This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Never seen this before

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is acting up, getting a message that it will shut down in 60 secs with a countdown screen due to an error in a file called lsass.exe. I've been able to stop that, but little else.
I get a desktop background picture, but the icons are erratic loading as are the programs in the toolbar. In addition I've lost my broadband connection. Right now I'm working off my laptop and transferring 'fixes' via jump drive where I can. It's been getting progressively worse over the past 4-5 days. I've run Malbytes and it found 3 infections but apparently wasn't the fix.Also used Stinger . Whatever this is, it has a pretty good hold on my PC. Looking for some serious help!

:pullhair: I put these files on a jump drive and d/l them to here. No internet connection on the desktop….more files to come per the instructions.


OTL logfile created on: 7/30/2011 10:02:31 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.70 Gb Available Physical Memory | 83.09% Memory free
6.34 Gb Paging File | 5.81 Gb Available in Paging File | 91.72% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 406.47 Gb Free Space | 87.27% Space Free | Partition Type: NTFS
Drive H: | 3.73 Gb Total Space | 3.55 Gb Free Space | 95.16% Space Free | Partition Type: FAT32

Computer Name: DAD | User Name: DAD
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - H:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe (CA)
PRC - C:\WINDOWS\system32\svcprs32.exe ()
PRC - C:\WINDOWS\system32\mdmcls32.exe ()
PRC - C:\Program Files\Iomega\QuikProtect\startQuikProtect.exe (Iomega Corporation - An EMC Company)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\RetroExpress.exe (EMC Corporation)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\Retrospect.exe (EMC Corporation)
PRC - C:\Program Files\Retrospect\Retrospect Express HD 2.5\retrorun.exe (EMC Corporation)
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\KeirNet\K9\K9.exe (KeirNet)
PRC - C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)


========== Modules (SafeList) ==========

MOD - H:\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\UmxSbxw.dll (CA)
MOD - C:\WINDOWS\system32\UmxSbxExw.dll (CA)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe (CA)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (WinSvchostManager) – C:\WINDOWS\system32\svcprs32.exe ()
SRV - (WinExtManager) – C:\WINDOWS\system32\mdmcls32.exe ()
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (QSCopyEngine) – C:\Program Files\Iomega\QuikProtect\QpMonitor.exe ()
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (LinksysUpdater) – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe ()
SRV - (RetroExpLauncher) – C:\Program Files\Retrospect\Retrospect Express HD 2.5\retrorun.exe (EMC Corporation)
SRV - (p2pgasvc) – C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (AtiHDAudioService) – C:\WINDOWS\system32\drivers\AtihdXP3.sys (Advanced Micro Devices)
DRV - (SmartDefragDriver) – C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (KmxAMRT) – C:\WINDOWS\system32\DRIVERS\KmxAMRT.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\system32\drivers\KmxCfg.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\system32\drivers\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\system32\drivers\KmxCF.sys (CA)
DRV - (KmxFw) – C:\WINDOWS\system32\drivers\KmxFw.sys (CA)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\system32\drivers\KmxSbx.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\system32\drivers\KmxAgent.sys (CA)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (KmxAMVet) – C:\WINDOWS\system32\drivers\KmxAMVet.sys (Computer Associates International, Inc.)
DRV - (QsFsFltr) – C:\WINDOWS\system32\drivers\QsFsFltr.sys (Windows ® Codename Longhorn DDK provider)
DRV - (NmPar) – C:\WINDOWS\system32\drivers\NmPar.sys (Windows ® 2000 DDK provider)
DRV - (nmserial) – C:\WINDOWS\system32\drivers\NmSerial.sys (Windows ® 2000 DDK provider)
DRV - (purendis) – C:\WINDOWS\system32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\WINDOWS\system32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (mf) – C:\WINDOWS\system32\drivers\mf.sys (Microsoft Corporation)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (Pnp680r) – C:\WINDOWS\system32\DRIVERS\pnp680r.sys (Silicon Image, Inc)
DRV - (SenFiltService) – C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (AN983) – C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1

========== FireFox ==========


FF - user.js..browser.search.openintab: false

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\4.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/03 11:15:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\Firefox [2011/07/27 17:40:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/07/10 06:28:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.11\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2010/10/17 11:44:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions
[2010/08/14 08:42:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/10/17 11:44:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Extensions\[removed]
[2011/07/23 14:19:27 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions
[2010/08/15 15:47:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/17 13:20:39 | 000,000,000 | —D | M] (AddThis) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/08/15 13:43:56 | 000,000,000 | —D | M] (IE View) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/09/05 17:51:44 | 000,000,000 | —D | M] (Ancestry Toolbar) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2011/07/23 14:19:27 | 000,000,000 | —D | M] (Разпознаване на устройство Logitech) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2010/08/26 19:18:19 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Documents and Settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\extensions\[removed]
[2011/07/30 08:50:58 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/10/10 11:21:36 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/10 20:55:51 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/12 22:26:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/06 20:48:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/17 21:28:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/25 16:19:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/01 08:41:18 | 000,000,000 | —D | M] (Babylon) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/06/23 19:27:32 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/01/02 08:43:19 | 000,002,226 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/06/23 19:27:28 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/08/15 18:50:39 | 000,003,803 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\MyHeritage.xml

O1 HOSTS File: ([2011/07/27 19:50:31 | 000,000,736 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4 - HKLM..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe (Iomega Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LELA] C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe (Linksys LLC - A Division of Cisco Systems)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [QuiKProtect] C:\Program Files\Iomega\QuikProtect\startQuikProtect.exe (Iomega Corporation - An EMC Company)
O4 - HKLM..\Run: [RetroExpress] C:\Program Files\Retrospect\Retrospect Express HD 2.5\RetroExpress.exe (EMC Corporation)
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe (Mozy, Inc.)
O4 - Startup: C:\Documents and Settings\JIM\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (Palm, Inc.)
O4 - Startup: C:\Documents and Settings\JIM\Start Menu\Programs\Startup\Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe (KeirNet)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\WINDOWS\System32\winsflt.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] * in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: vectorvest.com ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - AppInit_DLLs: (UmxSbxExw.dll) - C:\WINDOWS\System32\UmxSbxExw.dll (CA)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JIM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 00:31:03 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (SmartDefragBootTime.exe) - C:\WINDOWS\System32\SmartDefragBootTime.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/07/30 20:34:52 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Application Data\Malwarebytes
[2011/07/30 19:43:42 | 000,041,272 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/30 19:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/30 19:43:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/07/30 19:43:39 | 000,022,712 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/30 19:43:39 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/07/30 12:40:45 | 000,000,000 | RH-D | C] – C:\Documents and Settings\JIM\Recent
[2011/07/30 09:04:55 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/07/30 08:54:41 | 000,000,000 | —D | C] – C:\Program Files\WebEx
[2011/07/30 08:54:10 | 000,023,984 | —- | C] (Cisco Systems, Inc.) – C:\WINDOWS\System32\drivers\pnarp.sys
[2011/07/30 08:54:03 | 000,025,264 | —- | C] (Cisco Systems, Inc.) – C:\WINDOWS\System32\drivers\purendis.sys
[2011/07/30 08:53:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Pure Networks Shared
[2011/07/30 08:53:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2011/07/30 08:50:57 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/07/30 08:50:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/07/30 08:50:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/07/30 08:32:13 | 000,939,368 | R— | C] (Macromedia, Inc.) – C:\WINDOWS\System32\myflash.ocx
[2011/07/29 16:21:24 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/07/28 18:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Application Data\ElevatedDiagnostics
[2011/07/28 18:46:51 | 000,347,920 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2011/07/27 19:06:27 | 000,101,392 | —- | C] (Advanced Micro Devices) – C:\WINDOWS\System32\drivers\AtihdXP3.sys
[2011/07/27 19:05:59 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2011/07/27 19:05:04 | 000,000,000 | —D | C] – C:\ATI
[2011/07/27 17:40:05 | 000,000,000 | —D | C] – C:\Program Files\ISSThirdParty
[2011/07/27 17:39:49 | 001,028,096 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\libeay32.dll
[2011/07/27 17:39:49 | 000,200,704 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\ssleay32.dll
[2011/07/27 17:39:47 | 002,654,208 | —- | C] (PureSight Technologies Ltd) – C:\WINDOWS\System32\winsflte.dll
[2011/07/27 17:39:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CA
[2011/07/27 08:27:01 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/07/27 08:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Local Settings\Application Data\eSupport.com
[2011/07/26 22:39:03 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2011/07/24 19:59:30 | 000,202,064 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\Isafprod.dll
[2011/07/24 19:59:30 | 000,128,336 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Isafeif.dll
[2011/07/24 19:59:30 | 000,095,568 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\Vetredir.dll
[2011/07/24 19:20:51 | 000,000,000 | —D | C] – C:\WINDOWS\rnapxs
[2011/07/24 19:20:50 | 000,007,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sporder.dll
[2011/07/24 19:18:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2011/07/24 19:07:50 | 157,866,568 | —- | C] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/24 09:11:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
[2011/07/24 09:11:07 | 000,000,000 | —D | C] – C:\Program Files\WhoCrashed
[2011/07/23 14:24:26 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\Logitech
[2011/07/23 14:21:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control Software Common
[2011/07/23 14:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Logitech
[2011/07/23 14:21:38 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2011/07/23 14:21:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Remote Control USB Driver
[2011/07/23 14:20:13 | 048,357,912 | —- | C] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/16 16:34:20 | 000,000,000 | —D | C] – C:\Documents and Settings\JIM\.frostwire5
[2011/07/10 06:28:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/07/10 06:28:27 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/07/10 06:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/10/24 19:18:28 | 000,638,976 | —- | C] (IObit) – C:\Program Files\Uninstall IObit Toolbar.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/30 21:31:37 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/30 21:31:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/30 19:43:42 | 000,000,805 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/30 16:38:48 | 000,889,547 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/07/30 16:38:48 | 000,782,812 | —- | M] () – C:\WINDOWS\System32\drivers\KmxAgent.asc
[2011/07/30 16:38:48 | 000,010,421 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/07/30 16:38:48 | 000,000,593 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/07/30 16:38:48 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/07/30 16:38:48 | 000,000,437 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/07/30 16:38:48 | 000,000,293 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/07/30 16:38:48 | 000,000,085 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/07/30 16:38:48 | 000,000,049 | —- | M] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/07/30 13:13:28 | 000,000,260 | —- | M] () – C:\WINDOWS\tasks\RegistryBooster.job
[2011/07/30 13:13:25 | 000,000,876 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/30 13:13:24 | 000,000,274 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-789336058-602162358-725345543-1003.job
[2011/07/30 13:13:22 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/07/30 13:13:22 | 000,000,266 | —- | M] () – C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2011/07/30 13:13:21 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/07/30 12:05:02 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/30 12:01:00 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/07/30 11:07:43 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-602162358-725345543-1003.job
[2011/07/30 09:15:06 | 000,540,196 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/07/30 09:15:06 | 000,102,218 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/07/30 09:03:48 | 000,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Linksys EasyLink Advisor.lnk
[2011/07/30 08:45:00 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/07/30 08:25:29 | 000,038,727 | —- | M] () – C:\WINDOWS\Ascd_tmp.ini
[2011/07/30 03:05:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{EA4A5498-D34B-4E54-B449-6EBC61565F69}
[2011/07/29 22:32:23 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{4F86B5D2-B903-4760-A51D-4B73D391025A}
[2011/07/29 15:25:07 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{7E5355BA-9FCF-4DED-B942-6EFA03FA7CFF}
[2011/07/29 03:05:31 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{2411FD5A-16E2-47FC-B408-BD9D03CB6FD5}
[2011/07/28 19:26:29 | 000,000,000 | —- | M] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{C5A1D182-8BF8-479D-9228-782ED0014663}
[2011/07/28 18:46:53 | 000,347,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2011/07/27 23:59:09 | 000,004,522 | —- | M] () – C:\WINDOWS\mozy.blk
[2011/07/27 23:59:09 | 000,002,208 | —- | M] () – C:\WINDOWS\mozy.flt
[2011/07/27 22:04:24 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/07/27 21:12:33 | 000,000,082 | —- | M] () – C:\Documents and Settings\JIM\Desktop\email protection fix.bat
[2011/07/27 19:50:31 | 000,000,736 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/27 18:45:20 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/07/27 18:36:03 | 000,000,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/07/27 17:39:49 | 005,845,744 | —- | M] () – C:\WINDOWS\System32\win32cpr.dll
[2011/07/27 17:39:49 | 001,872,624 | —- | M] () – C:\WINDOWS\System32\winsflt.dll
[2011/07/27 17:35:43 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/07/27 17:26:54 | 000,128,733 | —- | M] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/07/27 08:27:02 | 000,001,695 | —- | M] () – C:\Documents and Settings\JIM\Desktop\Uniblue RegistryBooster.lnk
[2011/07/27 08:27:02 | 000,001,672 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
[2011/07/24 22:00:00 | 000,000,380 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag.job
[2011/07/24 19:09:20 | 157,866,568 | —- | M] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/24 09:11:08 | 000,000,713 | —- | M] () – C:\Documents and Settings\JIM\Desktop\WhoCrashed.lnk
[2011/07/24 06:34:55 | 000,000,852 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/07/24 06:34:55 | 000,000,834 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Smart Defrag 2.lnk
[2011/07/24 06:28:44 | 000,000,699 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MozyHome Status.lnk
[2011/07/24 05:40:32 | 000,001,552 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AllMySongs Database.lnk
[2011/07/24 05:39:06 | 011,193,773 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2011/07/24 05:38:37 | 000,375,054 | —- | M] () – C:\1.bmp
[2011/07/23 14:24:19 | 000,002,031 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Harmony Remote Software 7.lnk
[2011/07/23 14:20:32 | 048,357,912 | —- | M] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/16 15:41:39 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/07/13 16:22:42 | 000,265,416 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/10 06:30:42 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/07/06 19:52:42 | 000,041,272 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/07/06 19:52:42 | 000,022,712 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/07/06 15:43:46 | 000,107,633 | —- | M] () – C:\Documents and Settings\JIM\My Documents\TDFX-WITHDRAWAL-OF-FUNDS.pdf
[2011/07/06 15:36:03 | 000,002,074 | -H– | M] () – C:\Documents and Settings\JIM\Desktop\maxdesk.ini2
[2011/07/06 15:31:57 | 000,424,031 | —- | M] () – C:\Documents and Settings\JIM\Desktop\TadawulFX Withdrawal Form.pdf
[2011/07/06 15:23:07 | 000,002,315 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PaperPort.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/30 19:43:42 | 000,000,805 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/07/30 03:05:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{EA4A5498-D34B-4E54-B449-6EBC61565F69}
[2011/07/29 22:32:23 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{4F86B5D2-B903-4760-A51D-4B73D391025A}
[2011/07/29 15:25:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{7E5355BA-9FCF-4DED-B942-6EFA03FA7CFF}
[2011/07/29 03:05:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{2411FD5A-16E2-47FC-B408-BD9D03CB6FD5}
[2011/07/28 19:26:29 | 000,000,000 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\{C5A1D182-8BF8-479D-9228-782ED0014663}
[2011/07/27 22:04:23 | 000,001,790 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2011/07/27 22:04:23 | 000,001,470 | —- | C] () – C:\Documents and Settings\JIM\Start Menu\Programs\Startup\HotSync Manager.lnk
[2011/07/27 21:12:33 | 000,000,082 | —- | C] () – C:\Documents and Settings\JIM\Desktop\email protection fix.bat
[2011/07/27 18:45:19 | 000,000,354 | —- | C] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/07/27 17:44:31 | 000,889,547 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2011/07/27 17:44:31 | 000,010,421 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2011/07/27 17:44:31 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k2
[2011/07/27 17:44:31 | 000,000,437 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k1
[2011/07/27 17:44:31 | 000,000,437 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k0
[2011/07/27 17:44:31 | 000,000,293 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2011/07/27 17:44:31 | 000,000,085 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k7
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k6
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k5
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k4
[2011/07/27 17:44:31 | 000,000,049 | —- | C] () – C:\WINDOWS\System32\drivers\kmxzone.u2k3
[2011/07/27 17:39:49 | 005,845,744 | —- | C] () – C:\WINDOWS\System32\win32cpr.dll
[2011/07/27 17:39:49 | 001,377,008 | —- | C] () – C:\WINDOWS\System32\svcprs32.exe
[2011/07/27 17:39:47 | 002,347,760 | —- | C] () – C:\WINDOWS\System32\mdmcls32.exe
[2011/07/27 17:39:47 | 001,872,624 | —- | C] () – C:\WINDOWS\System32\winsflt.dll
[2011/07/27 17:39:47 | 000,286,208 | —- | C] () – C:\WINDOWS\System32\winsfinst.exe
[2011/07/27 17:26:53 | 000,128,733 | —- | C] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/07/26 22:20:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/07/24 19:58:50 | 001,054,032 | —- | C] () – C:\WINDOWS\System32\cfgmig32.dll
[2011/07/24 19:20:52 | 002,385,136 | —- | C] () – C:\WINDOWS\System32\winsflt_x64.dll
[2011/07/24 09:11:08 | 000,000,713 | —- | C] () – C:\Documents and Settings\JIM\Desktop\WhoCrashed.lnk
[2011/07/24 06:34:58 | 000,029,520 | —- | C] () – C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/07/24 06:34:57 | 000,013,496 | —- | C] () – C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/07/24 05:39:04 | 011,193,773 | —- | C] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2011/07/23 14:24:19 | 000,002,031 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Harmony Remote Software 7.lnk
[2011/07/06 15:43:45 | 000,107,633 | —- | C] () – C:\Documents and Settings\JIM\My Documents\TDFX-WITHDRAWAL-OF-FUNDS.pdf
[2011/07/06 15:33:19 | 000,002,074 | -H– | C] () – C:\Documents and Settings\JIM\Desktop\maxdesk.ini2
[2011/07/06 15:31:54 | 000,424,031 | —- | C] () – C:\Documents and Settings\JIM\Desktop\TadawulFX Withdrawal Form.pdf
[2011/05/09 08:15:35 | 000,251,298 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/03/26 14:51:50 | 000,031,561 | —- | C] () – C:\WINDOWS\maxlink.ini
[2011/03/26 14:43:39 | 000,073,220 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2011/03/26 14:43:39 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2011/03/26 14:43:38 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2011/03/26 14:43:38 | 000,029,114 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2011/03/26 14:43:38 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2011/03/26 14:43:38 | 000,021,021 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2011/03/26 14:43:38 | 000,015,670 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2011/03/26 14:43:38 | 000,013,280 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2011/03/26 14:43:38 | 000,010,673 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2011/03/26 14:43:38 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2011/03/26 14:43:38 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2011/03/26 14:43:38 | 000,001,140 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2011/03/26 14:43:38 | 000,001,137 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2011/03/26 14:43:38 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2011/03/26 14:43:38 | 000,001,130 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2011/03/26 14:43:38 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2011/03/26 14:40:58 | 000,065,793 | —- | C] () – C:\WINDOWS\System32\esfw86.bin
[2011/03/26 14:40:11 | 000,000,044 | —- | C] () – C:\WINDOWS\WFGT1500.ini
[2011/01/02 11:33:50 | 000,027,801 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2011/01/02 11:33:50 | 000,007,765 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2011/01/02 11:04:11 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\gswin32c.exe
[2011/01/02 10:30:38 | 000,027,456 | —- | C] () – C:\WINDOWS\System32\solidlocalmon.dll
[2011/01/02 10:30:38 | 000,018,752 | —- | C] () – C:\WINDOWS\System32\solidlocalui.dll
[2011/01/02 10:23:04 | 000,020,886 | —- | C] () – C:\WINDOWS\System32\ddmon.dll
[2011/01/02 08:43:30 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\redmonnt.dll
[2010/11/15 21:08:52 | 000,000,537 | -H– | C] () – C:\Program Files\hpothb07.tif
[2010/11/15 21:08:52 | 000,000,327 | -H– | C] () – C:\Program Files\hpothb07.dat
[2010/08/15 22:37:19 | 001,669,496 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/15 21:53:37 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/08/15 21:22:20 | 000,013,312 | —- | C] () – C:\Documents and Settings\JIM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/15 18:49:49 | 000,000,302 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2010/08/15 18:48:49 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2010/08/15 18:09:51 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/08/14 08:42:47 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/08/11 19:54:18 | 000,000,007 | —- | C] () – C:\WINDOWS\System32\mkghj.dll
[2010/08/11 09:21:11 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 02:48:28 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2010/08/11 02:44:10 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/08/11 02:42:05 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2010/08/11 02:42:00 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2010/08/11 02:41:59 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2010/08/11 02:41:58 | 003,107,788 | R— | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2010/08/11 02:41:58 | 000,227,587 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2010/08/11 01:18:34 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2010/08/11 01:18:34 | 000,012,400 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2010/08/11 01:18:33 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2010/08/11 01:18:33 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2010/08/11 00:56:45 | 000,039,119 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2010/08/11 00:56:37 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/08/11 00:56:28 | 000,038,727 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2010/08/11 00:56:27 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010/08/11 00:51:42 | 000,000,158 | —- | C] () – C:\WINDOWS\pagesuit.ini
[2010/08/11 00:51:41 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\irisco32.dll
[2010/08/11 00:32:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 00:29:03 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/10 19:25:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/10 19:24:41 | 000,265,416 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/08/05 16:14:12 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ATIBRTMON.EXE
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2007/10/18 18:36:54 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\deskMenu2.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2002/08/29 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/08/29 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/08/29 07:00:00 | 000,540,196 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/08/29 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/08/29 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/08/29 07:00:00 | 000,102,218 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/08/29 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/08/29 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/08/29 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/08/29 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/05/29 08:50:02 | 000,552,960 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2000/08/29 03:59:12 | 002,971,392 | —- | C] () – C:\WINDOWS\Catherine Zeta Jones Saver V1.exe
[1999/01/22 13:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 03:00:00 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL

========== LOP Check ==========

[2010/12/05 10:31:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/07/24 19:18:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2011/07/24 19:07:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2011/05/01 08:28:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2010/10/10 20:44:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2010/08/15 18:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2011/07/30 21:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RetroExp
[2011/03/27 11:28:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/01/02 10:29:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SolidDocuments
[2010/10/23 23:34:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2010/10/10 20:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/07/30 09:04:59 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2011/07/29 23:36:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2011/06/22 17:47:22 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{AB2D8F2E-F7AD-4446-A11A-50D846B2CF2A}
[2011/05/01 09:55:11 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Acoustica
[2011/06/12 19:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/18 17:50:13 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\EarMaster
[2011/07/28 18:48:19 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\ElevatedDiagnostics
[2011/03/26 15:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\EPSON
[2011/06/07 20:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FixCleaner
[2010/09/18 17:57:14 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FreeFileViewer
[2011/07/24 05:59:33 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\FrostWire
[2011/04/27 17:06:30 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\IObit
[2010/08/15 17:48:13 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\K9
[2011/03/26 15:04:07 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Leadertech
[2010/08/15 18:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\MyHeritage
[2011/03/26 14:58:54 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\ScanSoft
[2010/08/15 17:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\The Complete Genealogy Reporter - FTB
[2010/08/14 08:42:46 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Thunderbird
[2010/08/11 01:15:01 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\TMP
[2011/06/06 08:42:40 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Uniblue
[2010/08/15 17:52:27 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\VectorVest, Inc
[2011/06/17 20:36:34 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\VSRevoGroup
[2011/06/27 15:24:55 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\webex
[2010/08/12 18:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Windows Desktop Search
[2010/08/12 19:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\JIM\Application Data\Windows Search
[2011/07/30 13:13:22 | 000,000,266 | —- | M] () – C:\WINDOWS\Tasks\ASC4_PerformanceMonitor.job
[2011/07/27 18:45:20 | 000,000,354 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2011/04/02 10:38:22 | 000,000,338 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1293986285.job
[2011/07/30 13:13:28 | 000,000,260 | —- | M] () – C:\WINDOWS\Tasks\RegistryBooster.job
[2011/07/30 12:01:00 | 000,000,230 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/07/24 22:00:00 | 000,000,380 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag.job
[2011/07/30 13:13:21 | 000,000,276 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job
[2010/12/31 19:54:43 | 000,000,418 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F9AF475E-4BA9-4B59-BA57-28BE3A55B301}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/07/24 05:38:37 | 000,375,054 | —- | M] () – C:\1.bmp
[2011/05/28 18:58:40 | 014,970,880 | —- | M] () – C:\AdamsFanning.paf
[2010/08/11 00:31:03 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/27 22:04:24 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/09/30 23:56:13 | 000,001,360 | —- | M] () – C:\caEntitlementLog.txt
[2011/07/27 17:47:00 | 002,695,826 | —- | M] () – C:\caisslog.txt
[2010/08/11 00:31:03 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2010/02/28 14:23:24 | 008,109,897 | —- | M] () – C:\Fanning Family Tree.ged
[2011/05/28 18:58:22 | 003,265,738 | —- | M] () – C:\Fanning Family Tree.lst
[2010/02/28 14:32:19 | 001,575,056 | —- | M] () – C:\FFTree.zip
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/08/11 00:31:03 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/13 08:41:10 | 000,365,568 | —- | M] () – C:\market_timers.ppt
[2011/02/05 17:47:16 | 000,000,000 | —- | M] () – C:\Medical1.txt
[2007/03/10 13:48:13 | 000,030,208 | —- | M] () – C:\MenardsComp.xls
[2008/08/31 16:22:25 | 000,031,232 | —- | M] () – C:\MenardsExpenses.xls
[2009/10/31 23:27:50 | 000,384,512 | —- | M] () – C:\MenardsLeads.xls
[2009/10/25 09:43:19 | 000,054,784 | —- | M] () – C:\MenardsLeads1.xls
[2010/01/18 12:37:13 | 000,082,944 | —- | M] () – C:\MenardsPayroll.xls
[2010/08/11 00:31:03 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/08/11 09:39:59 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/11 20:49:13 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/30 21:31:05 | 3488,591,872 | -HS- | M] () – C:\pagefile.sys
[2011/07/30 08:41:12 | 000,000,032 | —- | M] () – C:\t.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2010/08/15 19:13:15 | 000,000,152 | —- | M] () – C:\YServer.txt
[2010/10/02 16:56:51 | 000,000,308 | R— | M] () – C:\YukonInstall.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/08/11 00:30:53 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/11/15 21:09:30 | 000,000,327 | -H– | M] () – C:\Program Files\hpothb07.dat
[2010/11/15 21:08:52 | 000,000,537 | -H– | M] () – C:\Program Files\hpothb07.tif
[2010/10/12 22:01:02 | 000,638,976 | —- | M] (IObit) – C:\Program Files\Uninstall IObit Toolbar.dll

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/08/10 19:23:37 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/08/10 19:23:37 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/08/10 19:23:37 | 000,450,560 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/11 20:54:17 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/11 20:59:54 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/11 00:34:12 | 000,000,079 | —- | M] () – C:\Documents and Settings\JIM\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/10/10 20:26:26 | 000,939,956 | —- | M] () – C:\Documents and Settings\JIM\Desktop\7z465.exe
[2011/07/24 05:39:06 | 011,193,773 | —- | M] () – C:\Documents and Settings\JIM\Desktop\AMSDat20.exe
[2009/01/31 20:50:36 | 000,524,288 | —- | M] (Chaos Software Group, Inc.) – C:\Documents and Settings\JIM\Desktop\Atomic.exe
[2011/07/27 17:26:54 | 000,128,733 | —- | M] () – C:\Documents and Settings\JIM\Desktop\bluescreenview_setup.exe
[2011/06/16 18:45:58 | 027,862,496 | —- | M] () – C:\Documents and Settings\JIM\Desktop\family_tree_builder_5209i.exe
[2011/07/24 19:09:20 | 157,866,568 | —- | M] (CA, inc) – C:\Documents and Settings\JIM\Desktop\issdm_ca_en(1).exe
[2011/07/23 14:20:32 | 048,357,912 | —- | M] (Logitech Inc.) – C:\Documents and Settings\JIM\Desktop\LogitechHarmonyRemote7.7.0-WIN-x86.exe
[2011/07/28 18:46:53 | 000,347,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\JIM\Desktop\MicrosoftFixit.wu.Run.exe
[2010/10/23 23:24:44 | 011,437,504 | —- | M] (Mozy, Inc.) – C:\Documents and Settings\JIM\Desktop\mozy-2_2_4_0.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-25 14:02:07

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\JIM\Desktop\Atomic.exe:SummaryInformation
< End of report >


OTL Extras logfile created on: 7/30/2011 9:45:51 PM - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = H:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.72 Gb Available Physical Memory | 83.58% Memory free
6.34 Gb Paging File | 5.87 Gb Available in Paging File | 92.59% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 406.47 Gb Free Space | 87.27% Space Free | Partition Type: NTFS
Drive H: | 3.73 Gb Total Space | 3.55 Gb Free Space | 95.16% Space Free | Partition Type: FAT32

Computer Name: DAD | User Name: DAD
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe" = C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe:*:Enabled:Iomega Home Media Network Discover Application – (Iomega Corporation)
"C:\Program Files\Iomega\Home Storage Manager\Iomega Storage Manager.exe" = C:\Program Files\Iomega\Home Storage Manager\Iomega Storage Manager.exe:*:Enabled:Iomega Storage Manager – (Iomega Corp.)
"C:\Program Files\Iomega\QuikProtect\QuikProtect.exe" = C:\Program Files\Iomega\QuikProtect\QuikProtect.exe:*:Enabled:QuikProtect – (Iomega Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Mozilla Thunderbird\thunderbird.exe" = C:\Program Files\Mozilla Thunderbird\thunderbird.exe:*:Enabled:Thunderbird – (Mozilla Messaging)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire – (FrostWire Group)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0038B7BB-C6E6-59D4-8F6F-2B2E707F89F6}" = MozyHome
"{01A3E75B-54C0-407F-8B95-B77705C7DCC4}" = AMRT
"{022C4B5F-4A59-48DD-08A6-6EC5832DBFFE}" = Catalyst Control Center Localization Chinese Standard
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1148CE6F-6956-6ED3-1DBF-0A0046427A3E}" = CCC Help Swedish
"{1350E13C-A031-6574-961B-367DE4721E86}" = Catalyst Control Center Graphics Light
"{1367D815-EC9F-4e2f-9FB9-E40A075AD19B}" = DNAMigrator
"{14A776EF-3904-3C55-508F-BB093954391E}" = Catalyst Control Center Localization Dutch
"{19762EA5-8279-8FA8-5F16-7DEEF571E5D6}" = CCC Help Russian
"{1A90FD8B-8A64-8B83-D486-E507AEC997EF}" = Catalyst Control Center Graphics Full Existing
"{1D4C0096-98D0-5290-A5F7-AAA05121FA0A}" = CCC Help Danish
"{2681A52E-FCFA-4982-A030-7B652BDD346C}" = CA Personal Firewall
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{2E73FAB9-7713-D109-24DB-28339CB7A3CC}" = Catalyst Control Center Localization Norwegian
"{30517D85-B2C9-5920-77B2-6034DDC90B7C}" = CCC Help Czech
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35A6DE92-DE2E-9FBB-C919-B9CA5079116D}" = Catalyst Control Center Localization Turkish
"{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}" = WorkForce GT-1500 Scanner Driver Update
"{38151262-FAF8-4778-9AAB-33E90B60D8E9}" = CA Anti-Virus Plus
"{39C1585C-1004-5091-180A-5AFCA3D505C2}" = Catalyst Control Center Localization Thai
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HYDRAVISION
"{41269776-CF11-AADD-A1A9-6E1701877F88}" = CCC Help Norwegian
"{455B46A4-17C2-DDDA-F695-7F157E2C6160}" = Catalyst Control Center Localization Danish
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E10FFCA-5C09-6E8E-4DA4-B71FFC58C435}" = CCC Help Korean
"{4E568350-98BF-A31B-4E90-B23428023916}" = Catalyst Control Center Localization Spanish
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5827D56B-9A4D-6858-95C9-28B2D46F56EB}" = CCC Help German
"{5954C9DD-80C5-27FB-67FA-1DF0B5E2565A}" = Catalyst Control Center Localization Portuguese
"{5A05B328-35EB-4CED-B16F-62FA5A2642E6}" =
"{5B6844F3-8C27-C589-E519-9AAE0AC87407}" = CCC Help Dutch
"{5DA6F06A-B389-407B-BF8C-1548767914D8}" = ATI Problem Report Wizard
"{5DC1DF0D-8B08-30D9-5F5F-857ADC69201A}" = Catalyst Control Center Graphics Full New
"{5DDBDE45-EB70-DC65-6D06-6D25906E7797}" = CCC Help Japanese
"{5E075172-D826-3CFC-51F4-C9E6CF6D0690}" = CCC Help Spanish
"{618EB4D7-7D67-9126-7D63-CA39F93673DE}" = Catalyst Control Center Graphics Previews Common
"{67F5A666-181F-8AA1-0D4E-BAD64AD43B42}" = CCC Help Chinese Standard
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FB4970-45D2-1EA4-F131-A95EB60FFDDF}" = CCC Help Italian
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A053172-1F36-0307-4CA0-6AA9317EBCC1}" = CCC Help Turkish
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6B6F61D0-BBD0-E91F-8639-6EF30206ABD2}" = Catalyst Control Center Localization Japanese
"{71389CB1-6B6D-6FC2-0B74-0357D1ADC41E}" = CCC Help Finnish
"{736D005A-96E3-3B70-836C-14C80A137862}" = CCC Help French
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{8124C5F0-D59A-DEFE-C3F7-02697D9BE53E}" = CCC Help Thai
"{82357963-7536-629A-F921-A3E72A5E124C}" = Catalyst Control Center Localization Korean
"{82DFB852-9594-4668-9C66-28BB6E94BCB2}" = HP Photo and Imaging 1.0 - PSC 2000 Series
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8625D3E5-2159-3FA4-3A74-AB306360E63E}" = Catalyst Control Center Localization Russian
"{888FAC3D-87CB-AB4C-EC2C-D17E0C4418E7}" = Catalyst Control Center Localization French
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{89FF3A82-A88F-4035-9E95-6E03B7BA9D9B}" = Catalyst Control Center Localization Swedish
"{8E3AA171-1D56-8A6B-E7A2-35D32800ECED}" = ATI Catalyst Install Manager
"{8E5EDE0A-6B13-A0E2-7F00-5C2660C9F771}" = Catalyst Control Center Localization Hungarian
"{8EE7E7B0-CEA9-E3FD-A63F-B27F49E9EC42}" = CCC Help Portuguese
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9418FEE4-28B4-96FD-C398-42654B956376}" = Skins
"{94AF0F78-E983-BD4B-1A26-80F2FBD5487C}" = Catalyst Control Center Localization Czech
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9749C770-90C4-EE5A-D3BB-287F53622104}" = Catalyst Control Center Core Implementation
"{99FC30C1-60A7-205F-1A00-367506E756F2}" = Catalyst Control Center Localization Greek
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9BFFB382-0B2C-11D6-AB3E-000102B0F79A}" = Readiris 7.5
"{9F36EDCC-81A8-5D37-9EB1-8BF6D96CAA23}" = Catalyst Control Center Localization Finnish
"{A0100CB5-E6CE-F516-59C1-28CF0195A875}" = ccc-core-preinstall
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A336E48B-A46E-81B5-936E-5A9A8D7FE3D8}" = CCC Help Hungarian
"{A4CCE9FD-4A40-5669-97B3-262672CD6C38}" = CCC Help Greek
"{A6B82920-25DD-41B5-A680-5B6FB65BA6D9}" = VectorVest U.S.
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.4
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B325EFE1-1301-5BC4-8788-B1C7D3702ED1}" = CCC Help Polish
"{B53FA0E4-739C-435F-9872-E3032F2E08FC}" = Iomega QuikProtect
"{BCC57687-98A2-4C4C-B0F8-BC6B6F52D4E3}" = Retrospect Express HD 2.5
"{BF2A74BF-8D12-47F1-8B19-22B30AF6B0D1}" = Linksys EasyLink Advisor
"{C08E4323-261D-4B2F-8F24-CDB26E2AA081}" = Iomega Home Storage Manager
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C47426F7-6434-4A18-995A-68CF6B310DDF}" = TD AMERITRADE StrategyDesk 3.4
"{C5EC81D0-3DED-435D-A46E-E3F60F7DC8AD}" = Palm Desktop
"{C8430789-D948-0314-C36B-A7D78AB67013}" = ccc-core-static
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB2FFEB2-AC62-8DE2-8806-7C263437F132}" = CCC Help English
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0F69BED-0B44-8D65-5834-6A74D8F83805}" = Catalyst Control Center Localization Chinese Traditional
"{D30C0F98-3EF4-4454-8C70-F7CFB933B48A}" = VectorVest 7
"{D41864EF-CC5D-4CF4-B0B9-CA3152164157}" = ISIS Driver - EPSON GT-1500 v1.6.10802.6001
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{DD45D741-53D9-80CF-D097-31131DD9C0B0}" = CCC Help Chinese Traditional
"{DE5730BC-81FB-633F-039D-5D8C8F787EDF}" = Catalyst Control Center Localization German
"{DEA18FF6-D84A-4242-9663-692E5BA56805}" = ScanSoft PaperPort 11
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E492D880-0B07-4769-9E92-6C2B7DE37716}" = Linksys EasyLink Advisor
"{E5FEB4A0-1480-F22B-9822-B56BA6172421}" = ccc-utility
"{ED93995E-8BF2-480F-8EA4-7D29E29A7052}" = HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EFF1802C-C1F1-03EC-F3E0-51048DF0009F}" = Catalyst Control Center Localization Italian
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F9956472-6E16-4F83-BF9A-F887EF4A45B7}" = EPSON Scan PDF EXtensions
"{F9C22FF2-639F-1016-7926-9A1B06CDD516}" = Catalyst Control Center Localization Polish
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acoustica MP3 CD Burner" = Acoustica MP3 CD Burner
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"AllMySongs Database1.4" = AllMySongs Database
"AllMySongs Database2.0" = AllMySongs Database
"CAAPH2" = APH placeholder
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Elisha Cuthbert Screen Saver" = Elisha Cuthbert Screen Saver
"EPSON Scanner" = EPSON Scan
"eTrust Suite Personal" = CA Internet Security Suite
"Family Tree Builder" = MyHeritage Family Tree Builder
"FrostWire" = FrostWire 4.21.5
"hp instant support" = hp instant support
"hp psc 2200 series_Driver" = hp psc 2200 series
"ie8" = Windows Internet Explorer 8
"K9" = K9
"Linksys EasyLink Advisor" = Linksys EasyLink Advisor
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"MozBackup" = MozBackup 1.4.10
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"Mozilla Thunderbird (3.1.11)" = Mozilla Thunderbird (3.1.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NeroVision!UninstallKey" = Nero Digital
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Picasa 3" = Picasa 3
"PSC 2000 Series" = HP Photo and Imaging 1.0 - PSC 2000 Series
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.92
"Silent Package Run-Time Sample" = EPSON GT-1500 User's Guide
"Smart Defrag 2_is1" = Smart Defrag 2
"Stacy Keibler Heavenly" = Stacy Keibler Heavenly
"thinkorswim from TD AMERITRADE" = thinkorswim from TD AMERITRADE
"Uniblue RegistryBooster" = Uniblue RegistryBooster
"WhoCrashed_is1" = WhoCrashed 3.01
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =

Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =

Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

[ Application Events ]
Error - 7/30/2011 5:10:25 PM | Computer Name = DAD | Source = Google Update | ID = 1
Description =

Error - 7/30/2011 5:10:58 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 5:36:46 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 5:37:26 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 5:41:42 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 5:41:51 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

Error - 7/30/2011 10:02:06 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:10:45 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:33:17 PM | Computer Name = DAD | Source = JavaQuickStarterService | ID = 1
Description =

Error - 7/30/2011 10:33:59 PM | Computer Name = DAD | Source = Winlogon | ID = 1015
Description = A critical system process, C:\WINDOWS\system32\lsass.exe, failed with
status code c0000005. The machine must now be restarted.

[ System Events ]
Error - 7/29/2011 11:29:33 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Simple TCP/IP Services service terminated with the following error:
%%10092

Error - 7/29/2011 11:29:35 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%2147952492

Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
mv61xx

Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7034
Description = The Linksys Updater service terminated unexpectedly. It has done
this 1 time(s).

Error - 7/29/2011 11:31:23 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7024
Description = The Background Intelligent Transfer Service service terminated with
service-specific error 2147952492 (0x8007276C).

Error - 7/29/2011 11:31:24 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%2147952492

Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register
with DCOM within the required timeout.

Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register
with DCOM within the required timeout.

Error - 7/29/2011 11:31:52 PM | Computer Name = DAD | Source = Service Control Manager | ID = 7024
Description = The Background Intelligent Transfer Service service terminated with
service-specific error 2147952492 (0x8007276C).

Error - 7/29/2011 11:32:22 PM | Computer Name = DAD | Source = DCOM | ID = 10010
Description = The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register
with DCOM within the required timeout.


< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:15:12 PM, on 7/30/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\RetroExpress.exe
C:\Program Files\Iomega\QuikProtect\StartQuikProtect.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\KeirNet\K9\K9.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\mdmcls32.exe
C:\WINDOWS\system32\svcprs32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
C:\PROGRA~1\RETROS~1\RETROS~1.5\retrospect.exe
H:\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: CA Anti-Phishing Toolbar Helper - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: CA Anti-Phishing Toolbar - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\toolbar\caIEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\Six Engine\SixEngine.exe" -r
O4 - HKLM\..\Run: [Iomega Home Storage Manager] C:\Program Files\Iomega\Home Storage Manager\Iomega Discovery.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.5\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuiKProtect] C:\Program Files\Iomega\QuikProtect\StartQuikProtect.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\casc.exe"
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-789336058-602162358-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - S-1-5-21-789336058-602162358-725345543-1003 Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (User '?')
O4 - S-1-5-21-789336058-602162358-725345543-1003 Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe (User '?')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: Launch K9.lnk = C:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: www.vectorvest.com
O15 - Trusted Zone: http://www.vectorvest.com
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAAMSvc - CA - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\caamsvc.exe
O23 - Service: CaCCProvSP - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe
O23 - Service: CA Common Scheduler Service (ccSchedulerSVC) - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: QSCopyEngine - Unknown owner - C:\Program Files\Iomega\QuikProtect\QpMonitor.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.5\retrorun.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: WinSock Extention Manager (WinExtManager) - Unknown owner - C:\WINDOWS\system32\mdmcls32.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\system32\svcprs32.exe

