AC9F6A564C}" = Scan
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{9F4EEA0C-7174-4BD3-89AF-7AB2F9F6AEDD}" = hpmdtab
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A363B66C-1547-47bf-90F0-3834E70A841A}" = CreativeProjects
"{A8F2DCDE-AE4E-4AC9-BECD-496FB80FBF6A}" = Notebook Utilities
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABEB838C-A1A7-4C5D-B7E1-8B4314B00527}" = MSN Messenger 5.0
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{bb6cac2a-1fa0-471a-bc3c-ade699c39f3c}" = Fax
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c330461f-c4a9-4fc7-af5d-c158e0b56aa7}" = AiOSoftware
"{C38BC5B7-62D3-4880-82DD-A4803FD81921}" = PhotoGallery
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC0A24CB-87C9-4F1C-A1F2-F87D8D4DDCAF}" = HP Software Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE4F8FFB-4063-4247-9F14-ECE61AFEFA25}" = TrayApp
"{CFD1B282-555D-494d-8231-4175C2AF08C2}" = PrintScreen
"{D0604F35-314C-4341-A05E-3FEABCFDD470}" = Desktop Zoom
"{D1D8C9C4-89BE-4f37-9EC4-B80E3C239C41}" = Copy
"{D545BB81-DEB0-49f7-BE26-197BC31AAF57}" = SkinsHP2
"{E4ABB302-9D82-4D18-83D5-AD1DFE786AA8}" = Unload
"{ec7d7a6a-31cb-4810-826f-74171bef44f1}" = AIOMinimal
"{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}" = HP PSC & OfficeJet 3.0
"{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"{FBBF532A-47AC-457d-AC06-0D3163D8911E}" = WebReg
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Display Driver" = ATI Display Driver
"CAL" = Canon Camera Access Library
"CameraUserGuide-PSA470" = Canon PowerShot A470 Camera User Guide
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"CNXT_MODEM_PCI_VEN_10B9&DEV;_5457&SUBSYS;_0850103C" = Conexant 56K ACLink Modem
"Conexant PCI Audio" = Conexant AC-Link Audio
"CSCLIB" = Canon Camera Support Core Library
"DirectPrintUserGuide" = Canon Direct Print User Guide
"EOS Utility" = Canon Utilities EOS Utility
"ESET Online Scanner" = ESET Online Scanner v3
"GoToAssist" = GoToAssist Corporate
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Photo & Imaging 3.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Imaginext™ Pirate Raider" = Imaginext™ Pirate Raider
"Inactive HP Printer Drivers (Remove only)" = Inactive HP Printer Drivers (Remove only)
"InstallShield_{1C0E9C6B-D4D5-4D3C-8A10-F10A3E7BEEA5}" = RangeMax Wireless-N USB Adapter WN111v2
"InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"InterActual Player" = InterActual Player
"Lost Cases Sherlock" = Lost Cases Sherlock
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Microsoft Security Client" = Microsoft Security Essentials
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MSNMS" = MSN Internet Software
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Photags Music Express" = iConcepts Music Express
"PhotoStitch" = Canon Utilities PhotoStitch
"PriceGong" = PriceGong 2.1.0
"QT4HPOT" = One-Touch Buttons
"QuickTime" = QuickTime
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Shockwave" = Shockwave
"SoftwareStarterGuide-DCSD34" = Canon Digital Camera Solution Disk 34 Software Starter Guide
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows XP Service Pack" = Windows XP Service Pack 3
"WordPerfect Productivity Pack" = WordPerfect Productivity Pack
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/8/2011 6:13:09 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072efe, P2 endsearch, P3 search, P4 3.0.8107.0,
P5 mpsigdwn.dll, P6 3.0.8107.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 2/8/2011 6:16:18 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.
Error - 2/8/2011 6:28:33 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Application Error | ID = 1001
Description = Fault bucket 1271752061.
Error - 2/8/2011 7:59:21 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 2/8/2011 7:59:21 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This network connection does not exist.
Error - 2/8/2011 8:20:06 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The connection with the server was terminated abnormally
Error - 2/19/2011 5:48:28 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 2/19/2011 5:48:28 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 2/19/2011 5:48:28 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 2/19/2011 6:00:22 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: This operation returned because the timeout period expired.
[ System Events ]
Error - 2/15/2011 3:36:09 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7001
Description = The Fax service depends on the Print Spooler service which failed
to start because of the following error: %%2
Error - 2/15/2011 3:36:09 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 2/17/2011 9:00:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7000
Description = The Print Spooler service failed to start due to the following error:
%%2
Error - 2/17/2011 9:00:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Ati HotKey Poller service
to connect.
Error - 2/17/2011 9:00:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7000
Description = The Ati HotKey Poller service failed to start due to the following
error: %%1053
Error - 2/17/2011 9:00:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7001
Description = The Fax service depends on the Print Spooler service which failed
to start because of the following error: %%2
Error - 2/17/2011 9:00:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 2/19/2011 5:06:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Ati HotKey Poller service
to connect.
Error - 2/19/2011 5:06:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7000
Description = The Ati HotKey Poller service failed to start due to the following
error: %%1053
Error - 2/19/2011 5:06:10 PM | Computer Name = YOUR-6BVPXYZTOQ | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
< End of report >