This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect/Symantec Antivirus disabled

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Yesterday my computer began running VERY slowly. Whatever is infecting my computer redirects Google when I search in Firefox and disabled Symantec antivirus: when I try to do a scan, the scan immediately completes without scanning any files.

I downloaded OTL as instructed. I also ran HijackThis as instructed. The logs are below. Any assistance would be much appreciated.


OTL logfile created on: 10/25/2011 9:40:03 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Megan Honig\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.11 Mb Total Physical Memory | 308.75 Mb Available Physical Memory | 30.45% Memory free
2.38 Gb Paging File | 1.77 Gb Available in Paging File | 74.21% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 104.79 Gb Total Space | 38.84 Gb Free Space | 37.07% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 296.93 Gb Free Space | 63.75% Space Free | Partition Type: NTFS
Drive F: | 135.54 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 953.72 Mb Total Space | 421.03 Mb Free Space | 44.15% Space Free | Partition Type: FAT

Computer Name: NEWFRIEND | User Name: Megan Honig | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Megan Honig\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
PRC - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Immunet\3.0.1\iptray.exe (Immunet)
PRC - C:\Program Files\Immunet\3.0.1\agent.exe (Sourcefire, Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe (Maxtor Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe ()
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)


========== Modules (No Company Name) ==========

MOD - c:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\Locales\en-US.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avutil-51.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avformat-53.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\avcodec-53.dll ()
MOD - C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gcswf32.dll ()
MOD - C:\Program Files\Immunet\3.0.1\dhr.dll ()
MOD - C:\Program Files\Immunet\3.0.1\dsp.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware 2007\Update.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()


========== Win32 Services (SafeList) ==========

SRV - (VzCdbSvc) – File not found
SRV - (VAIO Event Service) – File not found
SRV - (JavaQuickStarterService) – File not found
SRV - (iPod Service) – File not found
SRV - (Bonjour Service) – File not found
SRV - (Apple Mobile Device) – File not found
SRV - (VzFw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (SonicStageMonitoring) – C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft AB)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_807ba95.dll ()
SRV - (scan) – C:\Program Files\Immunet\tetra\scan.dll (S.C. BitDefender S.R.L)
SRV - (ImmunetProtect) – C:\Program Files\Immunet\3.0.1\agent.exe (Sourcefire, Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (ADVService) – C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
SRV - (Basics Service) – C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe ()
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111014.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111014.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (Trufos) – C:\WINDOWS\system32\drivers\Trufos.sys (BitDefender S.R.L.)
DRV - (ImmunetProtectDriver) – C:\WINDOWS\system32\drivers\ImmunetProtect.sys (Windows ® Codename Longhorn DDK provider)
DRV - (ImmunetSelfProtectDriver) – C:\WINDOWS\system32\drivers\ImmunetSelfProtect.sys (Windows ® Codename Longhorn DDK provider)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (Tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (Tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TosRfSnd) Bluetooth Audio Device (WDM) – C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (ti21sony) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (toshidpt) – C:\WINDOWS\system32\drivers\toshidpt.sys (TOSHIBA Corporation.)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@emusic.com/dlm-plugin: C:\Program Files\eMusic Download Manager\plugin\npemusic.dll (eMusic.com)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@emusic.com/dlm-plugin: C:\Program Files\eMusic Download Manager\plugin\npemusic.dll (eMusic.com)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2011/05/09 13:40:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2011/05/09 13:40:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Remote\Extensions\\Components: C:\Program Files\eMusic Remote\xulrunner\components [2011/05/09 13:40:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\eMusic Remote\Extensions\\Plugins: C:\Program Files\eMusic Remote\xulrunner\plugins [2011/05/09 13:40:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/08 12:14:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2011/10/17 23:29:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/28 11:16:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/28 11:16:31 | 000,000,000 | —D | M]

