Jack P
Topic Starter
Didn't understand that it was a virus at first and ran a checkdisk. When it came back up there were no desktop icons and warning messages where I figured out it was an infection.
Ran Malwarebytes, SuperAntiSpyware and Vipre (was outdated when the virus came, but updated it)
The main parts of the infection are gone, but it looked like that it had removed all desktop icons, all items under "All Programs", all files in My Documents. Realized that the attributes for them were set to Hidden and Read Only. Was able to reset them back. Unfortunately many of the submenus are empty.
Still a problem: The programs that were pinned to the Start button and redirects in Firefox. Haven't test IE. Also Microsoft Office icons haven't shown up. I can run them from Program Files.
Posted the results for them and just ran otl with it's results.
Thanks for your help.
SuperAntiSpyware
==============================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 05/30/2011 at 12:52 PM
Application Version : 4.41.1000
Core Rules Database Version : 7164
Trace Rules Database Version: 4976
Scan type : Complete Scan
Total Scan Time : 00:39:21
Memory items scanned : 474
Memory threats detected : 0
Registry items scanned : 6292
Registry threats detected : 0
File items scanned : 21156
File threats detected : 79
Adware.Tracking Cookie
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@atdmt[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstbeacon[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@imrworldwide[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@insightexpressai[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@pointroll[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@revsci[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@apmebf[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][3].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstnet[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@invitemedia[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@interclick[3].txt
C:\Documents and Settings\Barbie\Cookies\[removed][3].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediabrandsww[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@collective-media[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@zedo[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediaplex[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@serving-sys[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adbrite[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@doubleclick[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
ec.atdmt.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
media.mtvnservices.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
media1.break.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
msnbcmedia.msn.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
spe.atdmt.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
C:\Documents and Settings\Barbie\Cookies\barbie@yieldmanager[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@msnportal.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@interclick[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@dmtracker[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@leeenterprises.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@112.2o7[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adbrite[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstbeacon[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@specificmedia[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adxpose[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@invitemedia[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@eyewonder[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@insightexpressai[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@martiniadnetwork[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@legolas-media[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@specificclick[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@msnbc.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediabrandsww[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@advertising[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CE1C12AC-59BB-4220-B895-862AF2DD144F}\RP919\A0144276.EXE
MalWareBytes
================================================================================
======
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6705
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/28/2011 4:53:52 PM
mbam-log-2011-05-28 (16-53-52).txt
Scan type: Full scan (C:\|)
Objects scanned: 40950
Time elapsed: 14 minute(s), 47 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
c:\documents and settings\all users\application data\lobouyvvyw.exe (Trojan.FakeMS) -> 1024 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LoBoUYvVYw (Trojan.FakeMS) -> Value: LoBoUYvVYw -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\lobouyvvyw.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
Second scan
============================================================================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6705
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/28/2011 8:07:58 PM
mbam-log-2011-05-28 (20-07-58).txt
Scan type: Full scan (C:\|)
Objects scanned: 206389
Time elapsed: 1 hour(s), 8 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
===============================================================================
OTL logfile created on: 5/30/2011 4:55:00 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.67 Mb Total Physical Memory | 590.51 Mb Available Physical Memory | 57.74% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.20% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 25.16 Gb Free Space | 67.52% Space Free | Partition Type: NTFS
Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Barbie\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_user_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_system_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_host.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_comm_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Verizon\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Iomega\REV System Software\ImIconXp.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\REV System Software\RevUDF.exe (Iomega Corp)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Barbie\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
========== Win32 Services (SafeList) ==========
SRV - (GoToAssist Express Customer) – C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (RevUDFService) – C:\Program Files\Iomega\REV System Software\RevUDF.exe (Iomega Corp)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (SbHips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman258) Acronis Try&Decide; and Restore Points filter (build 258) – C:\WINDOWS\system32\DRIVERS\tdrpm258.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (usbsermpt) – C:\WINDOWS\system32\drivers\usbsermpt.sys (Microsoft Corporation)
DRV - (imdrvfsf) – C:\WINDOWS\system32\DRIVERS\imdrvfsf.sys (Iomega Corporation)
DRV - (IABFilt) – C:\WINDOWS\system32\DRIVERS\IABFilt.sys (Iomega)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SMBios) Intel ® – C:\WINDOWS\system32\drivers\SMBios.sys (Intel Corporation)
DRV - (sf) – C:\WINDOWS\system32\drivers\sf.sys (Sonic Focus, Inc)
DRV - (MidiSyn) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (QV2KUX) – C:\WINDOWS\system32\drivers\qv2kux.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/default.aspx?mypg=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 F6 58 51 2A 17 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.msn.com/default.aspx?mypg=1"
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/23 13:13:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/05/23 13:13:46 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Extensions
[2011/05/23 14:13:05 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Firefox\Profiles\46esaizr.default\extensions
[2011/05/23 14:13:05 | 000,000,000 | -H-D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Firefox\Profiles\46esaizr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/23 13:13:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2010/08/05 10:15:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/14 09:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2001/08/23 09:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com Toolbar) - {37153479-1976-43C3-A1EE-557513977B64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\ImIconXp.exe (Iomega Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [yrsgtjkbutlqmc] File not found
O4 - HKLM..\RunOnceEx: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1143505706468 (WUWebControl Class)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} file://C:\TempEI4\EI40_\msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist Express Customer: DllName - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\System32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/27 17:10:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/30 13:18:44 | 000,000,000 | —D | C] – C:\VIPRERESCUE
[2011/05/30 12:10:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Application Data\SUPERAntiSpyware.com
[2011/05/28 16:52:27 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Recent
[2011/05/28 16:31:48 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Malwarebytes
[2011/05/28 16:19:06 | 000,074,968 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2011/05/28 16:16:22 | 000,021,592 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[2011/05/28 16:16:21 | 000,212,568 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbtis.sys
[2011/05/28 16:16:21 | 000,094,040 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbhips.sys
[2011/05/28 16:16:17 | 000,332,248 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFw.sys
[2011/05/28 16:16:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Sunbelt Software
[2011/05/28 16:05:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Windows XP Recovery
[2011/05/28 15:55:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Adobe
[2011/05/24 10:53:11 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/24 10:52:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\My Documents\Downloads
[2011/05/23 13:13:30 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Mozilla
[2011/05/23 13:13:30 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Mozilla
[2011/05/23 13:13:21 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/05/22 09:05:17 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Conduit
[2011/05/22 09:05:17 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/05/22 09:05:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Coupons.com
[2011/05/22 09:05:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Temp
[2011/05/22 09:05:14 | 000,000,000 | —D | C] – C:\Program Files\Coupons.com
[2011/05/22 09:04:47 | 000,398,760 | R— | C] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/05/22 09:04:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/22 09:04:44 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/20 17:40:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\GamesForOne
[2011/05/20 17:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesForOne
[2011/05/20 17:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Solitaire Plus!
[2011/05/20 17:40:40 | 000,000,000 | —D | C] – C:\Program Files\Solitaire Plus
[2011/05/20 17:08:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Mega Mahjongg
[2011/05/20 17:08:02 | 000,000,000 | —D | C] – C:\Program Files\Mega Mahjongg
[2011/05/20 17:04:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Encore
[2011/05/20 17:02:48 | 000,000,000 | —D | C] – C:\Program Files\Encore
[2011/05/20 16:59:25 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2011/05/20 16:59:24 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2011/05/20 16:59:24 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2011/05/20 16:59:23 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2011/05/20 16:59:23 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2011/05/20 16:59:22 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2011/05/20 16:59:22 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2011/05/20 16:59:22 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2011/05/20 16:59:21 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2011/05/20 16:59:21 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2011/05/20 16:59:20 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2011/05/20 16:59:20 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2011/05/20 16:59:20 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2011/05/20 16:59:19 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2011/05/20 16:59:15 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2011/05/20 16:59:11 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2011/05/20 16:59:11 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2011/05/20 16:59:03 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2011/05/20 16:59:02 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2011/05/20 16:59:02 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2011/05/20 16:59:01 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2011/05/20 16:59:01 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2011/05/20 16:59:01 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2011/05/20 16:59:00 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2011/05/20 16:59:00 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2011/05/20 16:59:00 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2011/05/20 16:58:59 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2011/05/20 16:58:59 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2011/05/20 16:58:59 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2011/05/20 16:58:49 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2011/05/20 16:58:49 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2011/05/20 16:58:49 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2011/05/20 16:58:48 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2011/05/20 16:58:48 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2011/05/20 16:58:47 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2011/05/20 16:58:47 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2011/05/20 16:58:47 | 000,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2011/05/20 16:58:46 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2011/05/20 16:58:44 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2011/05/20 16:57:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Best Buy Games
[2011/05/20 16:57:01 | 000,000,000 | —D | C] – C:\Program Files\Best Buy Games
[2011/05/20 15:22:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Motive
[2011/05/20 13:26:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\My Documents\Webshots Data
[2011/05/20 13:15:32 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/05/20 13:15:06 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/05/20 13:14:36 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/05/20 13:13:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\IECompatCache
[2011/05/20 13:13:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Macromedia
[2011/05/20 13:13:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Adobe
[2011/05/20 13:13:01 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\PrivacIE
[2011/05/20 13:12:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Google
[2011/05/20 13:12:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Google
[2011/05/20 13:11:08 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\KodakGallery
[2011/05/20 13:10:30 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/05/20 13:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Citrix
[2011/05/20 13:08:23 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Citrix
[2011/05/20 13:07:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Sunbelt
[2011/05/20 13:07:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Identities
[2011/05/20 13:07:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\My Documents\My Music
[2011/05/20 13:07:44 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\My Documents\My Pictures
[2011/05/20 13:07:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\IETldCache
[2011/05/20 13:07:38 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Microsoft
[2011/05/20 13:07:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\Barbie\Application Data\Microsoft
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Start Menu
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\SendTo
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\My Documents
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Favorites
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Application Data
[2011/05/20 13:07:36 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Startup
[2011/05/20 13:07:36 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Accessories
[2011/05/20 13:07:36 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\Cookies
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Templates
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\PrintHood
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\NetHood
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Desktop
[2011/05/20 13:01:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Citrix
[2011/05/11 16:55:16 | 000,027,984 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/30 16:37:25 | 000,444,394 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/30 16:37:25 | 000,072,270 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/30 16:33:40 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/30 16:33:29 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/30 16:33:12 | 000,050,257 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/30 16:33:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/30 14:28:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
[2011/05/28 18:54:27 | 000,000,742 | —- | M] () – C:\Documents and Settings\Barbie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.lnk
[2011/05/28 16:07:43 | 000,000,136 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:43 | 000,000,104 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | M] () – C:\Documents and Settings\All Users\Application Data\19914532
[2011/05/28 13:50:55 | 000,020,767 | —- | M] () – C:\logfile
[2011/05/24 10:53:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/23 13:13:32 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2011/05/22 09:04:48 | 000,398,760 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/05/20 17:40:45 | 000,000,685 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Solitaire Plus!.lnk
[2011/05/20 17:08:37 | 000,001,584 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Mega Mahjongg.lnk
[2011/05/20 17:07:20 | 000,000,083 | —- | M] () – C:\WINDOWS\encore_launcher.ini
[2011/05/20 17:04:43 | 000,002,053 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Game Center.lnk
[2011/05/20 15:01:16 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/05/20 14:18:13 | 000,248,696 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/20 14:01:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/05/20 13:25:40 | 000,003,584 | -H– | M] () – C:\Documents and Settings\Barbie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 13:10:12 | 000,001,184 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\GoToAssist Customer.lnk
[2011/05/11 16:26:04 | 000,074,968 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2011/05/11 16:26:04 | 000,021,592 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/28 18:54:27 | 000,000,742 | —- | C] () – C:\Documents and Settings\Barbie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.lnk
[2011/05/28 16:07:43 | 000,000,136 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:42 | 000,000,104 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | C] () – C:\Documents and Settings\All Users\Application Data\19914532
[2011/05/23 13:13:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/05/20 17:40:45 | 000,000,685 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Solitaire Plus!.lnk
[2011/05/20 17:08:37 | 000,001,584 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Mega Mahjongg.lnk
[2011/05/20 17:07:20 | 000,000,083 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2011/05/20 17:04:43 | 000,002,053 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Game Center.lnk
[2011/05/20 13:25:40 | 000,003,584 | -H– | C] () – C:\Documents and Settings\Barbie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 13:13:53 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
[2011/05/20 13:10:11 | 000,001,184 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\GoToAssist Customer.lnk
[2011/05/20 13:08:19 | 000,000,803 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Internet Explorer.lnk
[2011/05/20 13:07:51 | 000,000,738 | -H– | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Outlook Express.lnk
[2011/05/20 13:07:37 | 000,001,599 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Remote Assistance.lnk
[2011/05/20 13:07:37 | 000,000,792 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Windows Media Player.lnk
[2010/01/06 17:49:29 | 000,000,135 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2007/08/31 13:14:07 | 000,000,086 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2006/07/21 09:41:59 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/03/27 19:22:09 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2006/03/27 19:10:01 | 000,032,200 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006/03/27 19:10:01 | 000,020,910 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2006/03/27 19:10:01 | 000,020,869 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2006/03/27 19:10:01 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/03/27 19:06:27 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2006/03/27 19:06:12 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSPR320.ini
[2006/03/27 18:39:00 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/03/27 17:22:24 | 000,012,288 | R— | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/03/27 17:16:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/27 17:12:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/27 17:08:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/27 09:02:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/27 09:01:54 | 000,248,696 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/03/09 16:29:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/03/09 16:29:00 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/03/09 16:29:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/03/09 16:29:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/03/09 16:29:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/03/09 16:29:00 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/03/09 16:29:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/03/09 16:29:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/03/09 16:29:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/03/09 16:29:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/03/09 16:29:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2004/08/02 15:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 00:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/10/29 14:51:02 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NavLogon.dll
[2001/08/23 09:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 09:00:00 | 000,444,394 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 09:00:00 | 000,072,270 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 09:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/07/29 17:55:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/05/20 17:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesForOne
[2010/07/29 11:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 17:40:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Barbie\Application Data\GamesForOne
[2011/05/30 14:28:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/03/27 17:10:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/27 17:52:20 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/03/27 17:10:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/03 14:29:41 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2009/10/07 12:19:22 | 000,000,238 | —- | M] () – C:\INSTALL.LOG
[2006/03/27 17:10:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/28 13:50:55 | 000,020,767 | —- | M] () – C:\logfile
[2010/07/28 12:57:49 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup-1.46.exe
[2006/03/27 17:10:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/03/27 17:43:14 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/08 13:38:42 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/30 16:33:05 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2010/07/28 12:56:02 | 009,157,960 | —- | M] (SUPERAntiSpyware.com) – C:\SUPERAntiSpyware.exe
[2010/07/28 14:05:57 | 000,009,647 | -H– | M] () – C:\_NavCClt.Log
[2006/05/23 12:02:03 | 000,000,256 | -HS- | M] () – C:\__IOM_DEVLIB__.__ATTRIBUTES__
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/03/27 17:10:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/03/27 09:01:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/03/27 09:01:09 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/03/27 09:01:09 | 000,417,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
[2009/11/23 15:51:40 | 000,103,720 | —- | M] () – C:\WINDOWS\java\GoToAssistDownloadHelper.exe
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-20 21:01:49
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >
================================================================================
==================
OTL Extras logfile created on: 5/30/2011 4:55:00 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.67 Mb Total Physical Memory | 590.51 Mb Available Physical Memory | 57.74% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.20% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 25.16 Gb Free Space | 67.52% Space Free | Partition Type: NTFS
Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{109D28C7-FB38-483A-9C91-001CB59E2699}" = EPSON CardMonitor
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{141F2872-D2F9-4A89-95D3-E222D1CBCC56}" = Vz In Home Agent
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D97E163-946B-468B-97F3-CF0C3CC3DC1B}" = Norton Ghost Boot Disk Creator for REV
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{411C5D92-2AE4-436F-A027-1E441EDC05CE}" = VIPRE Antivirus Premium
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56AB063D-1450-4BDE-9F0D-E9C693429C51}" = netbrdg
"{5983C895-DDA4-45D9-A8D1-877D5DE7693E}" = EPSON PhotoStarter3.0
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{65D85050-5610-4A91-A3B1-D5C744291AD4}" = PCDADDIN
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8EEA1427-5C0D-469F-9FC6-A622A99D98EB}" = Trixie
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90FF23FE-0E1B-40DF-A22E-B4C0372E5936}" = Iomega Product Registration
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B351E5AF-E6E2-46E4-8155-DAB130731F70}" = Iomega REV System Software
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}" = VIPRE Antivirus Premium
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1
"{C99DCDA4-7407-4F72-A77E-C81C551D0C4E}" = PCDHELP
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Bookworm Deluxe_is1" = Bookworm Deluxe
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Coupons.com Toolbar" = Coupons.com Toolbar
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Status Monitor 2" = EPSON Status Monitor 2
"Google Updater" = Google Updater
"GoToAssist Express Customer" = GoToAssist Customer 1.6.0.290
"Hoyle Puzzle and Board Games Classic" = Hoyle Puzzle and Board Games Classic
"ie8" = Windows Internet Explorer 8
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mega Mahjongg" = Hoyle Mahjongg (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"Silent Package Run-Time Sample" = ESPR320 Reference Guide
"Solitaire Plus!_is1" = Solitaire Plus! version 3.0
"Verizon Help and Support" = Verizon Help and Support Tool
"Webshots Desktop" = Webshots Desktop
"WGA" = Windows Genuine Advantage Validation Tool
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/21/2010 6:17:55 PM | Computer Name = FRENCH-MAIN | Source = ESENT | ID = 439
Description = Catalog Database (1268) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb. Error
-1032.
Error - 7/21/2010 6:17:55 PM | Computer Name = FRENCH-MAIN | Source = ESENT | ID = 473
Description = Catalog Database (1268) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.
Error - 7/22/2010 6:49:57 PM | Computer Name = FRENCH-MAIN | Source = Acronis True Image Home | ID = 33
Description =
Error - 7/23/2010 1:34:03 PM | Computer Name = FRENCH-MAIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 7/23/2010 7:46:24 PM | Computer Name = FRENCH-MAIN | Source = Acronis True Image Home | ID = 33
Description =
Error - 7/26/2010 3:20:02 PM | Computer Name = FRENCH-MAIN | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 7/28/2010 4:08:04 PM | Computer Name = FRENCH-MAIN | Source = Norton AntiVirus | ID = 16711685
Description =
Error - 7/28/2010 5:07:05 PM | Computer Name = FRENCH-MAIN | Source = pctsSvc.exe | ID = 0
Description =
Error - 8/10/2010 4:32:28 PM | Computer Name = FRENCH-MAIN | Source = MsiInstaller | ID = 11904
Description = Product: PCDADDIN – Error 1904.Module C:\Program Files\Kodak\Kodak
EasyShare software\AddIn\VistaPCD.cyx failed to register. HRESULT . Contact your
support personnel.
Error - 5/30/2011 11:20:38 AM | Computer Name = BARBIE-PC | Source = Application Error | ID = 1000
Description = Faulting application services.exe, version 5.1.2600.5755, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00001de6.
[ System Events ]
Error - 5/30/2011 6:59:59 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 5/30/2011 7:02:22 PM | Computer Name = BARBIE-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D38BC63C-B887-4224-A6F3-A6F4DF8EFB6F}. The
backup browser is stopping.
Error - 5/30/2011 7:14:51 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
Error - 5/30/2011 7:14:51 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053
Error - 5/30/2011 7:25:50 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The McciCMService service terminated unexpectedly. It has done this
1 time(s).
Error - 5/30/2011 7:26:45 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 5/30/2011 7:26:51 PM | Computer Name = BARBIE-PC | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 5/30/2011 7:27:24 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The Acronis Scheduler2 Service service terminated unexpectedly. It
has done this 1 time(s).
Error - 5/30/2011 7:33:36 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 5/30/2011 7:35:52 PM | Computer Name = BARBIE-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D38BC63C-B887-4224-A6F3-A6F4DF8EFB6F}. The
backup browser is stopping.
< End of report >
Ran Malwarebytes, SuperAntiSpyware and Vipre (was outdated when the virus came, but updated it)
The main parts of the infection are gone, but it looked like that it had removed all desktop icons, all items under "All Programs", all files in My Documents. Realized that the attributes for them were set to Hidden and Read Only. Was able to reset them back. Unfortunately many of the submenus are empty.
Still a problem: The programs that were pinned to the Start button and redirects in Firefox. Haven't test IE. Also Microsoft Office icons haven't shown up. I can run them from Program Files.
Posted the results for them and just ran otl with it's results.
Thanks for your help.
SuperAntiSpyware
==============================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 05/30/2011 at 12:52 PM
Application Version : 4.41.1000
Core Rules Database Version : 7164
Trace Rules Database Version: 4976
Scan type : Complete Scan
Total Scan Time : 00:39:21
Memory items scanned : 474
Memory threats detected : 0
Registry items scanned : 6292
Registry threats detected : 0
File items scanned : 21156
File threats detected : 79
Adware.Tracking Cookie
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@atdmt[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstbeacon[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@imrworldwide[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@insightexpressai[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@pointroll[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@revsci[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@apmebf[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][3].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstnet[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@invitemedia[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@interclick[3].txt
C:\Documents and Settings\Barbie\Cookies\[removed][3].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediabrandsww[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@collective-media[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@zedo[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediaplex[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@serving-sys[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adbrite[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@doubleclick[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
ec.atdmt.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
media.mtvnservices.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
media1.break.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
msnbcmedia.msn.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
spe.atdmt.com [ C:\Documents and Settings\Barbie\Application Data\Macromedia\Flash Player\#SharedObjects\7SWQLG9W ]
C:\Documents and Settings\Barbie\Cookies\barbie@yieldmanager[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@msnportal.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@interclick[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@dmtracker[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@leeenterprises.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@112.2o7[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adbrite[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@burstbeacon[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@specificmedia[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@adxpose[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@invitemedia[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@eyewonder[2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@insightexpressai[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@martiniadnetwork[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@legolas-media[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@specificclick[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@msnbc.112.2o7[1].txt
C:\Documents and Settings\Barbie\Cookies\barbie@mediabrandsww[2].txt
C:\Documents and Settings\Barbie\Cookies\[removed][2].txt
C:\Documents and Settings\Barbie\Cookies\barbie@advertising[1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
C:\Documents and Settings\Barbie\Cookies\[removed][1].txt
Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{CE1C12AC-59BB-4220-B895-862AF2DD144F}\RP919\A0144276.EXE
MalWareBytes
================================================================================
======
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6705
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/28/2011 4:53:52 PM
mbam-log-2011-05-28 (16-53-52).txt
Scan type: Full scan (C:\|)
Objects scanned: 40950
Time elapsed: 14 minute(s), 47 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
c:\documents and settings\all users\application data\lobouyvvyw.exe (Trojan.FakeMS) -> 1024 -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\LoBoUYvVYw (Trojan.FakeMS) -> Value: LoBoUYvVYw -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\lobouyvvyw.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
Second scan
============================================================================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6705
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/28/2011 8:07:58 PM
mbam-log-2011-05-28 (20-07-58).txt
Scan type: Full scan (C:\|)
Objects scanned: 206389
Time elapsed: 1 hour(s), 8 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
===============================================================================
OTL logfile created on: 5/30/2011 4:55:00 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.67 Mb Total Physical Memory | 590.51 Mb Available Physical Memory | 57.74% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.20% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 25.16 Gb Free Space | 67.52% Space Free | Partition Type: NTFS
Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Barbie\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_user_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_system_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_host.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_comm_customer.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Verizon\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Iomega\REV System Software\ImIconXp.exe (Iomega Corporation)
PRC - C:\Program Files\Iomega\REV System Software\RevUDF.exe (Iomega Corp)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Barbie\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
========== Win32 Services (SafeList) ==========
SRV - (GoToAssist Express Customer) – C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SBAMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SBPIMSvc) – C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe (Sunbelt Software)
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (RevUDFService) – C:\Program Files\Iomega\REV System Software\RevUDF.exe (Iomega Corp)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (SbHips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman258) Acronis Try&Decide; and Restore Points filter (build 258) – C:\WINDOWS\system32\DRIVERS\tdrpm258.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (usbsermpt) – C:\WINDOWS\system32\drivers\usbsermpt.sys (Microsoft Corporation)
DRV - (imdrvfsf) – C:\WINDOWS\system32\DRIVERS\imdrvfsf.sys (Iomega Corporation)
DRV - (IABFilt) – C:\WINDOWS\system32\DRIVERS\IABFilt.sys (Iomega)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SMBios) Intel ® – C:\WINDOWS\system32\drivers\SMBios.sys (Intel Corporation)
DRV - (sf) – C:\WINDOWS\system32\drivers\sf.sys (Sonic Focus, Inc)
DRV - (MidiSyn) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (QV2KUX) – C:\WINDOWS\system32\drivers\qv2kux.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/default.aspx?mypg=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 F6 58 51 2A 17 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "http://my.msn.com/default.aspx?mypg=1"
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/23 13:13:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/05/23 13:13:46 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Extensions
[2011/05/23 14:13:05 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Firefox\Profiles\46esaizr.default\extensions
[2011/05/23 14:13:05 | 000,000,000 | -H-D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Barbie\Application Data\Mozilla\Firefox\Profiles\46esaizr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/05/23 13:13:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2010/08/05 10:15:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/14 09:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2001/08/23 09:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Coupons.com Toolbar) - {37153479-1976-43c3-a1ee-557513977b64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com Toolbar) - {37153479-1976-43C3-A1EE-557513977B64} - C:\Program Files\Coupons.com\prxtbCou0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\ImIconXp.exe (Iomega Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [yrsgtjkbutlqmc] File not found
O4 - HKLM..\RunOnceEx: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1143505706468 (WUWebControl Class)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} file://C:\TempEI4\EI40_\msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\GoToAssist Express Customer: DllName - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll - C:\Program Files\Citrix\GoToAssist Express Customer\290\g2ax_winlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\System32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/27 17:10:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/30 13:18:44 | 000,000,000 | —D | C] – C:\VIPRERESCUE
[2011/05/30 12:10:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Application Data\SUPERAntiSpyware.com
[2011/05/28 16:52:27 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Recent
[2011/05/28 16:31:48 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Malwarebytes
[2011/05/28 16:19:06 | 000,074,968 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2011/05/28 16:16:22 | 000,021,592 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[2011/05/28 16:16:21 | 000,212,568 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbtis.sys
[2011/05/28 16:16:21 | 000,094,040 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbhips.sys
[2011/05/28 16:16:17 | 000,332,248 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFw.sys
[2011/05/28 16:16:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Sunbelt Software
[2011/05/28 16:05:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Windows XP Recovery
[2011/05/28 15:55:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Adobe
[2011/05/24 10:53:11 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/24 10:52:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\My Documents\Downloads
[2011/05/23 13:13:30 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Mozilla
[2011/05/23 13:13:30 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Mozilla
[2011/05/23 13:13:21 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/05/22 09:05:17 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Conduit
[2011/05/22 09:05:17 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2011/05/22 09:05:16 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Coupons.com
[2011/05/22 09:05:14 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Temp
[2011/05/22 09:05:14 | 000,000,000 | —D | C] – C:\Program Files\Coupons.com
[2011/05/22 09:04:47 | 000,398,760 | R— | C] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/05/22 09:04:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Coupons
[2011/05/22 09:04:44 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2011/05/20 17:40:45 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\GamesForOne
[2011/05/20 17:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesForOne
[2011/05/20 17:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Solitaire Plus!
[2011/05/20 17:40:40 | 000,000,000 | —D | C] – C:\Program Files\Solitaire Plus
[2011/05/20 17:08:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Mega Mahjongg
[2011/05/20 17:08:02 | 000,000,000 | —D | C] – C:\Program Files\Mega Mahjongg
[2011/05/20 17:04:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Encore
[2011/05/20 17:02:48 | 000,000,000 | —D | C] – C:\Program Files\Encore
[2011/05/20 16:59:25 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_10.dll
[2011/05/20 16:59:24 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_36.dll
[2011/05/20 16:59:24 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_36.dll
[2011/05/20 16:59:23 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_36.dll
[2011/05/20 16:59:23 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_9.dll
[2011/05/20 16:59:22 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_35.dll
[2011/05/20 16:59:22 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_35.dll
[2011/05/20 16:59:22 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_35.dll
[2011/05/20 16:59:21 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_8.dll
[2011/05/20 16:59:21 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\X3DAudio1_2.dll
[2011/05/20 16:59:20 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_34.dll
[2011/05/20 16:59:20 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_34.dll
[2011/05/20 16:59:20 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_34.dll
[2011/05/20 16:59:19 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_3.dll
[2011/05/20 16:59:15 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_7.dll
[2011/05/20 16:59:11 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_33.dll
[2011/05/20 16:59:11 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_33.dll
[2011/05/20 16:59:03 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_33.dll
[2011/05/20 16:59:02 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_6.dll
[2011/05/20 16:59:02 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_5.dll
[2011/05/20 16:59:01 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2011/05/20 16:59:01 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_4.dll
[2011/05/20 16:59:01 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_1.dll
[2011/05/20 16:59:00 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_31.dll
[2011/05/20 16:59:00 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_3.dll
[2011/05/20 16:59:00 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_2.dll
[2011/05/20 16:58:59 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_2.dll
[2011/05/20 16:58:59 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_1.dll
[2011/05/20 16:58:59 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput1_1.dll
[2011/05/20 16:58:49 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2011/05/20 16:58:49 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine2_0.dll
[2011/05/20 16:58:49 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\x3daudio1_0.dll
[2011/05/20 16:58:48 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_29.dll
[2011/05/20 16:58:48 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2011/05/20 16:58:47 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_27.dll
[2011/05/20 16:58:47 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2011/05/20 16:58:47 | 000,061,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xinput9_1_0.dll
[2011/05/20 16:58:46 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2011/05/20 16:58:44 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_24.dll
[2011/05/20 16:57:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Best Buy Games
[2011/05/20 16:57:01 | 000,000,000 | —D | C] – C:\Program Files\Best Buy Games
[2011/05/20 15:22:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Motive
[2011/05/20 13:26:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\My Documents\Webshots Data
[2011/05/20 13:15:32 | 000,953,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mfc40u.dll
[2011/05/20 13:15:06 | 000,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\comctl32.dll
[2011/05/20 13:14:36 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndproxy.sys
[2011/05/20 13:13:55 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\IECompatCache
[2011/05/20 13:13:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Macromedia
[2011/05/20 13:13:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Adobe
[2011/05/20 13:13:01 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\PrivacIE
[2011/05/20 13:12:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Google
[2011/05/20 13:12:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Google
[2011/05/20 13:11:08 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\KodakGallery
[2011/05/20 13:10:30 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wab.exe
[2011/05/20 13:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Citrix
[2011/05/20 13:08:23 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Citrix
[2011/05/20 13:07:57 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Sunbelt
[2011/05/20 13:07:51 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Application Data\Identities
[2011/05/20 13:07:45 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\My Documents\My Music
[2011/05/20 13:07:44 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\My Documents\My Pictures
[2011/05/20 13:07:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\IETldCache
[2011/05/20 13:07:38 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings\Application Data\Microsoft
[2011/05/20 13:07:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\Barbie\Application Data\Microsoft
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Start Menu
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\SendTo
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\My Documents
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Favorites
[2011/05/20 13:07:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Barbie\Application Data
[2011/05/20 13:07:36 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Startup
[2011/05/20 13:07:36 | 000,000,000 | R–D | C] – C:\Documents and Settings\Barbie\Start Menu\Programs\Accessories
[2011/05/20 13:07:36 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Barbie\Cookies
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Templates
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\PrintHood
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\NetHood
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Local Settings
[2011/05/20 13:07:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Barbie\Desktop
[2011/05/20 13:01:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Citrix
[2011/05/11 16:55:16 | 000,027,984 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\sbbd.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/30 16:37:25 | 000,444,394 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/30 16:37:25 | 000,072,270 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/30 16:33:40 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/30 16:33:29 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/30 16:33:12 | 000,050,257 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/05/30 16:33:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/30 14:28:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
[2011/05/28 18:54:27 | 000,000,742 | —- | M] () – C:\Documents and Settings\Barbie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.lnk
[2011/05/28 16:07:43 | 000,000,136 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:43 | 000,000,104 | —- | M] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | M] () – C:\Documents and Settings\All Users\Application Data\19914532
[2011/05/28 13:50:55 | 000,020,767 | —- | M] () – C:\logfile
[2011/05/24 10:53:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/05/23 13:13:32 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2011/05/22 09:04:48 | 000,398,760 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/05/20 17:40:45 | 000,000,685 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Solitaire Plus!.lnk
[2011/05/20 17:08:37 | 000,001,584 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Mega Mahjongg.lnk
[2011/05/20 17:07:20 | 000,000,083 | —- | M] () – C:\WINDOWS\encore_launcher.ini
[2011/05/20 17:04:43 | 000,002,053 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\Game Center.lnk
[2011/05/20 15:01:16 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/05/20 14:18:13 | 000,248,696 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/05/20 14:01:22 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/05/20 13:25:40 | 000,003,584 | -H– | M] () – C:\Documents and Settings\Barbie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 13:10:12 | 000,001,184 | -H– | M] () – C:\Documents and Settings\Barbie\Desktop\GoToAssist Customer.lnk
[2011/05/11 16:26:04 | 000,074,968 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2011/05/11 16:26:04 | 000,021,592 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/28 18:54:27 | 000,000,742 | —- | C] () – C:\Documents and Settings\Barbie\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.lnk
[2011/05/28 16:07:43 | 000,000,136 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~19914532r
[2011/05/28 16:07:42 | 000,000,104 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~19914532
[2011/05/28 16:05:51 | 000,000,344 | —- | C] () – C:\Documents and Settings\All Users\Application Data\19914532
[2011/05/23 13:13:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/05/20 17:40:45 | 000,000,685 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Solitaire Plus!.lnk
[2011/05/20 17:08:37 | 000,001,584 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Mega Mahjongg.lnk
[2011/05/20 17:07:20 | 000,000,083 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2011/05/20 17:04:43 | 000,002,053 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Hoyle Puzzle and Board Games Classic.lnk
[2011/05/20 17:00:01 | 000,001,128 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\Game Center.lnk
[2011/05/20 13:25:40 | 000,003,584 | -H– | C] () – C:\Documents and Settings\Barbie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/20 13:13:53 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
[2011/05/20 13:10:11 | 000,001,184 | -H– | C] () – C:\Documents and Settings\Barbie\Desktop\GoToAssist Customer.lnk
[2011/05/20 13:08:19 | 000,000,803 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Internet Explorer.lnk
[2011/05/20 13:07:51 | 000,000,738 | -H– | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Outlook Express.lnk
[2011/05/20 13:07:37 | 000,001,599 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Remote Assistance.lnk
[2011/05/20 13:07:37 | 000,000,792 | —- | C] () – C:\Documents and Settings\Barbie\Start Menu\Programs\Windows Media Player.lnk
[2010/01/06 17:49:29 | 000,000,135 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2007/08/31 13:14:07 | 000,000,086 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2006/07/21 09:41:59 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/03/27 19:22:09 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2006/03/27 19:10:01 | 000,032,200 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006/03/27 19:10:01 | 000,020,910 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2006/03/27 19:10:01 | 000,020,869 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2006/03/27 19:10:01 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/03/27 19:06:27 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2006/03/27 19:06:12 | 000,000,044 | —- | C] () – C:\WINDOWS\EPSPR320.ini
[2006/03/27 18:39:00 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/03/27 17:22:24 | 000,012,288 | R— | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/03/27 17:16:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/03/27 17:12:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/03/27 17:08:07 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/03/27 09:02:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/03/27 09:01:54 | 000,248,696 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/03/09 16:29:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/03/09 16:29:00 | 001,519,616 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2006/03/09 16:29:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/03/09 16:29:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2006/03/09 16:29:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/03/09 16:29:00 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/03/09 16:29:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/03/09 16:29:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2006/03/09 16:29:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2006/03/09 16:29:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/03/09 16:29:00 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2004/08/02 15:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 00:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/10/29 14:51:02 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\NavLogon.dll
[2001/08/23 09:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 09:00:00 | 000,444,394 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 09:00:00 | 000,072,270 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 09:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2010/07/29 17:55:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2011/05/20 17:40:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesForOne
[2010/07/29 11:33:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/20 17:40:45 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Barbie\Application Data\GamesForOne
[2011/05/30 14:28:11 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{A2C07E96-00DE-4350-BB1D-BA91A01F7E29}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/03/27 17:10:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/27 17:52:20 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/03/27 17:10:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/04/03 14:29:41 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2009/10/07 12:19:22 | 000,000,238 | —- | M] () – C:\INSTALL.LOG
[2006/03/27 17:10:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/28 13:50:55 | 000,020,767 | —- | M] () – C:\logfile
[2010/07/28 12:57:49 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\mbam-setup-1.46.exe
[2006/03/27 17:10:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/03/27 17:43:14 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/08 13:38:42 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/30 16:33:05 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2010/07/28 12:56:02 | 009,157,960 | —- | M] (SUPERAntiSpyware.com) – C:\SUPERAntiSpyware.exe
[2010/07/28 14:05:57 | 000,009,647 | -H– | M] () – C:\_NavCClt.Log
[2006/05/23 12:02:03 | 000,000,256 | -HS- | M] () – C:\__IOM_DEVLIB__.__ATTRIBUTES__
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/03/27 17:10:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/03/27 09:01:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/03/27 09:01:09 | 000,626,688 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/03/27 09:01:09 | 000,417,792 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
[2009/11/23 15:51:40 | 000,103,720 | —- | M] () – C:\WINDOWS\java\GoToAssistDownloadHelper.exe
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-20 21:01:49
========== Alternate Data Streams ==========
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >
================================================================================
==================
OTL Extras logfile created on: 5/30/2011 4:55:00 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Barbie\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.67 Mb Total Physical Memory | 590.51 Mb Available Physical Memory | 57.74% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.20% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 25.16 Gb Free Space | 67.52% Space Free | Partition Type: NTFS
Computer Name: BARBIE-PC | User Name: Barbie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{109D28C7-FB38-483A-9C91-001CB59E2699}" = EPSON CardMonitor
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{141F2872-D2F9-4A89-95D3-E222D1CBCC56}" = Vz In Home Agent
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1D97E163-946B-468B-97F3-CF0C3CC3DC1B}" = Norton Ghost Boot Disk Creator for REV
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{411C5D92-2AE4-436F-A027-1E441EDC05CE}" = VIPRE Antivirus Premium
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56AB063D-1450-4BDE-9F0D-E9C693429C51}" = netbrdg
"{5983C895-DDA4-45D9-A8D1-877D5DE7693E}" = EPSON PhotoStarter3.0
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{65D85050-5610-4A91-A3B1-D5C744291AD4}" = PCDADDIN
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8EEA1427-5C0D-469F-9FC6-A622A99D98EB}" = Trixie
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90FF23FE-0E1B-40DF-A22E-B4C0372E5936}" = Iomega Product Registration
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B351E5AF-E6E2-46E4-8155-DAB130731F70}" = Iomega REV System Software
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D1FC57-3EB9-4B21-BCA3-F1C927508200}" = VIPRE Antivirus Premium
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1
"{C99DCDA4-7407-4F72-A77E-C81C551D0C4E}" = PCDHELP
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"Bookworm Deluxe_is1" = Bookworm Deluxe
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"Coupons.com Toolbar" = Coupons.com Toolbar
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Status Monitor 2" = EPSON Status Monitor 2
"Google Updater" = Google Updater
"GoToAssist Express Customer" = GoToAssist Customer 1.6.0.290
"Hoyle Puzzle and Board Games Classic" = Hoyle Puzzle and Board Games Classic
"ie8" = Windows Internet Explorer 8
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mega Mahjongg" = Hoyle Mahjongg (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"Silent Package Run-Time Sample" = ESPR320 Reference Guide
"Solitaire Plus!_is1" = Solitaire Plus! version 3.0
"Verizon Help and Support" = Verizon Help and Support Tool
"Webshots Desktop" = Webshots Desktop
"WGA" = Windows Genuine Advantage Validation Tool
"Windows XP Service Pack" = Windows XP Service Pack 3
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/21/2010 6:17:55 PM | Computer Name = FRENCH-MAIN | Source = ESENT | ID = 439
Description = Catalog Database (1268) Unable to write a shadowed header for file
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb. Error
-1032.
Error - 7/21/2010 6:17:55 PM | Computer Name = FRENCH-MAIN | Source = ESENT | ID = 473
Description = Catalog Database (1268) Database C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
was partially detached. Error -1032 encountered updating database headers.
Error - 7/22/2010 6:49:57 PM | Computer Name = FRENCH-MAIN | Source = Acronis True Image Home | ID = 33
Description =
Error - 7/23/2010 1:34:03 PM | Computer Name = FRENCH-MAIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 7/23/2010 7:46:24 PM | Computer Name = FRENCH-MAIN | Source = Acronis True Image Home | ID = 33
Description =
Error - 7/26/2010 3:20:02 PM | Computer Name = FRENCH-MAIN | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 7/28/2010 4:08:04 PM | Computer Name = FRENCH-MAIN | Source = Norton AntiVirus | ID = 16711685
Description =
Error - 7/28/2010 5:07:05 PM | Computer Name = FRENCH-MAIN | Source = pctsSvc.exe | ID = 0
Description =
Error - 8/10/2010 4:32:28 PM | Computer Name = FRENCH-MAIN | Source = MsiInstaller | ID = 11904
Description = Product: PCDADDIN – Error 1904.Module C:\Program Files\Kodak\Kodak
EasyShare software\AddIn\VistaPCD.cyx failed to register. HRESULT . Contact your
support personnel.
Error - 5/30/2011 11:20:38 AM | Computer Name = BARBIE-PC | Source = Application Error | ID = 1000
Description = Faulting application services.exe, version 5.1.2600.5755, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00001de6.
[ System Events ]
Error - 5/30/2011 6:59:59 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 5/30/2011 7:02:22 PM | Computer Name = BARBIE-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D38BC63C-B887-4224-A6F3-A6F4DF8EFB6F}. The
backup browser is stopping.
Error - 5/30/2011 7:14:51 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
Error - 5/30/2011 7:14:51 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053
Error - 5/30/2011 7:25:50 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The McciCMService service terminated unexpectedly. It has done this
1 time(s).
Error - 5/30/2011 7:26:45 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 5/30/2011 7:26:51 PM | Computer Name = BARBIE-PC | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.
Error - 5/30/2011 7:27:24 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7034
Description = The Acronis Scheduler2 Service service terminated unexpectedly. It
has done this 1 time(s).
Error - 5/30/2011 7:33:36 PM | Computer Name = BARBIE-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 5/30/2011 7:35:52 PM | Computer Name = BARBIE-PC | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{D38BC63C-B887-4224-A6F3-A6F4DF8EFB6F}. The
backup browser is stopping.
< End of report >