Jcatsmom
Topic Starter
I am working on this computer for a friend. It is an e-machine with Windows XP SP 3. She brought the computer to me because it was shutting down within 5 minutes of startup. Dust removal from the power supply intact solved that. However the computer had expired McAfee on it and two rogue anti-virus programs. Malware Bytes and ESET Online Scanner removed those. When I installed Avast Free it found remnants of a bad trojan in an old Java. JavaRa and Control Panel program uninstaller will not remove a few of the old versions. I would appreciate your checking my scans since I was unable to complete the cleanup myself. -Jcatsmom
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/3/2011 9:31:24 AM
mbam-log-2011-05-03 (09-31-24).txt
Scan type: Quick scan
Objects scanned: 145451
Time elapsed: 16 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3AA42713-5C1E-48E2-B432-D8BF420DD31D} (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F919FBD3-A96B-4679-AF26-F551439BB5FD} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adware Pro_is1 (Rogue.AdwarePro) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DN_PA_VGT (Rogue.AntiMalwarePro) -> Value: DN_PA_VGT -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\program files\adware pro (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\definitions (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\adware pro (Rogue.AdWarePro) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\adware pro\adware_pro.exe (Rogue.AntiMalwarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\Desktop\adwarepro.lnk (Rogue.AdwarePro) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\microsoft\internet explorer\quick launch\adwarepro.lnk (Rogue.AdwarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\Cl.exe (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\folderpaths.txt (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\scheduleap.txt (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\Task.dat (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\unins000.dat (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\unins000.exe (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\definitions\200812.cab (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\adware pro\adwarepro.lnk (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\adware pro\uninstall adwarepro.lnk (Rogue.AdWarePro) -> Quarantined and deleted successfully.
AVAST
Found win32:kryptik-axt trojan in 2 restore files
ESET Online Scanner
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=91f6e881e2ea114eaf0e1f22a99054a4
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-05-03 04:56:35
# local_time=2011-05-03 11:56:35 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5121 16777189 100 75 11111481 32172237 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=87397
# found=1
# cleaned=1
# scan_time=5253
C:\Documents and Settings\Owner\My Documents\Downloads\onlinevegascasino.exe Win32/CazinoSilver application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
OTL logfile created on: 5/6/2011 12:42:35 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.07 Gb Total Space | 78.74 Gb Free Space | 72.87% Space Free | Partition Type: NTFS
Drive D: | 3.71 Gb Total Space | 1.67 Gb Free Space | 45.09% Space Free | Partition Type: FAT32
Computer Name: CHARLIE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\BigFix\BigFix.exe (BigFix Inc.)
PRC - C:\Program Files\Microsoft Office\Office\OSA.EXE ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - c:\Program Files\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll (RealPlayer)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (SunkFilt39) – C:\WINDOWS\system32\drivers\Sunkfilt39.sys (Alcor Micro Corp.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nv_agp) – C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:25442
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-tyc7"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-tyc7"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=f…YYYYYYYUS&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010/02/08 08:06:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/13 18:48:43 | 000,000,000 | —D | M]
[2010/06/15 12:30:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/04/04 16:41:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions
[2010/10/10 16:21:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/14 19:54:46 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/10 16:21:33 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/03/25 14:09:15 | 000,000,000 | —D | M] (Avery Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\[removed]
[2011/04/01 20:19:38 | 000,002,569 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\searchplugins\askcom.xml
[2011/04/11 04:41:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/10/19 06:55:06 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/23 07:05:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/23 07:04:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2010/02/03 02:58:06 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2010/05/23 07:04:18 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/19 18:07:01 | 000,002,024 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml
Hosts file not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk = C:\Program Files\BigFix\BigFix.exe (BigFix Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1121375441264 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://petsmartcharities.webex.com/client/…nbr/ieatgpc.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://www.qcc.com/images/kitch16_3.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 13:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O33 - MountPoints2\{b090ad61-6b37-11d9-9c11-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b090ad61-6b37-11d9-9c11-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b090ad61-6b37-11d9-9c11-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/06 12:39:51 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/05/03 15:30:12 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/05/03 14:10:12 | 001,858,032 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2011/05/03 14:10:12 | 000,072,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2011/05/03 14:10:12 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2011/05/03 14:10:12 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2011/05/03 14:10:12 | 000,063,984 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwma.dll
[2011/05/03 14:10:12 | 000,009,200 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2011/05/03 14:10:12 | 000,009,072 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2011/05/03 14:10:11 | 000,670,192 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2011/05/03 14:10:11 | 000,559,600 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2011/05/03 14:10:11 | 000,436,720 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2011/05/03 14:10:11 | 000,219,632 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2011/05/03 14:10:11 | 000,088,560 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2011/05/03 12:32:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/05/03 12:32:47 | 000,307,288 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/05/03 12:32:47 | 000,019,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/05/03 12:32:41 | 000,049,240 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/05/03 12:32:41 | 000,025,432 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/05/03 12:32:40 | 000,441,176 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/05/03 12:32:39 | 000,102,488 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/05/03 12:32:39 | 000,096,344 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/05/03 12:32:38 | 000,030,680 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/05/03 12:31:54 | 000,199,304 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/05/03 12:31:54 | 000,040,112 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/05/03 12:31:42 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/05/03 12:31:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/05/03 12:21:50 | 002,277,376 | —- | C] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw2010-no installer.exe
[2011/05/03 10:21:57 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/05/03 09:40:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\computer stuff
[2011/05/03 09:11:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/05/03 09:11:18 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/03 09:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/03 09:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/05/03 09:11:14 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/03 09:11:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/03 09:05:09 | 000,642,498 | —- | C] (EFD Software ) – C:\Documents and Settings\Owner\Desktop\hdtune_254.exe
[2011/05/03 09:04:56 | 001,390,080 | —- | C] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw.exe
[2011/04/27 12:20:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\May Transport 2
[2011/04/25 10:29:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\May Transport
[2011/04/22 16:18:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\9 Hullender Puppies
[2011/04/22 13:52:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Layne Puppies
[2011/04/20 17:21:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\June Transport
[2011/04/20 16:19:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Health Records
[2011/04/20 13:38:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Abandoned Puppies Hillcrest
[2011/04/19 20:13:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\May 17 Transport 1
[2006/01/07 11:56:03 | 020,798,256 | —- | C] (Netopsystems AG ) – C:\Program Files\AdbeRdr70_enu_full.exe
[6 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/06 12:42:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/06 12:41:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C2FA82CE-51FA-44CD-A334-E80749EB984D}.job
[2011/05/06 12:40:01 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/05/06 12:18:44 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/06 12:18:33 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/06 12:17:47 | 000,004,452 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/06 12:17:45 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/06 12:17:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/06 12:17:36 | 1543,032,832 | -HS- | M] () – C:\hiberfil.sys
[2011/05/05 10:30:05 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\NSSstub.job
[2011/05/03 21:01:00 | 000,000,234 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/05/03 17:36:00 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\WebReg HP Deskjet F4400 series.job
[2011/05/03 16:21:32 | 000,007,680 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/03 15:31:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/05/03 14:39:10 | 000,000,666 | —- | M] () – C:\Documents and Settings\Owner\Desktop\siw_init.xml
[2011/05/03 14:09:52 | 000,009,200 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2011/05/03 14:09:52 | 000,009,072 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2011/05/03 14:09:51 | 000,072,176 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2011/05/03 14:09:51 | 000,068,080 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2011/05/03 14:09:51 | 000,068,080 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2011/05/03 14:09:47 | 001,858,032 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2011/05/03 14:09:44 | 000,670,192 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2011/05/03 14:09:44 | 000,559,600 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2011/05/03 14:09:44 | 000,436,720 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2011/05/03 14:09:43 | 000,219,632 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2011/05/03 14:09:42 | 000,088,560 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2011/05/03 14:09:42 | 000,063,984 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxwma.dll
[2011/05/03 13:55:00 | 791,904,256 | —- | M] () – C:\WINDOWS\outlook.pst
[2011/05/03 12:32:48 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/05/03 12:32:39 | 000,002,625 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/05/03 09:11:19 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/01 22:04:16 | 001,079,743 | —- | M] () – C:\Documents and Settings\Owner\Desktop\United States federal budget - Wikipedia, the free encyclopedia.mht
[2011/05/01 04:45:06 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/04/28 17:05:36 | 000,325,083 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Sewanee Village Festival.jpg
[2011/04/26 08:29:01 | 000,330,327 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Regional SpayNeuter Workshops.jpg
[2011/04/22 11:56:55 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/20 15:23:54 | 000,018,841 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HealthRecord-Alexia.odt
[2011/04/18 12:25:12 | 000,040,112 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/04/18 12:25:10 | 000,199,304 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/04/18 12:17:46 | 000,441,176 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/18 12:17:34 | 000,307,288 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/04/18 12:16:18 | 000,049,240 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/04/18 12:16:06 | 000,102,488 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/04/18 12:16:02 | 000,096,344 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/04/18 12:13:21 | 000,025,432 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/04/18 12:13:02 | 000,030,680 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/04/18 12:12:58 | 000,019,544 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/04/16 03:36:04 | 000,352,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:18:38 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/16 03:14:54 | 000,441,388 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/16 03:14:54 | 000,071,324 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/16 03:07:12 | 000,000,118 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2011/04/15 18:39:20 | 000,002,093 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/04/13 09:18:38 | 000,100,006 | —- | M] () – C:\Documents and Settings\Owner\Desktop\TN License Plate Grant 2011_Spay-Neuter_Grants_AS_ISSUED_04_12_11.pdf
[6 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/05 10:30:04 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\NSSstub.job
[2011/05/03 14:39:10 | 000,000,666 | —- | C] () – C:\Documents and Settings\Owner\Desktop\siw_init.xml
[2011/05/03 12:32:48 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/05/03 09:11:19 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/01 22:04:08 | 001,079,743 | —- | C] () – C:\Documents and Settings\Owner\Desktop\United States federal budget - Wikipedia, the free encyclopedia.mht
[2011/04/28 17:05:07 | 000,325,083 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Sewanee Village Festival.jpg
[2011/04/26 08:28:40 | 000,330,327 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Regional SpayNeuter Workshops.jpg
[2011/04/20 06:52:06 | 000,018,841 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HealthRecord-Alexia.odt
[2011/04/17 09:35:21 | 000,055,689 | —- | C] () – C:\Documents and Settings\Owner\My Documents\W-4-V.xps
[2011/04/17 09:35:09 | 000,062,007 | —- | C] () – C:\Documents and Settings\Owner\My Documents\W-4V Form Kathy.xps
[2011/04/16 03:07:12 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2011/04/13 09:18:38 | 000,100,006 | —- | C] () – C:\Documents and Settings\Owner\Desktop\TN License Plate Grant 2011_Spay-Neuter_Grants_AS_ISSUED_04_12_11.pdf
[2010/06/15 11:58:56 | 000,147,813 | —- | C] () – C:\WINDOWS\hpoins37.dat.temp
[2010/06/15 11:58:56 | 000,000,504 | —- | C] () – C:\WINDOWS\hpomdl37.dat.temp
[2010/06/15 11:43:16 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\housecall.guid.cache
[2010/04/12 23:50:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\MSVolumeAP.dll
[2010/02/13 18:47:51 | 000,023,110 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2009/11/14 10:40:39 | 000,077,374 | —- | C] () – C:\WINDOWS\hpqins05.dat
[2009/09/09 09:44:41 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/07/28 10:27:57 | 000,147,345 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2009/07/28 10:27:57 | 000,000,504 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2008/12/29 11:22:56 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2008/11/28 23:21:31 | 000,000,736 | —- | C] () – C:\WINDOWS\SamsungMaster.INI
[2008/11/28 23:13:36 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/11/28 23:13:36 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/28 23:13:34 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\vidccleaner.exe
[2008/11/09 12:09:19 | 000,007,680 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/13 06:32:40 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/02 07:35:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2005/10/11 06:18:08 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/08/08 21:28:22 | 000,000,508 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/08/08 21:28:22 | 000,000,022 | —- | C] () – C:\WINDOWS\exchng.ini
[2005/07/20 14:38:43 | 000,020,094 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2005/01/20 18:27:48 | 000,471,300 | —- | C] () – C:\WINDOWS\wallpe.exe
[2005/01/20 18:24:17 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/08/27 05:50:59 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/27 04:54:47 | 000,516,096 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2004/08/26 13:07:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/26 13:01:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/26 11:12:43 | 000,001,222 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/08/26 11:12:43 | 000,000,487 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/08/26 11:12:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/26 11:12:10 | 000,441,388 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/26 11:12:10 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/26 11:12:10 | 000,071,324 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/26 11:12:10 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/26 11:12:08 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/26 11:12:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/26 11:12:05 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/26 11:12:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/26 11:11:59 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/26 11:11:54 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/26 11:11:46 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/26 05:54:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/26 05:54:01 | 000,352,176 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[1996/11/21 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1996/11/21 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/21 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2011/04/16 03:07:11 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\aeca67
[2011/05/03 12:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/21 10:06:31 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\BMHYGAPIBQP
[2009/02/03 13:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/09/18 13:54:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/12 23:50:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVP 2009
[2010/03/04 13:39:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2005/01/20 18:31:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2005/07/20 14:39:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/06/10 19:53:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2010/02/19 15:08:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\webex
[2011/05/05 10:30:05 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\NSSstub.job
[2011/05/03 21:01:00 | 000,000,234 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/05/06 12:46:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C2FA82CE-51FA-44CD-A334-E80749EB984D}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/09/28 07:17:21 | 000,361,984 | —- | M] () – C:\2008FastTrackLow-IncomeS-N.doc
[2009/09/20 16:12:56 | 000,208,896 | —- | M] () – C:\AASC Yard Sale 9-26-09.doc
[2004/08/26 13:04:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/05/03 15:31:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2005/07/14 11:29:00 | 000,000,103 | —- | M] () – C:\BootErr.log
[2010/04/27 08:33:51 | 000,307,379 | —- | M] () – C:\Bouldin Ad April 29 10 - 2 (1).pdf
[2010/04/27 08:46:40 | 000,307,379 | —- | M] () – C:\Bouldin Ad April 29 10 - 2 .pdf
[2010/04/12 22:11:50 | 000,306,380 | —- | M] () – C:\Bouldin Ad1.jpg
[2010/04/12 22:11:50 | 000,269,000 | —- | M] () – C:\Bouldin Ad1.pdf
[2010/04/12 22:11:50 | 000,371,970 | —- | M] () – C:\Bouldin Ad1.tif
[2005/08/25 07:00:05 | 000,041,984 | —- | M] () – C:\CallahanJennifer.xls
[2006/04/24 10:53:52 | 000,019,456 | —- | M] () – C:\Closing Words for Full Page Ad.doc
[2004/08/26 13:04:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/02/22 22:38:31 | 000,098,816 | —- | M] () – C:\ContractMod05-06,Budget&CoverPg-GRUNDY.doc;
[2005/08/25 06:59:38 | 000,041,984 | —- | M] () – C:\CoxLonnieMichaelShane.xls
[2010/04/12 23:04:59 | 000,005,735 | —- | M] () – C:\CybDefInstallInfo.log
[2005/10/14 05:33:10 | 000,004,717 | -H– | M] () – C:\ffastun.ffa
[2005/10/14 05:33:10 | 000,352,256 | -H– | M] () – C:\ffastun.ffl
[2005/10/14 05:33:10 | 000,143,360 | -H– | M] () – C:\ffastun.ffo
[2005/10/14 05:33:10 | 000,925,696 | -H– | M] () – C:\ffastun0.ffx
[2005/08/25 07:00:18 | 000,041,984 | —- | M] () – C:\FultsAmandaM.xls
[2005/09/14 22:00:12 | 001,312,256 | —- | M] () – C:\GCBE-IN 2005-2006.xls
[2006/09/17 20:54:03 | 001,312,256 | —- | M] () – C:\GCBEIN06-Aug.xls
[2005/08/25 06:59:55 | 000,041,984 | —- | M] () – C:\HackworthKimberlyJ.xls
[2011/05/06 12:17:36 | 1543,032,832 | -HS- | M] () – C:\hiberfil.sys
[2009/09/20 11:56:26 | 000,210,944 | —- | M] () – C:\HUGE YARD SALE TO BENEFIT AASC.doc
[2005/08/25 06:59:03 | 000,041,984 | —- | M] () – C:\HullenderJessicaD.xls
[2008/08/28 18:16:04 | 025,787,104 | —- | M] () – C:\InHope.mpeg
[2004/08/26 13:04:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/01/20 18:25:41 | 000,000,837 | -H– | M] () – C:\IPH.PH
[2011/05/03 19:51:39 | 000,028,357 | —- | M] () – C:\JavaRa.log
[2005/08/25 07:00:12 | 000,041,984 | —- | M] () – C:\KnightNatashaAnn.xls
[2005/08/25 06:59:47 | 000,042,496 | —- | M] () – C:\MeltonJessicaM.xls
[2004/08/26 13:04:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 14:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/19 18:02:46 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/06 12:17:35 | 704,643,072 | -HS- | M] () – C:\pagefile.sys
[2010/05/17 21:02:42 | 000,001,044 | —- | M] () – C:\Rescued Document.txt
[2005/08/25 07:00:31 | 000,042,496 | —- | M] () – C:\SandersCynthia.xls
[2005/07/14 12:19:35 | 000,452,096 | —- | M] () – C:\setup32.exe
[2006/01/03 20:21:21 | 000,000,254 | —- | M] () – C:\SmartInstaller.log
[2008/04/13 07:40:58 | 000,086,528 | —- | M] () – C:\Summary of Performance.doc
[2008/04/15 17:13:11 | 000,033,280 | —- | M] () – C:\Tips to Filling Application djt foundation sn.doc
[2008/08/04 13:56:10 | 000,033,280 | —- | M] () – C:\Tips to Filling Application for spay neuter grant.doc
[2009/09/28 13:22:42 | 000,040,960 | —- | M] () – C:\Wally's Confirmation List Blank.xls
[2009/10/10 12:22:04 | 000,017,920 | —- | M] () – C:\Wally's Transport Breakdown Blank.xls
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/26 13:03:59 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/10/06 15:37:30 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/04/18 12:25:12 | 000,040,112 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[1996/11/21 00:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\ArtGalry.cag
< %PROGRAMFILES%\*.* >
[2006/01/15 10:12:16 | 020,798,256 | —- | M] (Netopsystems AG ) – C:\Program Files\AdbeRdr70_enu_full.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/26 05:53:19 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/26 05:53:18 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/26 05:53:18 | 000,864,256 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/19 18:09:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/07/14 10:14:16 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/26 13:09:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/03/25 14:31:22 | 056,485,696 | —- | M] (Avery Dennison Corporation) – C:\Documents and Settings\Owner\Desktop\Avery Wizard 4.0.0.exe
[2008/01/20 13:49:28 | 000,642,498 | —- | M] (EFD Software ) – C:\Documents and Settings\Owner\Desktop\hdtune_254.exe
[2011/05/06 12:40:01 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2008/01/05 20:37:24 | 001,390,080 | —- | M] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw.exe
[2010/11/25 10:31:54 | 002,277,376 | —- | M] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw2010-no installer.exe
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-27 08:03:24
< >
< End of report >
OTL Extras logfile created on: 5/6/2011 12:42:35 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.07 Gb Total Space | 78.74 Gb Free Space | 72.87% Space Free | Partition Type: NTFS
Drive D: | 3.71 Gb Total Space | 1.67 Gb Free Space | 45.09% Space Free | Partition Type: FAT32
Computer Name: CHARLIE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent
"C:\Documents and Settings\Owner\Local Settings\Temp\7zSE2.tmp\SymNRT.exe" = C:\Documents and Settings\Owner\Local Settings\Temp\7zSE2.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0167F157-DAB9-46b0-86C4-7C66DDA85B48}" = HP Deskjet F4400 All-In-One Driver Software 12.0 Rel .5
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{03A7C57A-B2C8-409b-92E5-524A0DFD0DD3}" = Status
"{0409c45d-df44-4b98-93b0-572697aa054a}" = F4400
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2A329FB6-389D-4396-A974-29656D6864AE}" = MarketResearch
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3051B3D6-86F6-4FBB-8324-84EFC4FE296F}" = Motorola Phone Tools
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{3A94053A-EC5C-4061-8121-893FD68171C6}" = Greeting Card Factory Photo Card Maker 2.0
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{47808F78-F178-49DC-B708-15FE538B16FF}" = iTunes
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D304678-738E-42a0-931A-2B022F49DEB8}" = TrayApp
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6EED4269-588D-45b8-A80C-26A9CA62EE4E}" = HPSSupply
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}" = Motorola Driver Installation 3.4.0
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{91190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{9CCCFD9C-248F-47FE-9496-1680E3E5C163}" = Scan
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}" = Samsung Master
"{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}" = Motorola Phone Tools
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{d281ba0e-1617-4a62-bb37-b73671035e36}" = DJ_AIO_05_F4400_Software_Min
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F49FEF83-45CA-4CE8-8304-A7372BA07AA9}" = Motorola Phone Tools
"{F769B78E-FF0E-4db5-95E2-9F4C8D6352FE}" = DeviceDiscovery
"ActiveTouchMeetingClient" = WebEx
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"America Online us" = America Online (Choose which version to remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"avast" = avast! Free Antivirus
"BigFix" = BigFix
"Christmas" = Christmas Screen Saver
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"Easy Grade Pro" = Easy Grade Pro
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"Home Publishing" = Microsoft Greetings
"HP Imaging Device Functions" = HP Imaging Device Functions 12.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 12.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{47808F78-F178-49DC-B708-15FE538B16FF}" = iTunes
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Office8.0" = Microsoft Office 97, Standard Edition
"Port Magic" = Pure Networks Port Magic
"QuickTime" = QuickTime
"RealPlayer 12.0" = RealPlayer
"Shop for HP Supplies" = Shop for HP Supplies
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WJ III Compuscore and Profiles Program 2.1" = WJ III Compuscore and Profiles Program 2.1
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/3/2011 9:49:53 PM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:20 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:25 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:28 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:39 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:43 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:58 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: SolutionCenter – Error 1706. An installation package for
the product SolutionCenter cannot be found. Try the installation again using a
valid copy of the installation package 'SolutionCenter.msi'.
Error - 5/5/2011 11:32:04 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: GPBaseService2 – Error 1706. An installation package for
the product GPBaseService2 cannot be found. Try the installation again using a
valid copy of the installation package 'GPBaseService2.msi'.
Error - 5/5/2011 11:32:08 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: GPBaseService2 – Error 1706. An installation package for
the product GPBaseService2 cannot be found. Try the installation again using a
valid copy of the installation package 'GPBaseService2.msi'.
Error - 5/6/2011 1:22:30 PM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
[ System Events ]
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:58 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 9:49:14 PM | Computer Name = CHARLIE | Source = DCOM | ID = 10005
Description = DCOM got error "%5" attempting to start the service iPodService with
arguments "-Service" in order to run the server: {7A7FB085-6068-4898-8CCA-480A9187277C}
Error - 5/6/2011 1:21:55 PM | Computer Name = CHARLIE | Source = DCOM | ID = 10005
Description = DCOM got error "%5" attempting to start the service iPodService with
arguments "-Service" in order to run the server: {7A7FB085-6068-4898-8CCA-480A9187277C}
< End of report >
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/3/2011 9:31:24 AM
mbam-log-2011-05-03 (09-31-24).txt
Scan type: Quick scan
Objects scanned: 145451
Time elapsed: 16 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3AA42713-5C1E-48E2-B432-D8BF420DD31D} (Rogue.AntiVirus2008) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F919FBD3-A96B-4679-AF26-F551439BB5FD} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\init32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adware Pro_is1 (Rogue.AdwarePro) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DN_PA_VGT (Rogue.AntiMalwarePro) -> Value: DN_PA_VGT -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\program files\adware pro (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\definitions (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\adware pro (Rogue.AdWarePro) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\adware pro\adware_pro.exe (Rogue.AntiMalwarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\Desktop\adwarepro.lnk (Rogue.AdwarePro) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\microsoft\internet explorer\quick launch\adwarepro.lnk (Rogue.AdwarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\Cl.exe (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\folderpaths.txt (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\scheduleap.txt (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\Task.dat (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\unins000.dat (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\unins000.exe (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\program files\adware pro\definitions\200812.cab (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\adware pro\adwarepro.lnk (Rogue.AdWarePro) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\adware pro\uninstall adwarepro.lnk (Rogue.AdWarePro) -> Quarantined and deleted successfully.
AVAST
Found win32:kryptik-axt trojan in 2 restore files
ESET Online Scanner
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=91f6e881e2ea114eaf0e1f22a99054a4
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-05-03 04:56:35
# local_time=2011-05-03 11:56:35 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5121 16777189 100 75 11111481 32172237 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=87397
# found=1
# cleaned=1
# scan_time=5253
C:\Documents and Settings\Owner\My Documents\Downloads\onlinevegascasino.exe Win32/CazinoSilver application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
OTL logfile created on: 5/6/2011 12:42:35 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.07 Gb Total Space | 78.74 Gb Free Space | 72.87% Space Free | Partition Type: NTFS
Drive D: | 3.71 Gb Total Space | 1.67 Gb Free Space | 45.09% Space Free | Partition Type: FAT32
Computer Name: CHARLIE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe (NVIDIA Corporation)
PRC - C:\Program Files\BigFix\BigFix.exe (BigFix Inc.)
PRC - C:\Program Files\Microsoft Office\Office\OSA.EXE ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - c:\Program Files\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll (RealPlayer)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (SunkFilt39) – C:\WINDOWS\system32\drivers\Sunkfilt39.sys (Alcor Micro Corp.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nv_agp) – C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:25442
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-tyc7"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-tyc7"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: [removed]:3.9.1.14019
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=f…YYYYYYYUS&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2010/02/08 08:06:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/13 18:48:43 | 000,000,000 | —D | M]
[2010/06/15 12:30:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/04/04 16:41:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions
[2010/10/10 16:21:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/14 19:54:46 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/10 16:21:33 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/03/25 14:09:15 | 000,000,000 | —D | M] (Avery Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\extensions\[removed]
[2011/04/01 20:19:38 | 000,002,569 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\5jk8k0aa.default\searchplugins\askcom.xml
[2011/04/11 04:41:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/10/19 06:55:06 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/23 07:05:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/23 07:04:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2010/02/03 02:58:06 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2010/05/23 07:04:18 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/19 18:07:01 | 000,002,024 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml
Hosts file not found
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Avery Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk = C:\Program Files\BigFix\BigFix.exe (BigFix Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1121375441264 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://petsmartcharities.webex.com/client/…nbr/ieatgpc.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://www.qcc.com/images/kitch16_3.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 13:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O33 - MountPoints2\{b090ad61-6b37-11d9-9c11-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b090ad61-6b37-11d9-9c11-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{b090ad61-6b37-11d9-9c11-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/06 12:39:51 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/05/03 15:30:12 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/05/03 14:10:12 | 001,858,032 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2011/05/03 14:10:12 | 000,072,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2011/05/03 14:10:12 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2011/05/03 14:10:12 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2011/05/03 14:10:12 | 000,063,984 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwma.dll
[2011/05/03 14:10:12 | 000,009,200 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2011/05/03 14:10:12 | 000,009,072 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2011/05/03 14:10:11 | 000,670,192 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2011/05/03 14:10:11 | 000,559,600 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2011/05/03 14:10:11 | 000,436,720 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2011/05/03 14:10:11 | 000,219,632 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2011/05/03 14:10:11 | 000,088,560 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2011/05/03 12:32:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/05/03 12:32:47 | 000,307,288 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/05/03 12:32:47 | 000,019,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/05/03 12:32:41 | 000,049,240 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/05/03 12:32:41 | 000,025,432 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/05/03 12:32:40 | 000,441,176 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/05/03 12:32:39 | 000,102,488 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/05/03 12:32:39 | 000,096,344 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/05/03 12:32:38 | 000,030,680 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/05/03 12:31:54 | 000,199,304 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/05/03 12:31:54 | 000,040,112 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/05/03 12:31:42 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/05/03 12:31:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/05/03 12:21:50 | 002,277,376 | —- | C] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw2010-no installer.exe
[2011/05/03 10:21:57 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/05/03 09:40:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\computer stuff
[2011/05/03 09:11:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/05/03 09:11:18 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/05/03 09:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/03 09:11:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/05/03 09:11:14 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/05/03 09:11:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/03 09:05:09 | 000,642,498 | —- | C] (EFD Software ) – C:\Documents and Settings\Owner\Desktop\hdtune_254.exe
[2011/05/03 09:04:56 | 001,390,080 | —- | C] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw.exe
[2011/04/27 12:20:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\May Transport 2
[2011/04/25 10:29:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\May Transport
[2011/04/22 16:18:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\9 Hullender Puppies
[2011/04/22 13:52:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Layne Puppies
[2011/04/20 17:21:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\June Transport
[2011/04/20 16:19:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Health Records
[2011/04/20 13:38:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Abandoned Puppies Hillcrest
[2011/04/19 20:13:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\May 17 Transport 1
[2006/01/07 11:56:03 | 020,798,256 | —- | C] (Netopsystems AG ) – C:\Program Files\AdbeRdr70_enu_full.exe
[6 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/06 12:42:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/06 12:41:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C2FA82CE-51FA-44CD-A334-E80749EB984D}.job
[2011/05/06 12:40:01 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/05/06 12:18:44 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/06 12:18:33 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/06 12:17:47 | 000,004,452 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/06 12:17:45 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/06 12:17:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/06 12:17:36 | 1543,032,832 | -HS- | M] () – C:\hiberfil.sys
[2011/05/05 10:30:05 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\NSSstub.job
[2011/05/03 21:01:00 | 000,000,234 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/05/03 17:36:00 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\WebReg HP Deskjet F4400 series.job
[2011/05/03 16:21:32 | 000,007,680 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/03 15:31:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/05/03 14:39:10 | 000,000,666 | —- | M] () – C:\Documents and Settings\Owner\Desktop\siw_init.xml
[2011/05/03 14:09:52 | 000,009,200 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2011/05/03 14:09:52 | 000,009,072 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2011/05/03 14:09:51 | 000,072,176 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2011/05/03 14:09:51 | 000,068,080 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2011/05/03 14:09:51 | 000,068,080 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2011/05/03 14:09:47 | 001,858,032 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2011/05/03 14:09:44 | 000,670,192 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2011/05/03 14:09:44 | 000,559,600 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2011/05/03 14:09:44 | 000,436,720 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2011/05/03 14:09:43 | 000,219,632 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2011/05/03 14:09:42 | 000,088,560 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2011/05/03 14:09:42 | 000,063,984 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\pxwma.dll
[2011/05/03 13:55:00 | 791,904,256 | —- | M] () – C:\WINDOWS\outlook.pst
[2011/05/03 12:32:48 | 000,001,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/05/03 12:32:39 | 000,002,625 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/05/03 09:11:19 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/01 22:04:16 | 001,079,743 | —- | M] () – C:\Documents and Settings\Owner\Desktop\United States federal budget - Wikipedia, the free encyclopedia.mht
[2011/05/01 04:45:06 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/04/28 17:05:36 | 000,325,083 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Sewanee Village Festival.jpg
[2011/04/26 08:29:01 | 000,330,327 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Regional SpayNeuter Workshops.jpg
[2011/04/22 11:56:55 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/20 15:23:54 | 000,018,841 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HealthRecord-Alexia.odt
[2011/04/18 12:25:12 | 000,040,112 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2011/04/18 12:25:10 | 000,199,304 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2011/04/18 12:17:46 | 000,441,176 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/04/18 12:17:34 | 000,307,288 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2011/04/18 12:16:18 | 000,049,240 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/04/18 12:16:06 | 000,102,488 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/04/18 12:16:02 | 000,096,344 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2011/04/18 12:13:21 | 000,025,432 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/04/18 12:13:02 | 000,030,680 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/04/18 12:12:58 | 000,019,544 | —- | M] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/04/16 03:36:04 | 000,352,176 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:18:38 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/04/16 03:14:54 | 000,441,388 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/16 03:14:54 | 000,071,324 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/16 03:07:12 | 000,000,118 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[2011/04/15 18:39:20 | 000,002,093 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/04/13 09:18:38 | 000,100,006 | —- | M] () – C:\Documents and Settings\Owner\Desktop\TN License Plate Grant 2011_Spay-Neuter_Grants_AS_ISSUED_04_12_11.pdf
[6 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/05 10:30:04 | 000,000,380 | —- | C] () – C:\WINDOWS\tasks\NSSstub.job
[2011/05/03 14:39:10 | 000,000,666 | —- | C] () – C:\Documents and Settings\Owner\Desktop\siw_init.xml
[2011/05/03 12:32:48 | 000,001,689 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2011/05/03 09:11:19 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/01 22:04:08 | 001,079,743 | —- | C] () – C:\Documents and Settings\Owner\Desktop\United States federal budget - Wikipedia, the free encyclopedia.mht
[2011/04/28 17:05:07 | 000,325,083 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Sewanee Village Festival.jpg
[2011/04/26 08:28:40 | 000,330,327 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Regional SpayNeuter Workshops.jpg
[2011/04/20 06:52:06 | 000,018,841 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HealthRecord-Alexia.odt
[2011/04/17 09:35:21 | 000,055,689 | —- | C] () – C:\Documents and Settings\Owner\My Documents\W-4-V.xps
[2011/04/17 09:35:09 | 000,062,007 | —- | C] () – C:\Documents and Settings\Owner\My Documents\W-4V Form Kathy.xps
[2011/04/16 03:07:12 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2011/04/13 09:18:38 | 000,100,006 | —- | C] () – C:\Documents and Settings\Owner\Desktop\TN License Plate Grant 2011_Spay-Neuter_Grants_AS_ISSUED_04_12_11.pdf
[2010/06/15 11:58:56 | 000,147,813 | —- | C] () – C:\WINDOWS\hpoins37.dat.temp
[2010/06/15 11:58:56 | 000,000,504 | —- | C] () – C:\WINDOWS\hpomdl37.dat.temp
[2010/06/15 11:43:16 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\housecall.guid.cache
[2010/04/12 23:50:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\MSVolumeAP.dll
[2010/02/13 18:47:51 | 000,023,110 | —- | C] () – C:\WINDOWS\hpqins15.dat
[2009/11/14 10:40:39 | 000,077,374 | —- | C] () – C:\WINDOWS\hpqins05.dat
[2009/09/09 09:44:41 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/07/28 10:27:57 | 000,147,345 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2009/07/28 10:27:57 | 000,000,504 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2008/12/29 11:22:56 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2008/11/28 23:21:31 | 000,000,736 | —- | C] () – C:\WINDOWS\SamsungMaster.INI
[2008/11/28 23:13:36 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/11/28 23:13:36 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/28 23:13:34 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\vidccleaner.exe
[2008/11/09 12:09:19 | 000,007,680 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/12/13 06:32:40 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/12/02 07:35:17 | 000,037,027 | —- | C] () – C:\WINDOWS\atmoUn.exe
[2005/10/11 06:18:08 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2005/08/08 21:28:22 | 000,000,508 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/08/08 21:28:22 | 000,000,022 | —- | C] () – C:\WINDOWS\exchng.ini
[2005/07/20 14:38:43 | 000,020,094 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2005/01/20 18:27:48 | 000,471,300 | —- | C] () – C:\WINDOWS\wallpe.exe
[2005/01/20 18:24:17 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/08/27 05:50:59 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/27 04:54:47 | 000,516,096 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2004/08/26 13:07:50 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/26 13:01:37 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/26 11:12:43 | 000,001,222 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/08/26 11:12:43 | 000,000,487 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/08/26 11:12:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/26 11:12:10 | 000,441,388 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/26 11:12:10 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/26 11:12:10 | 000,071,324 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/26 11:12:10 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/26 11:12:08 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/26 11:12:07 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/26 11:12:05 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/26 11:12:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/26 11:11:59 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/26 11:11:54 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/26 11:11:46 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/26 05:54:56 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/26 05:54:01 | 000,352,176 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[1996/11/21 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1996/11/21 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/21 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2011/04/16 03:07:11 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\aeca67
[2011/05/03 12:31:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/21 10:06:31 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\BMHYGAPIBQP
[2009/02/03 13:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/09/18 13:54:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/04/12 23:50:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVP 2009
[2010/03/04 13:39:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2005/01/20 18:31:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2005/07/20 14:39:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/06/10 19:53:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2010/02/19 15:08:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\webex
[2011/05/05 10:30:05 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\NSSstub.job
[2011/05/03 21:01:00 | 000,000,234 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/05/06 12:46:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C2FA82CE-51FA-44CD-A334-E80749EB984D}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/09/28 07:17:21 | 000,361,984 | —- | M] () – C:\2008FastTrackLow-IncomeS-N.doc
[2009/09/20 16:12:56 | 000,208,896 | —- | M] () – C:\AASC Yard Sale 9-26-09.doc
[2004/08/26 13:04:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/05/03 15:31:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2005/07/14 11:29:00 | 000,000,103 | —- | M] () – C:\BootErr.log
[2010/04/27 08:33:51 | 000,307,379 | —- | M] () – C:\Bouldin Ad April 29 10 - 2 (1).pdf
[2010/04/27 08:46:40 | 000,307,379 | —- | M] () – C:\Bouldin Ad April 29 10 - 2 .pdf
[2010/04/12 22:11:50 | 000,306,380 | —- | M] () – C:\Bouldin Ad1.jpg
[2010/04/12 22:11:50 | 000,269,000 | —- | M] () – C:\Bouldin Ad1.pdf
[2010/04/12 22:11:50 | 000,371,970 | —- | M] () – C:\Bouldin Ad1.tif
[2005/08/25 07:00:05 | 000,041,984 | —- | M] () – C:\CallahanJennifer.xls
[2006/04/24 10:53:52 | 000,019,456 | —- | M] () – C:\Closing Words for Full Page Ad.doc
[2004/08/26 13:04:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/02/22 22:38:31 | 000,098,816 | —- | M] () – C:\ContractMod05-06,Budget&CoverPg-GRUNDY.doc;
[2005/08/25 06:59:38 | 000,041,984 | —- | M] () – C:\CoxLonnieMichaelShane.xls
[2010/04/12 23:04:59 | 000,005,735 | —- | M] () – C:\CybDefInstallInfo.log
[2005/10/14 05:33:10 | 000,004,717 | -H– | M] () – C:\ffastun.ffa
[2005/10/14 05:33:10 | 000,352,256 | -H– | M] () – C:\ffastun.ffl
[2005/10/14 05:33:10 | 000,143,360 | -H– | M] () – C:\ffastun.ffo
[2005/10/14 05:33:10 | 000,925,696 | -H– | M] () – C:\ffastun0.ffx
[2005/08/25 07:00:18 | 000,041,984 | —- | M] () – C:\FultsAmandaM.xls
[2005/09/14 22:00:12 | 001,312,256 | —- | M] () – C:\GCBE-IN 2005-2006.xls
[2006/09/17 20:54:03 | 001,312,256 | —- | M] () – C:\GCBEIN06-Aug.xls
[2005/08/25 06:59:55 | 000,041,984 | —- | M] () – C:\HackworthKimberlyJ.xls
[2011/05/06 12:17:36 | 1543,032,832 | -HS- | M] () – C:\hiberfil.sys
[2009/09/20 11:56:26 | 000,210,944 | —- | M] () – C:\HUGE YARD SALE TO BENEFIT AASC.doc
[2005/08/25 06:59:03 | 000,041,984 | —- | M] () – C:\HullenderJessicaD.xls
[2008/08/28 18:16:04 | 025,787,104 | —- | M] () – C:\InHope.mpeg
[2004/08/26 13:04:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/01/20 18:25:41 | 000,000,837 | -H– | M] () – C:\IPH.PH
[2011/05/03 19:51:39 | 000,028,357 | —- | M] () – C:\JavaRa.log
[2005/08/25 07:00:12 | 000,041,984 | —- | M] () – C:\KnightNatashaAnn.xls
[2005/08/25 06:59:47 | 000,042,496 | —- | M] () – C:\MeltonJessicaM.xls
[2004/08/26 13:04:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 14:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/19 18:02:46 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/06 12:17:35 | 704,643,072 | -HS- | M] () – C:\pagefile.sys
[2010/05/17 21:02:42 | 000,001,044 | —- | M] () – C:\Rescued Document.txt
[2005/08/25 07:00:31 | 000,042,496 | —- | M] () – C:\SandersCynthia.xls
[2005/07/14 12:19:35 | 000,452,096 | —- | M] () – C:\setup32.exe
[2006/01/03 20:21:21 | 000,000,254 | —- | M] () – C:\SmartInstaller.log
[2008/04/13 07:40:58 | 000,086,528 | —- | M] () – C:\Summary of Performance.doc
[2008/04/15 17:13:11 | 000,033,280 | —- | M] () – C:\Tips to Filling Application djt foundation sn.doc
[2008/08/04 13:56:10 | 000,033,280 | —- | M] () – C:\Tips to Filling Application for spay neuter grant.doc
[2009/09/28 13:22:42 | 000,040,960 | —- | M] () – C:\Wally's Confirmation List Blank.xls
[2009/10/10 12:22:04 | 000,017,920 | —- | M] () – C:\Wally's Transport Breakdown Blank.xls
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/26 13:03:59 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/10/06 15:37:30 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp083.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/04/18 12:25:12 | 000,040,112 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[1996/11/21 00:00:00 | 000,000,002 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\ArtGalry.cag
< %PROGRAMFILES%\*.* >
[2006/01/15 10:12:16 | 020,798,256 | —- | M] (Netopsystems AG ) – C:\Program Files\AdbeRdr70_enu_full.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/26 05:53:19 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/26 05:53:18 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/26 05:53:18 | 000,864,256 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/19 18:09:20 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/07/14 10:14:16 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/26 13:09:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/03/25 14:31:22 | 056,485,696 | —- | M] (Avery Dennison Corporation) – C:\Documents and Settings\Owner\Desktop\Avery Wizard 4.0.0.exe
[2008/01/20 13:49:28 | 000,642,498 | —- | M] (EFD Software ) – C:\Documents and Settings\Owner\Desktop\hdtune_254.exe
[2011/05/06 12:40:01 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2008/01/05 20:37:24 | 001,390,080 | —- | M] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw.exe
[2010/11/25 10:31:54 | 002,277,376 | —- | M] (Topala Software Solutions) – C:\Documents and Settings\Owner\Desktop\siw2010-no installer.exe
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-27 08:03:24
< >
< End of report >
OTL Extras logfile created on: 5/6/2011 12:42:35 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.07 Gb Total Space | 78.74 Gb Free Space | 72.87% Space Free | Partition Type: NTFS
Drive D: | 3.71 Gb Total Space | 1.67 Gb Free Space | 45.09% Space Free | Partition Type: FAT32
Computer Name: CHARLIE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe – (Hewlett-Packard Co.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent
"C:\Documents and Settings\Owner\Local Settings\Temp\7zSE2.tmp\SymNRT.exe" = C:\Documents and Settings\Owner\Local Settings\Temp\7zSE2.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0167F157-DAB9-46b0-86C4-7C66DDA85B48}" = HP Deskjet F4400 All-In-One Driver Software 12.0 Rel .5
"{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}" = RealNetworks - Microsoft Visual C++ 2005 Runtime
"{03A7C57A-B2C8-409b-92E5-524A0DFD0DD3}" = Status
"{0409c45d-df44-4b98-93b0-572697aa054a}" = F4400
"{087A66B8-1F0F-4a8d-A649-0CFE276AA7C0}" = WebReg
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2A329FB6-389D-4396-A974-29656D6864AE}" = MarketResearch
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{3051B3D6-86F6-4FBB-8324-84EFC4FE296F}" = Motorola Phone Tools
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{39CB30DB-27F8-4dd4-A294-CB4AE3B584FD}" = Copy
"{3A94053A-EC5C-4061-8121-893FD68171C6}" = Greeting Card Factory Photo Card Maker 2.0
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{47808F78-F178-49DC-B708-15FE538B16FF}" = iTunes
"{47ECCB1F-2811-49C0-B6A7-26778639ABA0}" = 32 Bit HP CIO Components Installer
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D304678-738E-42a0-931A-2B022F49DEB8}" = TrayApp
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6EED4269-588D-45b8-A80C-26A9CA62EE4E}" = HPSSupply
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{81B3BEF9-5D97-4096-86E9-5B48A5BC32D0}" = Motorola Driver Installation 3.4.0
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{91190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{9CCCFD9C-248F-47FE-9496-1680E3E5C163}" = Scan
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC13BA3A-336B-45a4-B3FE-2D3058A7B533}" = Toolbox
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}" = Samsung Master
"{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}" = Motorola Phone Tools
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{d281ba0e-1617-4a62-bb37-b73671035e36}" = DJ_AIO_05_F4400_Software_Min
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F49FEF83-45CA-4CE8-8304-A7372BA07AA9}" = Motorola Phone Tools
"{F769B78E-FF0E-4db5-95E2-9F4C8D6352FE}" = DeviceDiscovery
"ActiveTouchMeetingClient" = WebEx
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"America Online us" = America Online (Choose which version to remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"avast" = avast! Free Antivirus
"BigFix" = BigFix
"Christmas" = Christmas Screen Saver
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"Easy Grade Pro" = Easy Grade Pro
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"Home Publishing" = Microsoft Greetings
"HP Imaging Device Functions" = HP Imaging Device Functions 12.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 12.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{47808F78-F178-49DC-B708-15FE538B16FF}" = iTunes
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Office8.0" = Microsoft Office 97, Standard Edition
"Port Magic" = Pure Networks Port Magic
"QuickTime" = QuickTime
"RealPlayer 12.0" = RealPlayer
"Shop for HP Supplies" = Shop for HP Supplies
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WJ III Compuscore and Profiles Program 2.1" = WJ III Compuscore and Profiles Program 2.1
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/3/2011 9:49:53 PM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:20 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:25 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:28 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:39 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:43 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
Error - 5/5/2011 11:31:58 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: SolutionCenter – Error 1706. An installation package for
the product SolutionCenter cannot be found. Try the installation again using a
valid copy of the installation package 'SolutionCenter.msi'.
Error - 5/5/2011 11:32:04 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: GPBaseService2 – Error 1706. An installation package for
the product GPBaseService2 cannot be found. Try the installation again using a
valid copy of the installation package 'GPBaseService2.msi'.
Error - 5/5/2011 11:32:08 AM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: GPBaseService2 – Error 1706. An installation package for
the product GPBaseService2 cannot be found. Try the installation again using a
valid copy of the installation package 'GPBaseService2.msi'.
Error - 5/6/2011 1:22:30 PM | Computer Name = CHARLIE | Source = MsiInstaller | ID = 11706
Description = Product: HPProductAssistant – Error 1706. An installation package
for the product HPProductAssistant cannot be found. Try the installation again
using a valid copy of the installation package 'HPProductAssistant.msi'.
[ System Events ]
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:57 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 8:56:58 PM | Computer Name = CHARLIE | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 5/3/2011 9:49:14 PM | Computer Name = CHARLIE | Source = DCOM | ID = 10005
Description = DCOM got error "%5" attempting to start the service iPodService with
arguments "-Service" in order to run the server: {7A7FB085-6068-4898-8CCA-480A9187277C}
Error - 5/6/2011 1:21:55 PM | Computer Name = CHARLIE | Source = DCOM | ID = 10005
Description = DCOM got error "%5" attempting to start the service iPodService with
arguments "-Service" in order to run the server: {7A7FB085-6068-4898-8CCA-480A9187277C}
< End of report >