[2008/06/25 09:54:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Extensions
[2011/10/25 09:32:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions
[2011/04/02 23:35:36 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/25 00:28:07 | 000,000,000 | —D | M] (Facebook Friend Request, Notifications & Messages Alerts + Facebook Like Button) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{30A7232F-77C9-4bd3-A812-3036704DB7AC}(2)
[2010/11/28 10:50:40 | 000,000,000 | —D | M] (Gmail Notifier) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
[2011/09/09 15:44:53 | 000,000,000 | —D | M] (Gmail Manager) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2011/10/05 08:33:29 | 000,000,000 | —D | M] (eMusic Community Toolbar) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{9ee802e8-c931-47ab-b570-aa8f791598ca}
[2011/10/05 08:33:20 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/09/10 07:31:07 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/10/25 00:28:03 | 000,000,000 | —D | M] (Echofon) – C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Profiles\7f6rf94r.default\extensions\twitternotifier@naan(2).net
[2011/10/25 09:32:21 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/14 22:30:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/06/10 09:58:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/04/17 21:36:50 | 000,000,000 | —D | M] (eMusic - Apple iTunes Support) – C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\[removed]
[2009/04/17 21:36:50 | 000,000,000 | —D | M] (eMusic - Nullsoft Winamp Support) – C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\[removed]
[2009/04/17 21:36:51 | 000,000,000 | —D | M] (eMusic - Microsoft Media Player Support) – C:\PROGRAM FILES\EMUSIC DOWNLOAD MANAGER\XULRUNNER\EXTENSIONS\[removed]
[2011/05/04 04:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2005/12/05 23:31:00 | 000,114,688 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2005/04/27 17:31:10 | 000,225,280 | —- | M] (Asgard Software Inc.) – C:\Program Files\mozilla firefox\plugins\NPUploader.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Shutterfly Upload Plugin 2.0.4.0 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPUploader.dll
CHR - plugin: getPlusPlus for Adobe 16244 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: eMusic Remote Plugin (Enabled) = C:\Program Files\eMusic Download Manager\plugin\npemusic.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\

O1 HOSTS File: ([2006/03/15 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O4 - HKLM..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe ()
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [basicsmssmenu] C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe (Maxtor Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Immunet Protect] C:\Program Files\Immunet\3.0.1\iptray.exe (Immunet)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\SONYSYS\VAIO Recovery\Partseal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [MX Skype Recorder] "C:\Documents and Settings\All Users\Application Data\MXSkypeRecorder\MXSkypeRecorder.exe" /autorun File not found
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} http://simcity.ea.com/play/classic/SimCityX.cab (SimCityX Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://download.games.yahoo.com/games/web_…aploader_v6.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D0DE3224-BD67-4F0F-8EC9-93DB55F7FC00}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Megan Honig\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/29 00:43:07 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/08/17 13:48:16 | 000,000,040 | —- | M] () - E:\Autorun.inf – [ NTFS ]
O32 - AutoRun File - [2007/04/20 16:41:05 | 000,000,065 | R— | M] () - F:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{341d8268-d98a-11db-a432-0018de784af5}\Shell - "" = AutoRun
O33 - MountPoints2\{341d8268-d98a-11db-a432-0018de784af5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{341d8268-d98a-11db-a432-0018de784af5}\Shell\AutoRun\command - "" = H:\LaunchU3.exe
O33 - MountPoints2\{e3992f1c-870e-11dc-a45e-0018de784af5}\Shell\AutoRun\command - "" = E:\system\viewer\FlipVideoforPC.exe
O33 - MountPoints2\{e3992f1c-870e-11dc-a45e-0018de784af5}\Shell\Flip Video for PC\command - "" = E:\system\viewer\FlipVideoforPC.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.dvsd - C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll (Sony Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/10/25 09:02:23 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/10/25 00:28:51 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/10/25 00:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/10/24 12:57:04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/10/24 12:06:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Megan Honig\My Documents\LGBTQ teens.scriv
[2011/10/24 12:05:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Scrivener
[2011/10/24 12:02:02 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Megan Honig\Local Settings\Application Data\9f2e21e5
[2011/10/24 11:29:21 | 000,000,000 | —D | C] – C:\Program Files\Scrivener
[2011/10/17 23:27:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Deployment
[2011/10/06 18:51:26 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Megan Honig\Application Data\SecuROM
[2011/10/06 18:51:19 | 000,108,144 | —- | C] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2011/10/06 18:51:03 | 000,000,000 | —D | C] – C:\Program Files\Hasbro
[2011/10/05 11:37:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Megan Honig\.gimp-2.6
[2011/10/04 08:45:18 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/09/29 01:02:11 | 001,372,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6.dll
[2011/09/29 01:02:11 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml6r.dll
[2011/09/29 01:00:41 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comsdupd.exe
[2011/09/29 01:00:40 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2011/09/29 01:00:39 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2011/09/29 01:00:15 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\aaclient.dll
[2011/09/29 01:00:14 | 000,377,984 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvaa.dll
[2011/09/29 01:00:14 | 000,229,376 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2cqag.dll
[2011/09/29 01:00:14 | 000,201,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ati2dvag.dll
[2011/09/29 01:00:13 | 001,888,992 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3duag.dll
[2011/09/29 01:00:13 | 000,870,784 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ati3d1ag.dll
[2011/09/29 01:00:12 | 000,516,768 | —- | C] (ATI Technologies Inc. ) – C:\WINDOWS\System32\ativvaxx.dll
[2011/09/29 01:00:12 | 000,233,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\azroles.dll
[2011/09/29 01:00:12 | 000,032,768 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativtmxx.dll
[2011/09/29 01:00:12 | 000,023,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativmvxx.ax
[2011/09/29 01:00:12 | 000,009,728 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\ativdaxx.ax
[2011/09/29 01:00:10 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2011/09/29 01:00:04 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dhcpqec.dll
[2011/09/29 01:00:03 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3cfg.dll
[2011/09/29 01:00:03 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dimsroam.dll
[2011/09/29 01:00:02 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3msm.dll
[2011/09/29 01:00:02 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3gpclnt.dll
[2011/09/29 01:00:00 | 000,650,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dot3ui.dll
[2011/09/29 00:59:59 | 000,184,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapp3hst.dll
[2011/09/29 00:59:58 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapphost.dll
[2011/09/29 00:59:58 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eappgnui.dll
[2011/09/29 00:59:57 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\eapqec.dll
[2011/09/29 00:59:53 | 000,032,285 | —- | C] (Conexant Systems, Inc.) – C:\WINDOWS\System32\hsfcisp2.dll
[2011/09/29 00:59:47 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdbhc.dll
[2011/09/29 00:59:45 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdiultn.dll
[2011/09/29 00:59:43 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdpash.dll
[2011/09/29 00:59:43 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kbdnepr.dll
[2011/09/29 00:59:41 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\l2gpstore.dll
[2011/09/29 00:59:40 | 000,397,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcex.dll
[2011/09/29 00:59:40 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\microsoft.managementconsole.dll
[2011/09/29 00:59:39 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcfxcommon.dll
[2011/09/29 00:59:39 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mmcperf.exe
[2011/09/29 00:59:36 | 001,737,856 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\mtxparhd.dll
[2011/09/29 00:59:36 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mssha.dll
[2011/09/29 00:59:36 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msshavmsg.dll
[2011/09/29 00:59:36 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napipsec.dll
[2011/09/29 00:59:35 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napmontr.dll
[2011/09/29 00:59:35 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\napstat.exe
[2011/09/29 00:59:34 | 004,274,816 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nv4_disp.dll
[2011/09/29 00:59:29 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qagent.dll
[2011/09/29 00:59:29 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\qcliprov.dll
[2011/09/29 00:59:28 | 000,290,304 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rhttpaa.dll
[2011/09/29 00:59:27 | 000,397,056 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\s3gnb.dll
[2011/09/29 00:59:26 | 000,286,792 | —- | C] (Smart Link) – C:\WINDOWS\System32\slextspk.dll
[2011/09/29 00:59:26 | 000,188,508 | —- | C] (Smart Link) – C:\WINDOWS\System32\slgen.dll
[2011/09/29 00:59:26 | 000,073,832 | —- | C] (Smart Link) – C:\WINDOWS\System32\slcoinst.dll
[2011/09/29 00:59:26 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\System32\slrundll.exe
[2011/09/29 00:59:26 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\setupn.exe
[2011/09/29 00:59:25 | 000,073,796 | —- | C] (Smart Link) – C:\WINDOWS\System32\slserv.exe
[2011/09/29 00:59:23 | 000,053,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\tsgqec.dll
[2011/09/29 00:59:22 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vidcap.ax
[2011/09/29 00:59:17 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wlanapi.dll
[2011/09/29 00:59:08 | 000,032,866 | —- | C] (Smart Link) – C:\WINDOWS\slrundll.exe
[2011/09/29 00:59:01 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/09/29 00:58:51 | 000,000,000 | —D | C] – C:\WINDOWS\l2schemas
[2011/09/29 00:58:46 | 000,000,000 | —D | C] – C:\Program Files\msn
[2011/09/29 00:58:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/09/29 00:58:44 | 000,000,000 | —D | C] – C:\WINDOWS\System32\bits
[2011/09/29 00:33:32 | 000,004,255 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv01nt5.dll
[2011/09/29 00:33:32 | 000,003,967 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv02nt5.dll
[2011/09/29 00:33:32 | 000,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2011/09/29 00:33:31 | 000,003,775 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv11nt5.dll
[2011/09/29 00:33:31 | 000,003,711 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv09nt5.dll
[2011/09/29 00:33:31 | 000,003,647 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv07nt5.dll
[2011/09/29 00:33:31 | 000,003,615 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv05nt5.dll
[2011/09/29 00:33:31 | 000,003,135 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\adv08nt5.dll
[2011/09/29 00:33:30 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1btxx.sys
[2011/09/29 00:33:29 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1rvxx.sys
[2011/09/29 00:33:29 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1raxx.sys
[2011/09/29 00:33:29 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1pdxx.sys
[2011/09/29 00:33:29 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1mdxx.sys
[2011/09/29 00:33:28 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1snxx.sys
[2011/09/29 00:33:28 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1ttxx.sys
[2011/09/29 00:33:27 | 000,327,040 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtaa.sys
[2011/09/29 00:33:27 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1tuxx.sys
[2011/09/29 00:33:27 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xsxx.sys
[2011/09/29 00:33:27 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati1xbxx.sys
[2011/09/29 00:33:26 | 000,701,440 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\ati2mtag.sys
[2011/09/29 00:33:26 | 000,104,960 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinrvxx.sys
[2011/09/29 00:33:26 | 000,057,856 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinbtxx.sys
[2011/09/29 00:33:26 | 000,052,224 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinraxx.sys
[2011/09/29 00:33:26 | 000,014,336 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinpdxx.sys
[2011/09/29 00:33:26 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinmdxx.sys
[2011/09/29 00:33:25 | 000,073,216 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atintuxx.sys
[2011/09/29 00:33:25 | 000,063,488 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxsxx.sys
[2011/09/29 00:33:25 | 000,031,744 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinxbxx.sys
[2011/09/29 00:33:25 | 000,028,672 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinsnxx.sys
[2011/09/29 00:33:25 | 000,013,824 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\drivers\atinttxx.sys
[2011/09/29 00:33:24 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv04nt5.dll
[2011/09/29 00:33:24 | 000,021,183 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv01nt5.dll
[2011/09/29 00:33:24 | 000,011,359 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv02nt5.dll
[2011/09/29 00:33:23 | 000,017,279 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv10nt5.dll
[2011/09/29 00:33:23 | 000,014,143 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\atv06nt5.dll
[2011/09/29 00:33:21 | 000,036,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bthprint.sys
[2011/09/29 00:33:21 | 000,015,423 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\ch7xxnt5.dll
[2011/09/29 00:33:11 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2011/09/29 00:33:09 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2011/09/29 00:33:07 | 000,452,736 | —- | C] (Matrox Graphics Inc.) – C:\WINDOWS\System32\drivers\mtxparhm.sys
[2011/09/29 00:33:07 | 000,012,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mutohpen.sys
[2011/09/29 00:33:06 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2011/09/29 00:33:04 | 000,166,912 | —- | C] (S3 Graphics, Inc.) – C:\WINDOWS\System32\drivers\s3gnbm.sys
[2011/09/29 00:33:04 | 000,030,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\rndismpx.sys
[2011/09/29 00:33:04 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\recagent.sys
[2011/09/29 00:33:02 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnt7554.sys
[2011/09/29 00:33:02 | 000,003,901 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\siint5.dll
[2011/09/29 00:33:01 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slntamr.sys
[2011/09/29 00:33:00 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slnthal.sys
[2011/09/29 00:32:59 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\drivers\slwdmsup.sys
[2011/09/29 00:32:58 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\smbali.sys
[2011/09/29 00:32:50 | 000,011,325 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\vchnt5.dll
[2011/09/29 00:32:49 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv07nt.sys
[2011/09/29 00:32:49 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv08nt.sys
[2011/09/29 00:32:48 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv09nt.sys
[2011/09/29 00:32:47 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv10nt.sys
[2011/09/29 00:32:47 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\watv06nt.sys
[2011/09/29 00:32:47 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\drivers\wadv11nt.sys
[2011/09/29 00:13:57 | 000,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstall$
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found – C:\WINDOWS\System32\
[2011/10/25 10:03:03 | 000,001,002 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2872905650-4066941124-1819559532-1005UA.job
[2011/10/25 10:02:13 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/10/25 10:02:13 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/10/25 09:39:49 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2872905650-4066941124-1819559532-1005.job
[2011/10/25 09:39:44 | 000,000,298 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2872905650-4066941124-1819559532-1005.job
[2011/10/25 09:33:05 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/25 09:04:36 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/25 08:58:42 | 000,000,000 | —- | M] () – C:\WINDOWS\3844157087
[2011/10/25 08:58:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/25 08:58:37 | 1063,440,384 | -HS- | M] () – C:\hiberfil.sys
[2011/10/25 01:03:05 | 000,000,950 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2872905650-4066941124-1819559532-1005Core.job
[2011/10/24 23:59:46 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/24 23:47:25 | 000,000,945 | —- | M] () – C:\Documents and Settings\Megan Honig\My Documents\LGBTQ teens outline.rtf
[2011/10/24 22:05:47 | 000,000,436 | —- | M] () – C:\WINDOWS\tasks\SyncBack Nightly.job
[2011/10/24 21:09:31 | 000,000,434 | —- | M] () – C:\WINDOWS\tasks\SyncBack Weekly.job
[2011/10/22 12:31:54 | 000,405,864 | —- | M] () – C:\Documents and Settings\Megan Honig\.recently-used.xbel
[2011/10/21 15:59:48 | 000,000,015 | —- | M] () – C:\WINDOWS\System32\package.lst
[2011/10/17 23:32:15 | 000,001,850 | —- | M] () – C:\Documents and Settings\Megan Honig\Application Data\Microsoft\Internet Explorer\Quick Launch\Remember The Milk.lnk
[2011/10/06 18:51:19 | 000,108,144 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2011/10/06 18:51:13 | 000,000,806 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SCRABBLE.lnk
[2011/10/05 10:43:53 | 000,033,181 | —- | M] () – C:\Documents and Settings\Megan Honig\My Documents\TS001042766.dot
[2011/10/04 18:54:17 | 000,002,330 | —- | M] () – C:\Documents and Settings\Megan Honig\Desktop\Google Chrome.lnk
[2011/10/04 18:54:17 | 000,002,308 | —- | M] () – C:\Documents and Settings\Megan Honig\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/04 08:52:08 | 000,441,692 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/04 08:52:07 | 000,071,462 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/04 08:51:44 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/04 08:48:50 | 000,000,779 | —- | M] () – C:\Documents and Settings\Megan Honig\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/10/04 08:44:19 | 000,263,024 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/09/29 08:55:54 | 000,002,638 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/09/29 00:30:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/09/28 11:25:57 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/24 23:47:25 | 000,000,945 | —- | C] () – C:\Documents and Settings\Megan Honig\My Documents\LGBTQ teens outline.rtf
[2011/10/24 12:58:33 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/10/24 12:58:33 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/10/24 12:02:27 | 000,000,000 | —- | C] () – C:\WINDOWS\3844157087
[2011/10/22 12:31:54 | 000,405,864 | —- | C] () – C:\Documents and Settings\Megan Honig\.recently-used.xbel
[2011/10/17 23:32:15 | 000,001,850 | —- | C] () – C:\Documents and Settings\Megan Honig\Application Data\Microsoft\Internet Explorer\Quick Launch\Remember The Milk.lnk
[2011/10/17 23:32:15 | 000,001,838 | —- | C] () – C:\Documents and Settings\Megan Honig\Start Menu\Programs\Remember The Milk.lnk
[2011/10/17 23:28:42 | 000,000,896 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/17 23:28:41 | 000,000,892 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/06 18:51:12 | 000,000,806 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SCRABBLE.lnk
[2011/10/05 10:43:51 | 000,033,181 | —- | C] () – C:\Documents and Settings\Megan Honig\My Documents\TS001042766.dot
[2011/09/29 00:33:24 | 000,064,352 | —- | C] () – C:\WINDOWS\System32\drivers\ativmc20.cod
[2011/09/29 00:33:21 | 000,129,045 | —- | C] () – C:\WINDOWS\System32\drivers\cxthsfs2.cty
[2011/09/29 00:33:07 | 000,067,866 | —- | C] () – C:\WINDOWS\System32\drivers\netwlan5.img
[2011/09/28 11:25:57 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/12 11:50:51 | 000,017,912 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\365ygsv3vr2f73668tqlayik78tvj4laronal3ywq48g
[2011/06/12 11:50:50 | 000,017,912 | -HS- | C] () – C:\Documents and Settings\Megan Honig\Local Settings\Application Data\365ygsv3vr2f73668tqlayik78tvj4laronal3ywq48g
[2011/05/28 17:18:25 | 000,136,448 | —- | C] () – C:\WINDOWS\RMTOOLS.DLL
[2010/12/01 15:10:46 | 000,000,215 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2010/08/06 09:23:23 | 000,054,592 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/05/19 22:59:46 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/09/08 17:17:59 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/03/26 00:04:37 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/02/23 16:25:19 | 000,001,356 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/09/09 12:01:19 | 000,000,501 | —- | C] () – C:\WINDOWS\eReg.dat
[2007/04/13 15:19:52 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2007/03/26 21:16:23 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2007/03/19 07:40:45 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2007/02/16 19:30:42 | 000,001,203 | —- | C] () – C:\WINDOWS\mozver.dat
[2007/02/14 23:33:47 | 098,554,909 | —- | C] () – C:\Program Files\OOo_2.1.0_Win32Intel_install_en-US.exe
[2007/02/07 23:04:22 | 000,027,648 | —- | C] () – C:\Documents and Settings\Megan Honig\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/02/07 23:04:21 | 000,000,134 | —- | C] () – C:\Documents and Settings\Megan Honig\Local Settings\Application Data\fusioncache.dat
[2006/09/14 16:28:21 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/09/14 16:28:21 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/09/14 16:28:21 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/09/14 16:28:21 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/09/14 16:28:21 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/09/14 16:28:21 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/09/14 16:27:43 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2006/09/14 16:19:58 | 000,002,154 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2006/09/14 16:18:07 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2006/09/14 16:16:00 | 000,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/09/14 16:14:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/14 16:08:08 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2006/08/10 05:53:16 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/08/10 05:46:34 | 000,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/08/10 04:54:20 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006/08/10 04:54:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/08/10 04:34:49 | 000,111,552 | —- | C] () – C:\WINDOWS\setup.exe
[2006/08/10 04:25:29 | 000,000,031 | —- | C] () – C:\WINDOWS\System32\elcric.dat
[2006/08/10 03:57:42 | 000,000,811 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/08/10 03:53:45 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/08/10 03:47:26 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/08/10 03:33:16 | 000,000,758 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/08/10 03:32:53 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/08/10 03:32:52 | 000,441,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/08/10 03:32:52 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/08/10 03:32:52 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/08/10 03:32:51 | 000,071,462 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/08/10 03:32:51 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/08/10 03:32:50 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/08/10 03:32:50 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/08/10 03:32:47 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/08/10 03:32:47 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/08/10 03:32:44 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/08/10 03:32:40 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/08/09 20:40:28 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/08/09 20:39:41 | 000,263,024 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/08/09 14:44:08 | 000,610,304 | —- | C] () – C:\WINDOWS\System32\lpykrp.exe
[2006/08/09 14:24:32 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/01 21:53:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 17:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2002/06/12 15:21:12 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

========== LOP Check ==========

[2009/06/02 20:10:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Amazon
[2011/07/29 15:04:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/09/14 16:29:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2008/01/29 00:43:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2010/05/19 23:09:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MXSkypeRecorder
[2011/02/06 18:13:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/05/19 22:51:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/04/25 23:29:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/09/25 23:12:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2010/08/06 09:47:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/26 12:07:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/05 16:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/09/07 21:16:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\Amazon
[2011/09/29 09:05:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\Dropbox
[2007/10/13 13:27:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\eMusic
[2011/04/24 11:21:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\FileZilla
[2007/06/28 11:09:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\Gamelab
[2010/07/27 22:05:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\Gmail Backup
[2011/10/25 00:27:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\gtk-2.0
[2011/04/24 12:24:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\Immunet
[2007/04/21 20:09:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\InterVideo
[2007/09/09 09:53:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\iPodder
[2010/05/19 22:51:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\NCH Swift Sound
[2011/07/14 00:25:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\OpenOffice.org
[2007/11/25 12:30:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\OverDrive
[2011/10/24 09:23:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\Spotify
[2011/08/21 10:56:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Megan Honig\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2011/09/01 00:02:33 | 000,000,436 | —- | M] () – C:\WINDOWS\Tasks\SyncBack Monthly.job
[2011/10/24 22:05:47 | 000,000,436 | —- | M] () – C:\WINDOWS\Tasks\SyncBack Nightly.job
[2011/10/24 21:09:31 | 000,000,434 | —- | M] () – C:\WINDOWS\Tasks\SyncBack Weekly.job
[2011/04/28 15:10:02 | 000,000,294 | —- | M] () – C:\WINDOWS\Tasks\wavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/02 20:11:05 | 000,000,715 | —- | M] () – C:\Amazon Unbox.lnk
[2008/01/29 00:43:07 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2007/02/07 23:03:21 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2006/08/10 03:51:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/09/23 04:42:48 | 000,000,076 | —- | M] () – C:\DVDPATH.TXT
[2011/10/25 08:58:37 | 1063,440,384 | -HS- | M] () – C:\hiberfil.sys
[2006/08/10 03:51:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/09/14 16:26:47 | 000,001,217 | -H– | M] () – C:\IPH.PH
[2007/02/19 13:28:33 | 000,000,777 | —- | M] () – C:\log.txt
[2006/08/10 03:51:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/03/15 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/09/29 00:30:11 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/10/25 08:58:36 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/08/10 03:50:39 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/09/13 05:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD83.DLL
[2006/09/13 05:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP83.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2004/03/22 18:17:08 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2007/02/13 14:08:02 | 098,554,909 | —- | M] () – C:\Program Files\OOo_2.1.0_Win32Intel_install_en-US.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/08/09 20:39:03 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/08/09 20:39:03 | 000,663,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/08/09 20:39:03 | 000,901,120 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/09/29 01:05:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2004/05/05 21:59:01 | 000,004,096 | —- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/04 08:49:07 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Megan Honig\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/08/10 03:57:29 | 000,000,079 | —- | M] () – C:\Documents and Settings\Megan Honig\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-13 15:51:29

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB16692$] -> -> Unknown point type

< End of report >

OTL Extras logfile created on: 10/25/2011 9:40:04 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Megan Honig\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.11 Mb Total Physical Memory | 308.75 Mb Available Physical Memory | 30.45% Memory free
2.38 Gb Paging File | 1.77 Gb Available in Paging File | 74.21% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 104.79 Gb Total Space | 38.84 Gb Free Space | 37.07% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 296.93 Gb Free Space | 63.75% Space Free | Partition Type: NTFS
Drive F: | 135.54 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 953.72 Mb Total Space | 421.03 Mb Free Space | 44.15% Space Free | Partition Type: FAT

Computer Name: NEWFRIEND | User Name: Megan Honig | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"1043:TCP" = 1043:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Pando\pando.exe" = C:\Program Files\Pando Networks\Pando\pando.exe:*:Enabled:pando
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\Stanza.exe" = C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\Stanza.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Hasbro Interactive\Scrabble v2.0\Scrabble v2.0.exe" = C:\Program Files\Hasbro Interactive\Scrabble v2.0\Scrabble v2.0.exe:*:Enabled:Scrabble v2.0 – ()
"C:\Documents and Settings\Megan Honig\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Megan Honig\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\Program Files\Java\jre6\launch4j-tmp\Stanza.exe" = C:\Program Files\Java\jre6\launch4j-tmp\Stanza.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{04605217-DD32-4090-9D9A-E5345222B9E1}" =
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160" = Canon MP160
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 26
"{26ED4308-E0A5-4AE2-A1BC-7A55BC7DD32D}" = The Silver Lining
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29BB5153-133B-4C82-AF51-BF303F2BFD63}" = King's Quest Collection™
"{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}" = Wireless Switch Setting Utility
"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33CFCF98-F8D6-4549-B469-6F4295676D83}" = Symantec AntiVirus
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
"{48B0F38D-1913-44F3-99AA-D4C55A2B038E}" = Drive Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility
"{59FD743D-A699-449E-8197-BD2899DAD69A}" = OverDrive Media Console
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{5E8A1B08-0FBD-4543-9646-F2C2D0D05750}" = Macromedia Flash Player 8
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{82CA0A0C-A3EC-4167-B694-909205B2EDEC}" = muvee Plugin 1.0
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{908994F4-EBD2-40E0-B8F3-7004FA54E909}" = VAIO Media Tutorial
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B953606-000E-491C-B74D-78ECFDD520A0}" = OpenMG Metadata Extractor for Windows Media Player
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.0
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6EE99EA-420C-4FA6-8A7C-FDB60D278855}" = VS10RuntimeWin32
"{A87EBA79-93DB-4A87-B9BA-62F8FB12D993}" = ImageStation
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A947C2B3-7445-42C4-9063-EE704CACCB22}" = VAIO Hardware Diagnostics
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.7
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE246151-F0E8-ABC8-AEB2-7F3E188EFBF5}" = TweetDeck
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D88C3E7C-1DA6-4AD7-97FC-75BC8705B266}" = runtime
"{D9952D4E-766C-4CD3-BF2E-A2C3D8B15EF3}" = VAIO Backup Utility
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3D278BD-FC97-4F87-BB1F-689AE0CB9122}" = Macromedia Flash Player 8 Plugin
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Akamai" = Akamai NetSession Interface
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"AOL Search Enhancement" = Search Enhancement by AOL Search
"Audacity_is1" = Audacity 1.2.6
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2C06&SUBSYS;_104D1700" = Soft Data Fax Modem with SmartCP
"Digital Editions" = Adobe Digital Editions
"eMusic Download Manager" = eMusic Download Manager 4.1.1
"eMusic Remote" = eMusic Remote 1.0.0.2
"gmailbackup" = Gmail Backup
"G'MIC for GIMP_is1" = G'MIC for GIMP version 1.5.0.4_beta
"Immunet Protect" = Immunet 3.0
"InstallShield_{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01
"InstallShield_{48B0F38D-1913-44F3-99AA-D4C55A2B038E}" = Drive Manager
"InstallShield_{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InterActual Player" = InterActual Player
"Internet Scrabble Club_is1" = WordBiz version 1.8
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Play System (Patching)" = Network Play System (Patching)
"OpenMG HotFix4.5-06-05-10-01" = OpenMG Limited Patch 4.5-06-05-12-01
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 12.0" = RealPlayer
"SCRABBLE" = SCRABBLE
"Scrabble v2.0" = Scrabble v2.0
"Shutterfly Plugin" = Shutterfly Plugin
"Spotify" = Spotify
"Stanza" = Stanza
"SyncBack_is1" = SyncBack
"The Sims" = The Sims
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"WavePad" = WavePad Sound Editor
"WGA" = Windows Genuine Advantage Validation Tool
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.4.4
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 4.8.0.723

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/28/2011 2:05:56 PM | Computer Name = NEWFRIEND | Source = Application Error | ID = 1000
Description = Faulting application gimp-2.4.exe, version 0.0.0.0, faulting module
msvcrt.dll, version 7.0.2600.2180, fault address 0x000378c0.

Error - 9/28/2011 3:23:17 PM | Computer Name = NEWFRIEND | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.4280, faulting
module ntdll.dll, version 5.1.2600.3520, fault address 0x0000100b.

Error - 10/5/2011 12:28:51 PM | Computer Name = NEWFRIEND | Source = Application Error | ID = 1000
Description = Faulting application gimp-2.4.exe, version 0.0.0.0, faulting module
msvcrt.dll, version 7.0.2600.5512, fault address 0x000378c0.

Error - 10/16/2011 10:48:00 AM | Computer Name = NEWFRIEND | Source = Bonjour Service | ID = 100
Description =

Error - 10/16/2011 10:48:00 AM | Computer Name = NEWFRIEND | Source = Bonjour Service | ID = 100
Description =

Error - 10/16/2011 5:52:25 PM | Computer Name = NEWFRIEND | Source = Bonjour Service | ID = 100
Description =

Error - 10/16/2011 5:52:25 PM | Computer Name = NEWFRIEND | Source = Bonjour Service | ID = 100
Description =

Error - 10/16/2011 5:54:17 PM | Computer Name = NEWFRIEND | Source = Application Error | ID = 1000
Description = Faulting application ghscrabble.exe, version 1.0.1.3, faulting module
unknown, version 0.0.0.0, fault address 0xb70a2140.

Error - 10/24/2011 6:11:22 PM | Computer Name = NEWFRIEND | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.4280, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 10/25/2011 2:22:41 AM | Computer Name = NEWFRIEND | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module mshtml.dll, version 6.0.2900.5969, fault address 0x0023d5a0.

[ System Events ]
Error - 10/25/2011 9:22:54 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:22:54 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:22:54 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:25:28 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:25:34 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:26:25 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:29:35 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:34:02 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:34:24 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 10/25/2011 9:36:46 AM | Computer Name = NEWFRIEND | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127


< End of report >

HIJACK THIS LOG:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:27:27 AM, on 10/25/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files\Immunet\3.0.1\agent.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Immunet\3.0.1\iptray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Megan Honig\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Immunet Protect] "C:\Program Files\Immunet\3.0.1\iptray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [MX Skype Recorder] "C:\Documents and Settings\All Users\Application Data\MXSkypeRecorder\MXSkypeRecorder.exe" /autorun
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Megan Honig\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: Apple Mobile Device - Unknown owner - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (file missing)
O23 - Service: Basics Service - Unknown owner - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Immunet 3.0 (ImmunetProtect) - Sourcefire, Inc. - C:\Program Files\Immunet\3.0.1\agent.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Unknown owner - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (file missing)
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (file missing)
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 14578 bytes
Hi estuary1, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

You have a nasty rootkit that can sometimes be quite stuborn to remove.

Your system has been infected by one or more Rootkits/Backdoor Trojans.

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing what has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

Should you wish to continue cleaning this machine please follow the instructions below.

This tool must be ran in Normal Windows. Since the computer is heavily infected it may take some time for the tool to complete. At times it may appear to have stalled but if there is even the slightest hint of harddrive activity it is still running. Please be patient even at the points (if any) it seems stalled and let the tool run.

Make sure you download and save it directly to the C:\ drive and rename it as outlined below.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to C:\.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to C:\**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to C:\, rename Combofix to svchost.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (svchost.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Hi oldman960, Thanks for your help. It sounds like reformatting might be the best plan. Would you be willing to provide or link to instructions for doing so? I regularly back up my documents on an external hard drive. Do you think they could be safely retrieved from the drive? (it's drive E in the log if that helps.) Changing passwords (on a different machine!) as we speak. Sigh…
Hi estuary1,

There should be no problem retieving your documents from the e:\ drive. I suggest burning them to a CD or DVD. I also suggest you scan your backups before restoring them to the computer.

I'll give you a link to a very good tutorial on reformatting and reinstalling Windows. It's mentioned in the tutorial but I will say it also. Before you reformat make sure you have your anti virus program disk.

If your XP disk is below Service Pack 3 you may want to download and save to disk a copy from HERE

Install it before installing your antivirus program (biggest cause of failed installs) or install Service Pack3 in safe mode.

Install Service Pack3 and your antivirus program before connecting to the internet.

You may want to use a clean computer to download anything you may need just as a precaution.

You can find the Reinstall Tutorial HERE

Please post back if you have any questions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI