This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Fake Anti Malware AND Google redirect infection

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Fake Anti Malware notices started to pop up today. Ran Malwarebytes which ditected a bunch of stuff and removed most and said would remove the rest on reboot. Now Google redirect has started. Thanks in advance for your help.

DDS Log:


DDS (Ver_09-06-26.01) - FAT32x86
Run by [removed] at 16:04:51.39 on Fri 03/25/2011
internet explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2801 [GMT -4:00]

AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\WINDOWS\system32\CAPM1RSK.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Documents and Settings\Amy\Desktop\dds.scr.scr

============== Pseudo HJT Report ===============


SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_CURRENT_USER\software\microsoft\internet explorer\main
NoUpdateCheck REG_DWORD 1 (0x1)
NoJITSetup REG_DWORD 1 (0x1)
Disable Script Debugger REG_SZ no
Show_ChannelBand REG_SZ No
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ http://my.yahoo.com/index.html
Use_DlgBox_Colors REG_SZ yes
Use Search Asst REG_SZ no
Use Custom Search URL REG_BINARY 01000000
FullScreen REG_SZ no
Window_Placement REG_BINARY 2c0000000000000001000000ffffffffffffffffffffffffffffffff1d0000001d0000003c030000
75020000
Use FormSuggest REG_SZ yes
StatusBarOther REG_DWORD 1 (0x1)
NotifyDownloadComplete REG_SZ yes
FavChevron_Complete REG_SZ 3
FavChevron_Failed REG_SZ 2
FavChevron_Error REG_SZ 4
AddToFavoritesExpanded REG_DWORD 1 (0x1)
Use_Combobox_DlgBox_Colors_Complete REG_SZ 3
Use_Combobox_DlgBox_Colors_Failed REG_SZ 4
Use_Combobox_DlgBox_Colors_Error REG_SZ 4
FormSuggest PW Ask REG_SZ no
Save Directory REG_SZ c:\Documents and Settings\Amy\My Documents\Word\Miscellaneous\Amy Misc\Patternse\
Error Dlg Displayed On Every Error REG_SZ no
XMLHTTP REG_DWORD 1 (0x1)
UseClearType REG_SZ yes
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
CompatibilityFlags REG_DWORD 0 (0x0)
SearchMigrated REG_DWORD 1 (0x1)
RunOnceHasShown REG_DWORD 1 (0x1)
RunOnceComplete REG_DWORD 1 (0x1)
AlwaysShowMenus REG_DWORD 1 (0x1)
HistoryViewType REG_BINARY 0000
Enable_MyPics_Hoverbar REG_SZ no
ShowedCheckBrowser REG_SZ Yes
Check_Associations REG_SZ yes

HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Default Feeds

HKEY_CURRENT_USER\software\microsoft\internet explorer\main\FeatureControl

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0a000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1a000000
Placeholder_Height REG_BINARY 1a000000
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes

HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\ErrorThresholds

HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\FeatureControl

HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\UrlTemplate
uinternet connection wizard,shellnext = hxxp://www.dell4me.com/myway

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 7.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0 (0x0)
MigrateProxy REG_DWORD 1 (0x1)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 1 (0x1)
PrivacyAdvanced REG_DWORD 0 (0x0)
EnableNegotiate REG_DWORD 1 (0x1)
ProxyEnable REG_DWORD 0 (0x0)
GlobalUserOffline REG_DWORD 0 (0x0)
EnableAutodial REG_DWORD 0 (0x0)
PrivDiscUiShown REG_DWORD 1 (0x1)
WarnOnZoneCrossing REG_DWORD 0 (0x0)
UrlEncoding REG_DWORD 0 (0x0)
SecureProtocols REG_DWORD 160 (0xa0)
DisableCachingOfSSLPages REG_DWORD 0 (0x0)
WarnonBadCertRecving REG_DWORD 1 (0x1)
WarnOnPostRedirect REG_DWORD 0 (0x0)
WarnOnHTTPSToHTTPRedirect REG_DWORD 1 (0x1)
WarnOnIntranet REG_DWORD 0 (0x0)

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Cache

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Connections

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Lockdown_Zones

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\P3P

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Passport

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Protocols

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\TemplatePolicies

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Url History

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\ZoneMap

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Zones

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

Error: Key: software\microsoft\internet explorer\search does not exist!


SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_USERS\.default\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
{4D25F926-B9FE-4682-BF72-8AB8210D6D75}URLSearchHooks: H - No File

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
AutoRestartShell REG_DWORD 1 (0x1)
DefaultUserName REG_SZ Amy
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ c:\WINDOWS\system32e\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DefaultPassword REG_SZ
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ Amy
AltDefaultDomainName REG_SZ IRWINA
DefaultDomainName REG_SZ IRWINA
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Taskman REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExtensions

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\SpecialAccounts

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Credentials

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp;Local Settings\Application Data\Microsoft\Outlook
BuildNumber REG_DWORD 2600 (0xa28)

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
DebugOptions REG_SZ 2048
Documents REG_SZ
DosPrint REG_SZ no
NetMessage REG_SZ no
NullPort REG_SZ None
Programs REG_SZ com exe bat pif cmd
Run REG_SZ
Load REG_SZ
Device REG_SZ Brother MFC-7840W Printer,winspool,Ne06:
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File
BHO: - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5CA3D70E-1895-11CF-8E15-001234567890} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
BHO: - No File
BHO: NoExplorer - No File
urun: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Readere\AdobeUpdateManager.exe AcRdB7_0_9
urun: [LxrAutorun] c:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Mediae\LxrAutorun.exe
urun: [ctfmon.exe] c:\WINDOWS\system32e\ctfmon.exe
urun: [swg] "c:\Program Files\Google\GoogleToolbarNotifiere\GoogleToolbarNotifier.exe"
mrun: [SunJavaUpdateSched] "c:\Program Files\Common Files\Java\Java Updatee\jusched.exe"
mrun: [ATIPTA] c:\Program Files\ATI Technologies\ATI Control Panele\atiptaxx.exe
mrun: [IntelMeM] c:\Program Files\Intel\Modem Event Monitore\IntelMEM.exe
mrun: [DVDLauncher] "c:\Program Files\CyberLink\PowerDVDe\DVDLauncher.exe"
mrun: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Managere\sgtray.exe" /r
mrun: [dla] c:\WINDOWS\system32\dlae\tfswctrl.exe
mrun: [QuickTime Task] "c:\Program Files\QuickTimee\qttask.exe" -atboottime
mrun: [SSBkgdUpdate] "c:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdatee\SSBkgdupdate.exe" -Embedding -boot
mrun: [ControlCenter2.0] c:\Program Files\Brother\ControlCenter2e\brctrcen.exe /autorun
mrun: [TkBellExe] "c:\Program Files\Common Files\Real\Update_OBe\realsched.exe" -osboot
mrun: [CAVRID] "c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\CAVRID.exe"
mrun: [cctray] "c:\Program Files\CA\CA Internet Security Suite\cctraye\cctray.exe"
mrun: [PaperPort PTD] "c:\Program Files\ScanSoft\PaperPorte\pptd40nt.exe"
mrun: [IndexSearch] "c:\Program Files\ScanSoft\PaperPorte\IndexSearch.exe"
mrun: [PPort11reminder] "c:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Erege\Ereg.ini"
mrun: [BrMfcWnd] c:\Program Files\Brother\Brmfcmone\BrMfcWnd.exe /AUTORUN
mrun: [ControlCenter3] c:\Program Files\Brother\ControlCenter3e\brctrcen.exe /autorun
mrun: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Readere\Reader_sl.exe"
mrun: [Adobe ARM] "c:\Program Files\Common Files\Adobe\ARM\1.0e\AdobeARM.exe"
mrun: [QOELOADER] "c:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0e\QOELoader.exe"
mrun: [Memeo Instant Backup] c:\Program Files\Memeo\AutoBackupe\MemeoLauncher2.exe –silent –no_ui
mrun: [Seagate Dashboard] c:\Program Files\Seagate\Seagate Dashboarde\MemeoLauncher.exe –silent –no_ui
c:\DOCUME~1\Amy\STARTM~1\Programs\Startup\TrayDay.lnk - C:\Program Files\TrayDaye\TrayDay.exe
c:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdatee\qbupdate.exe

ie: SteelWerX Registry Console Tool 2.0
ie: Written by Bobbi Flekman 2006 ©

ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext

ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\E&xport to Microsoft Excel
ie: REG_SZ res://c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE/3000
ie: Contexts REG_DWORD 1 (0x1)

ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\Google Sidewiki…
ie: REG_SZ res://c:\Program Files\Google\Google Toolbar\Componente\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
ie: Contexts REG_DWORD 19 (0x13)

ie: {SteelWerX Registry Console Tool 2.0
ie: {Written by Bobbi Flekman 2006 ©

ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions

ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
ie: { ButtonText - REG_SZ Research
ie: { Icon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBAR.ICO
ie: { Default Visible - REG_SZ Yes
ie: { HotIcon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBARH.ICO

ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ie: { ButtonText - REG_SZ Real.com
ie: { HotIcon - REG_SZ c:\Program Files\Real\RealPlayere\eb_act.ico
ie: { Icon - REG_SZ c:\Program Files\Real\RealPlayere\eb_inact.ico
ie: { ToolTip - REG_SZ Real.com Explorer Bar
ie: { Default Visible - REG_SZ Yes

ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}
ie: { MenuText - REG_SZ @xpsp3res.dll,-20001
ie: { Exec - REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe

ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ie: { ButtonText - REG_SZ Messenger
ie: { Default Visible - REG_SZ Yes
ie: { Exec - REG_SZ c:\Program Files\Messengere\msmsgs.exe
ie: { HotIcon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,302
ie: { Icon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,301
ie: { MenuText - REG_SZ Windows Messenger
ie: { ToolTip - REG_SZ Windows Messenger
IE: { BandCLSID - REG_SZ {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - {ff059e31-cc5a-4e2e-bf3b-96e929d65503}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { BandCLSID - REG_SZ {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - {fe54fa40-d68c-11d2-98fa-00c0f0318afe}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!



SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\sdclicense.txt REG_SZ
c:\WINDOWS\Downloaded Program Filese\tgctlsi.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsi.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:07 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\tgctlsr.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsr.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:28 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains\Files
c:\WINDOWS\system32e\GWFSPidGen.DLL REG_SZ
c:\WINDOWS\system32e\LegitCheckControl.DLL REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\DownloadInformation
CODEBASE REG_SZ http://go.microsoft.com/fwlink/?linkid=39204
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\LegitCheckControl.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion
REG_SZ 1,4,389,0
LastModified REG_SZ Sat, 05 Nov 2005 00:53:56 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains\Files
c:\WINDOWSe\opuc.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\DownloadInformation
CODEBASE REG_SZ http://office.microsoft.com/officeupdate/content/opuc.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\opuc.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\InstalledVersion
REG_SZ 11,0,5626,0
LastModified REG_SZ Fri, 29 Aug 2003 19:59:02 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains\Files
c:\WINDOWS\system32e\muweb.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\DownloadInformation
CODEBASE REG_SZ http://update.microsoft.com/microsoftupdat…b?1136553665781
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\muweb.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\InstalledVersion
REG_SZ 5,8,0,2469
LastModified REG_SZ Thu, 26 May 2005 11:40:19 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InstalledVersion
REG_SZ 1.6.0.21

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains\Files
c:\WINDOWS\system32e\OFMailX.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\DownloadInformation
CODEBASE REG_SZ http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\OFMailX.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\InstalledVersion
REG_SZ 5,0,1,0
LastModified REG_SZ Sat, 19 Jan 2002 01:33:55 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\SymAData.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\InstalledVersion
REG_SZ 2,6,0,0
LastModified REG_SZ Mon, 14 Nov 2005 22:15:51 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\clearadjust.dll REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\DownloadInformation
CODEBASE REG_SZ http://download.microsoft.com/download/7/E…04/clearadj.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\clearadj.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\InstalledVersion
REG_SZ 1,0,0,4
LastModified REG_SZ Wed, 30 Apr 2003 01:12:15 GMT

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains\Files
c:\WINDOWS\SYSTEM32e\atl.dll REG_SZ
c:\WINDOWS\Downloaded Program Filese\gp.ocx REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation
CODEBASE REG_SZ http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\gp.inf

HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\InstalledVersion
REG_SZ 1,6,2,91
LastModified REG_SZ Wed, 01 Sep 2010 22:53:46 GMT

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

Error: Value: "NameServer" does not exist!


SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
d; /.* /!d; s//securityproviders: /
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Authentication Packages REG_MULTI_SZ msv1_0
Bounds REG_BINARY 0030000000200000
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest
ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 1 (0x1)
LsaPid REG_DWORD 1816 (0x718)
SecureBoot REG_DWORD 1 (0x1)
auditbaseobjects REG_DWORD 0 (0x0)
crashonauditfail REG_DWORD 0 (0x0)
disabledomaincreds REG_DWORD 0 (0x0)
everyoneincludesanonymous REG_DWORD 0 (0x0)
fipsalgorithmpolicy REG_DWORD 0 (0x0)
forceguest REG_DWORD 1 (0x1)
fullprivilegeauditing REG_BINARY 00
limitblankpassworduse REG_DWORD 1 (0x1)
lmcompatibilitylevel REG_DWORD 0 (0x0)
nodefaultadminowner REG_DWORD 1 (0x1)
nolmhash REG_DWORD 0 (0x0)
restrictanonymous REG_DWORD 0 (0x0)
restrictanonymoussam REG_DWORD 1 (0x1)
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Notification Packages REG_MULTI_SZ scecli
enabledcom REG_SZ y

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\MSV1_0

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache

SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems
windows REG_EXPAND_SZ %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

============= SERVICES / DRIVERS ===============

R0 xmasbus;xmasbus;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasbus.sys [2005-2-4 140800]
R0 xmasscsi;xmasscsi;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasscsi.sys [2005-2-4 5504]
R1 VET-FILT;VET File System Filter;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-filt.sys [2008-6-4 26352]
R1 VET-REC;VET File System Recognizer;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-rec.sys [2008-6-4 21104]
R1 VETEFILE;VET File Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\vetefile.sys [2010-6-3 746216]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetfddnt.sys [2008-6-4 21488]
R1 VETMONNT;VET File Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetmonnt.sys [2008-6-4 32240]
R2 CAISafe;CAISafe;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\isafe.exe [2008-6-4 144960]
R2 LxrSII1d;Secure II Driver;c:\WINDOWS\SYSTEM32\DRIVERSe\LxrSII1d.sys [2008-5-13 72672]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\Program Files\Memeo\AutoBackupe\MemeoBackgroundService.exe [2010-12-10 25824]
R2 RapidPortM1;RapidPortM1;c:\WINDOWS\SYSTEM32\DRIVERSe\CAPM1LP.SYS [2005-2-23 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\Program Files\Seagate\Seagate Dashboarde\SeagateDashboardService.exe [2010-12-14 14088]
R2 VETMSGNT;VET Message Service;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\vetmsg.exe [2008-6-4 238928]
R3 PPCtlPriv;PPCtlPriv;c:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrole\PPCtlPriv.exe [2007-8-16 189704]
R3 VETEBOOT;VET Boot Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\veteboot.sys [2010-6-3 130280]