–
End of file - 11467 bytes
.
==== Installed Programs ======================
.
.
ABBYY FineReader 6.0 Sprint
Acoustica MP3 CD Burner
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.0)
Advanced SystemCare 3
AllMySongs Database
AMRT
APH placeholder
Apple Application Support
Apple Software Update
ATI AVIVO Codecs
ATI Catalyst Control Center
ATI Catalyst Install Manager
ATI HYDRAVISION
ATI Problem Report Wizard
CA Anti-Phishing
CA Anti-Spam
CA Anti-Virus Plus
CA Backup and Migration
CA Internet Security Suite
CA Parental Controls
CA Personal Firewall
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Compatibility Pack for the 2007 Office system
Definition update for Microsoft Office 2010 (KB982726)
DNAMigrator
Elisha Cuthbert Screen Saver
Epson Copy Utility 3.4
Epson Event Manager
EPSON GT-1500 User's Guide
EPSON Scan
EPSON Scan PDF EXtensions
EPU-6 Engine
FrostWire 4.21.5
Google Earth Plug-in
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
hp instant support
HP Photo and Imaging 1.0 - PSC 2000 Series
HP Photo and Imaging 1.0 - PSC 2000 Series Drivers
hp psc 2200 series
Iomega Home Storage Manager
Iomega QuikProtect
ISIS Driver - EPSON GT-1500 v1.6.10802.6001
Java Auto Updater
Java™ 6 Update 26
Java™ 6 Update 3
K9
Linksys EasyLink Advisor
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 14
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft XML Parser
MozBackup 1.4.10
Mozilla Firefox (3.6.14)
Mozilla Thunderbird (3.1.11)
MozyHome
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MyHeritage Family Tree Builder
Nero Digital
Palm Desktop
PaperPort Image Printer
Picasa 3
Power Tab Editor 1.7
Pure Networks Platform
QuickTime
Readiris 7.5
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Retrospect Express HD 2.5
Revo Uninstaller 1.92
ScanSoft PaperPort 11
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Skins
Smart Defrag 2
SoundMAX
Stacy Keibler Heavenly
TD AMERITRADE StrategyDesk 3.4
thinkorswim from TD AMERITRADE
Uniblue RegistryBooster
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2362765)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB982632)
Update for Windows Internet Explorer 8 (KB982664)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VectorVest 7
VectorVest U.S.
WebEx
WebEx Support Manager for Internet Explorer
WebFldrs XP
WhoCrashed 3.01
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Management Framework Core
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Search 4.0
Windows XP Service Pack 3
WorkForce GT-1500 Scanner Driver Update
Yahoo! Messenger
.
==== End Of File ===========================
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 22:17:05.84 on Sat 07/30/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = hxxp://search.myheritage.com
uInternet Settings,ProxyOverride = 127.0.0.1
uURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll
mURLSearchHooks: MHURLSearchHook Class: {1c4ab6a5-595f-4e86-b15f-f93cce2bbd48} - c:\program files\family toolbar\tbhelper.dll
BHO: MHTBPos00 Class: {0c37b053-fd68-456a-82e1-d788ee342e6f} - c:\program files\family toolbar\tbcore3.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: CA Anti-Phishing Toolbar Helper: {45011cf5-e4a9-4f13-9093-f30a784eb9b2} - c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\caIEToolbar.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\microsoft office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Family Toolbar: {fd2fd708-1f6f-4b68-b141-c5778f0c19bb} - c:\program files\family toolbar\tbcore3.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: CA Anti-Phishing Toolbar: {0123b506-0ad9-43aa-b0cf-916c122ad4c5} - c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\caIEToolbar.dll
TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [Six Engine] "c:\program files\asus\six engine\SixEngine.exe" -r
mRun: [Iomega Home Storage Manager] c:\program files\iomega\home storage manager\Iomega Discovery.exe
mRun: [RetroExpress] c:\progra~1\retros~1\retros~1.5\RetroExpress.exe /h
mRun: [QuiKProtect] c:\program files\iomega\quikprotect\StartQuikProtect.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [cctray] "c:\program files\ca\ca internet security suite\casc.exe"
mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [LELA] "c:\program files\linksys\linksys easylink advisor\Linksys EasyLink Advisor.exe" /minimized
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\microsoft office\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\microsoft office\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: c:\windows\system32\winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: microsoft.com\www.update
Trusted Zone: vectorvest.com\www
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: PFW - UmxWnp.Dll
AppInit_DLLs: UmxSbxExw.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\jim\applic~1\mozilla\firefox\profiles\ktncdtcs.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.addthis.com/search?pco=fxe-3.1.2&locale;=en-US&sl;=ub&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\ca\ca internet security suite\ca anti-phishing\toolbar\firefox\components\CAFxToolBar.dll
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\FFHst.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\jim\application data\mozilla\firefox\profiles\ktncdtcs.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\jim\application data\mozilla\firefox\profiles\ktncdtcs.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\progra~1\microsoft office\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\microsoft office\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npatgpc.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.urlbar.hideGoButton -
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_open_feature.location - True
FF - user.js: dom.disable_window_open_feature.menubar - True
FF - user.js: dom.disable_window_open_feature.minimizable - True
FF - user.js: dom.disable_window_open_feature.scrollbars - True
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R? CAISafe;CAISafe
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? KmxAMVet;KmxAMVet
R? LinksysUpdater;Linksys Updater
R? MBAMSwissArmy;MBAMSwissArmy
R? MpKslc4009304;MpKslc4009304
R? MpKslcda4fc30;MpKslcda4fc30
R? mv61xx;mv61xx
R? NmPar;Unusable Parallel Port
R? nmserial;PCI Serial Port
R? osppsvc;Office Software Protection Platform
R? QSCopyEngine;QSCopyEngine
R? QsFsFltr;QsFsFltr
R? UmxAgent;HIPS Event Manager
R? UmxCfg;HIPS Configuration Interpreter
R? UmxPol;HIPS Policy Manager
R? WinRM;Windows Remote Management (WS-Management)
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
S? AtiHDAudioService;ATI Function Driver for HD Audio Service
S? AvgLdx86;AVG AVI Loader Driver x86
S? AvgMfx86;AVG On-access Scanner Minifilter Driver x86
S? AvgRkx86;avgrkx86.sys
S? AvgTdiX;AVG8 Network Redirector
S? CAAMSvc;CAAMSvc
S? ccSchedulerSVC;CA Common Scheduler Service
S? KmxAgent;KmxAgent
S? KmxAMRT;KmxAMRT
S? KmxCF;KmxCF
S? KmxCfg;KmxCfg
S? KmxFile;KmxFile
S? KmxFw;KmxFw
S? KmxSbx;KmxSbx
S? KmxStart;KmxStart
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? SmartDefragDriver;SmartDefragDriver
S? WinExtManager;WinSock Extention Manager
S? WinSvchostManager;WinSock Svchost Manager
.
=============== Created Last 30 ================
.
2011-07-31 01:34:52 ——– d—–w- c:\docume~1\jim\applic~1\Malwarebytes
2011-07-31 00:43:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-31 00:43:42 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-07-31 00:43:39 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-07-31 00:43:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-07-30 14:04:55 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{35ACA973-70F0-495F-9092-74A130711865}
2011-07-30 13:54:41 ——– d—–w- c:\program files\WebEx
2011-07-30 13:54:10 23984 —-a-w- c:\windows\system32\drivers\pnarp.sys
2011-07-30 13:54:03 25264 —-a-w- c:\windows\system32\drivers\purendis.sys
2011-07-30 13:53:57 ——– d—–w- c:\program files\common files\Pure Networks Shared
2011-07-30 13:53:41 ——– d—–w- c:\docume~1\alluse~1\applic~1\Pure Networks
2011-07-30 13:32:13 939368 —-a-r- c:\windows\system32\myflash.ocx
2011-07-28 23:48:19 ——– d—–w- c:\docume~1\jim\applic~1\ElevatedDiagnostics
2011-07-28 00:06:27 101392 —-a-w- c:\windows\system32\drivers\AtihdXP3.sys
2011-07-28 00:05:59 ——– d—–w- c:\program files\ATI
2011-07-28 00:05:04 ——– d—–w- C:\ATI
2011-07-27 22:40:05 ——– d—–w- c:\program files\ISSThirdParty
2011-07-27 22:39:49 5845744 —-a-w- c:\windows\system32\win32cpr.dll
2011-07-27 22:39:49 200704 —-a-w- c:\windows\system32\ssleay32.dll
2011-07-27 22:39:49 1377008 —-a-w- c:\windows\system32\svcprs32.exe
2011-07-27 22:39:49 1028096 —-a-w- c:\windows\system32\libeay32.dll
2011-07-27 22:39:47 286208 —-a-w- c:\windows\system32\winsfinst.exe
2011-07-27 22:39:47 2654208 —-a-w- c:\windows\system32\winsflte.dll
2011-07-27 22:39:47 2347760 —-a-w- c:\windows\system32\mdmcls32.exe
2011-07-27 22:39:47 1872624 —-a-w- c:\windows\system32\winsflt.dll
2011-07-27 13:27:01 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-27 13:25:56 ——– d—–w- c:\docume~1\jim\locals~1\applic~1\eSupport.com
2011-07-27 03:39:03 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-07-25 00:59:30 95568 —-a-w- c:\windows\system32\Vetredir.dll
2011-07-25 00:59:30 202064 —-a-w- c:\windows\system32\Isafprod.dll
2011-07-25 00:59:30 128336 —-a-w- c:\windows\system32\Isafeif.dll
2011-07-25 00:58:50 1054032 —-a-w- c:\windows\system32\cfgmig32.dll
2011-07-25 00:20:52 2385136 —-a-w- c:\windows\system32\winsflt_x64.dll
2011-07-25 00:20:51 ——– d—–w- c:\windows\rnapxs
2011-07-25 00:20:50 7440 —-a-w- c:\windows\system32\sporder.dll
2011-07-25 00:20:50 32768 —-a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-07-25 00:18:58 ——– d—–w- c:\docume~1\alluse~1\applic~1\CA
2011-07-24 14:11:07 ——– d—–w- c:\program files\WhoCrashed
2011-07-24 11:34:58 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-07-24 11:34:57 13496 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-07-23 19:24:26 ——– d—–w- c:\documents and settings\jim\Logitech
2011-07-23 19:21:45 ——– d—–w- c:\program files\common files\Remote Control Software Common
2011-07-23 19:21:30 ——– d—–w- c:\program files\common files\Remote Control USB Driver
2011-07-23 19:21:24 757760 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2011-07-23 19:21:24 69715 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2011-07-23 19:21:24 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2011-07-23 19:21:24 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2011-07-23 19:21:24 204800 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2011-07-23 19:21:24 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2011-07-23 19:21:23 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2011-07-16 21:34:20 ——– d—–w- c:\documents and settings\jim\.frostwire5
.
==================== Find3M ====================
.
2011-07-10 11:30:42 404640 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-29 16:36:20 387600 -c–a-w- c:\windows\system32\FTBSaver.scr
2011-05-04 09:52:22 472808 -c–a-w- c:\windows\system32\deployJava1.dll
2011-05-04 07:25:49 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll
2010-10-13 03:01:02 638976 —-a-w- c:\program files\Uninstall IObit Toolbar.dll
.
============= FINISH: 22:17:49.70 ===============

That's all I got! Now, if someone could look at these and tell me what happened to my PC, I'd appreciate it! It's been acting up for about 4-5 days now with weird error messages and shutdowns. I originally started this post in MS Windows forum so there's a bit of history there from the past few days also.

Thanks!

Taz :pullhair:
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi Cat! We've worked together before on an occassional issue or two…..:) Unfortunately on this one its pretty bad. I downloaded ComboFix to a jump drive as the main PC doesn't have an Internet connection. I tried to snooze or uninstall CA Internet Suites and its a no go. I even tried doing it with Revo but no luck. It insists on using the program uninstaller and it freezes. Any other ideas? I tried it in normal mode and safe mode….:( Thanks, Taz
Try using this AppRemover


Please download AppRemover and save it to your desktop.
  • Double click on AppRemover.exe to run it.
  • Uncheck "Enable anonymous usage statistics. No personal data will be recorded."
  • Click on the Next button.
  • Click on "Remove Security Application" or "Clean Up a Failed Uninstall" depending on what you want to do. (you want the failed uninstall)
  • Click on the Next button.
  • A scan begins, please wait. Once done, click on the Next button.
  • Now you should have a list of your installed programs, choose the one you want to remove and click on the Next button. (AVG)
  • Follow the last step and reboot if asked to do so.
Ok Cat….I WAS able to remove CA. Apparently the PC is moving very slowly. However, upon running CF, it says the Recovery Console is either not present or needs to be updated! :( Small problem, this infection has disabled my Internet connection. Plan B? Thanks, Taz
ok….cf ran and made a log but I can't seem to put it on the jump drive to send it to you. I've rebooted to normal mose but still getting the error that it's going to shut down in 60 secs with a timer Next? Taz
boot into safe mode with networking and see if you can connect


try these connection troubleshooting steps


Please do the following:

if your network icon appears on the Windows taskbar, then you can repair it by right-clicking on the icon and selecting Repair.


[external image: Posted Image]

If you have no task bar icon do this:

  • Click on the Start button.
  • Click on the Settings menu option.
  • Click on the Control Panel option.
  • When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
  • You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
  • click on the Repair menu option.

[external image: Posted Image]

Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.


if no luck - try this:

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.

In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes

In FireFox
  • Click on Advanced -> Network -> Settings…
  • the No Proxy option should be selected



Next: - try this:

Go to Start > Run > type in CMD to open a command prompt.

Type in the following command in the command prompt and press Enter.


netsh int ip reset reset.log

Then also type the following command and hit enter.

netsh winsock reset catalog

Once that completes then restart the system and see then if you are able to get online.


next this -

Go to Start > Run then type: CMD into the run box

You will now see a black DOS-like screen.

Type the following at the command prompt:

IPconfig /release. (Note the space between the "g" and the slash / it needs to be there)

Hit enter Then type:

IPconfig /Renew (Note the space between the "g" and the slash / it needs to be there)

Hit enter
Cat, All seems well until I get to the last step. When I go to renew the ipconfig, it tells me the RPC server is unavailable?
Cat, We are getting some very severe T-storms coming thru Chicago so I'm going to sut this down and work on it tomorrow. Please post and when I get home from work I'll finish it! Thanks… Taz
Hi

To check the status of the Remote Procedure Call (RPC), open the "Services" window:

Go to Start > Run > type services.msc into the open run box
scroll down in the services window till you locate Remote Procedure Call
Now right click the Remote Procedure Call (RPC) service.


If the status shows it is not running then it has been disabled!

If that is the case, to start the service - do the following:

You will not be able to start it from the "Services" Window… You will see it is "greyed out"!

Follow these instructions…

You will need to boot the computer into the Recovery Console: (for instructions on how to install and boot to the recovery console - see HERE)
Type the command: Enable RPCSS Service_Auto_Start at the c:\windows command prompt
Now press the Enter key to submit the command.
Now type: exit and press Enter to restart the computer.
Hi Cat! Well, Followed your instructions. The RPC keeps telling me its not available altho it show's its running in services . I've done the IPconfig release & renew and I keep getting that message. Something is still not right. Or am I doing something wrong or out of sequence? Should I attempt to install the Recovery Console now? Taz
yes, try and install the recovery console then type the enable RPCSS command in the Recovery Console. See if you can save the combofix file in another format, then copy it over to the USB stick so you can post it for me
Hi Cat.. Sorry I haven't been on but work called me away from the computer. ComboFix worked to a point. The PC still boots nslowly and I'm wondering if my NAS has been affected by whatever this was ? In addition I haven't been able to connect to Windows update thru IE. The browser says done, but nothing shows.My initial impression is that the system seems abit unstable yet….anything else I should do to make it more stable and consistent? BTW, once again you have been a lifesaver with your extensive knowledge of computers, viruses, and O/S's! I can't say enough thank you's for your patience and determination to see these issues thru to success! :) Taz :thumbup:
Here's the ComboFix report you requested…..

ComboFix 11-08-06.02 - JIM 08/07/2011 7:55.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2726 [GMT -5:00]
Running from: G:\ComboFix.exe
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((( Files Created from 2011-07-07 to 2011-08-07 )))))))))))))))))))))))))))))))
.
.
2011-08-05 22:32 . 2011-08-05 22:34 ——– d—–w- C:\McCartney
2011-08-03 23:49 . 2010-11-12 16:48 202064 —-a-w- c:\windows\system32\Isafprod.dll
2011-08-03 23:49 . 2010-11-12 16:47 95568 —-a-w- c:\windows\system32\Vetredir.dll
2011-08-03 23:49 . 2010-11-12 16:47 128336 —-a-w- c:\windows\system32\Isafeif.dll
2011-08-03 23:49 . 2010-11-23 14:04 1054032 —-a-w- c:\windows\system32\cfgmig32.dll
2011-08-03 23:49 . 2011-08-07 03:17 ——– d—–w- c:\windows\rnapxs
2011-08-03 23:49 . 2005-04-04 03:57 32768 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-08-03 23:20 . 2011-08-03 23:20 ——– d—–w- c:\documents and settings\All Users\Application Data\CA
2011-08-03 23:06 . 2011-08-03 23:08 ——– d—–w- c:\program files\CA
2011-07-31 04:21 . 2011-07-31 04:23 ——– d—–w- c:\documents and settings\JIM\Application Data\GetRightToGo
2011-07-31 01:34 . 2011-07-31 01:34 ——– d—–w- c:\documents and settings\JIM\Application Data\Malwarebytes
2011-07-31 00:43 . 2011-07-31 00:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-07-30 14:04 . 2011-07-30 14:04 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
2011-07-30 13:54 . 2011-07-30 13:54 ——– d—–w- c:\program files\WebEx
2011-07-30 13:54 . 2008-12-12 23:05 23984 —-a-w- c:\windows\system32\drivers\pnarp.sys
2011-07-30 13:54 . 2008-12-12 23:05 25264 —-a-w- c:\windows\system32\drivers\purendis.sys
2011-07-30 13:53 . 2011-07-30 13:53 ——– d—–w- c:\program files\Common Files\Pure Networks Shared
2011-07-30 13:53 . 2011-07-30 13:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2011-07-30 13:32 . 2009-03-18 19:58 939368 —-a-r- c:\windows\system32\myflash.ocx
2011-07-29 21:26 . 2011-07-29 21:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Share-to-Web Upload Folder
2011-07-28 23:48 . 2011-07-28 23:48 ——– d—–w- c:\documents and settings\JIM\Application Data\ElevatedDiagnostics
2011-07-28 02:04 . 2011-07-28 02:04 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-07-28 00:06 . 2011-03-30 18:46 101392 —-a-w- c:\windows\system32\drivers\AtihdXP3.sys
2011-07-28 00:05 . 2011-07-28 00:05 ——– d—–w- c:\program files\ATI
2011-07-28 00:05 . 2011-07-28 00:05 ——– d—–w- C:\ATI
2011-07-27 13:27 . 2011-07-30 04:36 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-27 13:25 . 2011-07-27 13:25 ——– d—–w- c:\documents and settings\JIM\Local Settings\Application Data\eSupport.com
2011-07-27 03:39 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-07-24 14:11 . 2011-07-29 20:39 ——– d—–w- c:\program files\WhoCrashed
2011-07-24 11:34 . 2011-02-23 21:54 29520 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-07-24 11:34 . 2011-02-23 22:04 13496 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-07-23 19:24 . 2011-07-23 19:24 ——– d—–w- c:\documents and settings\JIM\Logitech
2011-07-23 19:21 . 2011-07-24 11:32 ——– d—–w- c:\program files\Common Files\Remote Control Software Common
2011-07-23 19:21 . 2011-07-23 19:21 ——– d—–w- c:\program files\Logitech
2011-07-23 19:21 . 2011-07-23 19:21 ——– d—–w- c:\program files\Common Files\Remote Control USB Driver
2011-07-23 19:21 . 2011-07-23 19:21 200836 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-07-23 19:21 . 2006-02-07 20:45 757760 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-07-23 19:21 . 2006-02-07 20:40 204800 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-07-23 19:21 . 2006-02-07 20:40 69715 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-07-23 19:21 . 2006-02-07 20:40 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-07-23 19:21 . 2005-11-14 04:19 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2011-07-23 19:21 . 2011-07-23 19:21 331908 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2011-07-16 21:34 . 2011-07-21 00:51 ——– d—–w- c:\documents and settings\JIM\.frostwire5
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-27 22:39 . 2011-03-04 02:12 1872624 —-a-w- c:\windows\system32\winsflt.dl1
2011-07-12 02:21 . 2010-09-26 16:34 54776 —-a-w- c:\windows\system32\drivers\mozy.sys
2011-07-10 11:30 . 2011-05-24 02:34 404640 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02 . 2002-08-29 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-29 16:36 . 2011-05-29 16:36 387600 -c–a-w- c:\windows\system32\FTBSaver.scr
2010-10-13 03:01 . 2010-10-25 00:18 638976 —-a-w- c:\program files\Uninstall IObit Toolbar.dll
2011-06-24 00:27 . 2011-04-17 02:51 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-03_01.03.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-07 12:39 . 2011-08-07 12:39 16384 c:\windows\temp\Perflib_Perfdata_310.dat
+ 2011-08-07 12:39 . 2011-08-07 12:39 16384 c:\windows\temp\Perflib_Perfdata_264.dat
- 2010-08-11 06:07 . 2008-04-14 00:12 23552 c:\windows\system32\wdmaud.drv
+ 2010-08-11 06:07 . 2008-04-14 00:12 23552 c:\windows\system32\wdmaud.drv
+ 2002-08-29 12:00 . 2008-04-13 18:40 36352 c:\windows\system32\drivers\disk.sys
- 2002-08-29 12:00 . 2008-04-13 18:40 36352 c:\windows\system32\drivers\disk.sys
+ 2010-08-11 06:07 . 2008-04-14 00:12 23552 c:\windows\system32\dllcache\wdmaud.drv
+ 2010-08-11 05:32 . 2011-08-03 22:36 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-08-11 05:32 . 2010-08-12 01:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-08-11 05:32 . 2010-08-12 01:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-08-11 05:32 . 2011-08-03 22:36 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-07-28 02:04 . 2011-08-03 23:19 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2011-07-28 02:04 . 2011-07-28 02:46 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-08-11 07:44 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\ksuser.dll
+ 2011-08-03 02:48 . 2011-08-03 03:09 8008 c:\windows\system32\d3d9caps.dat
+ 2011-08-03 23:49 . 2011-08-03 23:49 4096 c:\windows\rnapxs\CSDK\urlcache\urlCacheDb.dat
- 2011-07-25 00:21 . 2011-07-25 00:21 4096 c:\windows\rnapxs\CSDK\urlcache\urlCacheDb.dat
- 2011-07-25 00:21 . 2011-07-25 00:21 4096 c:\windows\rnapxs\CSDK\urlcache\domainNames.dat
+ 2011-08-03 23:49 . 2011-08-03 23:49 4096 c:\windows\rnapxs\CSDK\urlcache\domainNames.dat
- 2002-08-29 12:00 . 2011-07-30 14:15 540196 c:\windows\system32\perfh009.dat
+ 2002-08-29 12:00 . 2011-08-07 03:07 540196 c:\windows\system32\perfh009.dat
+ 2002-08-29 12:00 . 2011-08-07 03:07 102218 c:\windows\system32\perfc009.dat
- 2002-08-29 12:00 . 2011-07-30 14:15 102218 c:\windows\system32\perfc009.dat
+ 2007-12-06 14:51 . 2007-08-15 08:22 265856 c:\windows\system32\drivers\yk51x86.sys
- 2011-07-25 00:20 . 2011-07-27 22:40 204800 c:\windows\rnapxs\rnapxs.dat
+ 2011-08-03 23:49 . 2011-08-03 23:49 204800 c:\windows\rnapxs\rnapxs.dat
+ 2011-08-05 01:39 . 2011-08-05 01:39 2178048 c:\windows\Installer\40f5f2.msi
- 2011-03-04 02:24 . 2011-07-27 22:40 5587456 c:\windows\Installer\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\{E682894F-3BC3-4903-B2F8-9066349062D5}\CAPF.msi
+ 2011-03-04 02:24 . 2011-08-03 23:50 5587456 c:\windows\Installer\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\{E682894F-3BC3-4903-B2F8-9066349062D5}\CAPF.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840]
.
[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 —-a-w- c:\program files\Family Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
.
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
.
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2011-08-04 20:15 3512088 —-a-w- c:\program files\MozyHome\mozyshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2011-08-04 20:15 3512088 —-a-w- c:\program files\MozyHome\mozyshell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Six Engine"="c:\program files\ASUS\Six Engine\SixEngine.exe" [2008-06-03 5964800]
"Iomega Home Storage Manager"="c:\program files\Iomega\Home Storage Manager\Iomega Discovery.exe" [2009-10-27 152936]
"RetroExpress"="c:\progra~1\RETROS~1\RETROS~1.5\RetroExpress.exe" [2008-07-16 9499928]
"QuiKProtect"="c:\program files\Iomega\QuikProtect\StartQuikProtect.exe" [2009-03-13 54504]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-01-14 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-01-14 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"LELA"="c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" [2009-05-20 221184]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-03-16 1040384]
.
c:\documents and settings\JIM\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\HOTSYNC.EXE [2002-7-18 299008]
Launch K9.lnk - c:\program files\KeirNet\K9\K9.exe [2004-4-18 82944]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-6-11 323646]
MozyHome Status.lnk - c:\program files\MozyHome\mozystat.exe [2011-8-4 3674904]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoFileAssociate"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-11-10 03:39 12536 —-a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2009-03-27 21:27 79368 —-a-w- c:\windows\system32\UmxWNP.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\UmxSbxExw.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Iomega\\Home Storage Manager\\Iomega Discovery.exe"=
"c:\\Program Files\\Iomega\\Home Storage Manager\\Iomega Storage Manager.exe"=
"c:\\Program Files\\Iomega\\QuikProtect\\QuikProtect.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [5/3/2010 2:12 AM 108112]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [7/24/2011 6:34 AM 13496]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [3/22/2010 1:58 PM 79864]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/9/2010 6:54 AM 61008]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [5/3/2010 2:12 AM 115792]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [5/3/2010 2:12 AM 146000]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [4/13/2010 4:54 AM 61008]
R2 QSCopyEngine;QSCopyEngine;c:\program files\Iomega\QuikProtect\QpMonitor.exe [4/22/2009 3:09 PM 122880]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [7/27/2011 7:06 PM 101392]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/9/2010 6:54 AM 244304]
R3 QsFsFltr;QsFsFltr;c:\windows\system32\drivers\QsFsFltr.sys [9/18/2010 2:48 PM 13824]
S0 AvgRkx86;avgrkx86.sys;c:\windows\system32\Drivers\avgrkx86.sys –> c:\windows\system32\Drivers\avgrkx86.sys [?]
S0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys –> c:\windows\system32\DRIVERS\mv61xx.sys [?]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys –> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys –> c:\windows\system32\Drivers\avgtdix.sys [?]
S1 MpKslc4009304;MpKslc4009304; [x]
S1 MpKslcda4fc30;MpKslcda4fc30; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/17/2010 9:24 PM 136176]
S2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [11/13/2008 2:43 PM 204800]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/17/2010 9:24 PM 136176]
S3 NmPar;Unusable Parallel Port;c:\windows\system32\drivers\NmPar.sys [12/24/2008 5:40 AM 80256]
S3 nmserial;PCI Serial Port;c:\windows\system32\drivers\NmSerial.sys [12/16/2008 6:10 AM 70016]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/29/2002 7:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-02 c:\windows\Tasks\FRU Task 2002-06-11 17:56ewlett-Packard2002-06-11 17:56p psc 2200 series0873DBB30DAF953F7DCEA1BDCC4F78BFDB130745293986285.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-06-11 16:56]
.
2011-08-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-18 02:24]
.
2011-08-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-18 02:24]
.
2011-08-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 19:25]
.
2011-08-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-602162358-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 19:25]
.
2011-08-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 19:25]
.
2011-08-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-602162358-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 19:25]
.
2011-08-07 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2011-03-14 13:29]
.
2011-08-07 c:\windows\Tasks\SmartDefrag_Startup.job
- c:\program files\IObit\Smart Defrag 2\SmartDefrag.exe [2011-04-18 01:19]
.
2011-01-01 c:\windows\Tasks\User_Feed_Synchronization-{F9AF475E-4BA9-4B59-BA57-28BE3A55B301}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://search.myheritage.com
uInternet Settings,ProxyOverride = 127.0.0.1
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\Microsoft Office\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\Microsoft Office\Office14\ONBttnIE.dll/105
Trusted Zone: microsoft.com\www.update
Trusted Zone: vectorvest.com\www
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\JIM\Application Data\Mozilla\Firefox\Profiles\ktncdtcs.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.addthis.com/search?pco=fxe-3.1.2&locale;=en-US&sl;=ub&q;=
FF - prefs.js: network.proxy.type - 0
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.urlbar.hideGoButton -
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_open_feature.location - True
FF - user.js: dom.disable_window_open_feature.menubar - True
FF - user.js: dom.disable_window_open_feature.minimizable - True
FF - user.js: dom.disable_window_open_feature.scrollbars - True
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-07 08:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,07,17,cd,57,22,ee,6b,4e,bc,4a,fb,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,07,17,cd,57,22,ee,6b,4e,bc,4a,fb,\
.
[HKEY_USERS\S-1-5-21-789336058-602162358-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(848)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\windows\system32\UmxWnp.Dll
.
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WININET.dll
c:\program files\MozyHome\mozyshell.dll
c:\program files\MozyHome\LIBEAY32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-08-07 08:05:20
ComboFix-quarantined-files.txt 2011-08-07 13:05
ComboFix2.txt 2011-08-07 12:05
ComboFix3.txt 2011-08-07 05:38
ComboFix4.txt 2011-08-03 01:39
.
Pre-Run: 434,861,928,448 bytes free
Post-Run: 434,840,371,200 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 4BECE4EA32E2420DF608DC8CF65C9F5C


I noticed that it's picking up some orphan files from an old installation of AVG. I can't seem to purge the system of these in c:\Windows\system32. Any thoughts? I suspect this MIGHT be a source of a few problems with my CA.

Thanks,

Jim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI