gino5555
Topic Starter
Windows XP
My best guess is that my 10 year old downloaded something from the internet. A few days ago it stopped connecting to the internet and I am unable to view or ping my router. I am wired. Using Windows to repair the connection I receive an error that the IP address could not be renewed.
Router: Dlink Dir-655
Model: SURFboard SB6121
Connecting via Cox Cable
Everything else is working. I have another computer wired to the router and several wireless devices working with no problems.
OTL Log (generated 1 log only)
OTL logfile created on: 9/7/2011 2:23:10 PM - Run 2
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Jaynelle\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.72% Memory free
3.84 Gb Paging File | 3.30 Gb Available in Paging File | 85.90% Paging File free
Paging file location(s): C:\pagefile.sys 2 4096H:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.59 Gb Total Space | 2.58 Gb Free Space | 3.60% Space Free | Partition Type: NTFS
Drive E: | 698.64 Gb Total Space | 200.69 Gb Free Space | 28.73% Space Free | Partition Type: NTFS
Drive H: | 149.05 Gb Total Space | 5.97 Gb Free Space | 4.00% Space Free | Partition Type: NTFS
Computer Name: ACER-DESKTOP | User Name: Jaynelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Jaynelle\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Documents and Settings\Jaynelle\Local Settings\temp\mcitinfo_1315337506.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Documents and Settings\Jaynelle\Local Settings\temp\mcupdate_1315267552.exe (McAfee, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe ()
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe (Memeo Inc.)
PRC - C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe (A-1 Technology, Inc.)
PRC - C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe (FirebirdSQL Project)
PRC - C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe (FirebirdSQL Project)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
PRC - C:\Program Files\acer\eRecovery\Monitor.exe (acer Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c6b19db2534042d435ede580f92bc75c\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\70a1400affdc775d7c7398e036359286\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\40893760431f8f0dcce3e18630e45b23\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b7e0214a811f81e09041864081139641\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\db2d84e279807592a680ef4135e9fe9a\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d00cc387e462e4c3cdcd112b137cac87\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7ed09623172a292eaee51e2e3bcaf784\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe ()
MOD - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()
MOD - C:\Program Files\Yahoo!\Widgets\jsd.dll ()
MOD - C:\Program Files\Yahoo!\Widgets\js32.dll ()
MOD - C:\Program Files\Seagate\AutoBackup\sqlite3.dll ()
MOD - C:\Program Files\Yahoo!\Widgets\sqlite3.dll ()
MOD - C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OELogger.dll ()
MOD - C:\Program Files\WS_FTP Pro\nsftpch.dll ()
MOD - C:\WINDOWS\system32\BrMuSNMP.dll ()
========== Win32 Services (SafeList) ==========
SRV - (CLTNetCnService) – File not found
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (atnthost) – C:\WINDOWS\Downlo~1\MyWebEx\319\atnthost.exe ()
SRV - (spupdsvc) – C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (FirebirdGuardianDefaultInstance) – C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe (FirebirdSQL Project)
SRV - (FirebirdServerDefaultInstance) – C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe (FirebirdSQL Project)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (StuffIt Task Manager) – C:\Program Files\Allume Systems\StuffIt\MXTask.exe (Allume Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (9630541drv) – File not found
DRV - (36605977) – File not found
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (radpms) – C:\WINDOWS\system32\drivers\radpms.sys (LogMeIn, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (RsFx0102) – C:\WINDOWS\system32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (scsiscan) – C:\WINDOWS\system32\drivers\scsiscan.sys (Microsoft Corporation)
DRV - (regi) – C:\WINDOWS\system32\drivers\regi.sys (InterVideo)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (FileDisk) – C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (DMX3191) – C:\WINDOWS\System32\drivers\DMX3191.SYS (Microsoft Corporation)
DRV - (AEC671X) – C:\WINDOWS\System32\drivers\AEC671X.SYS (Acard Technology Corp.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (zmxpzip) – C:\WINDOWS\system32\DRIVERS\zmxpzip.sys (Allume Systems)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (int15.sys) – C:\Program Files\acer\eRecovery\int15.sys ()
DRV - (ULCDRHlp) – C:\WINDOWS\system32\drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (SoC PC-Camera Service) – C:\WINDOWS\system32\drivers\pfc027.sys ()
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (cmuda2) – C:\WINDOWS\system32\drivers\cmuda2.sys (C-Media Inc)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (DriveMap) – C:\WINDOWS\System32\drivers\drivemap.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.578
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@mediaforge.com/MRP: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.0: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Jaynelle\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Jaynelle\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\Jaynelle\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/22 22:41:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.21\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/05 17:06:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.21\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/01 08:23:24 | 000,000,000 | —D | M]
[2008/08/26 08:50:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Extensions
[2011/09/06 13:59:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions
[2011/08/23 12:13:12 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/05/13 10:16:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 15:24:01 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/07/13 15:36:39 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/04 05:38:49 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\[removed]
[2009/07/03 02:23:17 | 000,000,000 | —D | M] (Move Media Player) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\[removed]
[2009/01/10 23:31:05 | 000,000,655 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo-search.xml
[2009/09/04 10:48:29 | 000,000,872 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo.gif
[2009/09/04 10:48:29 | 000,000,466 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo.src
[2009/09/04 10:48:26 | 000,001,775 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo.xml
[2011/09/06 13:59:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/03/22 22:41:41 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/02/22 10:14:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2006/01/18 12:50:00 | 000,319,488 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2005/04/27 17:31:10 | 000,225,280 | —- | M] (Asgard Software Inc.) – C:\Program Files\mozilla firefox\plugins\NPUploader.dll
[2007/03/09 16:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CmUsbAudio] File not found
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [eRecoveryService] C:\Program Files\acer\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [McAfee McItInfo] C:\Documents and Settings\Jaynelle\Local Settings\temp\mcitinfo_1315337506.exe (McAfee, Inc.)
O4 - HKCU..\Run: [McAfee Update] C:\Documents and Settings\Jaynelle\Local Settings\temp\mcupdate_1315267552.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Outlook Plugin.lnk = C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe (A-1 Technology, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Remote Access.lnk = C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe (Memeo Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\_uninst_36605977.lnk = C:\Documents and Settings\Jaynelle\Local Settings\temp\_uninst_36605977.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Google Search - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=48835 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} http://www.mediaforge.com/downloads/xmirage.exe (XMirage Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1129335948828 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_08)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: )
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/07 08:48:37 | 000,000,000 | —D | M] - C:\AutoBackup – [ NTFS ]
O32 - AutoRun File - [2005/05/19 18:31:14 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{38920ac9-de3a-11df-a3a8-0014854d2601}\Shell - "" = AutoRun
O33 - MountPoints2\{38920ac9-de3a-11df-a3a8-0014854d2601}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{38920ac9-de3a-11df-a3a8-0014854d2601}\Shell\AutoRun\command - "" = I:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/07 14:17:07 | 000,607,260 | —- | C] (Swearware) – C:\Documents and Settings\Jaynelle\Desktop\dds.scr
[2011/09/07 14:17:07 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jaynelle\Desktop\OTL.exe
[2011/09/07 14:17:07 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
[2011/09/06 13:06:46 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/09/05 16:57:07 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jaynelle\Recent
[2011/08/27 18:22:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Jaynelle\Local Settings\Application Data\Solid State Networks
[2011/08/27 02:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2011/08/25 09:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Brother
[2011/08/25 09:39:24 | 000,126,976 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BrfxD05a.dll
[2011/08/25 09:39:22 | 000,176,128 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BroSNMP.dll
[2011/08/25 09:39:22 | 000,005,120 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2L.dll
[2011/08/25 09:39:22 | 000,003,072 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2S.dll
[2011/08/25 09:39:21 | 000,073,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2.dll
[2011/08/25 09:34:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Jaynelle\Application Data\InstallShield
[2011/08/22 22:34:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/08/16 11:06:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Seagate
[2011/08/11 06:18:11 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/10 14:21:52 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/10 14:21:25 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/07 14:18:14 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/07 14:16:45 | 000,607,260 | —- | M] (Swearware) – C:\Documents and Settings\Jaynelle\Desktop\dds.scr
[2011/09/07 14:16:04 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
[2011/09/07 14:15:12 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jaynelle\Desktop\OTL.exe
[2011/09/07 02:04:00 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/06 17:18:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/06 13:05:52 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\eRLog.ini
[2011/09/06 13:05:22 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/09/06 13:05:20 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/06 13:05:20 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4051308335-3306677665-4219388724-1005.job
[2011/09/06 13:04:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/06 13:04:21 | 2142,818,304 | -HS- | M] () – C:\hiberfil.sys
[2011/09/06 12:55:09 | 000,000,874 | —- | M] () – C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\_uninst_36605977.lnk
[2011/09/02 14:07:16 | 000,000,000 | —- | M] () – C:\WINDOWS\1932768030
[2011/09/02 14:07:15 | 004,194,304 | —- | M] () – C:\WINDOWS\System32\awadhofn.dll
[2011/09/01 08:24:08 | 000,003,059 | —- | M] () – C:\WINDOWS\magic32.ini
[2011/09/01 08:23:14 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4051308335-3306677665-4219388724-1005.job
[2011/09/01 07:24:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\jucheck.job
[2011/08/28 02:07:13 | 011,400,490 | —- | M] () – C:\Documents and Settings\Jaynelle\My Documents\CD.psd
[2011/08/27 19:50:46 | 000,001,785 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/25 09:41:06 | 000,001,832 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Brother Creative Center.lnk
[2011/08/25 09:40:42 | 000,000,821 | —- | M] () – C:\WINDOWS\Brpfx04a.ini
[2011/08/25 09:40:42 | 000,000,154 | —- | M] () – C:\WINDOWS\brpcfx.ini
[2011/08/25 09:40:23 | 000,000,419 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2011/08/25 09:40:23 | 000,000,027 | —- | M] () – C:\WINDOWS\BRPP2KA.INI
[2011/08/25 09:39:39 | 000,000,086 | —- | M] () – C:\WINDOWS\Brfaxrx.ini
[2011/08/25 09:39:39 | 000,000,050 | —- | M] () – C:\WINDOWS\System32\bridf08a.dat
[2011/08/22 22:34:13 | 000,000,733 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/08/16 11:06:22 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2011/08/15 19:23:32 | 019,998,394 | —- | M] () – C:\Documents and Settings\Jaynelle\My Documents\11-SWA_Nov2010.pdf
[2011/08/11 06:18:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/11 03:10:25 | 000,529,574 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/11 03:10:25 | 000,103,814 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/10 14:13:53 | 001,964,773 | —- | M] () – C:\Documents and Settings\Jaynelle\Desktop\CowGirlSlideshow.pdf
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/06 12:55:09 | 000,000,874 | —- | C] () – C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\_uninst_36605977.lnk
[2011/09/02 14:07:16 | 000,000,000 | —- | C] () – C:\WINDOWS\1932768030
[2011/09/02 14:07:15 | 004,194,304 | —- | C] () – C:\WINDOWS\System32\awadhofn.dll
[2011/08/28 02:07:10 | 011,400,490 | —- | C] () – C:\Documents and Settings\Jaynelle\My Documents\CD.psd
[2011/08/27 19:50:46 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/08/27 19:50:46 | 000,001,785 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/25 09:41:06 | 000,001,832 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Brother Creative Center.lnk
[2011/08/25 09:39:25 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2011/08/25 09:39:24 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2011/08/22 22:34:13 | 000,000,733 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/08/16 11:06:22 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2011/08/15 19:23:31 | 019,998,394 | —- | C] () – C:\Documents and Settings\Jaynelle\My Documents\11-SWA_Nov2010.pdf
[2011/08/10 14:08:45 | 001,964,773 | —- | C] () – C:\Documents and Settings\Jaynelle\Desktop\CowGirlSlideshow.pdf
[2010/11/04 21:11:25 | 000,072,200 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/06/25 09:42:12 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/25 09:42:12 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/25 09:42:12 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/25 09:42:12 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/25 09:42:12 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/05/27 12:15:08 | 000,000,000 | —- | C] () – C:\WINDOWS\Jcmkr32.INI
[2009/09/04 00:17:31 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/14 09:44:13 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/06/29 02:16:21 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\Hlinkprx.dll
[2009/06/03 19:24:53 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/03/06 17:21:08 | 000,000,821 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/03/06 17:21:08 | 000,000,154 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/03/06 17:20:45 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/03/06 17:20:45 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/03/06 17:19:52 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\bridf08a.dat
[2009/03/06 17:19:41 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/03/06 16:54:20 | 000,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2008/11/30 21:08:25 | 000,273,641 | —- | C] () – C:\WINDOWS\My Reward Board Uninstaller.exe
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/10 23:50:38 | 000,038,441 | —- | C] () – C:\Documents and Settings\Jaynelle\Application Data\Comma Separated Values (DOS).ADR
[2008/02/16 11:02:12 | 000,001,327 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/09/25 23:41:13 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/09/12 19:29:53 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2007/05/08 10:48:12 | 000,027,077 | —- | C] () – C:\Documents and Settings\Jaynelle\Application Data\Comma Separated Values (Windows).ADR
[2007/03/03 21:15:20 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2006/11/03 09:01:29 | 000,000,026 | —- | C] () – C:\WINDOWS\FPKPMSV.INI
[2006/11/03 08:57:46 | 000,000,131 | —- | C] () – C:\Documents and Settings\Jaynelle\Local Settings\Application Data\fusioncache.dat
[2006/07/13 11:00:20 | 000,000,225 | —- | C] () – C:\WINDOWS\DAZZLE.INI
[2006/03/12 14:07:54 | 000,000,216 | —- | C] () – C:\WINDOWS\SearchAndRecover.INI
[2006/03/12 13:21:14 | 000,000,041 | —- | C] () – C:\WINDOWS\FileRecover.INI
[2006/03/09 19:41:46 | 000,001,356 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/09 09:38:34 | 000,000,029 | —- | C] () – C:\WINDOWS\CDMKR32.INI
[2006/01/14 16:08:11 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2005/12/31 16:32:24 | 000,063,488 | —- | C] () – C:\Documents and Settings\Jaynelle\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/10/24 08:31:14 | 000,000,144 | —- | C] () – C:\WINDOWS\MXDebug2.ini
[2005/10/19 11:47:57 | 000,003,059 | —- | C] () – C:\WINDOWS\magic32.ini
[2005/10/14 16:09:48 | 000,050,652 | —- | C] () – C:\WINDOWS\System32\drivers\atntwink.sys
[2005/10/11 16:05:20 | 000,333,288 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2005/10/11 16:05:19 | 000,427,986 | —- | C] () – C:\WINDOWS\System32\gmp202.dll
[2005/10/11 16:05:19 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\winawcli.dll
[2005/10/10 23:15:26 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\FTPStubInstUtils.dll
[2005/10/10 20:39:43 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2005/10/09 10:27:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/08 15:38:44 | 000,000,156 | —- | C] () – C:\WINDOWS\ezscsi.ini
[2005/10/08 15:00:31 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2005/10/08 12:47:36 | 000,000,191 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2005/10/08 12:47:36 | 000,000,097 | —- | C] () – C:\WINDOWS\umaxdrv.ini
[2005/10/08 11:31:36 | 000,000,083 | —- | C] () – C:\WINDOWS\ALAUNCH.INI
[2005/10/08 11:31:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\eRLog.ini