============== File Associations ===============

::RecordNow.GI="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.ISO="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.PXJ="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
acrobat="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" /u "%1"
AcroExch.acrobatsecuritysettings.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document.7="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.FDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.pdfxml.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XDPDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XFDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
acwfile=%SystemRoot%\system32\accwiz.exe %1
AIFFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AIR.InstallerPackage=c:\PROGRA~1\COMMON~1\ADOBEA~1\Versions\1.0e\ADOBEA~1.EXE "%1"
AnimationShop3.Animation="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" /dde
AnimationShop3.WorkSpaceFile="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" "/Workspace" "%1"
Application.Manifest=rundll32.exe dfshim.dll,ShOpenVerbApplication %1
Application.Reference=rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
ASFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
ASXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AUFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AVIFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:8 /Open "%L"
A_auto_file=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
!d
Briefcase=explorer.exe %1
callto=rundll32.exe msconf.dll,CallToProtocolHandler %l
CATFile=rundll32.exe cryptext.dll,CryptExtOpenCAT %1
cdafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
CERFile=rundll32.exe cryptext.dll,CryptExtOpenCER %1
CertificateStoreFile=rundll32.exe cryptext.dll,CryptExtOpenSTR %1
certificate_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /certificate %1
cfxxefile="%1" %*
!d
clpfile=clipbrd.exe %1
!d
!d
CompressedFolder=rundll32.exe zipfldr.dll,RouteTheCall %L
ConferenceLink=rundll32.exe msconf.dll,OpenConfLink %l
Coverpage=%systemroot%\system32\fxscover.exe "%1"
CRLFile=rundll32.exe cryptext.dll,CryptExtOpenCRL %1
DBC.MPEG.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
desFile=c:\PROGRA~1\Intuit\QUICKB~1e\qbw32.exe "%1"
DocShortcut=rundll32 %SystemRoot%\System32\shscrap.dll,OpenScrap_RunDLL /r /x %1
dqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
dunfile=%SystemRoot%\system32\RUNDLL32.EXE NETSHELL.DLL,InvokeDunFile %1
emffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
Eudora.Mailbox=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Eudora.Stationery=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Excel.Addin="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Backup="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Chart=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
Excel.Chart.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.CSV="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.DIF="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Macrosheet="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.SheetBinaryMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SheetMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SLK="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Template="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Workspace="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.XLL="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excelhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
Excelhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
!d
fndfile=%SystemRoot%\Explorer.exe
Folder=%SystemRoot%\Explorer.exe /idlist,%I,%L
fonfile=%SystemRoot%\System32\fontview.exe %1
ftp="c:\Program Files\Internet Explorere\IEXPLORE.EXE" %1
giffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
gopher="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
h323file="rundll32.exe" msconf.dll,NewMediaPhone %l
HCP=%SystemRoot%\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe -FromHCP -url "%1"
helpfile=winhlp32.exe %1
hlpfile=%SystemRoot%\System32\winhlp32.exe %1
holfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /hol "%1"
htafile=c:\WINDOWS\system32e\mshta.exe "%1" %*
htfile="c:\Program Files\Windows NTe\HYPERTRM.EXE" %1
htmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
HTTP="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
https="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
icsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /ical "%1"
ICY=c:\Program Files\Winampe\winamp.exe %1
iiifile="rundll32.exe" msconf.dll,NewMediaPhone %l
!d
!d
InternetShortcut=rundll32.exe ieframe.dll,OpenURL %l
iqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
ITS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
jarfile="c:\Program Files\Java\jre6\bine\javaw.exe" -jar "%1" %*
JascPaintShopPhotoAlbumAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumAudio=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumImage=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumUploadAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JNLPFile="c:\Program Files\Java\jre6\bine\javaws.exe" "%1"
jpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
JSFile=%SystemRoot%\System32\WScript.exe "%1" %*
LDAP="c:\Program Files\Outlook Expresse\wab.exe" /ldap:%1
LiveUpdate.MIDI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
m3ufile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
MacromediaFlashPaper.MacromediaFlashPaper="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome "%1"
mailto=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
MediaPackageFile="c:\Program Files\Microsoft Office\OFFICE11e\MSTORE.EXE" "%1"
mhtmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
Microsoft Internet Mail Message="%ProgramFiles%\Outlook Express\msimn.exe" /eml:%1
Microsoft Internet News Message="%ProgramFiles%\Outlook Express\msimn.exe" /nws:%1
Microsoft.InformationCard=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
Microsoft.WindowsCardSpaceBackup=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
MIDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
MITrain.Document=c:\WINDOWS\Help\SBSI\Traininge\ORUN32.EXE -f "%1"
MMJB.AUDIOCD="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" /AudioCD "%1"
MMJB.BPP="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmfwlaunch.exe" "%1"
MMJB.MMJB="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMO="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMZ="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMS="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMST="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMSU="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
mp3file="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
mpegfile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:9 /Open "%L"
MPlayer=mplay32.exe /play /close "%L"
MS-ITSS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome ms-itss:%1::/
msbackupfile=%SystemRoot%\system32\ntbackup.exe
MSBD="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MSCFile=%SystemRoot%\system32\mmc.exe "%1" %*
MSDASC=Rundll32.exe c:\PROGRA~1\COMMON~1\System\OLEDB~1e\oledb32.dll,OpenDSLFile %1
msgfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /f "%1"
Msi.Package="%SystemRoot%\System32\msiexec.exe" /i "%1" %*
Msi.Patch="%SystemRoot%\System32\msiexec.exe" /p "%1" %*
MSInfo.Document=c:\Program Files\Common Files\Microsoft Shared\MSInfoe\MSInfo32.exe /msinfo_file %1
MSPaper.Document="c:\Program Files\Common Files\Microsoft Shared\MODI\11.0e\MSPVIEW.EXE" "%1"
MSProgramGroup=c:\WINDOWS\system32e\grpconv.exe %1
MsRcIncident=%SystemRoot%\PCHealth\HelpCtr\Binaries\HelpCtr.exe -Mode "hcp://system/Remote%%20Assistance/RAClientLayout.xml" -url "hcp://system/Remote%%20Assistance/Interaction/Client/rctoolScreen1.htm" -ExtraArgument "IncidentFile=%1"
msstylesfile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"
news="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
nntp="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
Office.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.95="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Template.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Wizard.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.9="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Oice.Excel.Addin=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Sheet=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Show=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.SlideShow=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Word.Document=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
oqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
ossfile="c:\Program Files\Microsoft Office\OFFICE11e\FINDER.EXE" /f "%1"
otffile=%SystemRoot%\System32\fontview.exe %1
outlook="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /select "%1"
Outlook.NavigatorBarFile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /s "%1"
Outlook.Template="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /t "%1"
P7RFile=rundll32.exe cryptext.dll,CryptExtOpenP7R %1
P7SFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
Paint.Picture=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
PaintShopPro8.BrowserCacheFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Browse" "%1"
PaintShopPro8.Frame="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Image="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Mask="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.PictureTube="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Script="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Script" "%1"
PaintShopPro8.Shape="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.WorkspaceFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Workspace" "%1"
Panorama=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
Paper.Document=c:\Program Files\ScanSoft\PaperPorte\PPPAGEVW.EXE "%1"
PaperPort.AutoplayHandler=c:\Program Files\ScanSoft\PaperPorte\PaprPort.exe /folder %L
pbkfile=%SystemRoot%\system32\rasphone.exe -f "%1"
PerfFile=%SystemRoot%\system32\perfmon.exe %1
pfmfile=%SystemRoot%\System32\fontview.exe %1
!d
pjpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pngfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pnm="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
PowerPoint.Show.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Show.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.ShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.TemplateMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
ppifile=%SystemRoot%\System32\msppcnfg.exe /Config %1
prffile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /PromptImportPRF "%1"
Publishing Folder=explorer.exe /idlist,%I,%L
qbofile=c:\Program Files\Intuit\QuickBooks Basice\qbw32.exe -X "%1"
qbwFile=c:\PROGRA~1\COMMON~1\Intuit\QUICKB~1e\qblaunch.exe "%1"
QuickTime.aif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aifc=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aiff=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.cdda=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dv=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.mov=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qt=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qtl=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qup=c:\PROGRA~1\QUICKT~1e\QuickTimeUpdater.exe "%1"
QuickTime.sd2=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
ratfile=rundll32.exe msrating.dll,ClickedOnRAT %1
RealJukebox.CDA.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJS.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJT.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMJ.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMP.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMX.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.wma.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP2.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP_AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AIFF.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR_WB.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AU.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AutoPlay.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /autoplay "%1"
RealPlayer.AVI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.CDBurn.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /burn "%1"
RealPlayer.DIVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.Flash.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /m image/vnd.rn-realflash %1
RealPlayer.M4A.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP1.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP2.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3PL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP4.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPEG.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPGA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PIX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PLSPL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.qt.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMS.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMVB.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RP.6="c:\Program Files\Common Files\Real\Update_OBe\rnxproc.exe" "%1"
RealPlayer.RSML.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RT.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SDP.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SMIL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.WAV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wax.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wm.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmv.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wvx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
!d
!d
rlogin=rundll32.exe url.dll,TelnetProtocolHandler %l
rqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
rtffile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
rtsp="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
SavedDsQuery=rundll32 %SystemRoot%\system32\dsquery.dll,OpenSavedDsQuery %1
SC=c:\Program Files\Winampe\winamp.exe %1
SchedulePlus.Application.7="c:\Program Files\Microsoft Office\OFFICE11\1033e\SCHDPL32.EXE" '%1'
!d
scriptletfile="c:\WINDOWSe\NOTEPAD.EXE" "%1"
SHCmdFile=explorer.exe
Shell=%SystemRoot%\Explorer.exe /idlist,%I,%L
ShellScrap=rundll32 %SystemRoot%\system32\shscrap.dll,OpenScrap_RunDLL %1
SHOUT=c:\Program Files\Winampe\winamp.exe %1
SldSrtr.Document=c:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0e\MSPVIEW.EXE "%1"
snews="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
SoundRec="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
SPCFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
SpybotSD.DisabledFile="c:\Program Files\Spybot - Search & Destroye\blindman.exe" "%1"
SpybotSD.SBEFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.TInfoFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SSM="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
STLFile=rundll32.exe cryptext.dll,CryptExtOpenCTL %1
stssync="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /stssync "%1"
T126_Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" - "%1"
telnet=rundll32.exe url.dll,TelnetProtocolHandler %l
themefile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"%1"
TIFImage.Document=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
tn3270=rundll32.exe url.dll,TelnetProtocolHandler %l
ttcfile=%SystemRoot%\System32\fontview.exe %1
ttffile=%SystemRoot%\System32\fontview.exe %1
!d
ulsfile="rundll32.exe" msconf.dll,NewMediaPhone %l
UVOX=c:\Program Files\Winampe\winamp.exe %1
vcard_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /vcard %1
vcffile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /v "%1"
vcsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /vcal "%1"
wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" %1
WAXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
webcal=rundll32.exe c:\PROGRA~1\AMERIC~1.0e\WEBCAL~1.DLL,WebCalHandler %1
webpnpFile=%SystemRoot%\system32\wpnpinst.exe %1
Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" "%1"
Winamp.File="c:\Program Files\Winampe\Winamp.exe" "%1"
Winamp.Playlist="c:\Program Files\Winampe\Winamp.exe" "%1"
Windows.CompositeFont="%WinDir%\System32\notepad.exe" "%1"
Windows.Movie.Maker="c:\Program Files\Movie Makere\moviemk.exe" %1
Windows.XamlDocument="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
Windows.Xbap="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
wmafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:5 /Open "%L"
WMDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /WMPackage:"%L"
wmffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
WMP.DVR-MSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
WMSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
WMVFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
WMZFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
Word.Backup.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.DocumentMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.RTF.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Template.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
wordhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
wordhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
Wordpad.Document.1="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
WPLFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
wrifile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
WVXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
x-eudora-option=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
x-internet-signup=%ProgramFiles%\Internet Explorer\Connection Wizard\ISIGNUP.EXE %1
XEV.FailSafeApp=%SystemRoot%\system32\NOTEPAD.EXE %1
XEV.GenericApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
XEV.OriginalApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
xmlfile="c:\Program Files\Common Files\Microsoft Shared\OFFICE11e\MSOXMLED.EXE" /verb open "%1"
xnkfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /x "%1"
XPSViewer.Document.1="c:\WINDOWS\system32\XPSViewere\XPSViewer.exe" "%1" %*
xslfile="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
ZAMailSafe="c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewalle\ca.exe" -warning "%1"
zapfile=%SystemRoot%\system32\NOTEPAD.EXE %1

=============== Created Last 30 ================

2011-03-25 10:06:35 –D—– c:\docume~1\amy\applic~1e\F8825A71ED75651A8D57DC362A93BB58
!d