[2005/05/25 10:56:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/05/19 18:32:57 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2005/05/19 18:32:56 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2005/05/19 18:32:56 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2005/05/19 18:31:36 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIBUN4.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMPEG2.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMP3.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIFCD3.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTICDMK7.dll
[2005/05/19 18:22:59 | 000,032,768 | —- | C] () – C:\WINDOWS\AMove.exe
[2005/05/19 18:22:59 | 000,008,073 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/05/19 18:22:12 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/05/19 18:16:09 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/19 18:15:33 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/05/19 18:11:40 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/05/19 18:11:01 | 001,892,320 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/05/19 18:05:23 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/05/19 18:05:21 | 000,529,574 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/05/19 18:05:21 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/05/19 18:05:21 | 000,103,814 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/05/19 18:05:21 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/05/19 18:05:20 | 000,004,524 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/05/19 18:05:19 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/05/19 18:05:18 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/05/19 18:05:15 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/05/19 18:05:15 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/05/19 18:05:10 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/05/19 18:05:06 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/12/17 17:14:44 | 000,013,952 | —- | C] () – C:\WINDOWS\System32\drivers\UBHelper.sys
[2004/07/28 10:08:58 | 000,136,576 | —- | C] () – C:\WINDOWS\System32\drivers\pfc027.sys
[2004/01/08 10:30:22 | 000,011,170 | —- | C] () – C:\WINDOWS\System32\PA207Usd.dll
[2004/01/05 19:17:38 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\cmdrvrm.exe
[2003/05/30 15:27:46 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\cmdrvrm.dll
[2001/12/26 16:12:30 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 23:46:38 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 16:33:56 | 000,118,784 | R— | C] () – C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 22:04:36 | 000,118,784 | R— | C] () – C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1999/09/22 22:01:00 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\crush32.dll
[1999/09/22 22:01:00 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\scheidle.dll
[1999/09/22 22:01:00 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\drivers\format32.dll
[1999/09/22 22:01:00 | 000,004,480 | —- | C] () – C:\WINDOWS\System32\drivers\format16.dll
[1999/06/01 16:29:40 | 000,039,680 | —- | C] () – C:\WINDOWS\is11_16.exe
[1999/01/04 13:25:00 | 000,375,296 | —- | C] () – C:\WINDOWS\System32\tx32.dll
[1998/11/04 02:20:00 | 000,000,202 | —- | C] () – C:\WINDOWS\System32\Ic32.ini
[1998/08/12 19:10:16 | 000,054,784 | —- | C] () – C:\WINDOWS\bdongle.dll
[1998/01/13 16:38:58 | 000,370,176 | —- | C] () – C:\WINDOWS\ipmlib.dll
[1996/02/23 14:34:48 | 000,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[1996/02/22 12:09:20 | 000,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll
[1995/09/08 11:17:04 | 000,027,648 | —- | C] () – C:\WINDOWS\udcli32.dll
========== LOP Check ==========
[2005/10/24 08:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Allume Systems
[2010/06/28 15:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Altova
[2006/01/14 16:08:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/09/13 22:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2008/06/13 13:36:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2010/05/16 13:18:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2005/11/04 09:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.0 Setup
[2006/11/03 09:01:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kinko's
[2011/09/07 06:16:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2010/10/14 15:50:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LongBox
[2010/10/14 18:02:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LongBoxPublisher
[2010/09/06 15:02:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2008/09/14 08:10:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
[2009/03/06 16:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/07/17 10:53:10 | 000,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2008/02/17 07:51:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2008/02/17 07:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/06/28 15:47:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stylus Studio
[2007/12/30 12:27:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tanagra
[2010/02/01 09:04:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/03/26 08:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/01 09:17:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/07 16:13:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/14 08:37:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/10/24 08:31:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Allume Systems
[2010/03/27 19:49:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Amazon
[2010/09/04 07:43:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\com.Shutterfly.ExpressUploader
[2006/11/03 08:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Downloaded Installations
[2011/09/02 13:02:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Dropbox
[2008/10/02 16:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\eBay
[2008/05/06 15:36:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Endicia
[2010/03/12 17:59:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Facebook
[2007/09/16 00:19:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Flickr
[2009/06/29 01:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\GYST 2.8.3
[2010/06/21 16:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\GYST 3.0
[2007/07/08 12:45:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\InstaPostage
[2006/11/03 08:59:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Kinko's
[2006/03/24 12:53:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Leadertech
[2010/10/14 15:51:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\LongBoxPublisher
[2011/07/16 09:42:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\mjusbsp
[2008/05/17 15:11:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\OverDrive
[2009/07/15 16:19:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\PC-FAX TX
[2009/04/09 17:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\ScanSoft
[2006/11/25 11:17:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Snapfish
[2008/05/10 13:22:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Southwest Airlines
[2010/06/28 21:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Stylus Studio
[2006/09/30 12:51:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Turboflix
[2010/02/01 09:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Ulead Systems
[2009/11/04 06:29:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\uniblue
[2006/02/17 11:15:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Vendio
[2010/01/31 00:20:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Windows Desktop Search
[2010/02/25 11:55:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Windows Search
[2011/09/01 07:24:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\jucheck.job
[2011/09/07 02:04:00 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/09/06 13:05:22 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/07/23 01:47:25 | 000,001,024 | —- | M] () – C:\.rnd
[2005/05/19 18:31:14 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/24 20:56:49 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/26 10:36:32 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/06/25 10:35:49 | 000,026,111 | —- | M] () – C:\ComboFix.txt
[2005/05/19 18:18:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/05/05 16:18:25 | 000,000,116 | —- | M] () – C:\delecml.bat
[2007/11/20 10:27:00 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2011/09/06 13:04:21 | 2142,818,304 | -HS- | M] () – C:\hiberfil.sys
[2005/05/19 18:18:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/10/11 09:35:12 | 000,025,570 | —- | M] () – C:\MDacLog.txt
[2005/05/19 18:18:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/09/12 19:34:46 | 000,000,155 | —- | M] () – C:\myinstall.log
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/04 11:18:55 | 000,250,048 | RHS- | M] () – C:\ntldr
[2005/05/25 10:57:24 | 000,000,076 | RHS- | M] () – C:\PRELOAD.AAA
[2008/05/05 16:22:48 | 000,000,154 | —- | M] () – C:\qb3371.log
[2008/09/21 21:08:47 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2008/09/23 10:27:20 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2008/09/24 07:10:38 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2008/09/25 23:41:15 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2008/09/28 21:47:22 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2008/10/02 15:48:07 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2008/10/04 07:09:45 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2008/10/21 11:07:55 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2008/10/24 12:20:14 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2008/10/27 13:22:34 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2008/10/27 13:29:02 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2008/10/27 13:35:26 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2008/11/10 03:24:19 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2008/11/10 13:15:06 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2008/11/13 03:08:52 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2008/12/14 07:27:21 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2008/12/18 10:23:35 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2008/12/18 11:20:39 | 000,000,244 | -H– | M] () – C:\sqmdata17.sqm
[2008/12/18 11:20:40 | 000,000,196 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/08 00:04:20 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2008/09/23 10:27:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/09/24 07:10:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/09/25 23:41:15 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/09/28 21:47:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/10/02 15:48:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/10/04 07:09:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/10/21 11:07:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/10/24 12:20:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/10/27 13:22:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/10/27 13:29:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/10/27 13:35:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2008/11/10 03:24:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2008/11/10 13:15:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2008/11/13 03:08:52 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2008/12/14 07:27:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2008/12/18 10:23:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2008/12/18 11:20:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2008/12/18 11:20:40 | 000,000,172 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/08 00:04:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2008/09/21 21:08:47 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2006/01/28 08:26:30 | 000,230,454 | —- | M] () – C:\StiImg.dat
[2010/06/24 20:59:33 | 000,039,556 | —- | M] () – C:\TDSSKiller.2.3.2.0_24.06.2010_20.59.21_log.txt
[2007/09/12 19:34:46 | 000,000,273 | —- | M] () – C:\temp.log
[2007/09/12 19:33:44 | 003,378,518 | —- | M] () – C:\test.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/05/19 18:18:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/04/14 22:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2005/04/14 22:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2011/07/06 16:32:36 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2006/04/14 17:09:24 | 001,559,056 | —- | M] (XMLAuthor Inc.) – C:\WINDOWS\screengenie.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2006/02/01 11:53:28 | 000,001,626 | -H– | M] () – C:\Documents and Settings\Jaynelle\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/05/19 18:10:34 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/05/19 18:10:34 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/05/19 18:10:34 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/04 11:28:29 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/10/08 11:28:30 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/05/19 18:28:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/09/07 14:16:04 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
[2011/09/07 14:15:12 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jaynelle\Desktop\OTL.exe
[2009/08/21 12:30:07 | 000,714,760 | —- | M] (Endicia Internet Postage) – C:\Documents and Settings\Jaynelle\Desktop\PrintablePostageSetup.exe
[2009/01/16 17:14:08 | 000,156,312 | —- | M] (Seagate Technology LLC) – C:\Documents and Settings\Jaynelle\Desktop\Setup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-30 07:45:38
========== Alternate Data Streams ==========
@Alternate Data Stream - 816 bytes -> C:\WINDOWS\1932768030:3779906700.exe
< End of report >
Hijack This Log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:32:50 PM, on 9/7/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcitinfo_1315337506.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe
C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Jaynelle\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [McAfee Update] C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.exe /insfin C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.ini /syncfin
O4 - HKCU\..\Run: [McAfee McItInfo] C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcitinfo_1315337506.exe /itinsfin:C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcininfo_1315337506.ini
O4 - HKUS\S-1-5-21-4051308335-3306677665-4219388724-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: Dropbox.lnk = Dropbox\bin\Dropbox.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Startup: _uninst_36605977.lnk = Local Settings\temp\_uninst_36605977.bat
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Outlook Plugin.lnk = C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe
O4 - Global Startup: QuickBooks Remote Access.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} (XMirage Control) - http://www.mediaforge.com/downloads/xmirage.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129335948828
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9d5fa14c4c570) (gupdate1c9d5fa14c4c570) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
–
End of file - 14030 bytes
dds Log (again, only 1 log)
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Run by [removed] at 14:33:38 on 2011-09-07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2043.1283 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcitinfo_1315337506.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe
C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [cdloader] "c:\documents and settings\jaynelle\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [McAfee Update] c:\docume~1\jaynelle\locals~1\temp\mcupdate_1315267552.exe /insfin c:\docume~1\jaynelle\locals~1\temp\mcupdate_1315267552.ini /syncfin
uRun: [McAfee McItInfo] c:\docume~1\jaynelle\locals~1\temp\mcitinfo_1315337506.exe /itinsfin:c:\docume~1\jaynelle\locals~1\temp\mcininfo_1315337506.ini
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [eRecoveryService] c:\program files\acer\erecovery\Monitor.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\autoba~1.lnk - c:\program files\seagate\autobackup\MemeoLauncher.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\jaynelle\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\_unins~1.lnk - c:\documents and settings\jaynelle\local settings\temp\_uninst_36605977.bat
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\adobe acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ADOBEA~2.LNK -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ADOBEA~1.LNK -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\outloo~1.lnk - c:\program files\paypal payment request wizard\outlook wizard\OEHook.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~2.lnk - c:\windows\downlo~1\mywebex\319\raagtx.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=48835
DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} - hxxp://www.mediaforge.com/downloads/xmirage.exe
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129335948828
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: igfxcui - igfxsrvc.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\jaynelle\application data\mozilla\firefox\profiles\gavz1o6t.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\jaynelle\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\jaynelle\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\jaynelle\application data\mozilla\firefox\profiles\gavz1o6t.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\jaynelle\application data\mozilla\firefox\profiles\gavz1o6t.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\jaynelle\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPUploader.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Move Media Player: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: [removed] - %profile%\extensions\[removed]
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R0 DriveMap;DriveMap;c:\windows\system32\drivers\drivemap.sys [1999-9-22 13824]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_2_0\bin\fbguard.exe -s –> c:\program files\firebird\firebird_2_0\bin\fbguard.exe -s [?]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-9-25 189736]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-7-6 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-3-21 47640]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_2_0\bin\fbserver.exe -s –> c:\program files\firebird\firebird_2_0\bin\fbserver.exe -s [?]
R3 radpms;Driver for RADPMS Device;c:\windows\system32\drivers\radpms.sys [2008-7-24 13408]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2005-10-19 11520]
RUnknown 36605977;36605977; [x]
RUnknown 9630541drv;9630541drv; [x]
S1 AEC671X;AEC671X;c:\windows\system32\drivers\aec671x.sys [1998-5-5 12128]
S1 DMX3191;DMX3191;c:\windows\system32\drivers\dmx3191.sys [1999-2-23 17700]
S2 gupdate1c9d5fa14c4c570;Google Update Service (gupdate1c9d5fa14c4c570);c:\program files\google\update\GoogleUpdate.exe [2009-5-16 133104]
S3 cmuda2;C-Media USB Audio Interface;c:\windows\system32\drivers\cmuda2.sys [2004-1-6 705536]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-5-16 133104]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-9-17 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-9-17 40552]
S4 atnthost;WebEx Remote Access Agent;c:\windows\downlo~1\mywebex\319\atnthost.exe [2008-6-3 16792]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-8-15 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-8-15 369688]
.
=============== Created Last 30 ================
.
2011-09-02 21:07:15 4194304 —-a-w- c:\windows\system32\awadhofn.dll
2011-09-02 09:05:25 7152464 —-a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{8214e689-044f-421b-aa5f-8f048ea0801b}\mpengine.dll
2011-08-30 19:35:26 24480044 —-a-w- c:\windows\UPREVIEW.TMP
2011-08-28 01:22:30 ——– d—–w- c:\documents and settings\jaynelle\local settings\application data\Solid State Networks
2011-08-25 16:39:24 126976 ——w- c:\windows\system32\BrfxD05a.dll
2011-08-25 16:39:22 5120 ——w- c:\windows\system32\BrDctF2L.dll
2011-08-25 16:39:22 3072 ——w- c:\windows\system32\BrDctF2S.dll
2011-08-25 16:39:22 176128 ——w- c:\windows\system32\BroSNMP.dll
2011-08-25 16:39:21 73728 ——w- c:\windows\system32\BrDctF2.dll
2011-08-11 13:18:11 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-10 21:21:52 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 21:21:25 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-07-25 23:08:54 398760 —-a-r- c:\windows\system32\cpnprt2.cid
2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-06 23:32:50 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-06 23:32:36 53632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-07-06 23:32:30 29568 —-a-w- c:\windows\system32\LMIport.dll
2011-07-06 23:32:28 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-06-24 14:10:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll
.
============= FINISH: 14:34:07.29 ===============
My best guess is that my 10 year old downloaded something from the internet. A few days ago it stopped connecting to the internet and I am unable to view or ping my router. I am wired. Using Windows to repair the connection I receive an error that the IP address could not be renewed.
Router: Dlink Dir-655
Model: SURFboard SB6121
Connecting via Cox Cable
Everything else is working. I have another computer wired to the router and several wireless devices working with no problems.
OTL Log (generated 1 log only)
OTL logfile created on: 9/7/2011 2:23:10 PM - Run 2
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Jaynelle\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.72% Memory free
3.84 Gb Paging File | 3.30 Gb Available in Paging File | 85.90% Paging File free
Paging file location(s): C:\pagefile.sys 2 4096H:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.59 Gb Total Space | 2.58 Gb Free Space | 3.60% Space Free | Partition Type: NTFS
Drive E: | 698.64 Gb Total Space | 200.69 Gb Free Space | 28.73% Space Free | Partition Type: NTFS
Drive H: | 149.05 Gb Total Space | 5.97 Gb Free Space | 4.00% Space Free | Partition Type: NTFS
Computer Name: ACER-DESKTOP | User Name: Jaynelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Jaynelle\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Documents and Settings\Jaynelle\Local Settings\temp\mcitinfo_1315337506.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Documents and Settings\Jaynelle\Local Settings\temp\mcupdate_1315267552.exe (McAfee, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe ()
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfimon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe (Memeo Inc.)
PRC - C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe (A-1 Technology, Inc.)
PRC - C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe (FirebirdSQL Project)
PRC - C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe (FirebirdSQL Project)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
PRC - C:\Program Files\acer\eRecovery\Monitor.exe (acer Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c6b19db2534042d435ede580f92bc75c\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\70a1400affdc775d7c7398e036359286\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\40893760431f8f0dcce3e18630e45b23\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b7e0214a811f81e09041864081139641\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\db2d84e279807592a680ef4135e9fe9a\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d00cc387e462e4c3cdcd112b137cac87\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7ed09623172a292eaee51e2e3bcaf784\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\10154dcad2d62f226af2fd4211460a4b\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\77df2cd21a5b85a1605b335aa9ad9d44\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e6c79e1d71b0c9000afd7e5e439b5c54\System.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe ()
MOD - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()
MOD - C:\Program Files\Yahoo!\Widgets\jsd.dll ()
MOD - C:\Program Files\Yahoo!\Widgets\js32.dll ()
MOD - C:\Program Files\Seagate\AutoBackup\sqlite3.dll ()
MOD - C:\Program Files\Yahoo!\Widgets\sqlite3.dll ()
MOD - C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OELogger.dll ()
MOD - C:\Program Files\WS_FTP Pro\nsftpch.dll ()
MOD - C:\WINDOWS\system32\BrMuSNMP.dll ()
========== Win32 Services (SafeList) ==========
SRV - (CLTNetCnService) – File not found
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (atnthost) – C:\WINDOWS\Downlo~1\MyWebEx\319\atnthost.exe ()
SRV - (spupdsvc) – C:\WINDOWS\system32\spupdsvc.exe (Microsoft Corporation)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (FirebirdGuardianDefaultInstance) – C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe (FirebirdSQL Project)
SRV - (FirebirdServerDefaultInstance) – C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe (FirebirdSQL Project)
SRV - (IviRegMgr) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (StuffIt Task Manager) – C:\Program Files\Allume Systems\StuffIt\MXTask.exe (Allume Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (9630541drv) – File not found
DRV - (36605977) – File not found
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (radpms) – C:\WINDOWS\system32\drivers\radpms.sys (LogMeIn, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (RsFx0102) – C:\WINDOWS\system32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (scsiscan) – C:\WINDOWS\system32\drivers\scsiscan.sys (Microsoft Corporation)
DRV - (regi) – C:\WINDOWS\system32\drivers\regi.sys (InterVideo)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (FileDisk) – C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (DMX3191) – C:\WINDOWS\System32\drivers\DMX3191.SYS (Microsoft Corporation)
DRV - (AEC671X) – C:\WINDOWS\System32\drivers\AEC671X.SYS (Acard Technology Corp.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (zmxpzip) – C:\WINDOWS\system32\DRIVERS\zmxpzip.sys (Allume Systems)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (int15.sys) – C:\Program Files\acer\eRecovery\int15.sys ()
DRV - (ULCDRHlp) – C:\WINDOWS\system32\drivers\ULCDRHlp.sys (Ulead Systems, Inc.)
DRV - (SoC PC-Camera Service) – C:\WINDOWS\system32\drivers\pfc027.sys ()
DRV - (PQNTDrv) – C:\WINDOWS\System32\drivers\PQNTDRV.sys (PowerQuest Corporation)
DRV - (cmuda2) – C:\WINDOWS\system32\drivers\cmuda2.sys (C-Media Inc)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Aspi32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (DriveMap) – C:\WINDOWS\System32\drivers\drivemap.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.578
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@mediaforge.com/MRP: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.4: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.0: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Jaynelle\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Jaynelle\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.8: C:\Documents and Settings\Jaynelle\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/22 22:41:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.21\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/05 17:06:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.21\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/01 08:23:24 | 000,000,000 | —D | M]
[2008/08/26 08:50:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Extensions
[2011/09/06 13:59:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions
[2011/08/23 12:13:12 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/05/13 10:16:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/18 15:24:01 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/07/13 15:36:39 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/04 05:38:49 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\[removed]
[2009/07/03 02:23:17 | 000,000,000 | —D | M] (Move Media Player) – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\extensions\[removed]
[2009/01/10 23:31:05 | 000,000,655 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo-search.xml
[2009/09/04 10:48:29 | 000,000,872 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo.gif
[2009/09/04 10:48:29 | 000,000,466 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo.src
[2009/09/04 10:48:26 | 000,001,775 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Mozilla\Firefox\Profiles\gavz1o6t.default\searchplugins\yahoo.xml
[2011/09/06 13:59:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/03/22 22:41:41 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/02/22 10:14:08 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2006/01/18 12:50:00 | 000,319,488 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2005/04/27 17:31:10 | 000,225,280 | —- | M] (Asgard Software Inc.) – C:\Program Files\mozilla firefox\plugins\NPUploader.dll
[2007/03/09 16:16:44 | 000,189,496 | —- | M] (Yahoo! Inc.) – C:\Program Files\mozilla firefox\plugins\npyaxmpb.dll
Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CmUsbAudio] File not found
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [eRecoveryService] C:\Program Files\acer\eRecovery\Monitor.exe (acer Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [McAfee McItInfo] C:\Documents and Settings\Jaynelle\Local Settings\temp\mcitinfo_1315337506.exe (McAfee, Inc.)
O4 - HKCU..\Run: [McAfee Update] C:\Documents and Settings\Jaynelle\Local Settings\temp\mcupdate_1315267552.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk = File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Outlook Plugin.lnk = C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe (A-1 Technology, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Remote Access.lnk = C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe (Memeo Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\_uninst_36605977.lnk = C:\Documents and Settings\Jaynelle\Local Settings\temp\_uninst_36605977.bat ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Google Search - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: &Translate English Word - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate Page into English - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=48835 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} http://www.mediaforge.com/downloads/xmirage.exe (XMirage Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1129335948828 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_08)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: )
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/07 08:48:37 | 000,000,000 | —D | M] - C:\AutoBackup – [ NTFS ]
O32 - AutoRun File - [2005/05/19 18:31:14 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{38920ac9-de3a-11df-a3a8-0014854d2601}\Shell - "" = AutoRun
O33 - MountPoints2\{38920ac9-de3a-11df-a3a8-0014854d2601}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{38920ac9-de3a-11df-a3a8-0014854d2601}\Shell\AutoRun\command - "" = I:\setup.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/07 14:17:07 | 000,607,260 | —- | C] (Swearware) – C:\Documents and Settings\Jaynelle\Desktop\dds.scr
[2011/09/07 14:17:07 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jaynelle\Desktop\OTL.exe
[2011/09/07 14:17:07 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
[2011/09/06 13:06:46 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/09/05 16:57:07 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jaynelle\Recent
[2011/08/27 18:22:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Jaynelle\Local Settings\Application Data\Solid State Networks
[2011/08/27 02:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2011/08/25 09:40:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Brother
[2011/08/25 09:39:24 | 000,126,976 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BrfxD05a.dll
[2011/08/25 09:39:22 | 000,176,128 | —- | C] (Brother Industries, Ltd.) – C:\WINDOWS\System32\BroSNMP.dll
[2011/08/25 09:39:22 | 000,005,120 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2L.dll
[2011/08/25 09:39:22 | 000,003,072 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2S.dll
[2011/08/25 09:39:21 | 000,073,728 | —- | C] (Brother Industries Ltd.) – C:\WINDOWS\System32\BrDctF2.dll
[2011/08/25 09:34:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Jaynelle\Application Data\InstallShield
[2011/08/22 22:34:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/08/16 11:06:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Seagate
[2011/08/11 06:18:11 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/10 14:21:52 | 000,139,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpwd.sys
[2011/08/10 14:21:25 | 000,010,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndistapi.sys
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/07 14:18:14 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/07 14:16:45 | 000,607,260 | —- | M] (Swearware) – C:\Documents and Settings\Jaynelle\Desktop\dds.scr
[2011/09/07 14:16:04 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
[2011/09/07 14:15:12 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jaynelle\Desktop\OTL.exe
[2011/09/07 02:04:00 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/09/06 17:18:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/06 13:05:52 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\eRLog.ini
[2011/09/06 13:05:22 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/09/06 13:05:20 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/06 13:05:20 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-4051308335-3306677665-4219388724-1005.job
[2011/09/06 13:04:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/06 13:04:21 | 2142,818,304 | -HS- | M] () – C:\hiberfil.sys
[2011/09/06 12:55:09 | 000,000,874 | —- | M] () – C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\_uninst_36605977.lnk
[2011/09/02 14:07:16 | 000,000,000 | —- | M] () – C:\WINDOWS\1932768030
[2011/09/02 14:07:15 | 004,194,304 | —- | M] () – C:\WINDOWS\System32\awadhofn.dll
[2011/09/01 08:24:08 | 000,003,059 | —- | M] () – C:\WINDOWS\magic32.ini
[2011/09/01 08:23:14 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-4051308335-3306677665-4219388724-1005.job
[2011/09/01 07:24:00 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\jucheck.job
[2011/08/28 02:07:13 | 011,400,490 | —- | M] () – C:\Documents and Settings\Jaynelle\My Documents\CD.psd
[2011/08/27 19:50:46 | 000,001,785 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/25 09:41:06 | 000,001,832 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Brother Creative Center.lnk
[2011/08/25 09:40:42 | 000,000,821 | —- | M] () – C:\WINDOWS\Brpfx04a.ini
[2011/08/25 09:40:42 | 000,000,154 | —- | M] () – C:\WINDOWS\brpcfx.ini
[2011/08/25 09:40:23 | 000,000,419 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2011/08/25 09:40:23 | 000,000,027 | —- | M] () – C:\WINDOWS\BRPP2KA.INI
[2011/08/25 09:39:39 | 000,000,086 | —- | M] () – C:\WINDOWS\Brfaxrx.ini
[2011/08/25 09:39:39 | 000,000,050 | —- | M] () – C:\WINDOWS\System32\bridf08a.dat
[2011/08/22 22:34:13 | 000,000,733 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/08/16 11:06:22 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2011/08/15 19:23:32 | 019,998,394 | —- | M] () – C:\Documents and Settings\Jaynelle\My Documents\11-SWA_Nov2010.pdf
[2011/08/11 06:18:11 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/08/11 03:10:25 | 000,529,574 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/08/11 03:10:25 | 000,103,814 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/08/10 14:13:53 | 001,964,773 | —- | M] () – C:\Documents and Settings\Jaynelle\Desktop\CowGirlSlideshow.pdf
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/06 12:55:09 | 000,000,874 | —- | C] () – C:\Documents and Settings\Jaynelle\Start Menu\Programs\Startup\_uninst_36605977.lnk
[2011/09/02 14:07:16 | 000,000,000 | —- | C] () – C:\WINDOWS\1932768030
[2011/09/02 14:07:15 | 004,194,304 | —- | C] () – C:\WINDOWS\System32\awadhofn.dll
[2011/08/28 02:07:10 | 011,400,490 | —- | C] () – C:\Documents and Settings\Jaynelle\My Documents\CD.psd
[2011/08/27 19:50:46 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/08/27 19:50:46 | 000,001,785 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/08/25 09:41:06 | 000,001,832 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Brother Creative Center.lnk
[2011/08/25 09:39:25 | 000,000,086 | —- | C] () – C:\WINDOWS\Brfaxrx.ini
[2011/08/25 09:39:24 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2011/08/22 22:34:13 | 000,000,733 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/08/16 11:06:22 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2011/08/15 19:23:31 | 019,998,394 | —- | C] () – C:\Documents and Settings\Jaynelle\My Documents\11-SWA_Nov2010.pdf
[2011/08/10 14:08:45 | 001,964,773 | —- | C] () – C:\Documents and Settings\Jaynelle\Desktop\CowGirlSlideshow.pdf
[2010/11/04 21:11:25 | 000,072,200 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/06/25 09:42:12 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/06/25 09:42:12 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/06/25 09:42:12 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/06/25 09:42:12 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/06/25 09:42:12 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/05/27 12:15:08 | 000,000,000 | —- | C] () – C:\WINDOWS\Jcmkr32.INI
[2009/09/04 00:17:31 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/14 09:44:13 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/06/29 02:16:21 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\Hlinkprx.dll
[2009/06/03 19:24:53 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2009/03/06 17:21:08 | 000,000,821 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/03/06 17:21:08 | 000,000,154 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/03/06 17:20:45 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/03/06 17:20:45 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/03/06 17:19:52 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\bridf08a.dat
[2009/03/06 17:19:41 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/03/06 16:54:20 | 000,031,567 | —- | C] () – C:\WINDOWS\maxlink.ini
[2008/11/30 21:08:25 | 000,273,641 | —- | C] () – C:\WINDOWS\My Reward Board Uninstaller.exe
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/10 23:50:38 | 000,038,441 | —- | C] () – C:\Documents and Settings\Jaynelle\Application Data\Comma Separated Values (DOS).ADR
[2008/02/16 11:02:12 | 000,001,327 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/09/25 23:41:13 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/09/12 19:29:53 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2007/05/08 10:48:12 | 000,027,077 | —- | C] () – C:\Documents and Settings\Jaynelle\Application Data\Comma Separated Values (Windows).ADR
[2007/03/03 21:15:20 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2006/11/03 09:01:29 | 000,000,026 | —- | C] () – C:\WINDOWS\FPKPMSV.INI
[2006/11/03 08:57:46 | 000,000,131 | —- | C] () – C:\Documents and Settings\Jaynelle\Local Settings\Application Data\fusioncache.dat
[2006/07/13 11:00:20 | 000,000,225 | —- | C] () – C:\WINDOWS\DAZZLE.INI
[2006/03/12 14:07:54 | 000,000,216 | —- | C] () – C:\WINDOWS\SearchAndRecover.INI
[2006/03/12 13:21:14 | 000,000,041 | —- | C] () – C:\WINDOWS\FileRecover.INI
[2006/03/09 19:41:46 | 000,001,356 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/09 09:38:34 | 000,000,029 | —- | C] () – C:\WINDOWS\CDMKR32.INI
[2006/01/14 16:08:11 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2005/12/31 16:32:24 | 000,063,488 | —- | C] () – C:\Documents and Settings\Jaynelle\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/10/24 08:31:14 | 000,000,144 | —- | C] () – C:\WINDOWS\MXDebug2.ini
[2005/10/19 11:47:57 | 000,003,059 | —- | C] () – C:\WINDOWS\magic32.ini
[2005/10/14 16:09:48 | 000,050,652 | —- | C] () – C:\WINDOWS\System32\drivers\atntwink.sys
[2005/10/11 16:05:20 | 000,333,288 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2005/10/11 16:05:19 | 000,427,986 | —- | C] () – C:\WINDOWS\System32\gmp202.dll
[2005/10/11 16:05:19 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\winawcli.dll
[2005/10/10 23:15:26 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\FTPStubInstUtils.dll
[2005/10/10 20:39:43 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2005/10/09 10:27:56 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/10/08 15:38:44 | 000,000,156 | —- | C] () – C:\WINDOWS\ezscsi.ini
[2005/10/08 15:00:31 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2005/10/08 12:47:36 | 000,000,191 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2005/10/08 12:47:36 | 000,000,097 | —- | C] () – C:\WINDOWS\umaxdrv.ini
[2005/10/08 11:31:36 | 000,000,083 | —- | C] () – C:\WINDOWS\ALAUNCH.INI
[2005/10/08 11:31:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\eRLog.ini
[2005/05/25 10:56:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/05/19 18:32:57 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2005/05/19 18:32:56 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2005/05/19 18:32:56 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2005/05/19 18:31:36 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIBUN4.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMPEG2.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMP3.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIFCD3.dll
[2005/05/19 18:30:45 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTICDMK7.dll
[2005/05/19 18:22:59 | 000,032,768 | —- | C] () – C:\WINDOWS\AMove.exe
[2005/05/19 18:22:59 | 000,008,073 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/05/19 18:22:12 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/05/19 18:16:09 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/05/19 18:15:33 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/05/19 18:11:40 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/05/19 18:11:01 | 001,892,320 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/05/19 18:05:23 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/05/19 18:05:21 | 000,529,574 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/05/19 18:05:21 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/05/19 18:05:21 | 000,103,814 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/05/19 18:05:21 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/05/19 18:05:20 | 000,004,524 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/05/19 18:05:19 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/05/19 18:05:18 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/05/19 18:05:15 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/05/19 18:05:15 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/05/19 18:05:10 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/05/19 18:05:06 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/12/17 17:14:44 | 000,013,952 | —- | C] () – C:\WINDOWS\System32\drivers\UBHelper.sys
[2004/07/28 10:08:58 | 000,136,576 | —- | C] () – C:\WINDOWS\System32\drivers\pfc027.sys
[2004/01/08 10:30:22 | 000,011,170 | —- | C] () – C:\WINDOWS\System32\PA207Usd.dll
[2004/01/05 19:17:38 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\cmdrvrm.exe
[2003/05/30 15:27:46 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\cmdrvrm.dll
[2001/12/26 16:12:30 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 23:46:38 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 16:33:56 | 000,118,784 | R— | C] () – C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 22:04:36 | 000,118,784 | R— | C] () – C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1999/09/22 22:01:00 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\crush32.dll
[1999/09/22 22:01:00 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\scheidle.dll
[1999/09/22 22:01:00 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\drivers\format32.dll
[1999/09/22 22:01:00 | 000,004,480 | —- | C] () – C:\WINDOWS\System32\drivers\format16.dll
[1999/06/01 16:29:40 | 000,039,680 | —- | C] () – C:\WINDOWS\is11_16.exe
[1999/01/04 13:25:00 | 000,375,296 | —- | C] () – C:\WINDOWS\System32\tx32.dll
[1998/11/04 02:20:00 | 000,000,202 | —- | C] () – C:\WINDOWS\System32\Ic32.ini
[1998/08/12 19:10:16 | 000,054,784 | —- | C] () – C:\WINDOWS\bdongle.dll
[1998/01/13 16:38:58 | 000,370,176 | —- | C] () – C:\WINDOWS\ipmlib.dll
[1996/02/23 14:34:48 | 000,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[1996/02/22 12:09:20 | 000,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll
[1995/09/08 11:17:04 | 000,027,648 | —- | C] () – C:\WINDOWS\udcli32.dll
========== LOP Check ==========
[2005/10/24 08:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Allume Systems
[2010/06/28 15:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Altova
[2006/01/14 16:08:14 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/09/13 22:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2008/06/13 13:36:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2010/05/16 13:18:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2005/11/04 09:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.0 Setup
[2006/11/03 09:01:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kinko's
[2011/09/07 06:16:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2010/10/14 15:50:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LongBox
[2010/10/14 18:02:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LongBoxPublisher
[2010/09/06 15:02:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\magicJack
[2008/09/14 08:10:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
[2009/03/06 16:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/07/17 10:53:10 | 000,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2008/02/17 07:51:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2008/02/17 07:50:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/06/28 15:47:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stylus Studio
[2007/12/30 12:27:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tanagra
[2010/02/01 09:04:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/03/26 08:51:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/01 09:17:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/07 16:13:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/14 08:37:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2005/10/24 08:31:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Allume Systems
[2010/03/27 19:49:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Amazon
[2010/09/04 07:43:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\com.Shutterfly.ExpressUploader
[2006/11/03 08:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Downloaded Installations
[2011/09/02 13:02:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Dropbox
[2008/10/02 16:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\eBay
[2008/05/06 15:36:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Endicia
[2010/03/12 17:59:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Facebook
[2007/09/16 00:19:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Flickr
[2009/06/29 01:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\GYST 2.8.3
[2010/06/21 16:46:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\GYST 3.0
[2007/07/08 12:45:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\InstaPostage
[2006/11/03 08:59:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Kinko's
[2006/03/24 12:53:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Leadertech
[2010/10/14 15:51:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\LongBoxPublisher
[2011/07/16 09:42:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\mjusbsp
[2008/05/17 15:11:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\OverDrive
[2009/07/15 16:19:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\PC-FAX TX
[2009/04/09 17:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\ScanSoft
[2006/11/25 11:17:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Snapfish
[2008/05/10 13:22:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Southwest Airlines
[2010/06/28 21:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Stylus Studio
[2006/09/30 12:51:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Turboflix
[2010/02/01 09:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Ulead Systems
[2009/11/04 06:29:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\uniblue
[2006/02/17 11:15:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Vendio
[2010/01/31 00:20:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Windows Desktop Search
[2010/02/25 11:55:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Jaynelle\Application Data\Windows Search
[2011/09/01 07:24:00 | 000,000,336 | —- | M] () – C:\WINDOWS\Tasks\jucheck.job
[2011/09/07 02:04:00 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/09/06 13:05:22 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/07/23 01:47:25 | 000,001,024 | —- | M] () – C:\.rnd
[2005/05/19 18:31:14 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/24 20:56:49 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/06/26 10:36:32 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/06/25 10:35:49 | 000,026,111 | —- | M] () – C:\ComboFix.txt
[2005/05/19 18:18:34 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/05/05 16:18:25 | 000,000,116 | —- | M] () – C:\delecml.bat
[2007/11/20 10:27:00 | 000,000,182 | —- | M] () – C:\drwtsn32.log
[2011/09/06 13:04:21 | 2142,818,304 | -HS- | M] () – C:\hiberfil.sys
[2005/05/19 18:18:34 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/10/11 09:35:12 | 000,025,570 | —- | M] () – C:\MDacLog.txt
[2005/05/19 18:18:34 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/09/12 19:34:46 | 000,000,155 | —- | M] () – C:\myinstall.log
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/04 11:18:55 | 000,250,048 | RHS- | M] () – C:\ntldr
[2005/05/25 10:57:24 | 000,000,076 | RHS- | M] () – C:\PRELOAD.AAA
[2008/05/05 16:22:48 | 000,000,154 | —- | M] () – C:\qb3371.log
[2008/09/21 21:08:47 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2008/09/23 10:27:20 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2008/09/24 07:10:38 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2008/09/25 23:41:15 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2008/09/28 21:47:22 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2008/10/02 15:48:07 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2008/10/04 07:09:45 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2008/10/21 11:07:55 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2008/10/24 12:20:14 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2008/10/27 13:22:34 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2008/10/27 13:29:02 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2008/10/27 13:35:26 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2008/11/10 03:24:19 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2008/11/10 13:15:06 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2008/11/13 03:08:52 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2008/12/14 07:27:21 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2008/12/18 10:23:35 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2008/12/18 11:20:39 | 000,000,244 | -H– | M] () – C:\sqmdata17.sqm
[2008/12/18 11:20:40 | 000,000,196 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/08 00:04:20 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2008/09/23 10:27:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/09/24 07:10:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/09/25 23:41:15 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/09/28 21:47:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/10/02 15:48:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/10/04 07:09:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/10/21 11:07:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/10/24 12:20:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/10/27 13:22:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/10/27 13:29:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/10/27 13:35:26 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2008/11/10 03:24:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2008/11/10 13:15:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2008/11/13 03:08:52 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2008/12/14 07:27:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2008/12/18 10:23:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2008/12/18 11:20:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2008/12/18 11:20:40 | 000,000,172 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/08 00:04:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2008/09/21 21:08:47 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2006/01/28 08:26:30 | 000,230,454 | —- | M] () – C:\StiImg.dat
[2010/06/24 20:59:33 | 000,039,556 | —- | M] () – C:\TDSSKiller.2.3.2.0_24.06.2010_20.59.21_log.txt
[2007/09/12 19:34:46 | 000,000,273 | —- | M] () – C:\temp.log
[2007/09/12 19:33:44 | 003,378,518 | —- | M] () – C:\test.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/05/19 18:18:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/04/14 22:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD78.DLL
[2005/04/14 22:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP78.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2011/07/06 16:32:36 | 000,053,632 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2006/04/14 17:09:24 | 001,559,056 | —- | M] (XMLAuthor Inc.) – C:\WINDOWS\screengenie.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2006/02/01 11:53:28 | 000,001,626 | -H– | M] () – C:\Documents and Settings\Jaynelle\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/05/19 18:10:34 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/05/19 18:10:34 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/05/19 18:10:34 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/04 11:28:29 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/10/08 11:28:30 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/05/19 18:28:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jaynelle\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/09/07 14:16:04 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
[2011/09/07 14:15:12 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jaynelle\Desktop\OTL.exe
[2009/08/21 12:30:07 | 000,714,760 | —- | M] (Endicia Internet Postage) – C:\Documents and Settings\Jaynelle\Desktop\PrintablePostageSetup.exe
[2009/01/16 17:14:08 | 000,156,312 | —- | M] (Seagate Technology LLC) – C:\Documents and Settings\Jaynelle\Desktop\Setup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-30 07:45:38
========== Alternate Data Streams ==========
@Alternate Data Stream - 816 bytes -> C:\WINDOWS\1932768030:3779906700.exe
< End of report >
Hijack This Log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:32:50 PM, on 9/7/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcitinfo_1315337506.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe
C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Jaynelle\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Jaynelle\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [McAfee Update] C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.exe /insfin C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.ini /syncfin
O4 - HKCU\..\Run: [McAfee McItInfo] C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcitinfo_1315337506.exe /itinsfin:C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcininfo_1315337506.ini
O4 - HKUS\S-1-5-21-4051308335-3306677665-4219388724-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Seagate\AutoBackup\MemeoLauncher.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: Dropbox.lnk = Dropbox\bin\Dropbox.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Startup: _uninst_36605977.lnk = Local Settings\temp\_uninst_36605977.bat
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Outlook Plugin.lnk = C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe
O4 - Global Startup: QuickBooks Remote Access.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} (XMirage Control) - http://www.mediaforge.com/downloads/xmirage.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129335948828
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9d5fa14c4c570) (gupdate1c9d5fa14c4c570) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
–
End of file - 14030 bytes
dds Log (again, only 1 log)
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Run by [removed] at 14:33:38 on 2011-09-07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2043.1283 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbguard.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Firebird\Firebird_2_0\bin\fbserver.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcupdate_1315267552.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\Jaynelle\LOCALS~1\Temp\mcitinfo_1315337506.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\PayPal Payment Request Wizard\Outlook Wizard\OEHook.exe
C:\WINDOWS\Downlo~1\MyWebEx\319\raagtx.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Documents and Settings\Jaynelle\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Seagate\AutoBackup\MemeoBackup.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [cdloader] "c:\documents and settings\jaynelle\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [McAfee Update] c:\docume~1\jaynelle\locals~1\temp\mcupdate_1315267552.exe /insfin c:\docume~1\jaynelle\locals~1\temp\mcupdate_1315267552.ini /syncfin
uRun: [McAfee McItInfo] c:\docume~1\jaynelle\locals~1\temp\mcitinfo_1315337506.exe /itinsfin:c:\docume~1\jaynelle\locals~1\temp\mcininfo_1315337506.ini
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [eRecoveryService] c:\program files\acer\erecovery\Monitor.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\autoba~1.lnk - c:\program files\seagate\autobackup\MemeoLauncher.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\jaynelle\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\docume~1\jaynelle\startm~1\programs\startup\_unins~1.lnk - c:\documents and settings\jaynelle\local settings\temp\_uninst_36605977.bat
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\adobe acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ADOBEA~2.LNK -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ADOBEA~1.LNK -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\outloo~1.lnk - c:\program files\paypal payment request wizard\outlook wizard\OEHook.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~2.lnk - c:\windows\downlo~1\mywebex\319\raagtx.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=48835
DPF: {21F16767-8DA7-4113-BEB0-F161B313407F} - hxxp://www.mediaforge.com/downloads/xmirage.exe
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1129335948828
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: igfxcui - igfxsrvc.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\jaynelle\application data\mozilla\firefox\profiles\gavz1o6t.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\jaynelle\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\jaynelle\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\jaynelle\application data\mozilla\firefox\profiles\gavz1o6t.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\jaynelle\application data\mozilla\firefox\profiles\gavz1o6t.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\jaynelle\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPUploader.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - Ext: Forecastfox: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: Move Media Player: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: LogMeIn, Inc. Remote Access Plugin: [removed] - %profile%\extensions\[removed]
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R0 DriveMap;DriveMap;c:\windows\system32\drivers\drivemap.sys [1999-9-22 13824]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_2_0\bin\fbguard.exe -s –> c:\program files\firebird\firebird_2_0\bin\fbguard.exe -s [?]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-9-25 189736]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-7-6 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-3-21 47640]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_2_0\bin\fbserver.exe -s –> c:\program files\firebird\firebird_2_0\bin\fbserver.exe -s [?]
R3 radpms;Driver for RADPMS Device;c:\windows\system32\drivers\radpms.sys [2008-7-24 13408]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2005-10-19 11520]
RUnknown 36605977;36605977; [x]
RUnknown 9630541drv;9630541drv; [x]
S1 AEC671X;AEC671X;c:\windows\system32\drivers\aec671x.sys [1998-5-5 12128]
S1 DMX3191;DMX3191;c:\windows\system32\drivers\dmx3191.sys [1999-2-23 17700]
S2 gupdate1c9d5fa14c4c570;Google Update Service (gupdate1c9d5fa14c4c570);c:\program files\google\update\GoogleUpdate.exe [2009-5-16 133104]
S3 cmuda2;C-Media USB Audio Interface;c:\windows\system32\drivers\cmuda2.sys [2004-1-6 705536]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-5-16 133104]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-9-17 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-9-17 40552]
S4 atnthost;WebEx Remote Access Agent;c:\windows\downlo~1\mywebex\319\atnthost.exe [2008-6-3 16792]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-8-15 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-8-15 369688]
.
=============== Created Last 30 ================
.
2011-09-02 21:07:15 4194304 —-a-w- c:\windows\system32\awadhofn.dll
2011-09-02 09:05:25 7152464 —-a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{8214e689-044f-421b-aa5f-8f048ea0801b}\mpengine.dll
2011-08-30 19:35:26 24480044 —-a-w- c:\windows\UPREVIEW.TMP
2011-08-28 01:22:30 ——– d—–w- c:\documents and settings\jaynelle\local settings\application data\Solid State Networks
2011-08-25 16:39:24 126976 ——w- c:\windows\system32\BrfxD05a.dll
2011-08-25 16:39:22 5120 ——w- c:\windows\system32\BrDctF2L.dll
2011-08-25 16:39:22 3072 ——w- c:\windows\system32\BrDctF2S.dll
2011-08-25 16:39:22 176128 ——w- c:\windows\system32\BroSNMP.dll
2011-08-25 16:39:21 73728 ——w- c:\windows\system32\BrDctF2.dll
2011-08-11 13:18:11 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-10 21:21:52 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 21:21:25 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-07-25 23:08:54 398760 —-a-r- c:\windows\system32\cpnprt2.cid
2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-06 23:32:50 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-06 23:32:36 53632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-07-06 23:32:30 29568 —-a-w- c:\windows\system32\LMIport.dll
2011-07-06 23:32:28 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-06-24 14:10:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll
.
============= FINISH: 14:34:07.29 ===============