==================== Find3M ====================

2004-08-11 19:13:26 A—HR– 749 c:\windowse\WindowsShell.Manifest
2004-08-04 07:00:00 A–SH— 48,680 c:\windowse\WINNT.BMP
2004-08-04 07:00:00 A–SH— 48,680 c:\windowse\WINNT256.BMP
2004-08-11 19:21:56 A–SHR– 227 c:\windows\ASSEMBLYe\Desktop.ini
2010-10-05 13:50:04 A—HR– 0 c:\windows\ASSEMBLYe\PublisherPolicy.tme
2010-10-05 13:50:04 —-HR– 0 c:\windows\ASSEMBLYe\pubpol1.dat
2010-10-07 17:12:41 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\index63.dat
2010-10-08 16:40:31 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\indexe6.dat
2010-10-08 16:41:17 —-HR– 0 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32e\indexe7.dat
2010-09-21 11:05:44 A–S—- 64 c:\windows\CSCe\00000001
2010-09-20 10:22:46 A–S—- 64 c:\windows\CSCe\00000002
2010-04-15 12:15:25 A–S—- 64 c:\windows\CSCe\csc1.tmp
2004-08-11 19:13:34 A—H— 65 c:\windows\Downloaded Program Filese\DESKTOP.INI
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIX.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIXE.FON
2004-08-04 07:00:00 A—H— 11,520 c:\windows\Fontse\8514FIXG.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\8514FIXR.FON
2004-08-04 07:00:00 A—H— 11,488 c:\windows\Fontse\8514FIXT.FON
2004-08-04 07:00:00 A—H— 12,288 c:\windows\Fontse\8514OEM.FON
2004-08-04 07:00:00 A—H— 13,248 c:\windows\Fontse\8514OEME.FON
2004-08-04 07:00:00 A—H— 12,800 c:\windows\Fontse\8514OEMG.FON
2004-08-04 07:00:00 A—H— 13,200 c:\windows\Fontse\8514OEMR.FON
2004-08-04 07:00:00 A—H— 12,720 c:\windows\Fontse\8514OEMT.FON
2004-08-04 07:00:00 A—H— 9,280 c:\windows\Fontse\8514SYS.FON
2004-08-04 07:00:00 A—H— 9,504 c:\windows\Fontse\8514SYSE.FON
2004-08-04 07:00:00 A—H— 9,856 c:\windows\Fontse\8514SYSG.FON
2004-08-04 07:00:00 A—H— 10,064 c:\windows\Fontse\8514SYSR.FON
2004-08-04 07:00:00 A—H— 9,792 c:\windows\Fontse\8514SYST.FON
2004-08-04 07:00:00 A—H— 12,304 c:\windows\Fontse\85775.FON
2004-08-04 07:00:00 A—H— 12,256 c:\windows\Fontse\85855.FON
2004-08-04 07:00:00 A—H— 10,976 c:\windows\Fontse\85F1257.FON
2004-08-04 07:00:00 A—H— 9,472 c:\windows\Fontse\85S1257.FON
2004-08-04 07:00:00 A—H— 35,808 c:\windows\Fontse\APP775.FON
2004-08-04 07:00:00 A—H— 36,672 c:\windows\Fontse\APP850.FON
2004-08-04 07:00:00 A—H— 36,656 c:\windows\Fontse\APP852.FON
2004-08-04 07:00:00 A—H— 37,296 c:\windows\Fontse\APP855.FON
2004-08-04 07:00:00 A—H— 36,672 c:\windows\Fontse\APP857.FON
2004-08-04 07:00:00 A—H— 37,472 c:\windows\Fontse\APP866.FON
2004-08-04 07:00:00 A—H— 7,216 c:\windows\Fontse\CGA40737.FON
2004-08-04 07:00:00 A—H— 6,352 c:\windows\Fontse\CGA40850.FON
2004-08-04 07:00:00 A—H— 6,672 c:\windows\Fontse\CGA40852.FON
2004-08-04 07:00:00 A—H— 6,672 c:\windows\Fontse\CGA40857.FON
2004-08-04 07:00:00 A—H— 7,232 c:\windows\Fontse\CGA40866.FON
2004-08-04 07:00:00 A—H— 7,216 c:\windows\Fontse\CGA40869.FON
2004-08-04 07:00:00 A—H— 6,336 c:\windows\Fontse\CGA40WOA.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80737.FON
2004-08-04 07:00:00 A—H— 4,320 c:\windows\Fontse\CGA80850.FON
2004-08-04 07:00:00 A—H— 5,200 c:\windows\Fontse\CGA80852.FON
2004-08-04 07:00:00 A—H— 4,640 c:\windows\Fontse\CGA80857.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80866.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\CGA80869.FON
2004-08-04 07:00:00 A—H— 4,304 c:\windows\Fontse\CGA80WOA.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COUE1257.FON
2004-08-04 07:00:00 A—H— 31,760 c:\windows\Fontse\COUF1257.FON
2004-08-04 07:00:00 A—H— 23,408 c:\windows\Fontse\COURE.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COUREE.FON
2004-08-04 07:00:00 A—H— 25,024 c:\windows\Fontse\COUREG.FON
2004-08-04 07:00:00 A—H— 23,440 c:\windows\Fontse\COURER.FON
2004-08-04 07:00:00 A—H— 25,024 c:\windows\Fontse\COURET.FON
2004-08-04 07:00:00 A—H— 31,712 c:\windows\Fontse\COURF.FON
2004-08-04 07:00:00 A—H— 31,776 c:\windows\Fontse\COURFE.FON
2004-08-04 07:00:00 A—H— 33,344 c:\windows\Fontse\COURFG.FON
2004-08-04 07:00:00 A—H— 31,808 c:\windows\Fontse\COURFR.FON
2004-08-04 07:00:00 A—H— 33,360 c:\windows\Fontse\COURFT.FON
2004-08-11 19:14:22 A–SH— 67 c:\windows\Fontse\DESKTOP.INI
2004-08-04 07:00:00 A—H— 36,336 c:\windows\Fontse\DOS737.FON
2004-08-04 07:00:00 A—H— 36,656 c:\windows\Fontse\DOSAPP.FON
2004-08-04 07:00:00 A—H— 9,248 c:\windows\Fontse\EGA40737.FON
2004-08-04 07:00:00 A—H— 8,384 c:\windows\Fontse\EGA40850.FON
2004-08-04 07:00:00 A—H— 8,368 c:\windows\Fontse\EGA40852.FON
2004-08-04 07:00:00 A—H— 8,704 c:\windows\Fontse\EGA40857.FON
2004-08-04 07:00:00 A—H— 9,232 c:\windows\Fontse\EGA40866.FON
2004-08-04 07:00:00 A—H— 9,248 c:\windows\Fontse\EGA40869.FON
2004-08-04 07:00:00 A—H— 8,368 c:\windows\Fontse\EGA40WOA.FON
2004-08-04 07:00:00 A—H— 6,192 c:\windows\Fontse\EGA80737.FON
2004-08-04 07:00:00 A—H— 5,328 c:\windows\Fontse\EGA80850.FON
2004-08-04 07:00:00 A—H— 5,344 c:\windows\Fontse\EGA80852.FON
2004-08-04 07:00:00 A—H— 5,648 c:\windows\Fontse\EGA80857.FON
2004-08-04 07:00:00 A—H— 5,280 c:\windows\Fontse\EGA80866.FON
2004-08-04 07:00:00 A—H— 6,192 c:\windows\Fontse\EGA80869.FON
2004-08-04 07:00:00 A—H— 5,312 c:\windows\Fontse\EGA80WOA.FON
2004-08-04 07:00:00 A—H— 24,124 c:\windows\Fontse\MARLETT.TTF
2004-08-04 07:00:00 A—H— 59,024 c:\windows\Fontse\SERE1257.FON
2004-08-04 07:00:00 A—H— 84,080 c:\windows\Fontse\SERF1257.FON
2004-08-04 07:00:00 A—H— 57,936 c:\windows\Fontse\SERIFE.FON
2004-08-04 07:00:00 A—H— 59,952 c:\windows\Fontse\SERIFEE.FON
2004-08-04 07:00:00 A—H— 60,752 c:\windows\Fontse\SERIFEG.FON
2004-08-04 07:00:00 A—H— 63,296 c:\windows\Fontse\SERIFER.FON
2004-08-04 07:00:00 A—H— 61,024 c:\windows\Fontse\SERIFET.FON
2004-08-04 07:00:00 A—H— 81,728 c:\windows\Fontse\SERIFF.FON
2004-08-04 07:00:00 A—H— 85,360 c:\windows\Fontse\SERIFFE.FON
2004-08-04 07:00:00 A—H— 86,256 c:\windows\Fontse\SERIFFG.FON
2004-08-04 07:00:00 A—H— 90,736 c:\windows\Fontse\SERIFFR.FON
2004-08-04 07:00:00 A—H— 84,848 c:\windows\Fontse\SERIFFT.FON
2004-08-04 07:00:00 A—H— 24,672 c:\windows\Fontse\SMAE1257.FON
2004-08-04 07:00:00 A—H— 19,904 c:\windows\Fontse\SMAF1257.FON
2004-08-04 07:00:00 A—H— 26,112 c:\windows\Fontse\SMALLE.FON
2004-08-04 07:00:00 A—H— 24,784 c:\windows\Fontse\SMALLEE.FON
2004-08-04 07:00:00 A—H— 28,912 c:\windows\Fontse\SMALLEG.FON
2004-08-04 07:00:00 A—H— 24,832 c:\windows\Fontse\SMALLER.FON
2004-08-04 07:00:00 A—H— 29,200 c:\windows\Fontse\SMALLET.FON
2004-08-04 07:00:00 A—H— 21,504 c:\windows\Fontse\SMALLF.FON
2004-08-04 07:00:00 A—H— 19,600 c:\windows\Fontse\SMALLFE.FON
2004-08-04 07:00:00 A—H— 23,120 c:\windows\Fontse\SMALLFG.FON
2004-08-04 07:00:00 A—H— 19,760 c:\windows\Fontse\SMALLFR.FON
2004-08-04 07:00:00 A—H— 23,008 c:\windows\Fontse\SMALLFT.FON
2004-08-04 07:00:00 A—H— 65,456 c:\windows\Fontse\SSEE1257.FON
2004-08-04 07:00:00 A—H— 90,336 c:\windows\Fontse\SSEF1257.FON
2004-08-04 07:00:00 A—H— 64,656 c:\windows\Fontse\SSERIFE.FON
2004-08-04 07:00:00 A—H— 66,464 c:\windows\Fontse\SSERIFEE.FON
2004-08-04 07:00:00 A—H— 65,328 c:\windows\Fontse\SSERIFEG.FON
2004-08-04 07:00:00 A—H— 68,848 c:\windows\Fontse\SSERIFER.FON
2004-08-04 07:00:00 A—H— 64,400 c:\windows\Fontse\SSERIFET.FON
2004-08-04 07:00:00 A—H— 89,856 c:\windows\Fontse\SSERIFF.FON
2004-08-04 07:00:00 A—H— 92,032 c:\windows\Fontse\SSERIFFE.FON
2004-08-04 07:00:00 A—H— 90,288 c:\windows\Fontse\SSERIFFG.FON
2004-08-04 07:00:00 A—H— 98,256 c:\windows\Fontse\SSERIFFR.FON
2004-08-04 07:00:00 A—H— 89,456 c:\windows\Fontse\SSERIFFT.FON
2004-08-04 07:00:00 A—H— 56,336 c:\windows\Fontse\SYMBOLE.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGA737.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGA775.FON
2004-08-04 07:00:00 A—H— 5,232 c:\windows\Fontse\VGA850.FON
2004-08-04 07:00:00 A—H— 6,160 c:\windows\Fontse\VGA852.FON
2004-08-04 07:00:00 A—H— 5,120 c:\windows\Fontse\VGA855.FON
2004-08-04 07:00:00 A—H— 5,552 c:\windows\Fontse\VGA857.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA860.FON
2004-08-04 07:00:00 A—H— 5,200 c:\windows\Fontse\VGA863.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA865.FON
2004-08-04 07:00:00 A—H— 6,128 c:\windows\Fontse\VGA866.FON
2004-08-04 07:00:00 A—H— 5,184 c:\windows\Fontse\VGA869.FON
2004-08-04 07:00:00 A—H— 5,376 c:\windows\Fontse\VGAF1257.FON
2004-08-04 07:00:00 A—H— 5,360 c:\windows\Fontse\VGAFIX.FON
2004-08-04 07:00:00 A—H— 5,376 c:\windows\Fontse\VGAFIXE.FON
2004-08-04 07:00:00 A—H— 6,112 c:\windows\Fontse\VGAFIXG.FON
2004-08-04 07:00:00 A—H— 5,600 c:\windows\Fontse\VGAFIXR.FON
2004-08-04 07:00:00 A—H— 6,112 c:\windows\Fontse\VGAFIXT.FON
2004-08-04 07:00:00 A—H— 5,168 c:\windows\Fontse\VGAOEM.FON
2004-08-04 07:00:00 A—H— 6,656 c:\windows\Fontse\VGAS1257.FON
2004-08-04 07:00:00 A—H— 7,280 c:\windows\Fontse\VGASYS.FON
2004-08-04 07:00:00 A—H— 6,608 c:\windows\Fontse\VGASYSE.FON
2004-08-04 07:00:00 A—H— 7,008 c:\windows\Fontse\VGASYSG.FON
2004-08-04 07:00:00 A—H— 6,912 c:\windows\Fontse\VGASYSR.FON
2004-08-04 07:00:00 A—H— 6,912 c:\windows\Fontse\VGASYST.FON
2005-04-29 13:54:17 A—H— 10,820 c:\windows\Helpe\update.GID
2007-02-25 12:10:46 A–S—- 2,372 c:\windows\INFe\oem20.inf
2004-08-11 19:13:34 A—H— 65 c:\windows\Offline Web Pagese\DESKTOP.INI
2004-08-04 07:00:00 A–SHR– 2,737,914 c:\windows\PCHEALTH\HELPCTR\PackageStoree\instance_Professional_32_1033.cab
2004-08-11 19:14:00 A–SHR– 727 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_1.cab
2005-01-05 14:57:43 —SHR– 21,378 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_10.cab
2005-01-05 14:57:48 —SHR– 71,564 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_11.cab
2005-01-05 14:57:55 —SHR– 657,089 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_12.cab
2005-01-05 14:58:16 —SHR– 364,090 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_13.cab
2009-08-10 08:22:44 —SHR– 309,519 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_14.cab
2009-08-10 08:24:16 —SHR– 68,704 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_15.cab
2004-08-11 19:14:00 A–SHR– 19,854 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_2.cab
2004-08-11 19:14:00 A–SHR– 244,933 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_3.cab
2004-08-04 07:00:00 A–SHR– 7,068 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_4.cab
2004-08-04 07:00:00 A–SHR– 68,327 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_5.cab
2004-08-04 07:00:00 A–SHR– 305,145 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_6.cab
2004-08-11 19:24:40 A–SHR– 68,704 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_7.cab
2005-01-05 14:56:28 —SHR– 7,166 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_8.cab
2005-01-05 14:56:43 —SHR– 7,351 c:\windows\PCHEALTH\HELPCTR\PackageStoree\package_9.cab
2004-08-11 19:15:08 A—H— 229,376 c:\windows\REPAIRe\NTUSER.DAT
2005-04-04 18:38:50 —-H— 0 c:\windows\SYSTEMe\TSCNTDWN.80
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\cdplayer.exe.manifest
2004-08-11 19:13:34 A—HR– 488 c:\windows\SYSTEM32e\logonui.exe.manifest
1999-09-09 22:06:38 A–S—- 252,688 c:\windows\SYSTEM32e\msexcl35.dll
1999-09-28 21:42:48 A–S—- 1,050,896 c:\windows\SYSTEM32e\msjet35.dll
1999-06-10 09:34:04 A–S—- 123,664 c:\windows\SYSTEM32e\msjint35.dll
1999-06-10 09:34:04 A–S—- 24,848 c:\windows\SYSTEM32e\msjter35.dll
1999-09-09 22:06:38 A–S—- 168,720 c:\windows\SYSTEM32e\msltus35.dll
1999-06-07 18:59:34 A–S—- 250,128 c:\windows\SYSTEM32e\mspdox35.dll
1999-04-25 17:00:00 A–S—- 252,176 c:\windows\SYSTEM32e\Msrd2x35.dll
1999-08-25 14:57:26 A–S—- 415,504 c:\windows\SYSTEM32e\msrepl35.dll
1999-09-30 19:21:24 A–S—- 166,672 c:\windows\SYSTEM32e\mstext35.dll
1999-04-25 17:00:00 A–S—- 287,504 c:\windows\SYSTEM32e\Msxbse35.dll
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\ncpa.cpl.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\nwc.cpl.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\sapi.cpl.manifest
1999-04-25 17:00:00 A–S—- 368,912 c:\windows\SYSTEM32e\Vbar332.dll
2004-08-11 19:13:34 A—HR– 488 c:\windows\SYSTEM32e\WindowsLogon.manifest
2004-08-11 19:13:26 A—HR– 749 c:\windows\SYSTEM32e\wuaucpl.cpl.manifest
2007-01-15 16:36:25 A—H— 4,212 c:\windows\SYSTEM32e\zllictbl_cpy.dat
2005-01-28 14:44:28 —S—- 8,520 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\codecs10.CAT
2005-01-28 14:44:28 —S—- 8,818 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\DRM10.CAT
2008-04-13 22:04:37 —S—- 34,063 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\fp4.cat
2004-08-04 07:00:00 —S—- 13,472 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\HPCRDP.CAT
2004-08-04 07:00:00 —S—- 8,574 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\IASNT4.CAT
2006-06-29 09:11:06 —S—- 10,181 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\IDNMitigationAPIs.cat
2006-11-07 22:04:24 —S—- 42,340 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ie7.cat
2008-04-13 22:04:34 —S—- 16,535 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ims.cat
2010-07-15 03:28:23 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2079403.cat
2010-06-15 12:43:45 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2115168.cat
2010-06-18 13:56:32 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2121546.cat
2010-08-04 05:40:48 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2141007.cat
2010-06-22 21:03:17 —S—- 7,170 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2158563.cat
2010-06-28 06:41:05 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2160329.cat
2010-06-24 08:46:40 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2183461-IE7.cat
2010-06-15 12:37:34 —S—- 9,146 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2229593.cat
2010-06-28 06:55:54 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2259922.cat
2010-09-01 12:21:44 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2279986.cat
2010-07-27 02:46:39 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2286198.cat
2010-08-23 12:36:18 —S—- 8,150 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2296011.cat
2010-10-28 09:20:08 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2296199.cat
2010-09-07 07:12:29 —S—- 8,864 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2345886.cat
2010-08-17 10:30:39 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2347290.cat
2010-09-09 10:09:06 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2360131-IE7.cat
2010-08-16 05:01:08 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2360937.cat
2010-09-06 16:20:42 —S—- 7,470 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2378111.cat
2010-09-18 03:26:24 —S—- 9,965 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2387149.cat
2010-12-09 11:29:31 —S—- 11,198 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2393802.cat
2010-11-05 20:57:46 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2416400-IE7.cat
2010-11-09 11:09:15 —S—- 14,920 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2419632.cat
2010-10-20 09:08:05 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2423089.cat
2010-10-26 10:24:13 —S—- 8,158 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2436673.cat
2010-11-03 14:50:34 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2440591.cat
2010-11-19 01:32:06 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2443105.cat
2010-11-05 10:13:09 —S—- 7,170 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2443685.cat
2010-11-20 08:08:00 —S—- 7,154 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2467659.cat
2010-12-09 10:37:58 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2476687.cat
2010-12-20 13:30:43 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2478960.cat
2010-12-22 08:47:57 —S—- 7,860 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2478971.cat
2010-12-20 19:27:25 —S—- 31,754 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB2482017-IE7.cat
2005-05-04 14:45:46 —S—- 29,493 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB893803v2_wxp.cat
2005-03-21 15:00:24 —S—- 29,491 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB893803_wxp.cat
2005-05-24 11:00:54 —S—- 8,817 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB898458.cat
2006-01-03 14:17:06 —S—- 8,792 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB911564.cat
2006-03-13 16:45:34 —S—- 7,898 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB911565.cat
2006-05-04 18:37:36 —S—- 7,898 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB917734.cat
2009-03-27 03:59:12 —S—- 13,937 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923561.cat
2006-12-07 21:30:20 —S—- 9,057 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923689.cat
2006-08-29 17:29:20 —S—- 8,824 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB923723.cat
2006-09-13 18:32:26 —S—- 9,090 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB925398.cat
2007-01-17 15:40:04 —S—- 18,377 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB928090-IE7.cat
2006-12-22 12:53:02 —S—- 7,894 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB929969.cat
2007-04-20 14:41:50 —S—- 30,145 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB931768-IE7.cat
2007-05-08 13:21:34 —S—- 29,530 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB933566-IE7.cat
2007-05-01 02:27:14 —S—- 10,335 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB936782.cat
2007-07-19 04:20:15 —S—- 29,530 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB937143-IE7.cat
2007-07-12 19:44:36 —S—- 11,284 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938127-IE7.cat
2008-12-19 07:56:47 —S—- 10,074 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938464-v2.cat
2008-04-15 14:51:51 —S—- 12,305 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB938464.cat
2007-08-21 01:41:29 —S—- 30,942 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB939653-IE7.cat
2007-10-27 18:16:40 —S—- 12,090 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB941569.cat
2007-10-30 23:30:41 —S—- 30,942 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB942615-IE7.cat
2008-01-11 08:11:14 —S—- 32,354 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB944533-IE7.cat
2008-05-02 11:01:37 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB946648.cat
2008-03-01 09:54:54 —S—- 32,354 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB947864-IE7.cat
2008-05-20 08:57:26 —S—- 32,215 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950759-IE7.cat
2008-04-24 04:12:17 —S—- 10,439 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950760.cat
2008-05-08 17:25:36 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950762.cat
2008-07-07 16:59:03 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB950974.cat
2008-04-11 15:18:52 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951066.cat
2008-07-15 05:34:26 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951072-v2.cat
2008-06-16 16:12:03 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951376-v2.cat
2008-04-14 12:54:14 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951376.cat
2008-05-07 01:38:53 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951698.cat
2008-06-21 06:36:26 —S—- 18,785 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951748.cat
2008-06-19 05:25:51 —S—- 15,271 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB951978.cat
2008-06-12 11:35:43 —S—- 19,491 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952004.cat
2008-11-10 23:51:22 —S—- 13,031 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952069.cat
2008-05-01 11:30:31 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952287.cat
2008-06-24 13:04:07 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB952954.cat
2008-06-26 14:16:04 —S—- 32,215 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB953838-IE7.cat
2008-06-23 15:26:19 —S—- 10,439 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB953839.cat
2009-05-27 09:51:12 —S—- 8,327 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954155.cat
2008-09-15 12:17:16 —S—- 12,729 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954211.cat
2008-09-09 21:31:57 —S—- 11,145 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954459.cat
2008-07-06 08:06:56 —S—- 16,633 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954550-v5.cat
2008-10-03 06:46:35 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB954600.cat
2008-09-09 23:12:10 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955069.cat
2009-11-21 13:03:06 —S—- 11,111 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955759.cat
2008-10-23 15:58:30 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB955839.cat
2008-10-03 14:49:47 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956390-IE7.cat
2008-10-03 11:27:13 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956391.cat
2009-03-06 14:33:08 —S—- 29,707 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956572.cat
2009-06-19 01:31:17 —S—- 13,466 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956744.cat
2008-10-23 09:26:07 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956802.cat
2008-08-14 11:33:08 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956803.cat
2008-08-14 11:33:34 —S—- 17,099 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956841.cat
2009-06-23 17:40:35 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB956844.cat
2008-09-08 10:49:46 —S—- 12,431 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB957095.cat
2008-10-24 11:06:44 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB957097.cat
2008-10-16 17:28:28 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958215-IE7.cat
2008-10-15 13:47:09 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958644.cat
2008-12-11 13:01:19 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958687.cat
2009-02-09 11:10:55 —S—- 10,511 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958690.cat
2009-08-13 10:09:27 —S—- 8,021 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB958869.cat
2009-03-21 13:26:47 —S—- 11,612 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB959426.cat
2008-12-05 08:36:13 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960225.cat
2008-12-13 03:21:48 —S—- 8,914 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960714-IE7.cat
2009-01-15 15:26:27 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960715.cat
2008-12-16 09:52:12 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960803.cat
2009-07-01 05:32:15 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB960859.cat
2009-01-09 15:19:04 —S—- 8,208 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961118.cat
2009-01-20 08:31:32 —S—- 29,984 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961260-IE7.cat
2009-06-16 11:11:02 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961371.cat
2008-12-20 20:08:55 —S—- 10,200 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961373.cat
2009-05-07 11:58:55 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB961501.cat
2009-03-02 21:26:55 —S—- 31,396 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB963027-IE7.cat
2009-02-10 16:48:41 —S—- 10,566 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB967715.cat
2009-07-02 09:37:45 —S—- 18,195 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968389.cat
2009-04-19 16:40:09 —S—- 10,713 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968537.cat
2009-06-15 14:34:24 —S—- 8,327 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB968816.cat
2009-07-17 12:52:43 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969059.cat
2009-04-29 02:30:35 —S—- 31,624 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969897-IE7.cat
2009-05-08 17:40:43 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969898.cat
2009-08-14 13:32:02 —S—- 9,681 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB969947.cat
2009-04-15 11:54:59 —S—- 10,511 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970238.cat
2009-10-21 02:20:16 —S—- 12,194 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970430.cat
2009-07-16 00:28:18 —S—- 7,394 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB970653-v3.cat
2009-07-27 20:02:24 —S—- 11,148 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971029.cat
2010-01-04 14:00:28 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971468.cat
2009-08-04 14:04:27 —S—- 14,051 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971486.cat
2009-06-10 11:05:54 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971557.cat
2009-06-03 15:43:52 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971633.cat
2009-06-10 02:48:03 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971657.cat
2009-08-25 05:59:29 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971737.cat
2009-08-14 01:29:45 —S—- 8,097 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB971961.cat
2009-07-19 10:48:40 —S—- 31,272 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB972260-IE7.cat
2009-10-15 13:58:37 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB972270.cat
2009-07-07 01:47:40 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973346.cat
2009-07-10 11:02:30 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973354.cat
2009-07-17 17:21:45 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973507.cat
2009-09-09 20:50:45 —S—- 7,378 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973525.cat
2009-07-14 16:33:04 —S—- 8,625 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973540.cat
2009-07-31 01:16:24 —S—- 10,076 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973687.cat
2009-08-05 05:31:23 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973815.cat
2009-07-27 19:53:52 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973869.cat
2009-11-21 06:25:06 —S—- 10,999 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB973904.cat
2009-08-26 04:28:20 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974112.cat
2009-10-12 10:08:11 —S—- 10,782 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974318.cat
2009-10-13 07:23:13 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974392.cat
2009-08-29 04:23:40 —S—- 31,285 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974455-IE7.cat
2009-09-04 17:35:38 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB974571.cat
2009-09-01 10:55:13 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975025.cat
2009-09-11 11:03:45 —S—- 9,723 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975467.cat
2010-04-05 18:56:52 —S—- 8,303 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975558.cat
2009-11-27 13:51:20 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975560.cat
2009-10-23 19:54:20 —S—- 9,370 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975561.cat
2010-04-07 12:36:59 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975562.cat
2009-12-08 05:38:37 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB975713.cat
2009-10-28 22:21:12 —S—- 7,407 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976098-v2.cat
2009-10-29 04:35:29 —S—- 31,272 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976325-IE7.cat
2009-10-21 01:42:47 —S—- 8,084 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB976749-IE7.cat
2009-12-09 07:05:16 —S—- 14,051 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977165.cat
2010-01-29 10:58:34 —S—- 8,803 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977816.cat
2009-11-27 13:13:06 —S—- 15,031 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB977914.cat
2009-12-14 03:47:45 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978037.cat
2010-01-05 07:08:01 —S—- 31,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978207-IE7.cat
2009-12-07 01:43:53 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978251.cat
2010-01-08 10:26:08 —S—- 7,391 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978262.cat
2010-02-12 00:57:39 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978338.cat
2010-01-29 11:41:45 —S—- 10,795 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978542.cat
2009-12-24 03:18:58 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978601.cat
2010-04-14 10:38:16 —S—- 8,299 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978695.cat
2009-12-17 04:22:05 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB978706.cat
2010-01-23 06:51:24 —S—- 7,407 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979306.cat
2010-01-13 10:22:54 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979309.cat
2010-03-05 11:26:23 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979482.cat
2010-05-02 04:42:05 —S—- 9,442 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979559.cat
2010-03-05 12:30:54 —S—- 14,349 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979683.cat
2010-07-16 08:36:39 —S—- 8,862 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB979687.cat
2010-03-11 09:36:42 —S—- 31,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980182-IE7.cat
2010-05-05 01:25:18 —S—- 7,152 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980195.cat
2010-04-20 02:01:28 —S—- 9,144 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980218.cat
2010-02-25 08:51:56 —S—- 9,383 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980232.cat
2010-06-30 08:42:32 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB980436.cat
2010-07-15 09:10:50 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981322.cat
2010-03-09 07:49:33 —S—- 8,097 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981349.cat
2010-04-22 18:33:04 —S—- 7,168 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981793.cat
2010-06-18 02:43:52 —S—- 10,490 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981852.cat
2010-09-01 12:21:54 —S—- 8,156 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981957.cat
2010-06-21 11:04:43 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB981997.cat
2010-08-27 04:30:36 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982132.cat
2010-06-21 13:36:18 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982214.cat
2010-05-04 14:45:23 —S—- 31,752 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982381-IE7.cat
2010-06-17 10:12:41 —S—- 7,858 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982665.cat
2010-07-23 02:18:53 —S—- 8,156 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\KB982802.cat
2004-08-04 07:00:00 —S—- 399,645 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MAPIMIG.CAT
2008-04-13 22:04:36 —S—- 34,747 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\mediactr.cat
2005-01-28 14:44:28 —S—- 7,626 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPCD10.CAT
2005-01-28 14:44:28 —S—- 7,030 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPPRE10.CAT
2005-01-28 14:44:28 —S—- 7,626 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MPSTUB10.CAT
2008-04-13 22:04:35 —S—- 12,363 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msmsgs.cat
2008-04-13 22:04:35 —S—- 26,991 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msn7.cat
2008-04-13 22:04:36 —S—- 14,433 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msn9.cat
2008-04-13 22:04:36 —S—- 10,027 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\mstsweb.cat
2008-07-06 08:06:57 —S—- 10,929 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\msxpsdrv.CAT
2004-08-04 07:00:00 —S—- 37,484 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\MW770.CAT
2008-04-13 22:04:39 —S—- 144,484 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\netfx.cat
2006-06-28 19:00:54 —S—- 8,420 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\NLSDownlevelMapping.cat
2008-04-13 22:04:45 —S—- 2,144,487 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\nt5.cat
2004-08-04 07:00:00 —S—- 797,189 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\NT5IIS.CAT
2008-04-13 22:04:43 —S—- 522,220 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\nt5inf.cat
2009-01-09 15:19:28 —S—- 1,089,593 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\ntprint.cat
2004-09-09 11:09:42 —S—- 16,890 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem0.CAT
2004-04-06 12:25:08 —S—- 20,362 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem1.CAT
2003-01-10 18:13:04 —S—- 7,592 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem10.CAT
2002-04-02 20:57:06 —S—- 15,263 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem14.CAT
2008-08-18 06:35:14 —S—- 19,280 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem16.CAT
2004-06-29 15:43:56 —S—- 10,316 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem2.CAT
2007-03-07 11:02:32 —S—- 11,085 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem20.CAT
2007-04-16 22:58:18 —S—- 41,586 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem21.CAT
2007-04-16 22:56:46 —S—- 17,648 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem22.CAT
2007-07-30 19:36:28 —S—- 48,256 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem23.CAT
2007-07-30 19:35:04 —S—- 17,648 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem24.CAT
2008-07-18 22:26:06 —S—- 48,117 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem25.CAT
2008-07-18 22:24:52 —S—- 17,509 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem26.CAT
2008-10-16 15:24:30 —S—- 45,886 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem27.CAT
2008-10-16 15:22:38 —S—- 15,278 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem28.CAT
2009-08-06 19:37:06 —S—- 45,056 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem29.CAT
2004-04-27 23:15:10 —S—- 14,533 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem3.CAT
2009-08-06 19:36:40 —S—- 14,448 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem30.CAT
2009-08-06 20:36:54 —S—- 45,069 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem31.CAT
2004-05-25 11:43:50 —S—- 8,227 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem4.CAT
2004-05-25 11:43:50 —S—- 9,257 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem5.CAT
2004-05-25 11:43:50 —S—- 9,265 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem6.CAT
2004-05-25 11:43:50 —S—- 9,265 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem7.CAT
2002-03-13 10:50:36 —S—- 7,172 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\oem9.CAT
2004-08-11 12:31:24 —S—- 7,710 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\OEMBIOS.CAT
2004-08-04 07:00:00 —S—- 1,042,903 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\SP2.CAT
2008-04-14 07:40:48 —S—- 1,296,669 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\sp3.cat
2008-04-13 22:04:37 —S—- 36,549 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\spdelta.cat
2008-04-13 22:10:46 —S—- 112,918 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\tabletpc.cat
2009-03-10 22:18:28 —S—- 7,236 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WgaNotify.cat
2005-01-28 14:44:28 —S—- 9,116 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMDM10.CAT
2004-08-04 07:00:00 —S—- 7,334 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\wmerrenu.cat
2005-01-28 14:44:28 —S—- 11,202 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMFSDK10.CAT
2005-01-28 14:44:28 —S—- 14,432 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMP10.CAT
2005-01-28 14:44:28 —S—- 7,328 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WMSET10.CAT
2005-01-28 14:44:28 —S—- 10,598 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\WPD10.CAT
2009-03-10 22:18:28 —S—- 7,236 c:\windows\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}e\_000000_.cat
2010-04-18 09:04:39 A—H— 0 c:\windows\SYSTEM32\CONFIGe\DEFAULT.tmp.LOG
2010-04-18 09:04:39 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SAM.tmp.LOG
2010-04-18 11:03:42 A—H— 8,192 c:\windows\SYSTEM32\CONFIGe\SECURITY.tmp.LOG
2010-04-18 09:04:38 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SOFTWARE.tmp.LOG
2010-04-18 09:04:38 A—H— 0 c:\windows\SYSTEM32\CONFIGe\SYSTEM.tmp.LOG
2004-08-11 19:06:14 A—H— 1,024 c:\windows\SYSTEM32\CONFIGe\TempKey.LOG
2004-08-11 19:06:14 A—H— 1,024 c:\windows\SYSTEM32\CONFIGe\USERDIFF.LOG
2010-04-18 08:59:17 A—H— 1,024 c:\windows\SYSTEM32\CONFIG\systemprofilee\NTUSER.DAT.LOG
2004-08-11 19:07:12 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Datae\DESKTOP.INI
2010-09-22 10:01:51 A–S—- 30,704 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\0797C381B2F87EB5A1D5573BD15BA4F4
2010-06-09 16:21:23 A–S—- 2,202 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\0897206B35294097C3660E62BCDB227C
2010-09-20 09:44:21 A–S—- 2,594 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\23B523C9E7746F715D33C6527C18EB9D
2010-04-22 16:34:04 A–S—- 341 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\303572DF538EDD8B1D606185F1D559B8
2010-06-09 16:21:23 A–S—- 1,294 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\3C19F8F5C2A69BEC912EF5B953293907
2010-04-12 08:50:30 A–S—- 242,756 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\4DB1DABDF57ED9997FE8DCC77E93C04F
2010-06-09 16:20:54 A–S—- 781 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\696F3DE637E6DE85B458996D49D759AD
2010-04-22 16:34:04 A–S—- 413 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\79841F8EF00FBA86D33CC5A47696F165
2006-01-30 09:18:41 A–S—- 1,047 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\7C8A03C4580C6B04FDF34357F3474EDC
2010-06-09 16:20:54 A–S—- 597 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\A1377F7115F1F126A15360369B165211
2010-10-07 16:48:15 A–S—- 558 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\A44F4E7CB3133FF765C39A53AD8FCFDD
2006-01-30 09:18:41 A–S—- 1,370 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\B82262A5D5DA4DDACE9EDA7F787D0DEB
2007-04-06 08:04:04 A–S—- 1,039 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\CFC456E7E410D69E2C6F3E2DB75C7DB3
2010-09-20 09:44:21 A–S—- 1,310 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\D0F063B6B88A2B8BFE21C3993A613447
2009-08-10 08:22:45 A–S—- 574 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\E04822AD18D472EA5B582E6E6F8C6B9A
2010-04-13 09:03:29 A–S—- 2,148 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Contente\F03FBEED31BB9347A2DDFF031058505F
2010-09-22 10:01:51 A–S—- 132 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\0797C381B2F87EB5A1D5573BD15BA4F4
2010-06-09 16:21:23 A–S—- 194 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\0897206B35294097C3660E62BCDB227C
2010-09-20 09:44:21 A–S—- 112 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\23B523C9E7746F715D33C6527C18EB9D
2010-04-22 16:34:04 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\303572DF538EDD8B1D606185F1D559B8
2010-06-09 16:21:23 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\3C19F8F5C2A69BEC912EF5B953293907
2010-04-12 08:50:30 A–S—- 98 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\4DB1DABDF57ED9997FE8DCC77E93C04F
2010-06-09 16:20:54 A–S—- 156 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\696F3DE637E6DE85B458996D49D759AD
2010-04-22 16:34:04 A–S—- 98 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\79841F8EF00FBA86D33CC5A47696F165
2006-01-30 09:18:41 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\7C8A03C4580C6B04FDF34357F3474EDC
2010-06-09 16:20:54 A–S—- 142 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\A1377F7115F1F126A15360369B165211
2010-10-07 16:48:15 A–S—- 146 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\A44F4E7CB3133FF765C39A53AD8FCFDD
2006-01-30 09:18:41 A–S—- 194 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\B82262A5D5DA4DDACE9EDA7F787D0DEB
2007-04-06 08:04:04 A–S—- 126 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\CFC456E7E410D69E2C6F3E2DB75C7DB3
2010-09-20 09:44:21 A–S—- 178 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\D0F063B6B88A2B8BFE21C3993A613447
2009-08-10 08:22:45 A–S—- 140 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\E04822AD18D472EA5B582E6E6F8C6B9A
2010-04-13 09:03:29 A–S—- 132 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaDatae\F03FBEED31BB9347A2DDFF031058505F
2004-08-11 19:20:34 A–SH— 2,570 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Internet Explorere\Desktop.htt
2004-08-11 19:20:44 A–SH— 119 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launche\DESKTOP.INI
2005-01-05 15:04:36 A–SH— 24 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protecte\CREDHIST
2005-01-05 15:04:36 A–SH— 388 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protect\S-1-5-21-4073680847-1405297832-2471763517-500e\202d2b84-66f5-4e75-b822-5327038c8418
2005-01-05 15:04:36 A–SH— 24 c:\windows\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Protect\S-1-5-21-4073680847-1405297832-2471763517-500e\Preferred
2004-08-11 19:20:42 A–SH— 122 c:\windows\SYSTEM32\CONFIG\systemprofile\Favoritese\Desktop.ini
2005-01-05 15:12:38 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settingse\DESKTOP.INI
2005-01-05 15:13:11 A—H— 3,780,440 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Datae\IconCache.db
2005-01-05 15:13:16 A—H— 262,144 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Windowse\UsrClass.dat
2010-09-22 09:36:43 A—H— 1,024 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Windowse\UsrClass.dat.LOG
2004-08-11 19:20:42 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documentse\DESKTOP.INI
2004-08-11 19:20:42 A–SH— 189 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documents\My Musice\Desktop.ini
2004-08-11 19:20:42 A–SH— 191 c:\windows\SYSTEM32\CONFIG\systemprofile\My Documents\My Picturese\Desktop.ini
2004-08-11 19:20:42 A–SH— 150 c:\windows\SYSTEM32\CONFIG\systemprofile\Recente\Desktop.ini
2004-08-11 19:13:36 A–SH— 181 c:\windows\SYSTEM32\CONFIG\systemprofile\SendToe\DESKTOP.INI
2004-08-11 19:07:12 A–SH— 62 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menue\DESKTOP.INI
2004-08-11 19:20:44 A–SH— 234 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programse\DESKTOP.INI
2004-08-11 19:20:38 A–SH— 542 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessoriese\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 348 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessories\Accessibilitye\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Accessories\Entertainmente\DESKTOP.INI
2004-08-11 19:15:06 A–SH— 84 c:\windows\SYSTEM32\CONFIG\systemprofile\Start Menu\Programs\Startupe\DESKTOP.INI
2007-02-25 12:10:48 A–S—- 5,376 c:\windows\SYSTEM32\DRIVERSe\dsunidrv.sys
2009-05-19 07:34:35 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\10a0dd3d-1243-413a-af4c-2700575aed74
2008-02-19 09:24:30 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5155bff1-cf26-4a83-b1ef-daa19de0c2ef
2006-08-22 08:18:13 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\53e883ae-956c-45fc-b73b-296992ab389a
2007-08-21 08:10:38 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\59b8af98-e04a-447e-897d-b724c5371c7c
2010-05-18 07:46:01 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5fb6150b-1e79-417e-8342-5cb2d7a11cd8
2010-11-15 08:39:32 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\5fc84818-3d64-4864-9045-51e2e75c9cdc
2007-02-20 09:25:13 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\69ce5cd2-5a40-403e-997f-7d4180998931
2009-08-17 07:56:08 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\8a97635a-97e9-41d5-8e74-b198f1cd7ed2
2008-05-20 12:10:45 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\9b7fedbe-d66b-4251-8f01-57c2e2c042dc
2009-11-16 08:56:40 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\a934cd14-fb0d-458f-9a4e-52585782fa41
2007-05-22 09:25:24 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\aefb63ba-1f72-4d43-9483-dbfa08dc0c7e
2008-11-17 08:49:23 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\c471253b-3b65-47e0-8fb9-662ed949d73b
2008-08-19 08:09:46 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\d26d0e97-5480-4696-89eb-f9dba0d75677
2007-11-19 09:12:04 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\dfe57563-88ba-4849-b0c7-be9a1f70ad0c
2010-02-16 08:57:47 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\e64e888d-ec07-46fb-ac7a-c6dcd87e0465
2006-11-20 09:20:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\ea4dbf83-82ac-4225-9f16-823237d49fd6
2010-08-17 07:38:41 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\f8f959af-8c6a-4384-8bdb-f419ea5e7e08
2009-02-17 08:52:28 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18e\fdef9a0b-550d-46d2-aa90-e6ae46e48aa8
2010-01-11 17:35:22 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\05bc76cd-4e7a-416f-9cd0-ed992ccf2f59
2010-04-12 16:30:36 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\091b4593-52ef-4a6a-a1e1-bd8e7f1fc02a
2006-07-06 08:08:40 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\0dd0d6bb-450d-48c9-9478-14444f798fca
2007-10-01 15:22:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\17ae5c58-ce18-45c9-aa11-40538c278e7e
2008-07-01 16:43:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\1a807fd2-2448-4763-b35d-3caac0bbf067
2006-10-05 08:13:06 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\1e169ea5-1596-4f1e-a132-69594f3c0f6c
2008-04-01 16:30:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\3c2955d7-efc9-426c-bcd4-c48148b8ef9e
2009-01-05 17:30:34 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\6d9d023e-4565-40c3-a6e8-5a0b07addb7b
2008-01-02 11:53:35 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\756d5e01-92c1-42ee-9159-52616698f301
2007-07-02 17:19:08 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\7f5d469c-51d8-4044-90d1-61fcb1c4b46e
2010-07-12 16:30:10 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\801f4ec4-52c1-43bd-8c38-6c19657f9087
2006-01-04 17:28:00 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\88436881-c4dc-454b-8944-4907c75a2715
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\9802f62f-7131-40f8-9253-0d179a4f04a8
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\b32bff2c-e984-4293-8eaa-1f752d57008e
2009-07-13 08:19:29 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\bbecb165-a411-4fa9-932e-6ed681f14b68
2005-10-06 15:06:58 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\be42e465-1bac-4c0b-a072-6449800fd309
2007-01-03 10:16:54 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\c8311a89-e381-4fb9-9ecb-fc44da3c1071
2005-04-07 17:03:01 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\ca79ec33-5d19-4a09-ab26-0a07e94c915c
2007-04-03 16:43:19 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\d7323d93-3aa4-429f-a503-ddf30494fa5e
2005-07-07 16:29:50 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\d8d82f1d-0933-4e3b-bca9-449c85451557
2008-09-30 16:33:00 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\e65c2b97-0284-426c-9644-49b15ea559d7
2010-10-12 07:59:24 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\eeafe90e-5355-4ecd-8995-1ebcb3c87e60
2005-01-07 13:02:05 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\ef583787-f66e-4878-b421-79f03e060f33
2009-10-13 16:29:33 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\f06a9100-141c-427a-b13d-f40857ccdbb7
2009-04-06 16:41:22 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\fab2f95c-37aa-48e9-a7ee-b67b65a2d184
2006-04-05 16:31:04 A–SH— 388 c:\windows\SYSTEM32\Microsoft\Protect\S-1-5-18\Usere\fe34b83d-fc01-4ecd-83a4-5a2ae3bb7204
2006-12-28 15:01:31 —SHR– 19,569 c:\windows\SYSTEM32\Restoree\filelist.xml
2004-08-04 07:00:00 —-HR– 65 c:\windows\Taskse\DESKTOP.INI
2008-01-08 13:15:07 A—H— 8,628 c:\windows\TWAIN_32\BrMfSc05\Lange\BrS04Usa.GID

============= FINISH: 16:06:04.64 ===============
Hi , welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


That is a very old version of DDS you used. Please delete the copy you have and post the logs from the current version.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.An additional log called Attach.txt should appear minimized on the task bar.
  • Save both reports to your desktop before closing the DDS window.

Next

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode

Please post back with
  • Both DDS logs
  • GMER log
Thanks
Thanks very much for your help, Oldman.

DDS.txt and GMER.txt follow.
Attach.txt from DDS is zipped and attached

============================

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 13:25:24.28 on Sat 03/26/2011
internet explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2680 [GMT -4:00]
.
AV: CA Anti-Virus *Enabled/Updated* {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\WINDOWS\system32\CAPM1RSK.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Amy\Desktop\dds.scr
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\WINDOWS\system32\CAPM1RSK.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Amy\Desktop\dds.scr
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
NoUpdateCheck REG_DWORD 1 (0x1)
NoJITSetup REG_DWORD 1 (0x1)
Disable Script Debugger REG_SZ no
Show_ChannelBand REG_SZ No
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ http://my.yahoo.com/index.html
Use_DlgBox_Colors REG_SZ yes
Use Search Asst REG_SZ no
Use Custom Search URL REG_BINARY 01000000
FullScreen REG_SZ no
Window_Placement REG_BINARY 2c00000002000000030000000083ffff0083ffffffffffffffffffff1d0000001d0000003c030000
75020000
Use FormSuggest REG_SZ yes
StatusBarOther REG_DWORD 1 (0x1)
NotifyDownloadComplete REG_SZ yes
FavChevron_Complete REG_SZ 3
FavChevron_Failed REG_SZ 2
FavChevron_Error REG_SZ 4
AddToFavoritesExpanded REG_DWORD 1 (0x1)
Use_Combobox_DlgBox_Colors_Complete REG_SZ 3
Use_Combobox_DlgBox_Colors_Failed REG_SZ 4
Use_Combobox_DlgBox_Colors_Error REG_SZ 4
FormSuggest PW Ask REG_SZ no
Save Directory REG_SZ c:\Documents and Settings\Amy\My Documents\Word\Miscellaneous\Amy Misc\Patternse\
Error Dlg Displayed On Every Error REG_SZ no
XMLHTTP REG_DWORD 1 (0x1)
UseClearType REG_SZ yes
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
CompatibilityFlags REG_DWORD 0 (0x0)
SearchMigrated REG_DWORD 1 (0x1)
RunOnceHasShown REG_DWORD 1 (0x1)
RunOnceComplete REG_DWORD 1 (0x1)
AlwaysShowMenus REG_DWORD 1 (0x1)
HistoryViewType REG_BINARY 0000
Enable_MyPics_Hoverbar REG_SZ no
ShowedCheckBrowser REG_SZ Yes
Check_Associations REG_SZ yes
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Default Feeds
.
HKEY_CURRENT_USER\software\microsoft\internet explorer\main\FeatureControl
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0a000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1a000000
Placeholder_Height REG_BINARY 1a000000
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\ErrorThresholds
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\FeatureControl
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\UrlTemplate
uinternet connection wizard,shellnext = hxxp://www.dell4me.com/myway
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 7.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0 (0x0)
MigrateProxy REG_DWORD 1 (0x1)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 1 (0x1)
PrivacyAdvanced REG_DWORD 0 (0x0)
EnableNegotiate REG_DWORD 1 (0x1)
ProxyEnable REG_DWORD 0 (0x0)
GlobalUserOffline REG_DWORD 0 (0x0)
EnableAutodial REG_DWORD 0 (0x0)
PrivDiscUiShown REG_DWORD 1 (0x1)
WarnOnZoneCrossing REG_DWORD 0 (0x0)
UrlEncoding REG_DWORD 0 (0x0)
SecureProtocols REG_DWORD 160 (0xa0)
DisableCachingOfSSLPages REG_DWORD 0 (0x0)
WarnonBadCertRecving REG_DWORD 1 (0x1)
WarnOnPostRedirect REG_DWORD 0 (0x0)
WarnOnHTTPSToHTTPRedirect REG_DWORD 1 (0x1)
WarnOnIntranet REG_DWORD 0 (0x0)
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Cache
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Connections
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Lockdown_Zones
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\P3P
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Passport
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Protocols
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\TemplatePolicies
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Url History
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\ZoneMap
.
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Zones
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
Error: Key: software\microsoft\internet explorer\search does not exist!
.
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
Written by Bobbi Flekman 2006 ©URLSearchHooks: H - No File
HKEY_USERS\.default\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
{4D25F926-B9FE-4682-BF72-8AB8210D6D75}URLSearchHooks: H - No File
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
AutoRestartShell REG_DWORD 1 (0x1)
DefaultUserName REG_SZ Amy
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ c:\WINDOWS\system32e\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DefaultPassword REG_SZ
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ Amy
AltDefaultDomainName REG_SZ IRWINA
DefaultDomainName REG_SZ IRWINA
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Taskman REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExtensions
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\SpecialAccounts
.
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Credentials
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon
ParseAutoexec REG_SZ 1
ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;History;Temp;Local Settings\Application Data\Microsoft\Outlook
BuildNumber REG_DWORD 2600 (0xa28)
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
DebugOptions REG_SZ 2048
Documents REG_SZ
DosPrint REG_SZ no
NetMessage REG_SZ no
NullPort REG_SZ None
Programs REG_SZ com exe bat pif cmd
Run REG_SZ
Load REG_SZ
Device REG_SZ Brother MFC-7840W Printer,winspool,Ne06:
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File
BHO: - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5CA3D70E-1895-11CF-8E15-001234567890} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
BHO: NoExplorer - No File
BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
BHO: - No File
BHO: NoExplorer - No File
urun: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Readere\AdobeUpdateManager.exe AcRdB7_0_9
urun: [LxrAutorun] c:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Mediae\LxrAutorun.exe
urun: [ctfmon.exe] c:\WINDOWS\system32e\ctfmon.exe
urun: [swg] "c:\Program Files\Google\GoogleToolbarNotifiere\GoogleToolbarNotifier.exe"
mrun: [SunJavaUpdateSched] "c:\Program Files\Common Files\Java\Java Updatee\jusched.exe"
mrun: [ATIPTA] c:\Program Files\ATI Technologies\ATI Control Panele\atiptaxx.exe
mrun: [IntelMeM] c:\Program Files\Intel\Modem Event Monitore\IntelMEM.exe
mrun: [DVDLauncher] "c:\Program Files\CyberLink\PowerDVDe\DVDLauncher.exe"
mrun: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Managere\sgtray.exe" /r
mrun: [dla] c:\WINDOWS\system32\dlae\tfswctrl.exe
mrun: [QuickTime Task] "c:\Program Files\QuickTimee\qttask.exe" -atboottime
mrun: [SSBkgdUpdate] "c:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdatee\SSBkgdupdate.exe" -Embedding -boot
mrun: [ControlCenter2.0] c:\Program Files\Brother\ControlCenter2e\brctrcen.exe /autorun
mrun: [TkBellExe] "c:\Program Files\Common Files\Real\Update_OBe\realsched.exe" -osboot
mrun: [CAVRID] "c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\CAVRID.exe"
mrun: [cctray] "c:\Program Files\CA\CA Internet Security Suite\cctraye\cctray.exe"
mrun: [PaperPort PTD] "c:\Program Files\ScanSoft\PaperPorte\pptd40nt.exe"
mrun: [IndexSearch] "c:\Program Files\ScanSoft\PaperPorte\IndexSearch.exe"
mrun: [PPort11reminder] "c:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Erege\Ereg.ini"
mrun: [BrMfcWnd] c:\Program Files\Brother\Brmfcmone\BrMfcWnd.exe /AUTORUN
mrun: [ControlCenter3] c:\Program Files\Brother\ControlCenter3e\brctrcen.exe /autorun
mrun: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Readere\Reader_sl.exe"
mrun: [Adobe ARM] "c:\Program Files\Common Files\Adobe\ARM\1.0e\AdobeARM.exe"
mrun: [QOELOADER] "c:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0e\QOELoader.exe"
mrun: [Memeo Instant Backup] c:\Program Files\Memeo\AutoBackupe\MemeoLauncher2.exe –silent –no_ui
mrun: [Seagate Dashboard] c:\Program Files\Seagate\Seagate Dashboarde\MemeoLauncher.exe –silent –no_ui
mrun: [Malwarebytes' Anti-Malware (reboot)] "c:\Program Files\Malwarebytes' Anti-Malwaree\mbam.exe" /runcleanupscript
c:\DOCUME~1\Amy\STARTM~1\Programs\Startup\TrayDay.lnk - C:\Program Files\TrayDaye\TrayDay.exe
c:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdatee\qbupdate.exe
.
ie: SteelWerX Registry Console Tool 2.0
ie: Written by Bobbi Flekman 2006 ©
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\E&xport to Microsoft Excel
ie: REG_SZ res://c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE/3000
ie: Contexts REG_DWORD 1 (0x1)
.
ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\Google Sidewiki…
ie: REG_SZ res://c:\Program Files\Google\Google Toolbar\Componente\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
ie: Contexts REG_DWORD 19 (0x13)
.
ie: {SteelWerX Registry Console Tool 2.0
ie: {Written by Bobbi Flekman 2006 ©
.
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions
.
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
ie: { ButtonText - REG_SZ Research
ie: { Icon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBAR.ICO
ie: { Default Visible - REG_SZ Yes
ie: { HotIcon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBARH.ICO
.
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
ie: { ButtonText - REG_SZ Real.com
ie: { HotIcon - REG_SZ c:\Program Files\Real\RealPlayere\eb_act.ico
ie: { Icon - REG_SZ c:\Program Files\Real\RealPlayere\eb_inact.ico
ie: { ToolTip - REG_SZ Real.com Explorer Bar
ie: { Default Visible - REG_SZ Yes
.
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}
ie: { MenuText - REG_SZ @xpsp3res.dll,-20001
ie: { Exec - REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe
.
ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ie: { ButtonText - REG_SZ Messenger
ie: { Default Visible - REG_SZ Yes
ie: { Exec - REG_SZ c:\Program Files\Messengere\msmsgs.exe
ie: { HotIcon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,302
ie: { Icon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,301
ie: { MenuText - REG_SZ Windows Messenger
ie: { ToolTip - REG_SZ Windows Messenger
IE: { BandCLSID - REG_SZ {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - {ff059e31-cc5a-4e2e-bf3b-96e929d65503}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
IE: { BandCLSID - REG_SZ {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - {fe54fa40-d68c-11d2-98fa-00c0f0318afe}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
IE: { CLSID - REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\sdclicense.txt REG_SZ
c:\WINDOWS\Downloaded Program Filese\tgctlsi.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsi.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01010E00-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:07 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\tgctlsr.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\tgctlsr.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{01012101-5E80-11D8-9E86-0007E96C65AE}\InstalledVersion
REG_SZ 6,9,545,0
LastModified REG_SZ Tue, 21 Jun 2005 06:01:28 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\Contains\Files
c:\WINDOWS\system32e\GWFSPidGen.DLL REG_SZ
c:\WINDOWS\system32e\LegitCheckControl.DLL REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\DownloadInformation
CODEBASE REG_SZ http://go.microsoft.com/fwlink/?linkid=39204
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\LegitCheckControl.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion
REG_SZ 1,4,389,0
LastModified REG_SZ Sat, 05 Nov 2005 00:53:56 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\Contains\Files
c:\WINDOWSe\opuc.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\DownloadInformation
CODEBASE REG_SZ http://office.microsoft.com/officeupdate/content/opuc.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\opuc.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}\InstalledVersion
REG_SZ 11,0,5626,0
LastModified REG_SZ Fri, 29 Aug 2003 19:59:02 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\Contains\Files
c:\WINDOWS\system32e\muweb.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\DownloadInformation
CODEBASE REG_SZ http://update.microsoft.com/microsoftupdat…b?1136553665781
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\muweb.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}\InstalledVersion
REG_SZ 5,8,0,2469
LastModified REG_SZ Thu, 26 May 2005 11:40:19 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InstalledVersion
REG_SZ 1.6.0.21
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\Contains\Files
c:\WINDOWS\system32e\OFMailX.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\DownloadInformation
CODEBASE REG_SZ http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\OFMailX.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A762E064-A885-40E4-AC10-671BB62DC2B2}\InstalledVersion
REG_SZ 5,0,1,0
LastModified REG_SZ Sat, 19 Jan 2002 01:33:55 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
REG_SZ Java Runtime Environment 1.6.0
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\DownloadInformation
CODEBASE REG_SZ http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
INF REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\InstalledVersion
REG_SZ 1.6.0.21
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\SymAData.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\DownloadInformation
CODEBASE REG_SZ http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}\InstalledVersion
REG_SZ 2,6,0,0
LastModified REG_SZ Mon, 14 Nov 2005 22:15:51 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\Contains\Files
c:\WINDOWS\Downloaded Program Filese\clearadjust.dll REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\DownloadInformation
CODEBASE REG_SZ http://download.microsoft.com/download/7/E…04/clearadj.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\clearadj.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}\InstalledVersion
REG_SZ 1,0,0,4
LastModified REG_SZ Wed, 30 Apr 2003 01:12:15 GMT
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
SystemComponent REG_DWORD 0 (0x0)
Installer REG_SZ MSICD
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\Contains\Files
c:\WINDOWS\SYSTEM32e\atl.dll REG_SZ
c:\WINDOWS\Downloaded Program Filese\gp.ocx REG_SZ
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\DownloadInformation
CODEBASE REG_SZ http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
INF REG_SZ c:\WINDOWS\Downloaded Program Filese\gp.inf
.
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\InstalledVersion
REG_SZ 1,6,2,91
LastModified REG_SZ Wed, 01 Sep 2010 22:53:46 GMT
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
Error: Value: "NameServer" does not exist!
.
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
d; /.* /!d; s//securityproviders: /
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Authentication Packages REG_MULTI_SZ msv1_0
Bounds REG_BINARY 0030000000200000
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest
ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 1 (0x1)
LsaPid REG_DWORD 1816 (0x718)
SecureBoot REG_DWORD 1 (0x1)
auditbaseobjects REG_DWORD 0 (0x0)
crashonauditfail REG_DWORD 0 (0x0)
disabledomaincreds REG_DWORD 0 (0x0)
everyoneincludesanonymous REG_DWORD 0 (0x0)
fipsalgorithmpolicy REG_DWORD 0 (0x0)
forceguest REG_DWORD 1 (0x1)
fullprivilegeauditing REG_BINARY 00
limitblankpassworduse REG_DWORD 1 (0x1)
lmcompatibilitylevel REG_DWORD 0 (0x0)
nodefaultadminowner REG_DWORD 1 (0x1)
nolmhash REG_DWORD 0 (0x0)
restrictanonymous REG_DWORD 0 (0x0)
restrictanonymoussam REG_DWORD 1 (0x1)
d;/^((authentication|notification) packages) .* /i!d; s//lsa: 1 = /
Notification Packages REG_MULTI_SZ scecli
enabledcom REG_SZ y
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\MSV1_0
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache
.
SteelWerX Registry Console Tool 2.0
Written by Bobbi Flekman 2006 ©
.
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems
windows REG_EXPAND_SZ %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
ÿþ1 2 7 . 0 . 0 . 1 l o c a l h o s t

: : 1 l o c a l h o s t


============= SERVICES / DRIVERS ===============
.
R0 xmasbus;xmasbus;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasbus.sys [2005-2-4 140800]
R0 xmasscsi;xmasscsi;c:\WINDOWS\SYSTEM32\DRIVERSe\xmasscsi.sys [2005-2-4 5504]
R1 VET-FILT;VET File System Filter;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-filt.sys [2008-6-4 26352]
R1 VET-REC;VET File System Recognizer;c:\WINDOWS\SYSTEM32\DRIVERSe\vet-rec.sys [2008-6-4 21104]
R1 VETEFILE;VET File Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\vetefile.sys [2010-6-3 746216]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetfddnt.sys [2008-6-4 21488]
R1 VETMONNT;VET File Monitor;c:\WINDOWS\SYSTEM32\DRIVERSe\vetmonnt.sys [2008-6-4 32240]
R2 CAISafe;CAISafe;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\isafe.exe [2008-6-4 144960]
R2 LxrSII1d;Secure II Driver;c:\WINDOWS\SYSTEM32\DRIVERSe\LxrSII1d.sys [2008-5-13 72672]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\Program Files\Memeo\AutoBackupe\MemeoBackgroundService.exe [2010-12-10 25824]
R2 RapidPortM1;RapidPortM1;c:\WINDOWS\SYSTEM32\DRIVERSe\CAPM1LP.SYS [2005-2-23 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\Program Files\Seagate\Seagate Dashboarde\SeagateDashboardService.exe [2010-12-14 14088]
R2 VETMSGNT;VET Message Service;c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antiviruse\vetmsg.exe [2008-6-4 238928]
R3 PPCtlPriv;PPCtlPriv;c:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrole\PPCtlPriv.exe [2007-8-16 189704]
R3 VETEBOOT;VET Boot Scan Engine;c:\WINDOWS\SYSTEM32\DRIVERSe\veteboot.sys [2010-6-3 130280]
.
=============== File Associations ===============
.
::RecordNow.GI="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.ISO="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
::RecordNow.PXJ="c:\Program Files\Sonic\RecordNow!e\RecordNow.exe" "%1"
acrobat="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" /u "%1"
AcroExch.acrobatsecuritysettings.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.Document.7="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.FDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.pdfxml.1="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XDPDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
AcroExch.XFDFDoc="c:\Program Files\Adobe\Reader 9.0\Readere\AcroRd32.exe" "%1"
acwfile=%SystemRoot%\system32\accwiz.exe %1
AIFFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AIR.InstallerPackage=c:\PROGRA~1\COMMON~1\ADOBEA~1\Versions\1.0e\ADOBEA~1.EXE "%1"
AnimationShop3.Animation="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" /dde
AnimationShop3.WorkSpaceFile="c:\Program Files\Jasc Software Inc\Animation Shop 3e\Anim.exe" "/Workspace" "%1"
Application.Manifest=rundll32.exe dfshim.dll,ShOpenVerbApplication %1
Application.Reference=rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
ASFFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
ASXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AUFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
AVIFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:8 /Open "%L"
A_auto_file=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
!d
Briefcase=explorer.exe %1
callto=rundll32.exe msconf.dll,CallToProtocolHandler %l
CATFile=rundll32.exe cryptext.dll,CryptExtOpenCAT %1
cdafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
CERFile=rundll32.exe cryptext.dll,CryptExtOpenCER %1
CertificateStoreFile=rundll32.exe cryptext.dll,CryptExtOpenSTR %1
certificate_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /certificate %1
cfxxefile="%1" %*
!d
clpfile=clipbrd.exe %1
!d
!d
CompressedFolder=rundll32.exe zipfldr.dll,RouteTheCall %L
ConferenceLink=rundll32.exe msconf.dll,OpenConfLink %l
Coverpage=%systemroot%\system32\fxscover.exe "%1"
CRLFile=rundll32.exe cryptext.dll,CryptExtOpenCRL %1
DBC.MPEG.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
desFile=c:\PROGRA~1\Intuit\QUICKB~1e\qbw32.exe "%1"
DocShortcut=rundll32 %SystemRoot%\System32\shscrap.dll,OpenScrap_RunDLL /r /x %1
dqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
dunfile=%SystemRoot%\system32\RUNDLL32.EXE NETSHELL.DLL,InvokeDunFile %1
emffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
Eudora.Mailbox=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Eudora.Stationery=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe "%1"
Excel.Addin="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Backup="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Chart=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
Excel.Chart.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.CSV="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.DIF="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Macrosheet="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.Sheet.8="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.SheetBinaryMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SheetMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE" /e
Excel.SLK="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Template="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.Workspace="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excel.XLL="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE" /e
Excelhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
Excelhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\EXCEL.EXE"
!d
fndfile=%SystemRoot%\Explorer.exe
Folder=%SystemRoot%\Explorer.exe /idlist,%I,%L
fonfile=%SystemRoot%\System32\fontview.exe %1
ftp="c:\Program Files\Internet Explorere\IEXPLORE.EXE" %1
giffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
gopher="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
h323file="rundll32.exe" msconf.dll,NewMediaPhone %l
HCP=%SystemRoot%\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe -FromHCP -url "%1"
helpfile=winhlp32.exe %1
hlpfile=%SystemRoot%\System32\winhlp32.exe %1
holfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /hol "%1"
htafile=c:\WINDOWS\system32e\mshta.exe "%1" %*
htfile="c:\Program Files\Windows NTe\HYPERTRM.EXE" %1
htmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
HTTP="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
https="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
icsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /ical "%1"
ICY=c:\Program Files\Winampe\winamp.exe %1
iiifile="rundll32.exe" msconf.dll,NewMediaPhone %l
!d
!d
InternetShortcut=rundll32.exe ieframe.dll,OpenURL %l
iqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE /e
ITS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
jarfile="c:\Program Files\Java\jre6\bine\javaw.exe" -jar "%1" %*
JascPaintShopPhotoAlbumAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumAudio=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumImage=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JascPaintShopPhotoAlbumUploadAlbum=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
JNLPFile="c:\Program Files\Java\jre6\bine\javaws.exe" "%1"
jpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
JSFile=%SystemRoot%\System32\WScript.exe "%1" %*
LDAP="c:\Program Files\Outlook Expresse\wab.exe" /ldap:%1
LiveUpdate.MIDI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
m3ufile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
MacromediaFlashPaper.MacromediaFlashPaper="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome "%1"
mailto=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
MediaPackageFile="c:\Program Files\Microsoft Office\OFFICE11e\MSTORE.EXE" "%1"
mhtmlfile="c:\Program Files\Internet Explorere\IEXPLORE.EXE" -nohome
Microsoft Internet Mail Message="%ProgramFiles%\Outlook Express\msimn.exe" /eml:%1
Microsoft Internet News Message="%ProgramFiles%\Outlook Express\msimn.exe" /nws:%1
Microsoft.InformationCard=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
Microsoft.WindowsCardSpaceBackup=c:\WINDOWS\system32\rundll32.exe c:\WINDOWS\system32e\infocardcpl.cpl,ImportInformationCard_RunDll %1
MIDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
MITrain.Document=c:\WINDOWS\Help\SBSI\Traininge\ORUN32.EXE -f "%1"
MMJB.AUDIOCD="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" /AudioCD "%1"
MMJB.BPP="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmfwlaunch.exe" "%1"
MMJB.MMJB="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMO="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMJB.MMZ="c:\Program Files\Musicmatch\Musicmatch Jukeboxe\mmjblaunch.exe" "%1"
MMS="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMST="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MMSU="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
mp3file="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:6 /Open "%L"
mpegfile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:9 /Open "%L"
MPlayer=mplay32.exe /play /close "%L"
MS-ITSS FILE="c:\Program Files\Internet Explorere\iexplore.exe" -nohome ms-itss:%1::/
msbackupfile=%SystemRoot%\system32\ntbackup.exe
MSBD="c:\Program Files\Windows Media Playere\wmplayer.exe" "%L"
MSCFile=%SystemRoot%\system32\mmc.exe "%1" %*
MSDASC=Rundll32.exe c:\PROGRA~1\COMMON~1\System\OLEDB~1e\oledb32.dll,OpenDSLFile %1
msgfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /f "%1"
Msi.Package="%SystemRoot%\System32\msiexec.exe" /i "%1" %*
Msi.Patch="%SystemRoot%\System32\msiexec.exe" /p "%1" %*
MSInfo.Document=c:\Program Files\Common Files\Microsoft Shared\MSInfoe\MSInfo32.exe /msinfo_file %1
MSPaper.Document="c:\Program Files\Common Files\Microsoft Shared\MODI\11.0e\MSPVIEW.EXE" "%1"
MSProgramGroup=c:\WINDOWS\system32e\grpconv.exe %1
MsRcIncident=%SystemRoot%\PCHealth\HelpCtr\Binaries\HelpCtr.exe -Mode "hcp://system/Remote%%20Assistance/RAClientLayout.xml" -url "hcp://system/Remote%%20Assistance/Interaction/Client/rctoolScreen1.htm" -ExtraArgument "IncidentFile=%1"
msstylesfile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Appearance /Action:OpenMSTheme /file:"%1"
news="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
nntp="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
Office.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.95="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Template.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
Office.Binder.Wizard.9="c:\Program Files\Microsoft Office\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.8="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
OfficeBinder.Binder.9="c:\PROGRA~1\MICROS~2\OFFICE11e\UNBIND.EXE" "%1"
Oice.Excel.Addin=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Sheet=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Excel.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Show=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.SlideShow=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.PowerPoint.Template=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
Oice.Word.Document=c:\PROGRA~1\MICROS~2\Office12e\Oice.exe "%1"
oqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
ossfile="c:\Program Files\Microsoft Office\OFFICE11e\FINDER.EXE" /f "%1"
otffile=%SystemRoot%\System32\fontview.exe %1
outlook="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /select "%1"
Outlook.NavigatorBarFile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /s "%1"
Outlook.Template="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /t "%1"
P7RFile=rundll32.exe cryptext.dll,CryptExtOpenP7R %1
P7SFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
Paint.Picture=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
PaintShopPro8.BrowserCacheFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Browse" "%1"
PaintShopPro8.Frame="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Image="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Mask="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.PictureTube="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.Script="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Script" "%1"
PaintShopPro8.Shape="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" /dde
PaintShopPro8.WorkspaceFile="c:\Program Files\Jasc Software Inc\Paint Shop Pro 8e\Paint Shop Pro.exe" "/Workspace" "%1"
Panorama=c:\PROGRA~1\JASCSO~1\PAINTS~1e\pspa.exe "%1"
Paper.Document=c:\Program Files\ScanSoft\PaperPorte\PPPAGEVW.EXE "%1"
PaperPort.AutoplayHandler=c:\Program Files\ScanSoft\PaperPorte\PaprPort.exe /folder %L
pbkfile=%SystemRoot%\system32\rasphone.exe -f "%1"
PerfFile=%SystemRoot%\system32\perfmon.exe %1
pfmfile=%SystemRoot%\System32\fontview.exe %1
!d
pjpegfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pngfile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
pnm="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
PowerPoint.Show.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Show.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.ShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShow.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.SlideShowMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.Template.8=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
PowerPoint.TemplateMacroEnabled.12=c:\PROGRA~1\MICROS~2\Office12e\Moc.exe "%1"
ppifile=%SystemRoot%\System32\msppcnfg.exe /Config %1
prffile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /PromptImportPRF "%1"
Publishing Folder=explorer.exe /idlist,%I,%L
qbofile=c:\Program Files\Intuit\QuickBooks Basice\qbw32.exe -X "%1"
qbwFile=c:\PROGRA~1\COMMON~1\Intuit\QUICKB~1e\qblaunch.exe "%1"
QuickTime.aif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aifc=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.aiff=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.cdda=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dif=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.dv=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.mov=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qt=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qtl=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
QuickTime.qup=c:\PROGRA~1\QUICKT~1e\QuickTimeUpdater.exe "%1"
QuickTime.sd2=c:\PROGRA~1\QUICKT~1e\QuickTimePlayer.exe "%1"
ratfile=rundll32.exe msrating.dll,ClickedOnRAT %1
RealJukebox.CDA.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJS.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RJT.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMJ.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMP.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.RMX.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealJukebox.wma.1="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP2.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.3GPP_AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AIFF.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AMR_WB.10="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AU.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.AutoPlay.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /autoplay "%1"
RealPlayer.AVI.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.CDBurn.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /burn "%1"
RealPlayer.DIVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.Flash.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" /m image/vnd.rn-realflash %1
RealPlayer.M4A.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP1.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP2.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP3PL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MP4.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPEG.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.MPGA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PIX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.PLSPL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.qt.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RA.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RAX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RM.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMS.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RMVB.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RP.6="c:\Program Files\Common Files\Real\Update_OBe\rnxproc.exe" "%1"
RealPlayer.RSML.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RT.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.RVX.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SDP.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.SMIL.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.WAV.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wax.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wm.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmv.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wmx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
RealPlayer.wvx.6="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
!d
!d
rlogin=rundll32.exe url.dll,TelnetProtocolHandler %l
rqyfile=c:\PROGRA~1\MICROS~2\OFFICE11e\EXCEL.EXE
rtffile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
rtsp="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
SavedDsQuery=rundll32 %SystemRoot%\system32\dsquery.dll,OpenSavedDsQuery %1
SC=c:\Program Files\Winampe\winamp.exe %1
SchedulePlus.Application.7="c:\Program Files\Microsoft Office\OFFICE11\1033e\SCHDPL32.EXE" '%1'
!d
scriptletfile="c:\WINDOWSe\NOTEPAD.EXE" "%1"
SHCmdFile=explorer.exe
Shell=%SystemRoot%\Explorer.exe /idlist,%I,%L
ShellScrap=rundll32 %SystemRoot%\system32\shscrap.dll,OpenScrap_RunDLL %1
SHOUT=c:\Program Files\Winampe\winamp.exe %1
SldSrtr.Document=c:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0e\MSPVIEW.EXE "%1"
snews="%ProgramFiles%\Outlook Express\msimn.exe" /newsurl:"%1"
SoundRec="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
SPCFile=rundll32.exe cryptext.dll,CryptExtOpenPKCS7 %1
SpybotSD.DisabledFile="c:\Program Files\Spybot - Search & Destroye\blindman.exe" "%1"
SpybotSD.SBEFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.SBSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.TInfoFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTIFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SpybotSD.UTSFile="c:\Program Files\Spybot - Search & Destroye\SpybotSD.exe" "%1"
SSM="c:\Program Files\Real\RealPlayere\RealPlay.exe" "%1"
STLFile=rundll32.exe cryptext.dll,CryptExtOpenCTL %1
stssync="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /stssync "%1"
T126_Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" - "%1"
telnet=rundll32.exe url.dll,TelnetProtocolHandler %l
themefile=%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:"%1"
TIFImage.Document=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
tn3270=rundll32.exe url.dll,TelnetProtocolHandler %l
ttcfile=%SystemRoot%\System32\fontview.exe %1
ttffile=%SystemRoot%\System32\fontview.exe %1
!d
ulsfile="rundll32.exe" msconf.dll,NewMediaPhone %l
UVOX=c:\Program Files\Winampe\winamp.exe %1
vcard_wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" /vcard %1
vcffile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /v "%1"
vcsfile="c:\PROGRA~1\MICROS~2\OFFICE11e\OUTLOOK.EXE" /vcal "%1"
wab_auto_file="c:\Program Files\Outlook Expresse\wab.exe" %1
WAXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
webcal=rundll32.exe c:\PROGRA~1\AMERIC~1.0e\WEBCAL~1.DLL,WebCalHandler %1
webpnpFile=%SystemRoot%\system32\wpnpinst.exe %1
Whiteboard="c:\Program Files\NetMeetinge\wb32.exe" "%1"
Winamp.File="c:\Program Files\Winampe\Winamp.exe" "%1"
Winamp.Playlist="c:\Program Files\Winampe\Winamp.exe" "%1"
Windows.CompositeFont="%WinDir%\System32\notepad.exe" "%1"
Windows.Movie.Maker="c:\Program Files\Movie Makere\moviemk.exe" %1
Windows.XamlDocument="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
Windows.Xbap="c:\WINDOWS\system32e\PresentationHost.exe" "%1" %*
wmafile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:5 /Open "%L"
WMDFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /WMPackage:"%L"
wmffile=rundll32.exe c:\WINDOWS\system32e\shimgvw.dll,ImageView_Fullscreen %1
WMP.DVR-MSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
WMSFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
WMVFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /prefetch:7 /Open "%L"
WMZFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /layout:"%L"
Word.Backup.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.Document.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.DocumentMacroEnabled.12="c:\PROGRA~1\MICROS~2\OFFICE11e\WINWORD.EXE" /n /dde
Word.RTF.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
Word.Template.8="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE" /n /dde
wordhtmlfile="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
wordhtmltemplate="c:\Program Files\Microsoft Office\OFFICE11e\WINWORD.EXE"
Wordpad.Document.1="%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE" "%1"
WPLFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
wrifile="c:\Program Files\Windows NT\Accessoriese\WORDPAD.EXE" "%1"
WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
WVXFile="c:\Program Files\Windows Media Playere\wmplayer.exe" /Open "%L"
x-eudora-option=c:\PROGRA~1\Qualcomm\Eudorae\Eudora.exe /m %1
x-internet-signup=%ProgramFiles%\Internet Explorer\Connection Wizard\ISIGNUP.EXE %1
XEV.FailSafeApp=%SystemRoot%\system32\NOTEPAD.EXE %1
XEV.GenericApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
XEV.OriginalApp="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
xmlfile="c:\Program Files\Common Files\Microsoft Shared\OFFICE11e\MSOXMLED.EXE" /verb open "%1"
xnkfile="c:\Program Files\Microsoft Office\OFFICE11e\OUTLOOK.EXE" /x "%1"
XPSViewer.Document.1="c:\WINDOWS\system32\XPSViewere\XPSViewer.exe" "%1" %*
xslfile="c:\Program Files\Internet Explorere\iexplore.exe" -nohome
ZAMailSafe="c:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewalle\ca.exe" -warning "%1"
zapfile=%SystemRoot%\system32\NOTEPAD.EXE %1
.bat
.cmd
.com
.exe
.scr
.reg
.txt
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2010-12-31 13:10:33 1854976 —-a-w- c:\WINDOWS\system32e\win32k.sys
.
============= FINISH: 13:27:00.17 ===============




GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-26 13:49:09
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort1 WDC_WD800JD-75JNA0 rev.05.01C05
Running: 3r8ydxip.exe; Driver: C:\DOCUME~1\Amy\LOCALS~1\Temp\awtdrpod.sys


—- Kernel code sections - GMER 1.0.15 —-

? bmytufg.sys The system cannot find the file specified. !
.rsrc C:\WINDOWS\system32\drivers\sparrow.sys entry point in ".rsrc" section [0xF771B4D4]
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xBA6E1760]
? C:\DOCUME~1\Amy\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8AE96B2C

AttachedDevice \FileSystem\Ntfs \Ntfs VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)

Device \Driver\Cdrom \Device\CdRom0 8A9BAB28
Device \FileSystem\Rdbss \Device\FsWrap 8AE6AFAC
Device \Driver\Cdrom \Device\CdRom1 8A9BAB28
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8ADFBAF1
Device \Driver\atapi \Device\Ide\IdePort0 8A9BACE8
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 8ADFBAF1
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8A9BACE8
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8ADFBAF1
Device \Driver\atapi \Device\Ide\IdePort1 8A9BACE8
Device \FileSystem\Srv \Device\LanmanServer 8A7DDF44
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8AEBAFAC
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8AEBAFAC
Device \FileSystem\Npfs \Device\NamedPipe 8AE840CC
Device \FileSystem\Msfs \Device\Mailslot 8AB5B98C
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1 8AB67008
Device \Driver\xmasscsi \Device\Scsi\xmasscsi1Port2Path0Target0Lun0 8AB67008
Device \FileSystem\Fastfat \Fat A368AD20
Device \FileSystem\Fastfat \Fat 8AD348C4

AttachedDevice \FileSystem\Fastfat \Fat VET-REC.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat VET-FILT.SYS (CA Antivirus File Protection Driver/Computer Associates International, Inc.)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8ACE11E4
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8ACE11E4
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8ACE11E4
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8ACE11E4
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8ACE11E4
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs 8ACFA2DC
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskWDC_WD800JD-75JNA0______________________05.01C05#5&139d26ec&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

—- Modules - GMER 1.0.15 —-

Module _________ F745F000-F7477000 (98304 bytes)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG08.00.00.01WORKSTATION 4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D291923
44801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D5290136FAD4
1FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C87B3CA
5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F7876C
B1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C
FEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC7933B
A7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA1B5F1
912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE909001
8327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822752F4
157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBEFD89D
756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B1B516
982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD10ECC7
C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\sparrow.sys suspicious modification; TDL3 <– ROOTKIT !!!

—- EOF - GMER 1.0.15 —-

Attachments:

  • [attachment removed: Attach.zip]
Hi EricDSr,

That's a very odd looking log.

Please read carefully and follow these steps.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • TDSKiller log
  • both OTL logs
How's the computer?

Thanks
Thanks again for your help.

Scans were run as instructed. OTL produced only OTL.txt – no Extras.txt

Fake AntiVirus notices and Google redirect have stopped but system seems slow.

TDSSkiller and OTL loggs follow


2011/03/26 15:17:50.0812 3208 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/26 15:17:51.0390 3208 ================================================================================
2011/03/26 15:17:51.0390 3208 SystemInfo:
2011/03/26 15:17:51.0390 3208
2011/03/26 15:17:51.0390 3208 OS Version: 5.1.2600 ServicePack: 3.0
2011/03/26 15:17:51.0390 3208 Product type: Workstation
2011/03/26 15:17:51.0390 3208 ComputerName: IRWINA
2011/03/26 15:17:51.0390 3208 UserName: Amy
2011/03/26 15:17:51.0390 3208 Windows directory: C:\WINDOWS
2011/03/26 15:17:51.0390 3208 System windows directory: C:\WINDOWS
2011/03/26 15:17:51.0390 3208 Processor architecture: Intel x86
2011/03/26 15:17:51.0390 3208 Number of processors: 2
2011/03/26 15:17:51.0390 3208 Page size: 0x1000
2011/03/26 15:17:51.0390 3208 Boot type: Normal boot
2011/03/26 15:17:51.0390 3208 ================================================================================
2011/03/26 15:17:51.0781 3208 Initialize success
2011/03/26 15:17:59.0093 0212 ================================================================================
2011/03/26 15:17:59.0093 0212 Scan started
2011/03/26 15:17:59.0093 0212 Mode: Manual;
2011/03/26 15:17:59.0093 0212 ================================================================================
2011/03/26 15:17:59.0609 0212 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/03/26 15:17:59.0703 0212 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/03/26 15:18:00.0375 0212 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/03/26 15:18:00.0921 0212 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/03/26 15:18:01.0578 0212 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
2011/03/26 15:18:02.0171 0212 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/03/26 15:18:02.0859 0212 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/03/26 15:18:03.0421 0212 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/03/26 15:18:03.0984 0212 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/03/26 15:18:04.0531 0212 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/03/26 15:18:04.0562 0212 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/03/26 15:18:05.0140 0212 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/03/26 15:18:05.0718 0212 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/03/26 15:18:06.0296 0212 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/03/26 15:18:06.0859 0212 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/03/26 15:18:07.0421 0212 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/03/26 15:18:07.0484 0212 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/03/26 15:18:08.0015 0212 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/03/26 15:18:08.0578 0212 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/03/26 15:18:09.0140 0212 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/03/26 15:18:09.0671 0212 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/03/26 15:18:10.0328 0212 ati2mtag (f0d0b0cdec0be32d775f404cac2604bf) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
2011/03/26 15:18:10.0843 0212 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/03/26 15:18:11.0390 0212 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/03/26 15:18:11.0937 0212 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/03/26 15:18:12.0062 0212 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/03/26 15:18:12.0109 0212 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/03/26 15:18:12.0187 0212 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/03/26 15:18:12.0281 0212 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/03/26 15:18:12.0328 0212 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/03/26 15:18:12.0375 0212 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/03/26 15:18:12.0437 0212 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/03/26 15:18:12.0515 0212 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
2011/03/26 15:18:12.0625 0212 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
2011/03/26 15:18:13.0265 0212 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/03/26 15:18:13.0328 0212 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/03/26 15:18:13.0406 0212 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/03/26 15:18:13.0484 0212 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/03/26 15:18:13.0531 0212 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/03/26 15:18:13.0578 0212 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/03/26 15:18:13.0640 0212 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/03/26 15:18:13.0687 0212 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/03/26 15:18:13.0734 0212 drvmcdb (b15f9e526ba511a48b1b1b8537815740) C:\WINDOWS\system32\drivers\drvmcdb.sys
2011/03/26 15:18:13.0781 0212 drvnddm (fa4670cae95ae2bb857c68e535661145) C:\WINDOWS\system32\drivers\drvnddm.sys
2011/03/26 15:18:13.0968 0212 DSproct (413f2d5f9d802688242c23b38f767ecb) C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
2011/03/26 15:18:14.0015 0212 dsunidrv (dfeabb7cfffadea4a912ab95bdc3177a) C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
2011/03/26 15:18:14.0078 0212 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
2011/03/26 15:18:14.0218 0212 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/03/26 15:18:14.0281 0212 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/03/26 15:18:14.0328 0212 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/03/26 15:18:14.0390 0212 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/03/26 15:18:14.0453 0212 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/03/26 15:18:14.0531 0212 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/03/26 15:18:14.0546 0212 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/03/26 15:18:14.0578 0212 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/03/26 15:18:14.0640 0212 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/03/26 15:18:14.0718 0212 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/03/26 15:18:14.0875 0212 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/03/26 15:18:14.0937 0212 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/03/26 15:18:14.0968 0212 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/03/26 15:18:15.0046 0212 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/03/26 15:18:15.0125 0212 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/03/26 15:18:15.0203 0212 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
2011/03/26 15:18:15.0265 0212 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
2011/03/26 15:18:15.0312 0212 IntelC53 (cf0b937710cec6ef39416edecd803cbb) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
2011/03/26 15:18:15.0343 0212 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/03/26 15:18:15.0421 0212 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/03/26 15:18:15.0468 0212 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/03/26 15:18:15.0515 0212 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/03/26 15:18:15.0578 0212 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/03/26 15:18:15.0625 0212 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/03/26 15:18:15.0671 0212 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/03/26 15:18:15.0718 0212 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/03/26 15:18:15.0796 0212 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/03/26 15:18:15.0843 0212 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/03/26 15:18:15.0890 0212 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/03/26 15:18:16.0125 0212 LxrSII1d (7c12f93c005021861a36c11df951891a) C:\WINDOWS\system32\Drivers\LxrSII1d.sys
2011/03/26 15:18:16.0234 0212 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/03/26 15:18:16.0296 0212 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/03/26 15:18:16.0359 0212 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
2011/03/26 15:18:16.0437 0212 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
2011/03/26 15:18:16.0484 0212 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/03/26 15:18:16.0531 0212 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/03/26 15:18:16.0640 0212 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/03/26 15:18:16.0718 0212 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/03/26 15:18:16.0828 0212 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/03/26 15:18:16.0875 0212 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/03/26 15:18:16.0937 0212 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/03/26 15:18:17.0000 0212 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/03/26 15:18:17.0046 0212 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/03/26 15:18:17.0093 0212 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/03/26 15:18:17.0125 0212 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/03/26 15:18:17.0187 0212 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/03/26 15:18:17.0250 0212 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/03/26 15:18:17.0281 0212 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/03/26 15:18:17.0343 0212 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/03/26 15:18:17.0406 0212 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/03/26 15:18:17.0500 0212 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/03/26 15:18:17.0562 0212 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/03/26 15:18:17.0640 0212 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/03/26 15:18:17.0734 0212 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/03/26 15:18:17.0828 0212 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/03/26 15:18:17.0921 0212 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/03/26 15:18:18.0125 0212 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/03/26 15:18:18.0312 0212 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/03/26 15:18:18.0468 0212 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
2011/03/26 15:18:18.0593 0212 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/03/26 15:18:18.0750 0212 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/03/26 15:18:18.0921 0212 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/03/26 15:18:19.0046 0212 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/03/26 15:18:19.0250 0212 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/03/26 15:18:19.0328 0212 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/03/26 15:18:19.0484 0212 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
2011/03/26 15:18:19.0609 0212 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
2011/03/26 15:18:19.0812 0212 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/03/26 15:18:19.0906 0212 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/03/26 15:18:20.0015 0212 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/03/26 15:18:20.0062 0212 PxHelp20 (db3b30c3a4cdcf07e164c14584d9d0f2) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/03/26 15:18:20.0140 0212 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/03/26 15:18:20.0203 0212 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/03/26 15:18:20.0234 0212 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/03/26 15:18:20.0265 0212 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/03/26 15:18:20.0296 0212 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/03/26 15:18:20.0375 0212 RapidPortM1 (7f599e8bcc5ebc78fa711e9e55eea40c) C:\WINDOWS\system32\Drivers\CAPM1LP.SYS
2011/03/26 15:18:20.0468 0212 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/03/26 15:18:20.0609 0212 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/03/26 15:18:20.0812 0212 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/03/26 15:18:20.0890 0212 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/03/26 15:18:21.0015 0212 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/03/26 15:18:21.0078 0212 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/03/26 15:18:21.0203 0212 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/03/26 15:18:21.0468 0212 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/03/26 15:18:21.0796 0212 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/03/26 15:18:21.0984 0212 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/03/26 15:18:22.0109 0212 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/03/26 15:18:22.0203 0212 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/03/26 15:18:22.0375 0212 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/03/26 15:18:22.0546 0212 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
2011/03/26 15:18:22.0656 0212 smwdm (4aa922332433cdeb8b82c072c212e32e) C:\WINDOWS\system32\drivers\smwdm.sys
2011/03/26 15:18:22.0828 0212 Sparrow (0dfdeebb67f228a0f4fad78e2f8ab215) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/03/26 15:18:22.0890 0212 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\sparrow.sys. Real md5: 0dfdeebb67f228a0f4fad78e2f8ab215, Fake md5: 83c0f71f86d3bdaf915685f3d568b20e
2011/03/26 15:18:22.0906 0212 Sparrow - detected Rootkit.Win32.TDSS.tdl3 (0)
2011/03/26 15:18:22.0968 0212 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/03/26 15:18:23.0015 0212 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/03/26 15:18:23.0171 0212 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/03/26 15:18:23.0234 0212 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
2011/03/26 15:18:23.0312 0212 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
2011/03/26 15:18:23.0421 0212 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
2011/03/26 15:18:23.0515 0212 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/03/26 15:18:23.0625 0212 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/03/26 15:18:23.0734 0212 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/03/26 15:18:23.0796 0212 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/03/26 15:18:23.0890 0212 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/03/26 15:18:23.0937 0212 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/03/26 15:18:24.0062 0212 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/03/26 15:18:24.0203 0212 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/03/26 15:18:24.0328 0212 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/03/26 15:18:24.0500 0212 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/03/26 15:18:24.0828 0212 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/03/26 15:18:25.0125 0212 tfsnboio (1d265cd2fb1673a0873bf8cec19ddc7f) C:\WINDOWS\system32\dla\tfsnboio.sys
2011/03/26 15:18:25.0218 0212 tfsncofs (62e4901295e0467cac78e5b4b131ae5c) C:\WINDOWS\system32\dla\tfsncofs.sys
2011/03/26 15:18:25.0468 0212 tfsndrct (a2f380f9252ab3464c859adf91eead9c) C:\WINDOWS\system32\dla\tfsndrct.sys
2011/03/26 15:18:25.0546 0212 tfsndres (eee79bbefe9c6a2a3ce6c8753cfea950) C:\WINDOWS\system32\dla\tfsndres.sys
2011/03/26 15:18:25.0640 0212 tfsnifs (9d644eb11fec9487450c4cfcd63a5df4) C:\WINDOWS\system32\dla\tfsnifs.sys
2011/03/26 15:18:25.0781 0212 tfsnopio (e656af05c67edb7c0e9230a5df71ed1b) C:\WINDOWS\system32\dla\tfsnopio.sys
2011/03/26 15:18:25.0906 0212 tfsnpool (64fccb9cce703ca507dffc3cebf6b2cb) C:\WINDOWS\system32\dla\tfsnpool.sys
2011/03/26 15:18:25.0984 0212 tfsnudf (48bc9d8ab4e4b9bff70fb18e55cec3d6) C:\WINDOWS\system32\dla\tfsnudf.sys
2011/03/26 15:18:26.0109 0212 tfsnudfa (79f60822224256b49bfc855da8d651d5) C:\WINDOWS\system32\dla\tfsnudfa.sys
2011/03/26 15:18:26.0265 0212 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/03/26 15:18:26.0375 0212 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/03/26 15:18:26.0515 0212 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/03/26 15:18:26.0640 0212 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/03/26 15:18:26.0812 0212 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/03/26 15:18:26.0906 0212 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/03/26 15:18:27.0000 0212 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/03/26 15:18:27.0171 0212 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/03/26 15:18:27.0265 0212 VET-FILT (daadb622164e93376b31598c053a9e87) C:\WINDOWS\system32\drivers\VET-FILT.sys
2011/03/26 15:18:27.0390 0212 VET-REC (66747d67066e29b24363d5537b93d294) C:\WINDOWS\system32\drivers\VET-REC.sys
2011/03/26 15:18:27.0515 0212 VETEBOOT (c079f80582c31728029f3efcdfeaf221) C:\WINDOWS\system32\drivers\VETEBOOT.sys
2011/03/26 15:18:28.0156 0212 VETEFILE (31bab965e7af8295c22f641401d622b3) C:\WINDOWS\system32\drivers\VETEFILE.sys
2011/03/26 15:18:28.0281 0212 VETFDDNT (10545ed2f206c922eb02e522b1a3fa75) C:\WINDOWS\system32\drivers\VETFDDNT.sys
2011/03/26 15:18:28.0359 0212 VETMONNT (77ef6a724334313b808fb6fe36b57be6) C:\WINDOWS\system32\drivers\VETMONNT.sys
2011/03/26 15:18:28.0453 0212 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/03/26 15:18:28.0578 0212 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/03/26 15:18:28.0687 0212 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/03/26 15:18:28.0796 0212 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/03/26 15:18:28.0890 0212 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/03/26 15:18:29.0078 0212 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/03/26 15:18:29.0312 0212 xmasbus (ddd8286b88fe764ad2a8bd171e7b569a) C:\WINDOWS\system32\DRIVERS\xmasbus.sys
2011/03/26 15:18:29.0375 0212 xmasscsi (2222677f06fb7fbe44b04316437585d2) C:\WINDOWS\system32\Drivers\xmasscsi.sys
2011/03/26 15:18:29.0500 0212 ================================================================================
2011/03/26 15:18:29.0500 0212 Scan finished
2011/03/26 15:18:29.0500 0212 ================================================================================
2011/03/26 15:18:29.0515 1084 Detected object count: 1
2011/03/26 15:19:23.0718 1084 Sparrow (0dfdeebb67f228a0f4fad78e2f8ab215) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/03/26 15:19:23.0734 1084 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\sparrow.sys. Real md5: 0dfdeebb67f228a0f4fad78e2f8ab215, Fake md5: 83c0f71f86d3bdaf915685f3d568b20e
2011/03/26 15:19:26.0203 1084 Backup copy found, using it..
2011/03/26 15:19:26.0218 1084 C:\WINDOWS\system32\DRIVERS\sparrow.sys - will be cured after reboot
2011/03/26 15:19:26.0218 1084 Rootkit.Win32.TDSS.tdl3(Sparrow) - User select action: Cure
2011/03/26 15:19:45.0000 1844 Deinitialize success




OTL logfile created on: 3/26/2011 3:43:45 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Amy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.39 Gb Total Space | 43.54 Gb Free Space | 60.98% Space Free | Partition Type: NTFS

Computer Name: IRWINA | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Amy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
PRC - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\vetmsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\cavrid.exe (CA, Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe (CA, Inc.)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
PRC - C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\SYSTEM32\oodag.exe (O&O Software GmbH)
PRC - C:\WINDOWS\SYSTEM32\LxrSII1s.exe ()
PRC - C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
PRC - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAPM1SWK.EXE (CANON INC.)
PRC - C:\WINDOWS\SYSTEM32\CAPM1RSK.EXE (CANON INC.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Amy\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOEHook.dll (CA)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (VETMSGNT) – C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\vetmsg.exe (CA, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe) – C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe (Computer Associates International, Inc.)
SRV - (PPCtlPriv) – C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe (CA, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ITMRTSVC) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (O&O Defrag) – C:\WINDOWS\SYSTEM32\oodag.exe (O&O Software GmbH)
SRV - (LxrSII1s) – C:\WINDOWS\System32\LxrSII1s.exe ()


========== Driver Services (SafeList) ==========

DRV - (VETEFILE) – C:\WINDOWS\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\WINDOWS\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (VET-FILT) – C:\WINDOWS\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\WINDOWS\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\WINDOWS\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (LxrSII1d) – C:\WINDOWS\SYSTEM32\DRIVERS\LxrSII1d.sys ()
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (xmasbus) – C:\WINDOWS\system32\DRIVERS\xmasbus.sys ( )
DRV - (xmasscsi) – C:\WINDOWS\System32\Drivers\xmasscsi.sys ( )
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (RapidPortM1) – C:\WINDOWS\SYSTEM32\DRIVERS\CAPM1LP.SYS (CANON INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/index.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{71EA6046-8286-4ADC-BF58-501E76626E60}: C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}
FF - HKLM\software\mozilla\Firefox\extensions\\{0C619940-D883-4492-9EC5-EAFB3EBF9421}: C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421} [2011/03/25 10:08:20 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/09/22 09:14:35 | 000,000,098 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O3 - HKLM\..\Toolbar: (Viewpoint Toolbar) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll (Viewpoint Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [QOELOADER] C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [LxrAutorun] C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
O4 - HKCU..\Run: [updateMgr] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O4 - Startup: C:\Documents and Settings\Amy\Start Menu\Programs\Startup\TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1136553665781 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} http://www.eomniform.com/OF5/nsplugins/OFMailX.cab (OFMailHTMLCtl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Amy\My Documents\My Pictures\Sunshineoncouch (2).bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Amy\My Documents\My Pictures\Sunshineoncouch (2).bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2011/03/26 15:01:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Amy\Desktop\tdsskiller
[2011/03/26 15:00:29 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Amy\Desktop\OTL.exe
[2011/03/25 14:59:51 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/25 14:59:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/25 14:59:41 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/25 14:57:34 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Amy\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/25 10:08:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}
[2011/03/25 10:06:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58
[2005/02/04 14:11:08 | 000,140,800 | —- | C] ( ) – C:\WINDOWS\System32\drivers\xmasbus.sys
[2005/02/04 14:11:08 | 000,005,504 | —- | C] ( ) – C:\WINDOWS\System32\drivers\xmasscsi.sys
[1980/01/01 02:00:00 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll

========== Files - Modified Within 30 Days ==========

[2011/03/26 16:39:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/26 16:14:32 | 000,000,418 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
[2011/03/26 15:26:13 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/26 15:22:13 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/03/26 15:21:49 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/26 15:21:42 | 3487,715,328 | -HS- | M] () – C:\hiberfil.sys
[2011/03/26 15:21:40 | 000,322,137 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2011/03/26 15:00:30 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Amy\Desktop\OTL.exe
[2011/03/26 15:00:08 | 001,263,721 | —- | M] () – C:\Documents and Settings\Amy\Desktop\tdsskiller.zip
[2011/03/26 13:50:28 | 000,022,583 | —- | M] () – C:\Documents and Settings\Amy\Desktop\Attach.zip
[2011/03/26 13:23:46 | 000,301,568 | —- | M] () – C:\Documents and Settings\Amy\Desktop\3r8ydxip.exe
[2011/03/26 13:22:18 | 000,625,664 | —- | M] () – C:\Documents and Settings\Amy\Desktop\dds.scr
[2011/03/25 14:59:52 | 000,000,836 | —- | M] () – C:\Documents and Settings\Amy\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/03/25 14:59:52 | 000,000,818 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/25 14:57:34 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Amy\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/25 14:38:51 | 000,000,060 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/03/25 14:38:51 | 000,000,042 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/03/25 13:11:59 | 000,002,521 | —- | M] () – C:\Documents and Settings\Amy\Desktop\Microsoft Office Outlook 2003.lnk
[2011/03/25 11:45:41 | 000,002,495 | —- | M] () – C:\Documents and Settings\Amy\Desktop\Microsoft Office Excel 2003.lnk
[2011/03/25 10:08:22 | 000,000,000 | —- | M] () – C:\WINDOWS\Sqoqidimeqa.bin
[2011/03/25 10:08:21 | 000,000,120 | —- | M] () – C:\WINDOWS\Lzudologo.dat
[2011/03/24 11:48:00 | 000,000,947 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Zuma's Revenge!.lnk
[2011/03/21 14:51:00 | 000,001,569 | —- | M] () – C:\WINDOWS\TIMESLIP.INI
[2011/03/21 09:31:00 | 000,000,426 | —- | M] () – C:\WINDOWS\brwmark.ini
[2011/03/16 11:52:35 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/14 07:55:38 | 000,445,370 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/03/14 07:55:38 | 000,072,576 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/03/10 09:04:33 | 000,000,826 | —- | M] () – C:\Documents and Settings\Amy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk

========== Files Created - No Company Name ==========

[2011/03/26 15:00:03 | 001,263,721 | —- | C] () – C:\Documents and Settings\Amy\Desktop\tdsskiller.zip
[2011/03/26 13:50:28 | 000,022,583 | —- | C] () – C:\Documents and Settings\Amy\Desktop\Attach.zip
[2011/03/26 13:23:44 | 000,301,568 | —- | C] () – C:\Documents and Settings\Amy\Desktop\3r8ydxip.exe
[2011/03/26 13:22:16 | 000,625,664 | —- | C] () – C:\Documents and Settings\Amy\Desktop\dds.scr
[2011/03/25 14:59:52 | 000,000,836 | —- | C] () – C:\Documents and Settings\Amy\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/03/25 14:59:52 | 000,000,818 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/25 10:08:22 | 000,000,000 | —- | C] () – C:\WINDOWS\Sqoqidimeqa.bin
[2011/03/25 10:08:21 | 000,000,120 | —- | C] () – C:\WINDOWS\Lzudologo.dat
[2011/03/24 11:48:00 | 000,000,947 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Zuma's Revenge!.lnk
[2010/11/17 10:10:29 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD7840W.DAT
[2010/09/20 14:11:22 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/08 13:16:29 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2010/09/08 13:16:29 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2010/09/08 13:16:27 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2010/09/08 13:12:16 | 000,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2010/07/20 14:10:17 | 000,000,060 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/07/20 14:10:17 | 000,000,042 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/04/18 12:11:18 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2010/03/03 12:49:06 | 000,000,010 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2008/06/04 16:44:55 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl_cpy.dat
[2008/05/13 14:31:32 | 000,072,672 | —- | C] () – C:\WINDOWS\System32\drivers\LxrSII1d.sys
[2008/05/13 14:31:32 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\LxrSII1s.exe
[2008/04/14 14:35:41 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2008/04/14 14:35:40 | 000,000,055 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2007/01/15 17:28:30 | 000,000,000 | —- | C] () – C:\WINDOWS\PestPatrol5.INI
[2006/02/11 21:32:50 | 000,000,841 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2006/02/11 21:32:50 | 000,000,093 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2006/02/11 21:32:50 | 000,000,065 | —- | C] () – C:\WINDOWS\System32\BD7820N.dat
[2006/02/11 21:32:49 | 000,000,426 | —- | C] () – C:\WINDOWS\brwmark.ini
[2006/02/11 21:32:49 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2006/02/11 21:32:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2006/02/11 21:32:10 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2005/08/15 09:27:07 | 000,000,514 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/04/04 18:11:02 | 000,001,569 | —- | C] () – C:\WINDOWS\TIMESLIP.INI
[2005/04/04 18:10:55 | 000,244,984 | —- | C] () – C:\WINDOWS\System32\tutil32.dll
[2005/01/28 15:27:49 | 000,010,240 | —- | C] () – C:\Documents and Settings\Amy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/07 18:12:08 | 000,000,126 | —- | C] () – C:\Documents and Settings\Amy\Local Settings\Application Data\fusioncache.dat
[2005/01/05 15:13:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/05 15:09:29 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005/01/05 15:06:35 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/01/05 15:03:16 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/01/05 14:53:20 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2005/01/05 14:51:44 | 000,445,370 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2005/01/05 14:51:44 | 000,072,576 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2005/01/05 14:31:56 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/09/16 00:03:14 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/11 19:25:56 | 000,000,791 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/11 19:20:10 | 000,146,808 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 19:14:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 19:12:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 12:31:24 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/11 12:31:24 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 18:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 17:09:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2003/01/07 17:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/04 11:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
[1980/01/01 02:00:00 | 000,389,120 | —- | C] () – C:\WINDOWS\System32\ati2evxx.exe
[1980/01/01 02:00:00 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[1980/01/01 02:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2007/01/15 16:33:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2010/10/05 14:06:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2010/07/20 14:10:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/09/17 12:13:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/03/11 13:03:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/03 10:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/05/13 14:28:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Ceedo
[2011/03/25 10:06:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58
[2005/02/04 13:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Leadertech
[2010/10/05 14:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Memeo
[2005/01/21 12:36:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Qualcomm
[2006/02/13 13:23:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\ScanSoft
[2010/10/05 13:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Seagate
[2009/05/20 15:44:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\The Labyrinth Plus! Edition
[2006/10/24 11:03:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\UVU
[2007/06/11 14:25:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Viewpoint
[2010/07/26 07:44:13 | 000,000,474 | —- | M] () – C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Amy at 4 43 PM.job
[2005/01/07 13:43:18 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2011/03/26 15:22:13 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
[2011/03/26 16:14:32 | 000,000,418 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/11 19:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/01/07 13:43:20 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/04/18 08:59:52 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2007/01/15 16:35:56 | 000,008,342 | —- | M] () – C:\caavsetup.log
[2008/06/04 16:43:32 | 000,033,917 | —- | M] () – C:\caavsetupLog.txt
[2011/02/23 10:07:05 | 000,423,790 | —- | M] () – C:\caisslog.txt
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/18 11:10:00 | 000,018,997 | —- | M] () – C:\ComboFix.txt
[2004/08/11 19:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/12/06 16:29:08 | 000,510,834 | —- | M] () – C:\D4700A10.EXE
[2005/01/05 14:36:24 | 000,004,889 | RH– | M] () – C:\DELL.SDR
[2007/01/15 16:35:10 | 000,000,026 | —- | M] () – C:\ezsetuplog.txt
[2011/03/26 15:21:42 | 3487,715,328 | -HS- | M] () – C:\hiberfil.sys
[2004/08/11 19:27:32 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/04/04 18:11:02 | 000,003,752 | —- | M] () – C:\INSTALL.LOG
[2004/08/11 19:15:00 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/01/05 15:11:18 | 000,000,744 | -H– | M] () – C:\IPH.PH
[2010/09/22 09:57:16 | 000,010,739 | —- | M] () – C:\JavaRa.log
[2010/09/20 13:20:32 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/08/11 19:15:00 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/08/10 08:15:16 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2011/03/26 15:21:41 | 3487,641,600 | -HS- | M] () – C:\pagefile.sys
[2005/01/05 15:11:30 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2011/03/26 15:19:45 | 000,050,648 | —- | M] () – C:\TDSSKiller.2.4.21.0_26.03.2011_15.17.50_log.txt
[1998/07/31 15:01:56 | 000,019,904 | —- | M] (Stirling Technologies Inc.) – C:\_ISREG16.DLL

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 19:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
[2001/11/20 15:37:28 | 000,047,616 | R— | M] (Black Ice Software) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\ppbiPr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/11 19:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/11 19:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/11 19:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2009/08/10 08:22:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
[2006/01/06 09:21:23 | 000,001,566 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Microsoft Update.lnk
[2007/03/05 14:14:04 | 000,002,505 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\New Office Document.lnk
[2007/03/05 14:14:04 | 000,002,515 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Open Office Document.lnk
[2009/08/10 08:22:20 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2004/08/11 19:15:06 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2006/08/16 09:45:49 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2005/01/05 14:58:28 | 000,000,310 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\convert.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-24 20:02:45


< MD5 for: EXPLORER.EX_ >
[2004/08/04 07:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 07:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2011/03/26 15:28:29 | 000,052,146 | —- | M] () MD5=00695A5E7A0428A770BDC21D55616F8A – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf

< MD5 for: EXPLORER.SC_ >
[2004/08/04 07:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2004/08/04 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\EXPLORER.SCF

< MD5 for: IEXPLORE.CHM >
[2004/08/04 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\I386\IEXPLORE.CHM
[2004/08/04 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 07:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/29 03:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/19 01:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 02:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 07:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\Program Files\Internet Explorer\iexplore.exe
[2010/12/20 07:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2007/04/24 10:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/19 01:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 04:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/23 01:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 11:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2008/04/22 03:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 07:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 04:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 04:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2009/08/27 01:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 06:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2009/06/29 04:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/28 02:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2006/10/17 13:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 09:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 06:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/10 04:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/21 04:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 05:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 07:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/28 02:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 04:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 19:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 10:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/15 03:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 00:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 10:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/23 01:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2010/12/20 06:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/28 00:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/27 05:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/23 01:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 03:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/28 02:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 06:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2010/08/25 07:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/23 01:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 06:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 07:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 01:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 13:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2011/03/26 15:38:02 | 000,105,044 | —- | M] () MD5=214385711EF4BAC489C0E550ADBCBC96 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2004/08/04 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\IEXPLORE.HLP

< MD5 for: WINLOGON.EXE >
[2004/08/04 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\I386\WINLOGON.EXE
[2004/08/04 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07D3634B
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B623B5B8
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7EF24820

< End of report >
Hi EricDSr,

OTl shouldn't have taken very long unless it was having difficulty with the Restore Point. The log says it is turned off. We need it turned on. No Extra log was produced because OTL was ran before.

First make sure System Restore is turned on.

  • Click your start button
  • right click on My Computer and select properties
  • Click the System Restore tab
  • Make sure there isn't a check mark beside Turn off System Restore
  • If it is checked click it to clear it
  • click Apply, click OK



Next

Please open OTL .

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the Extra Registry section change it to All
  • In the window under Custom Scans/Fixes copy and paste the following


    C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\*.* /s
    C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\*.* /s
    /md5start
    sparrow.sys
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. The Extra.txt will be minimised on the tray. Please post both. The OTL will be much shorter this time.



Next
You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

If everthing is ok there, create a Restore point
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create

Please post back with
  • both OTL logs
  • MBAM log
Thanks
Thanks again for your help, oldman.

Computer still seems slow.

When you double click on something it takes quite a while to react.

Clicking on My Computer wound hang up and require me to end the non responding program. I got into System Restore through Help.

System Restore did not appear to be turned off but I noticed there were no restore points.
I had no problem creating a new restore point though.

Logs follow:

OTL logfile created on: 3/28/2011 12:20:04 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Amy\Desktop\Virus032611
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.39 Gb Total Space | 43.38 Gb Free Space | 60.76% Space Free | Partition Type: NTFS
Drive X: | 931.51 Gb Total Space | 891.24 Gb Free Space | 95.68% Space Free | Partition Type: NTFS
Drive Y: | 931.51 Gb Total Space | 891.24 Gb Free Space | 95.68% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 891.24 Gb Free Space | 95.68% Space Free | Partition Type: NTFS

Computer Name: IRWINA | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\*.* /s >
[2011/03/25 10:08:19 | 000,000,122 | —- | M] () – C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\chrome.manifest
[2011/03/25 10:08:20 | 000,000,764 | —- | M] () – C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\install.rdf
[2011/03/25 10:08:20 | 000,005,954 | —- | M] () – C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\chrome\content\overlay.xul
[2011/03/25 10:08:20 | 000,002,128 | —- | M] () – C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\chrome\content\_cfg.js

< C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\*.* /s >
[2011/03/25 10:06:51 | 000,028,842 | —- | M] () – C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\enemies-names.txt
[2011/03/25 10:06:51 | 000,026,602 | —- | M] () – C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\local.ini
[2011/03/25 12:06:09 | 000,002,332 | —- | M] () – C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58\lsrslt.ini


< MD5 for: SPARROW.SYS >
[2001/08/17 16:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) MD5=83C0F71F86D3BDAF915685F3D568B20E – C:\I386\SPARROW.SYS
[2011/03/26 15:21:23 | 000,019,072 | —- | M] (Adaptec, Inc.) MD5=83C0F71F86D3BDAF915685F3D568B20E – C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS

< End of report >


OTL Extras logfile created on: 3/28/2011 12:20:04 PM - Run 3
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Amy\Desktop\Virus032611
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.39 Gb Total Space | 43.38 Gb Free Space | 60.76% Space Free | Partition Type: NTFS
Drive X: | 931.51 Gb Total Space | 891.24 Gb Free Space | 95.68% Space Free | Partition Type: NTFS
Drive Y: | 931.51 Gb Total Space | 891.24 Gb Free Space | 95.68% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 891.24 Gb Free Space | 95.68% Space Free | Partition Type: NTFS

Computer Name: IRWINA | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] – rundll32.exe C:\WINDOWS\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
jsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"54925:UDP" = 54925:UDP:*:Enabled:Brother Network Scanner

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Disabled:AOL
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\UVU\UVU Media Player\HSAudioPlayer.exe" = C:\Program Files\UVU\UVU Media Player\HSAudioPlayer.exe:*:Enabled:UVU Media Player
"C:\Program Files\Brother\Brmfl07b\FAXRX.exe" = C:\Program Files\Brother\Brmfl07b\FAXRX.exe:*:Enabled:FAXRX.EXE – (Brother Industries Ltd.)
"C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe" = C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe:*:Enabled:GoFlex Home Agent Application – (Axentra Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 21
"{2b02f821-a9b9-458c-80e5-3ea8c0de8471}" = QuickBooks Basic Edition 2004
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{395131D0-71C3-4411-8DDD-84E7A4EC8754}" = Intellisync® for Yahoo!
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{46E1B1F2-A279-4356-9B17-029F9CC72EAE}" = Brother MFL-Pro Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{53480370-6CA2-47EC-BC05-02B4B9271C31}" = O&O Defrag Professional Edition
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.3
"{6E179C77-7335-458D-9537-4F4EAC0181ED}" = Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78D944D7-A97B-4004-AB0A-B5AD06839940}" = My Way Search Assistant
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7A8FF745-BBC5-482B-88E4-18D3178249A9}" = ScanSoft PaperPort 11
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{84F1DE76-C48C-4281-87A0-CC9548D1E7F9}" = Rhapsody Player Engine
"{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
"{C47C88C6-9F9E-11D1-9FDF-00403330A134}" = Timeslips v11
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6610DDC-5339-4AF4-A28E-F0DDBD1A2859}" = EFS version 4.0
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" = Alcohol 120%
"{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}" = Microsoft Plus! for Windows XP
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"ATI Display Driver" = ATI Display Driver
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Canon PC1200/iC D600/iR1200G" = Canon PC1200/iC D600/iR1200G
"eTrust Suite Personal" = CA Internet Security Suite
"Eudora" = Eudora
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSNINST" = MSN
"MyWaySearchAssistantDE" = My Way Search Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.3
"TrayDay" = TrayDay
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"Zuma's Revenge!" = Zuma's Revenge!

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/9/2011 12:10:10 PM | Computer Name = IRWINA | Source = Application Error | ID = 1000
Description = Faulting application isafe.exe, version 8.0.8.0, faulting module isafserv.dll,
version 8.0.8.0, fault address 0x00011790.

Error - 2/28/2011 9:04:55 AM | Computer Name = IRWINA | Source = Application Error | ID = 1000
Description = Faulting application isafe.exe, version 8.0.8.0, faulting module isafserv.dll,
version 8.0.8.0, fault address 0x00011790.

Error - 3/10/2011 11:49:39 AM | Computer Name = IRWINA | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17095, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/10/2011 11:49:39 AM | Computer Name = IRWINA | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17095, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/14/2011 9:09:51 AM | Computer Name = IRWINA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.17095, faulting
module mshtml.dll, version 7.0.6000.17095, fault address 0x0007578a.

Error - 3/25/2011 12:13:33 PM | Computer Name = IRWINA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ucibasus.dll, version 0.0.0.0, fault address 0x000097fb.

Error - 3/25/2011 1:51:04 PM | Computer Name = IRWINA | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/25/2011 3:08:17 PM | Computer Name = IRWINA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ucibasus.dll, version 0.0.0.0, fault address 0x000097fb.

Error - 3/25/2011 3:11:11 PM | Computer Name = IRWINA | Source = Application Hang | ID = 1002
Description = Hanging application asp70vdviss.exe, version 2.4.5600.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/25/2011 4:36:26 PM | Computer Name = IRWINA | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/26/2011 3:07:17 PM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 3/26/2011 3:07:26 PM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
ini910u
IntelIde
intelppm
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde

Error - 3/26/2011 3:25:30 PM | Computer Name = IRWINA | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 3/26/2011 3:25:53 PM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 3/26/2011 3:26:00 PM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
ini910u
IntelIde
intelppm
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde

Error - 3/26/2011 3:58:27 PM | Computer Name = IRWINA | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 3/26/2011 3:58:28 PM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 3/28/2011 7:54:17 AM | Computer Name = IRWINA | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 3/28/2011 7:54:42 AM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 3/28/2011 7:54:49 AM | Computer Name = IRWINA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
intelppm


< End of report >


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6198

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

3/28/2011 12:53:54 PM
mbam-log-2011-03-28 (12-53-54).txt

Scan type: Quick scan
Objects scanned: 163905
Time elapsed: 22 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi EricDSr,

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Reg
[HKLM\software\mozilla\Firefox\extensions]
"{0C619940-D883-4492-9EC5-EAFB3EBF9421}"=- 

:Files
C:\Documents and Settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}
C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58
ipconfig /flushdns /c

:Commands
[createrestorepoint]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Please open OTL if it is not opened after the reboot.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}\*.* /s



  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Please post back with
  • OTL fix log
  • OTL.txt
Any better?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI