DeViouS
Topic Starter
Hi All,
I've been hit by the same ping.exe & google redirect virus that has been flooding the forums here. Ran all types of scans to no avail, but I see that you guys seem to have this nut cracked. Thanks for any assistance provided. Here are the logs:
OTL logfile created on: 12/20/2011 10:07:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Patricia\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.27% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.35% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 11.72 Gb Total Space | 0.89 Gb Free Space | 7.62% Space Free | Partition Type: NTFS
Drive E: | 74.55 Gb Total Space | 9.44 Gb Free Space | 12.66% Space Free | Partition Type: NTFS
Drive F: | 116.27 Gb Total Space | 7.38 Gb Free Space | 6.35% Space Free | Partition Type: NTFS
Drive I: | 170.10 Gb Total Space | 128.45 Gb Free Space | 75.51% Space Free | Partition Type: NTFS
Computer Name: THE-BEAST | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Patricia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\WRSA.exe (Webroot)
PRC - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - E:\Programs\Sage\Peachtree\SmartPostingService2011.exe (Sage Software, Inc.)
PRC - C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc.)
PRC - C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - E:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\GIGABYTE\GEST\gest.exe ()
PRC - C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - E:\Programs\Sage\Peachtree\pchqb32.dll ()
MOD - F:\Programs\Office\Office14\1033\GrooveIntlResource.dll ()
MOD - F:\Programs\WINRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\GIGABYTE\GEST\gest.exe ()
MOD - C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
MOD - C:\Program Files\GIGABYTE\GEST\ycc.dll ()
MOD - C:\Program Files\GIGABYTE\GEST\etiv.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NeroRegInCDSrv) – File not found
SRV - (WRSVC) – C:\Program Files\Webroot\WRSA.exe (Webroot)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (MBAMService) – F:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – F:\Programs\Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (Peachtree SmartPosting 2011) – E:\Programs\Sage\Peachtree\SmartPostingService2011.exe (Sage Software, Inc.)
SRV - (psqlWGE) – C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc.)
SRV - (InCDsrv) – E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
========== Driver Services (SafeList) ==========
DRV - (pIclxoGw) – C:\WINDOWS\System32\drivers\pIclxoGw.sys (Webroot)
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MpKsl4eb7697b) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EBDA840-A36E-474A-A355-8831D9343538}\MpKsl4eb7697b.sys (Microsoft Corporation)
DRV - (WRkrn) – C:\WINDOWS\System32\drivers\WRkrn.sys (Webroot)
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (urvpndrv) – C:\WINDOWS\system32\drivers\covpndrv.sys (F5 Networks, Inc.)
DRV - (f5ipfw) – C:\WINDOWS\system32\drivers\urfltw2k.sys (F5 Networks, Inc.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (incdrm) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (ET5Drv) – C:\WINDOWS\system32\drivers\ET5Drv.sys (Windows ® 2000 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: I:\programs\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: F:\Programs\Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: F:\Programs\Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: F:\Programs\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: F:\Programs\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011/11/27 17:40:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011/12/10 10:09:20 | 000,000,000 | —D | M]
[2011/05/01 08:06:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Patricia\Application Data\Mozilla\Extensions
[2010/04/28 20:50:00 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/06 03:08:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
O1 HOSTS File: ([2011/12/04 09:11:17 | 000,001,401 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programs\Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programs\Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\run.exe ()
O4 - HKLM..\Run: [InCD] E:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PeachtreePrefetcher.exe] E:\Programs\Sage\Peachtree\PeachtreePrefetcher.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [SecurDisc] E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WRSVC] C:\Program Files\Webroot\WRSA.exe (Webroot)
O4 - HKCU..\Run: [Core Temp] C:\Program Files\Core Temp\Core Temp.exe ()
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11c_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT AntiViruses Class)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} https://vpn.na.sage.com/vdesk/terminal/urxv…0,2011,104,2321 (F5 Networks VPN Manager)
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT FireWalls Class)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} https://vpn.na.sage.com/vdesk/terminal/f5tu…0,2011,104,2309 (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://vpn.na.sage.com/vdesk/terminal/Inst…,2010,1020,1507 (F5 Networks Auto Update)
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT ProcessesScanner Class)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} https://vpn.na.sage.com/vdesk/terminal/f5In…,2010,1020,1407 (F5 Networks Policy Agent Host Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} https://vpn.na.sage.com/vdesk/terminal/urxs…,2010,1020,1428 (F5 Networks SuperHost Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} https://vpn.na.sage.com/vdesk/terminal/urxh…00,2011,124,911 (F5 Networks Host Control)
O16 - DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} https://vpn.na.sage.com/policy/download_bin…,2010,1020,1432 (F5 Networks OS Policy Agent)
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (F5 Networks OPSWAT Helper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0A4CBC1-2119-4C19-8FD1-BF4952EFE657}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\Programs\Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/26 01:55:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/12 10:59:30 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1999/08/11 12:09:06 | 000,000,233 | —- | M] () - I:\AUTOEXEC – [ NTFS ]
O32 - AutoRun File - [2000/08/28 13:56:10 | 000,000,023 | —- | M] () - I:\AUTOEXEC.112 – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/20 09:40:43 | 000,107,336 | —- | C] (Webroot) – C:\WINDOWS\System32\drivers\pIclxoGw.sys
[2011/12/20 09:40:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:23 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
[2011/12/20 08:58:44 | 000,028,992 | —- | C] (TuneUp Software) – C:\WINDOWS\System32\uxtuneup.dll
[2011/12/20 08:37:56 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/12/20 08:34:51 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\BineenXt.sys
[2011/12/19 20:31:05 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\srvlnASy.sys
[2011/12/18 23:27:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\xocVqFMR.sys
[2011/12/18 23:27:22 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\odcgeLCR.sys
[2011/12/18 19:33:24 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\VGlxxmhq.sys
[2011/12/18 16:17:39 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\tftUsCuh.sys
[2011/12/18 16:12:40 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\UtNACVPB.sys
[2011/12/18 15:56:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Webroot SecureAnywhere
[2011/12/18 15:56:34 | 000,141,272 | —- | C] (Webroot) – C:\WINDOWS\System32\WRusr.dll
[2011/12/18 15:56:34 | 000,107,336 | —- | C] (Webroot) – C:\WINDOWS\System32\drivers\WRkrn.sys
[2011/12/18 15:56:32 | 000,000,000 | —D | C] – C:\Program Files\Webroot
[2011/12/18 15:56:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WRData
[2011/12/15 19:23:27 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/12/11 10:35:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2011/12/10 10:09:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DivX
[2011/12/10 10:09:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2011/12/05 05:18:18 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/04 10:31:30 | 000,031,552 | —- | C] (TuneUp Software) – C:\WINDOWS\System32\TURegOpt.exe
[2011/12/04 10:31:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TuneUp Utilities 2012
[2011/12/04 10:30:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\Application Data\TuneUp Software
[2011/12/04 10:30:34 | 000,000,000 | —D | C] – C:\Program Files\TuneUp Utilities 2012
[2011/12/04 10:29:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/12/04 10:28:39 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2011/12/04 09:50:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\My Documents\Downloads
[2011/12/04 09:11:18 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\ubxxitam.sys
[2011/12/04 09:09:55 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/04 09:09:55 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/04 09:09:55 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/03 15:30:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 14:49:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\Application Data\Malwarebytes
[2011/12/03 12:48:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 12:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/23 08:10:19 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/20 10:12:20 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/20 09:41:39 | 000,625,664 | —- | M] () – C:\Documents and Settings\Patricia\Desktop\dds.scr
[2011/12/20 09:40:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:43 | 000,107,336 | —- | M] (Webroot) – C:\WINDOWS\System32\drivers\pIclxoGw.sys
[2011/12/20 09:40:30 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
[2011/12/20 08:41:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/20 08:36:10 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2011/12/20 08:36:09 | 000,272,484 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/12/20 08:35:58 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/20 08:35:53 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/18 15:56:34 | 000,141,272 | —- | M] (Webroot) – C:\WINDOWS\System32\WRusr.dll
[2011/12/18 15:56:34 | 000,107,336 | —- | M] (Webroot) – C:\WINDOWS\System32\drivers\WRkrn.sys
[2011/12/16 03:20:50 | 000,282,928 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 20:27:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/12/14 06:47:06 | 000,031,552 | —- | M] (TuneUp Software) – C:\WINDOWS\System32\TURegOpt.exe
[2011/12/14 06:46:50 | 000,028,992 | —- | M] (TuneUp Software) – C:\WINDOWS\System32\uxtuneup.dll
[2011/12/09 09:28:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/08 08:49:11 | 000,118,582 | —- | M] () – C:\logfile
[2011/12/04 10:31:27 | 000,001,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/12/04 10:31:27 | 000,001,741 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2012.lnk
[2011/12/04 09:33:10 | 000,437,014 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/04 09:33:10 | 000,069,358 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/04 09:11:19 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\ubxxitam.sys
[2011/12/04 09:11:17 | 000,001,401 | RHS- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/04 09:09:55 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/04 09:09:55 | 000,100,880 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/04 09:09:55 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/03 14:29:04 | 000,015,476 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\627013l4q800u827c180j1gsa0e0
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/20 09:41:16 | 000,625,664 | —- | C] () – C:\Documents and Settings\Patricia\Desktop\dds.scr
[2011/12/18 15:58:51 | 000,162,816 | —- | C] () – C:\WINDOWS\System32\drivers\tkGBMHJb.sys
[2011/12/06 15:25:36 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/04 10:31:27 | 000,001,747 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\TuneUp Utilities 2012.lnk
[2011/12/04 10:31:27 | 000,001,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/12/04 10:31:27 | 000,001,741 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2012.lnk
[2011/12/03 12:35:57 | 000,015,476 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\627013l4q800u827c180j1gsa0e0
[2011/09/21 21:09:59 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/09/19 21:59:17 | 000,017,905 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2011/09/19 19:52:15 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/02/20 10:32:50 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/02/20 10:32:50 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2010/12/12 09:28:54 | 000,000,000 | —- | C] () – C:\WINDOWS\f5unistall.INI
[2010/10/19 07:42:47 | 000,013,132 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/12 11:28:05 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2010/09/12 11:28:05 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2010/06/20 21:45:29 | 000,003,402 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2010/05/14 20:25:38 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/04/26 23:48:17 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/04/26 23:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/26 22:57:01 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/04/26 01:56:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/04/26 01:52:52 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/04/25 18:44:47 | 000,004,633 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/25 18:43:55 | 000,282,928 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/06/25 02:57:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/03/21 07:28:50 | 000,000,106 | —- | C] () – C:\WINDOWS\System32\mmc.exe.config
[2004/08/04 01:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 00:56:44 | 000,193,024 | —- | C] () – C:\WINDOWS\System32\msrating.dll
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,437,014 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,069,358 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/03/05 10:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aatrix Software
[2010/12/19 10:54:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/12 09:28:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F5 Networks
[2010/05/14 20:23:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/03/05 10:35:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pervasive Software
[2011/12/04 10:31:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/07/31 10:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/12/20 09:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WRData
[2011/12/04 10:28:39 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2010/05/01 16:11:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/04 10:30:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Patricia\Application Data\TuneUp Software
[2011/12/20 08:41:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/26 01:55:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/09/19 22:09:45 | 000,000,000 | —- | M] () – C:\BnetLog.txt
[2011/12/15 20:27:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/11/02 04:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2010/04/26 01:55:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/26 23:29:09 | 000,000,206 | —- | M] () – C:\csb.log
[2010/03/10 20:20:52 | 000,799,352 | —- | M] () – C:\D2XP_IX86_112a_113c.mpq
[2010/04/26 01:55:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/12/08 08:49:11 | 000,118,582 | —- | M] () – C:\logfile
[2010/04/26 01:55:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/07 19:59:38 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/04/26 23:29:09 | 000,000,480 | —- | M] () – C:\RHDSetup.log
[2011/03/05 10:41:25 | 000,899,274 | —- | M] () – C:\SageMessageCenter_Install.log
[2011/12/20 08:36:39 | 000,000,122 | —- | M] () – C:\service.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/04/26 01:54:43 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/04/25 18:42:52 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/04/25 18:42:52 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/04/25 18:42:52 | 000,925,696 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/07 20:03:06 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/02 14:55:11 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/05/02 14:55:11 | 000,000,079 | —- | M] () – C:\Documents and Settings\Patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/12/20 09:40:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:30 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate]
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-16 08:04:55
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB10581$] -> -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 514 bytes -> C:\WINDOWS\System32\drivers\ubxxitam.sys:changelist
< End of report >
OTL Extras logfile created on: 12/20/2011 10:07:18 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Patricia\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.27% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.35% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 11.72 Gb Total Space | 0.89 Gb Free Space | 7.62% Space Free | Partition Type: NTFS
Drive E: | 74.55 Gb Total Space | 9.44 Gb Free Space | 12.66% Space Free | Partition Type: NTFS
Drive F: | 116.27 Gb Total Space | 7.38 Gb Free Space | 6.35% Space Free | Partition Type: NTFS
Drive I: | 170.10 Gb Total Space | 128.45 Gb Free Space | 75.51% Space Free | Partition Type: NTFS
Computer Name: THE-BEAST | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = internetshortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – E:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "F:\Programs\Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "F:\Programs\Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"1583:TCP" = 1583:TCP:*:Enabled:Pervasive DBEngine
"3351:TCP" = 3351:TCP:*:Enabled:Pervasive DBEngine
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Programs\BitTorrent\bittorrent.exe" = F:\Programs\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"H:\CDS\Nero\Installation\SetupX.exe" = H:\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup
"E:\Program Files\StarCraft II Beta\StarCraft II.exe" = E:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\Adobe\Acrobat_com\Acrobat_com.exe" = C:\Program Files\Adobe\Acrobat_com\Acrobat_com.exe:*:Enabled:Acrobat_com – ()
"E:\Program Files\StarCraft II\StarCraft II.exe" = E:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"E:\Program Files\StarCraft II\Versions\Base15405\SC2.exe" = E:\Program Files\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"C:\Documents and Settings\DeViouS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\DeViouS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"E:\Program Files\PFPortChecker\PFPortChecker.exe" = E:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded. – (portforward.com)
"F:\Programs\Office\Office14\GROOVE.EXE" = F:\Programs\Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"F:\Programs\Office\Office14\ONENOTE.EXE" = F:\Programs\Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"F:\Programs\Office\Office14\OUTLOOK.EXE" = F:\Programs\Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe" = C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe:*:Enabled:Database Service Manager – (Pervasive Software Inc.)
"C:\Program Files\GIGABYTE\GEST\run.exe" = C:\Program Files\GIGABYTE\GEST\run.exe:*:Disabled:update – ()
"E:\Program Files\StarCraft II\Versions\Base18092\SC2.exe" = E:\Program Files\StarCraft II\Versions\Base18092\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"F:\Programs\XBMC\XBMC.exe" = F:\Programs\XBMC\XBMC.exe:*:Enabled:XBMC – (Team XBMC)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2
"{0A3238D7-AB32-1010-B717-F3E3F18B4A8C}" = Pervasive PSQL v10 SP2 Workgroup (32-bit)
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE1008C-11A1-4F4F-8DB7-27573924DE78}" = DMIView B06.1227.01
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5869CE1E-BC0B-4648-B1AE-6EF4A985590C}" = Dynamic Energy Saver 1.0 B8.0128.1
"{6798DD4E-BD16-4735-87EB-D712637CCB8C}" = Sage Message Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{714ACFF3-B8A3-4AD6-937B-13C833D71033}" = Nero 7 Essentials
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B8.0711.1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BCB844B-0814-4354-A413-1063DB4618E9}" = PeachTree Signature Ready Forms
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E67BFA7-2A1C-4439-95CE-D6ACD3E85073}" = Peachtree Accounting 2011
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A95A76C9-6F65-477E-83A0-9F884B6DC21B}" = TuneUp Utilities Language Pack (en-US)
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C484CC8D-03CF-4022-89C4-DB4F02E8A15B}" = Crystal Reports 2008 Runtime SP1
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF8C077A-B467-4C43-8DB5-3A9B94FF9681}" = LightScribe System Software [removed]
"{D237A127-1229-41EF-8F89-F5B2363868E7}" = Diablo II Character Manager
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATT-PRT22" = ATT-PRT22
"BitTorrent" = BitTorrent
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Diablo II" = Diablo II
"DriverCD" = DriverCD
"DVDFab 8 Qt_is1" = DVDFab 8.1.0.5 (04/07/2011) Qt
"F5 Networks Client Components" = BIG-IP Edge Client Components (All Users)
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{9E67BFA7-2A1C-4439-95CE-D6ACD3E85073}" = Peachtree Accounting 2011
"Integration Services" = Sage Integration Services
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PFPortChecker" = PFPortChecker 1.0.36
"Portforward Static IP Address" = Portforward Static IP Address 1.0.44
"RealAlt_is1" = Real Alternative 2.0.2
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WRUNINST" = Webroot SecureAnywhere
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:18:38 AM, on 12/20/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17095)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
E:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\GIGABYTE\GEST\gest.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\WINDOWS\system32\svchost.exe
E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\Documents and Settings\Patricia\Desktop\OTL.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Core Temp\Core Temp.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programs\Office\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programs\Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SecurDisc] E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PeachtreePrefetcher.exe] E:\Programs\Sage\Peachtree\PeachtreePrefetcher.exe /configfile:peachtreeprefetcher.winstart.config
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [InCD] E:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\RUN.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WRSVC] "C:\Program Files\Webroot\WRSA.exe" -ul
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Core Temp] "C:\Program Files\Core Temp\Core Temp.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_Plugin.exe -update plugin
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} (OPSWAT AntiViruses Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} (F5 Networks VPN Manager) - https://vpn.na.sage.com/vdesk/terminal/urxv…0,2011,104,2321
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} (OPSWAT FireWalls Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} (F5 Networks Dynamic Application Tunnel Control) - https://vpn.na.sage.com/vdesk/terminal/f5tu…0,2011,104,2309
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://vpn.na.sage.com/vdesk/terminal/Inst…,2010,1020,1507
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} (OPSWAT ProcessesScanner Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} (F5 Networks Policy Agent Host Class) - https://vpn.na.sage.com/vdesk/terminal/f5In…,2010,1020,1407
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://vpn.na.sage.com/vdesk/terminal/urxs…,2010,1020,1428
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://vpn.na.sage.com/vdesk/terminal/urxh…00,2011,124,911
O16 - DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} (F5 Networks OS Policy Agent) - https://vpn.na.sage.com/policy/download_bin…,2010,1020,1432
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} (F5 Networks OPSWAT Helper Control) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - E:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Peachtree SmartPosting 2011 - Sage Software, Inc. - E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
O23 - Service: Pervasive PSQL Workgroup Engine (psqlWGE) - Pervasive Software Inc. - C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
O23 - Service: WRSVC - Webroot - C:\Program Files\Webroot\WRSA.exe
–
End of file - 11703 bytes
DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:21:52.10 on Tue 12/20/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2476 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
.
============== Running Processes ===============
.
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
E:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\GIGABYTE\GEST\gest.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Core Temp\Core Temp.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\ping.exe
C:\Documents and Settings\Patricia\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - f:\programs\office\office14\GROOVEEX.DLL
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - f:\programs\office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Core Temp] "c:\program files\core temp\Core Temp.exe"
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11c_Plugin.exe -update plugin
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SecurDisc] e:\program files\nero\nero 7\incd\NBHGui.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [PeachtreePrefetcher.exe] e:\programs\sage\peachtree\PeachtreePrefetcher.exe /configfile:peachtreeprefetcher.winstart.config
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [InCD] e:\program files\nero\nero 7\incd\InCD.exe
mRun: [GEST] c:\program files\gigabyte\gest\RUN.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WRSVC] "c:\program files\webroot\WRSA.exe" -ul
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
uPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
mPolicies-explorer: NoViewOnDrive = 0 (0x0)
mPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
mPolicies-explorer: NoWindowsUpdate = 0 (0x0)
mPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
dPolicies-explorer: NoViewOnDrive = 0 (0x0)
dPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
dPolicies-explorer: NoWindowsUpdate = 0 (0x0)
dPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\programs\office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - f:\programs\office\office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://vpn.na.sage.com/vdesk/terminal/urxvpn.cab#version=7000,2011,104,2321
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vpn.na.sage.com/vdesk/terminal/f5tunsrv.cab#version=7000,2011,104,2309
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vpn.na.sage.com/vdesk/terminal/InstallerControl.cab#version=7000,2010,1020,1507
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} - hxxps://vpn.na.sage.com/vdesk/terminal/f5InspectionHost.cab#version=7000,2010,1020,1407
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vpn.na.sage.com/vdesk/terminal/urxshost.cab#version=7000,2010,1020,1428
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vpn.na.sage.com/vdesk/terminal/urxhost.cab#version=7000,2011,124,911
DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} - hxxps://vpn.na.sage.com/policy/download_binary.php/win32/f5syschk.cab#Version=7000,2010,1020,1432
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - f:\programs\office\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 216.240.133.193 www.google-analytics.com.
Hosts: 216.240.133.193 ad-emea.doubleclick.net.
Hosts: 216.240.133.193 www.statcounter.com.
Hosts: 69.72.252.254 www.google-analytics.com.
Hosts: 69.72.252.254 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\patricia\applic~1\mozilla\firefox\profiles\wkqja21d.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: e:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: f:\programs\office\office14\NPAUTHZ.DLL
FF - plugin: f:\programs\office\office14\NPSPWRAP.DLL
FF - plugin: f:\programs\real alternative\browser\plugins\nppl3260.dll
FF - plugin: f:\programs\real alternative\browser\plugins\nprpjplug.dll
FF - plugin: i:\programs\divx\divx web player\npdivx32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2011-12-18 107336]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl4eb7697b;MpKsl4eb7697b;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\MpKsl4eb7697b.sys [2011-12-20 29904]
R2 Peachtree SmartPosting 2011;Peachtree SmartPosting 2011;e:\programs\sage\peachtree\SmartPostingService2011.exe [2010-9-13 43848]
R2 psqlWGE;Pervasive PSQL Workgroup Engine;c:\program files\pervasive software\psql\bin\w3dbsmgr.exe [2008-6-6 435496]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2012\TuneUpUtilitiesService32.exe [2011-12-14 1514304]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2011-12-18 637208]
R3 ALSysIO;ALSysIO;\??\c:\docume~1\patricia\locals~1\temp\alsysio.sys –> c:\docume~1\patricia\locals~1\temp\ALSysIO.sys [?]
R3 GEST Service;GEST Service for program management.;c:\program files\gigabyte\gest\GSvr.exe [2010-4-26 47624]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2012\TuneUpUtilitiesDriver32.sys [2011-11-8 10064]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [2010-6-11 35448]
S0 pIclxoGw;pIclxoGw;c:\windows\system32\drivers\pIclxoGw.sys [2011-12-20 107336]
S1 MpKsl05309e57;MpKsl05309e57;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c584baa6-e20e-44be-9141-61d6417b9b42}\mpksl05309e57.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c584baa6-e20e-44be-9141-61d6417b9b42}\MpKsl05309e57.sys [?]
S1 MpKsl2714a0e1;MpKsl2714a0e1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdbb7fc4-3c2a-4e0b-80ad-4e490922cee0}\mpksl2714a0e1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdbb7fc4-3c2a-4e0b-80ad-4e490922cee0}\MpKsl2714a0e1.sys [?]
S1 MpKsl2f23e610;MpKsl2f23e610;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\mpksl2f23e610.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\MpKsl2f23e610.sys [?]
S1 MpKsl354afefd;MpKsl354afefd;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01751214-b360-4f2b-a0f5-14a514a2d6ed}\mpksl354afefd.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01751214-b360-4f2b-a0f5-14a514a2d6ed}\MpKsl354afefd.sys [?]
S1 MpKsl6d86a591;MpKsl6d86a591;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32aa8df5-fbc5-4db8-a871-71feadde419f}\mpksl6d86a591.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32aa8df5-fbc5-4db8-a871-71feadde419f}\MpKsl6d86a591.sys [?]
S1 MpKsl7990e691;MpKsl7990e691;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{803f0683-2921-4ba4-b339-847eb250ceb5}\mpksl7990e691.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{803f0683-2921-4ba4-b339-847eb250ceb5}\MpKsl7990e691.sys [?]
S1 MpKsl836b7f90;MpKsl836b7f90;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{29d607b1-73f8-4c69-b41d-cc62685ab812}\mpksl836b7f90.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{29d607b1-73f8-4c69-b41d-cc62685ab812}\MpKsl836b7f90.sys [?]
S1 MpKsl88e6af3b;MpKsl88e6af3b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e8c76270-ac80-4a45-9ace-65c7af84bc87}\mpksl88e6af3b.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e8c76270-ac80-4a45-9ace-65c7af84bc87}\MpKsl88e6af3b.sys [?]
S1 MpKsl944debed;MpKsl944debed;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4dbb258c-2bde-43d7-9caa-61ba55584da1}\mpksl944debed.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4dbb258c-2bde-43d7-9caa-61ba55584da1}\MpKsl944debed.sys [?]
S1 MpKsl99c0f781;MpKsl99c0f781;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f8af1b56-0c99-4ac0-b79f-fb5d0c0c8140}\mpksl99c0f781.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f8af1b56-0c99-4ac0-b79f-fb5d0c0c8140}\MpKsl99c0f781.sys [?]
S1 MpKslaae793a0;MpKslaae793a0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\mpkslaae793a0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\MpKslaae793a0.sys [?]
S1 MpKslcbd862da;MpKslcbd862da;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042caf0a-ea2f-4642-bd5c-d436c09b9add}\mpkslcbd862da.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042caf0a-ea2f-4642-bd5c-d436c09b9add}\MpKslcbd862da.sys [?]
S1 MpKslce097d11;MpKslce097d11;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a1b535f4-7bf2-4167-8573-7720aa6f42d6}\mpkslce097d11.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a1b535f4-7bf2-4167-8573-7720aa6f42d6}\MpKslce097d11.sys [?]
S1 MpKsld45cf3e6;MpKsld45cf3e6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab8b7ebc-2b9e-4937-8142-4be51f0ebf69}\mpksld45cf3e6.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab8b7ebc-2b9e-4937-8142-4be51f0ebf69}\MpKsld45cf3e6.sys [?]
S1 MpKsldaa75e46;MpKsldaa75e46;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f17962e0-8376-4980-9ad4-622c9950922f}\mpksldaa75e46.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f17962e0-8376-4980-9ad4-622c9950922f}\MpKsldaa75e46.sys [?]
S1 MpKsle7be0667;MpKsle7be0667;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17c6adc8-1ee4-4a18-bce9-821f136857ed}\mpksle7be0667.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17c6adc8-1ee4-4a18-bce9-821f136857ed}\MpKsle7be0667.sys [?]
S1 MpKslecb2ba95;MpKslecb2ba95;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb483246-1cd6-4db2-896f-12372ff095cf}\mpkslecb2ba95.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb483246-1cd6-4db2-896f-12372ff095cf}\MpKslecb2ba95.sys [?]
S2 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\nero\nero 7\incd\nbhregincdsrv.exe –> e:\program files\nero\nero 7\incd\NBHRegInCDSrv.exe [?]
S3 esgiguard;esgiguard;\??\c:\program files\enigma software group\spyhunter\esgiguard.sys –> c:\program files\enigma software group\spyhunter\esgiguard.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2010-12-12 10744]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-4-17 22216]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;f:\programs\office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-4 50704]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 MBAMService;MBAMService;f:\programs\malwarebytes' anti-malware\mbamservice.exe [2011-4-17 366152]
.
=============== File Associations ===============
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
=============== Created Last 30 ================
.
2011-12-20 14:40:43 107336 —-a-w- c:\windows\system32\drivers\pIclxoGw.sys
2011-12-20 13:58:44 28992 —-a-w- c:\windows\system32\uxtuneup.dll
2011-12-20 13:36:01 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\MpKsl4eb7697b.sys
2011-12-20 13:35:59 56200 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\offreg.dll
2011-12-20 13:34:51 162816 —-a-w- c:\windows\system32\drivers\BineenXt.sys
2011-12-20 01:31:05 162816 —-a-w- c:\windows\system32\drivers\srvlnASy.sys
2011-12-19 21:16:33 6823496 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\mpengine.dll
2011-12-19 04:27:36 162816 —-a-w- c:\windows\system32\drivers\xocVqFMR.sys
2011-12-19 04:27:22 162816 —-a-w- c:\windows\system32\drivers\odcgeLCR.sys
2011-12-19 00:33:24 162816 —-a-w- c:\windows\system32\drivers\VGlxxmhq.sys
2011-12-18 21:17:39 162816 —-a-w- c:\windows\system32\drivers\tftUsCuh.sys
2011-12-18 21:12:40 162816 —-a-w- c:\windows\system32\drivers\UtNACVPB.sys
2011-12-18 20:58:51 162816 —-a-w- c:\windows\system32\drivers\tkGBMHJb.sys
2011-12-18 20:56:34 141272 —-a-w- c:\windows\system32\WRusr.dll
2011-12-18 20:56:34 107336 —-a-w- c:\windows\system32\drivers\WRkrn.sys
2011-12-18 20:56:32 ——– d—–w- c:\program files\Webroot
2011-12-18 20:56:30 ——– d—–w- c:\docume~1\alluse~1\applic~1\WRData
2011-12-10 15:09:11 ——– d—–w- c:\program files\common files\DivX Shared
2011-12-04 15:31:30 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2011-12-04 15:30:56 ——– d—–w- c:\docume~1\patricia\applic~1\TuneUp Software
2011-12-04 15:30:34 ——– d—–w- c:\program files\TuneUp Utilities 2012
2011-12-04 15:29:11 ——– d—–w- c:\docume~1\alluse~1\applic~1\TuneUp Software
2011-12-04 15:28:39 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-12-04 14:11:18 41680 —-a-w- c:\windows\system32\drivers\ubxxitam.sys
2011-12-04 14:09:55 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-04 14:09:55 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-04 14:09:55 100880 —-a-w- c:\windows\system32\Packet.dll
2011-12-03 22:05:01 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-12-03 22:05:01 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-03 19:49:17 ——– d—–w- c:\docume~1\patricia\applic~1\Malwarebytes
.
==================== Find3M ====================
.
2011-12-20 13:36:10 16608 —-a-w- c:\windows\gdrv.sys
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-23 17:08:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 -c–a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 -c–a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 -c–a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 10:22:06.64 ===============
——————————————————————————–
I've been hit by the same ping.exe & google redirect virus that has been flooding the forums here. Ran all types of scans to no avail, but I see that you guys seem to have this nut cracked. Thanks for any assistance provided. Here are the logs:
OTL logfile created on: 12/20/2011 10:07:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Patricia\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.27% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.35% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 11.72 Gb Total Space | 0.89 Gb Free Space | 7.62% Space Free | Partition Type: NTFS
Drive E: | 74.55 Gb Total Space | 9.44 Gb Free Space | 12.66% Space Free | Partition Type: NTFS
Drive F: | 116.27 Gb Total Space | 7.38 Gb Free Space | 6.35% Space Free | Partition Type: NTFS
Drive I: | 170.10 Gb Total Space | 128.45 Gb Free Space | 75.51% Space Free | Partition Type: NTFS
Computer Name: THE-BEAST | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Patricia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Webroot\WRSA.exe (Webroot)
PRC - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - E:\Programs\Sage\Peachtree\SmartPostingService2011.exe (Sage Software, Inc.)
PRC - C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc.)
PRC - C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
PRC - E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - E:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\GIGABYTE\GEST\gest.exe ()
PRC - C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\8efcd633af87989355382b5039f1b7df\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\69792bef8a100a055db88848836a7d88\System.EnterpriseServices.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ec323cf1df697cc0a45f67de685db90c\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - E:\Programs\Sage\Peachtree\pchqb32.dll ()
MOD - F:\Programs\Office\Office14\1033\GrooveIntlResource.dll ()
MOD - F:\Programs\WINRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\GIGABYTE\GEST\gest.exe ()
MOD - C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
MOD - C:\Program Files\GIGABYTE\GEST\ycc.dll ()
MOD - C:\Program Files\GIGABYTE\GEST\etiv.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NeroRegInCDSrv) – File not found
SRV - (WRSVC) – C:\Program Files\Webroot\WRSA.exe (Webroot)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (MBAMService) – F:\Programs\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – F:\Programs\Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (Peachtree SmartPosting 2011) – E:\Programs\Sage\Peachtree\SmartPostingService2011.exe (Sage Software, Inc.)
SRV - (psqlWGE) – C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe (Pervasive Software Inc.)
SRV - (InCDsrv) – E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
========== Driver Services (SafeList) ==========
DRV - (pIclxoGw) – C:\WINDOWS\System32\drivers\pIclxoGw.sys (Webroot)
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (MpKsl4eb7697b) – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EBDA840-A36E-474A-A355-8831D9343538}\MpKsl4eb7697b.sys (Microsoft Corporation)
DRV - (WRkrn) – C:\WINDOWS\System32\drivers\WRkrn.sys (Webroot)
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (urvpndrv) – C:\WINDOWS\system32\drivers\covpndrv.sys (F5 Networks, Inc.)
DRV - (f5ipfw) – C:\WINDOWS\system32\drivers\urfltw2k.sys (F5 Networks, Inc.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (incdrm) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (ET5Drv) – C:\WINDOWS\system32\drivers\ET5Drv.sys (Windows ® 2000 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: I:\programs\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: F:\Programs\Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: F:\Programs\Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\2.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: F:\Programs\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: F:\Programs\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\MyWebSearch\bar\2.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011/11/27 17:40:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011/12/10 10:09:20 | 000,000,000 | —D | M]
[2011/05/01 08:06:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Patricia\Application Data\Mozilla\Extensions
[2010/04/28 20:50:00 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/06 03:08:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
O1 HOSTS File: ([2011/12/04 09:11:17 | 000,001,401 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programs\Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programs\Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\run.exe ()
O4 - HKLM..\Run: [InCD] E:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PeachtreePrefetcher.exe] E:\Programs\Sage\Peachtree\PeachtreePrefetcher.exe (Sage Software, Inc.)
O4 - HKLM..\Run: [SecurDisc] E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WRSVC] C:\Program Files\Webroot\WRSA.exe (Webroot)
O4 - HKCU..\Run: [Core Temp] C:\Program Files\Core Temp\Core Temp.exe ()
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil11c_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT AntiViruses Class)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} https://vpn.na.sage.com/vdesk/terminal/urxv…0,2011,104,2321 (F5 Networks VPN Manager)
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT FireWalls Class)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} https://vpn.na.sage.com/vdesk/terminal/f5tu…0,2011,104,2309 (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://vpn.na.sage.com/vdesk/terminal/Inst…,2010,1020,1507 (F5 Networks Auto Update)
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (OPSWAT ProcessesScanner Class)
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} https://vpn.na.sage.com/vdesk/terminal/f5In…,2010,1020,1407 (F5 Networks Policy Agent Host Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} https://vpn.na.sage.com/vdesk/terminal/urxs…,2010,1020,1428 (F5 Networks SuperHost Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} https://vpn.na.sage.com/vdesk/terminal/urxh…00,2011,124,911 (F5 Networks Host Control)
O16 - DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} https://vpn.na.sage.com/policy/download_bin…,2010,1020,1432 (F5 Networks OS Policy Agent)
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126 (F5 Networks OPSWAT Helper Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0A4CBC1-2119-4C19-8FD1-BF4952EFE657}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - F:\Programs\Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/26 01:55:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/10/12 10:59:30 | 000,000,000 | —- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1999/08/11 12:09:06 | 000,000,233 | —- | M] () - I:\AUTOEXEC – [ NTFS ]
O32 - AutoRun File - [2000/08/28 13:56:10 | 000,000,023 | —- | M] () - I:\AUTOEXEC.112 – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/20 09:40:43 | 000,107,336 | —- | C] (Webroot) – C:\WINDOWS\System32\drivers\pIclxoGw.sys
[2011/12/20 09:40:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:23 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
[2011/12/20 08:58:44 | 000,028,992 | —- | C] (TuneUp Software) – C:\WINDOWS\System32\uxtuneup.dll
[2011/12/20 08:37:56 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/12/20 08:34:51 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\BineenXt.sys
[2011/12/19 20:31:05 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\srvlnASy.sys
[2011/12/18 23:27:36 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\xocVqFMR.sys
[2011/12/18 23:27:22 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\odcgeLCR.sys
[2011/12/18 19:33:24 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\VGlxxmhq.sys
[2011/12/18 16:17:39 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\tftUsCuh.sys
[2011/12/18 16:12:40 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\UtNACVPB.sys
[2011/12/18 15:56:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Webroot SecureAnywhere
[2011/12/18 15:56:34 | 000,141,272 | —- | C] (Webroot) – C:\WINDOWS\System32\WRusr.dll
[2011/12/18 15:56:34 | 000,107,336 | —- | C] (Webroot) – C:\WINDOWS\System32\drivers\WRkrn.sys
[2011/12/18 15:56:32 | 000,000,000 | —D | C] – C:\Program Files\Webroot
[2011/12/18 15:56:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WRData
[2011/12/15 19:23:27 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2011/12/11 10:35:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2011/12/10 10:09:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DivX
[2011/12/10 10:09:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2011/12/05 05:18:18 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/04 10:31:30 | 000,031,552 | —- | C] (TuneUp Software) – C:\WINDOWS\System32\TURegOpt.exe
[2011/12/04 10:31:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TuneUp Utilities 2012
[2011/12/04 10:30:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\Application Data\TuneUp Software
[2011/12/04 10:30:34 | 000,000,000 | —D | C] – C:\Program Files\TuneUp Utilities 2012
[2011/12/04 10:29:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/12/04 10:28:39 | 000,000,000 | -HSD | C] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2011/12/04 09:50:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\My Documents\Downloads
[2011/12/04 09:11:18 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\ubxxitam.sys
[2011/12/04 09:09:55 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/04 09:09:55 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/04 09:09:55 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/03 15:30:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/03 14:49:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Patricia\Application Data\Malwarebytes
[2011/12/03 12:48:35 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/03 12:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/23 08:10:19 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/20 10:12:20 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/20 09:41:39 | 000,625,664 | —- | M] () – C:\Documents and Settings\Patricia\Desktop\dds.scr
[2011/12/20 09:40:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:43 | 000,107,336 | —- | M] (Webroot) – C:\WINDOWS\System32\drivers\pIclxoGw.sys
[2011/12/20 09:40:30 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
[2011/12/20 08:41:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/20 08:36:10 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2011/12/20 08:36:09 | 000,272,484 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2011/12/20 08:35:58 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/20 08:35:53 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/18 15:56:34 | 000,141,272 | —- | M] (Webroot) – C:\WINDOWS\System32\WRusr.dll
[2011/12/18 15:56:34 | 000,107,336 | —- | M] (Webroot) – C:\WINDOWS\System32\drivers\WRkrn.sys
[2011/12/16 03:20:50 | 000,282,928 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 20:27:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/12/14 06:47:06 | 000,031,552 | —- | M] (TuneUp Software) – C:\WINDOWS\System32\TURegOpt.exe
[2011/12/14 06:46:50 | 000,028,992 | —- | M] (TuneUp Software) – C:\WINDOWS\System32\uxtuneup.dll
[2011/12/09 09:28:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/08 08:49:11 | 000,118,582 | —- | M] () – C:\logfile
[2011/12/04 10:31:27 | 000,001,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/12/04 10:31:27 | 000,001,741 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2012.lnk
[2011/12/04 09:33:10 | 000,437,014 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/04 09:33:10 | 000,069,358 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/04 09:11:19 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\ubxxitam.sys
[2011/12/04 09:11:17 | 000,001,401 | RHS- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/04 09:09:55 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/12/04 09:09:55 | 000,100,880 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/12/04 09:09:55 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/12/03 14:29:04 | 000,015,476 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\627013l4q800u827c180j1gsa0e0
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\win32k.sys
[2011/11/23 08:25:32 | 001,859,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\win32k.sys
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/20 09:41:16 | 000,625,664 | —- | C] () – C:\Documents and Settings\Patricia\Desktop\dds.scr
[2011/12/18 15:58:51 | 000,162,816 | —- | C] () – C:\WINDOWS\System32\drivers\tkGBMHJb.sys
[2011/12/06 15:25:36 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/04 10:31:27 | 000,001,747 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\TuneUp Utilities 2012.lnk
[2011/12/04 10:31:27 | 000,001,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/12/04 10:31:27 | 000,001,741 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Utilities 2012.lnk
[2011/12/03 12:35:57 | 000,015,476 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\627013l4q800u827c180j1gsa0e0
[2011/09/21 21:09:59 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2011/09/19 21:59:17 | 000,017,905 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2011/09/19 19:52:15 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/02/20 10:32:50 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2011/02/20 10:32:50 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2010/12/12 09:28:54 | 000,000,000 | —- | C] () – C:\WINDOWS\f5unistall.INI
[2010/10/19 07:42:47 | 000,013,132 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/12 11:28:05 | 000,103,535 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2010/09/12 11:28:05 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2010/06/20 21:45:29 | 000,003,402 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate
[2010/05/14 20:25:38 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/04/26 23:48:17 | 002,183,470 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/04/26 23:14:28 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/26 22:57:01 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/04/26 01:56:21 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/04/26 01:52:52 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/04/25 18:44:47 | 000,004,633 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/04/25 18:43:55 | 000,282,928 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/06/25 02:57:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/03/21 07:28:50 | 000,000,106 | —- | C] () – C:\WINDOWS\System32\mmc.exe.config
[2004/08/04 01:07:22 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 00:56:44 | 000,193,024 | —- | C] () – C:\WINDOWS\System32\msrating.dll
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,437,014 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,069,358 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/03/05 10:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Aatrix Software
[2010/12/19 10:54:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/12 09:28:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F5 Networks
[2010/05/14 20:23:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/03/05 10:35:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pervasive Software
[2011/12/04 10:31:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/07/31 10:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011/12/20 09:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WRData
[2011/12/04 10:28:39 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2010/05/01 16:11:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/04 10:30:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Patricia\Application Data\TuneUp Software
[2011/12/20 08:41:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/26 01:55:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/09/19 22:09:45 | 000,000,000 | —- | M] () – C:\BnetLog.txt
[2011/12/15 20:27:59 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2006/11/02 04:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2010/04/26 01:55:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/26 23:29:09 | 000,000,206 | —- | M] () – C:\csb.log
[2010/03/10 20:20:52 | 000,799,352 | —- | M] () – C:\D2XP_IX86_112a_113c.mpq
[2010/04/26 01:55:00 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/12/08 08:49:11 | 000,118,582 | —- | M] () – C:\logfile
[2010/04/26 01:55:00 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/07 19:59:38 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/04/26 23:29:09 | 000,000,480 | —- | M] () – C:\RHDSetup.log
[2011/03/05 10:41:25 | 000,899,274 | —- | M] () – C:\SageMessageCenter_Install.log
[2011/12/20 08:36:39 | 000,000,122 | —- | M] () – C:\service.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/04/26 01:54:43 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/04/25 18:42:52 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/04/25 18:42:52 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/04/25 18:42:52 | 000,925,696 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/07 20:03:06 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/02 14:55:11 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/05/02 14:55:11 | 000,000,079 | —- | M] () – C:\Documents and Settings\Patricia\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/12/20 09:40:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
[2011/12/20 09:40:30 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Patricia\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate]
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-16 08:04:55
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB10581$] -> -> Unknown point type
========== Alternate Data Streams ==========
@Alternate Data Stream - 514 bytes -> C:\WINDOWS\System32\drivers\ubxxitam.sys:changelist
< End of report >
OTL Extras logfile created on: 12/20/2011 10:07:18 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Patricia\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.54 Gb Available Physical Memory | 78.27% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.35% Paging File free
Paging file location(s): F:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 11.72 Gb Total Space | 0.89 Gb Free Space | 7.62% Space Free | Partition Type: NTFS
Drive E: | 74.55 Gb Total Space | 9.44 Gb Free Space | 12.66% Space Free | Partition Type: NTFS
Drive F: | 116.27 Gb Total Space | 7.38 Gb Free Space | 6.35% Space Free | Partition Type: NTFS
Drive I: | 170.10 Gb Total Space | 128.45 Gb Free Space | 75.51% Space Free | Partition Type: NTFS
Computer Name: THE-BEAST | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = internetshortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – E:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "F:\Programs\Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "F:\Programs\Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
"1583:TCP" = 1583:TCP:*:Enabled:Pervasive DBEngine
"3351:TCP" = 3351:TCP:*:Enabled:Pervasive DBEngine
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Programs\BitTorrent\bittorrent.exe" = F:\Programs\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"H:\CDS\Nero\Installation\SetupX.exe" = H:\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup
"E:\Program Files\StarCraft II Beta\StarCraft II.exe" = E:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\Adobe\Acrobat_com\Acrobat_com.exe" = C:\Program Files\Adobe\Acrobat_com\Acrobat_com.exe:*:Enabled:Acrobat_com – ()
"E:\Program Files\StarCraft II\StarCraft II.exe" = E:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"E:\Program Files\StarCraft II\Versions\Base15405\SC2.exe" = E:\Program Files\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"C:\Documents and Settings\DeViouS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\DeViouS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"E:\Program Files\PFPortChecker\PFPortChecker.exe" = E:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded. – (portforward.com)
"F:\Programs\Office\Office14\GROOVE.EXE" = F:\Programs\Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"F:\Programs\Office\Office14\ONENOTE.EXE" = F:\Programs\Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"F:\Programs\Office\Office14\OUTLOOK.EXE" = F:\Programs\Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe" = C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe:*:Enabled:Database Service Manager – (Pervasive Software Inc.)
"C:\Program Files\GIGABYTE\GEST\run.exe" = C:\Program Files\GIGABYTE\GEST\run.exe:*:Disabled:update – ()
"E:\Program Files\StarCraft II\Versions\Base18092\SC2.exe" = E:\Program Files\StarCraft II\Versions\Base18092\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"F:\Programs\XBMC\XBMC.exe" = F:\Programs\XBMC\XBMC.exe:*:Enabled:XBMC – (Team XBMC)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2
"{0A3238D7-AB32-1010-B717-F3E3F18B4A8C}" = Pervasive PSQL v10 SP2 Workgroup (32-bit)
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE1008C-11A1-4F4F-8DB7-27573924DE78}" = DMIView B06.1227.01
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5869CE1E-BC0B-4648-B1AE-6EF4A985590C}" = Dynamic Energy Saver 1.0 B8.0128.1
"{6798DD4E-BD16-4735-87EB-D712637CCB8C}" = Sage Message Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{714ACFF3-B8A3-4AD6-937B-13C833D71033}" = Nero 7 Essentials
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7ED169D4-5053-4166-93DF-53B12AE6C539}" = Energy Saver Advance B8.0711.1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BCB844B-0814-4354-A413-1063DB4618E9}" = PeachTree Signature Ready Forms
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E67BFA7-2A1C-4439-95CE-D6ACD3E85073}" = Peachtree Accounting 2011
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A95A76C9-6F65-477E-83A0-9F884B6DC21B}" = TuneUp Utilities Language Pack (en-US)
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C484CC8D-03CF-4022-89C4-DB4F02E8A15B}" = Crystal Reports 2008 Runtime SP1
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF8C077A-B467-4C43-8DB5-3A9B94FF9681}" = LightScribe System Software [removed]
"{D237A127-1229-41EF-8F89-F5B2363868E7}" = Diablo II Character Manager
"{DEA314C4-0929-4250-BC92-98E4C105F28D}" = NVIDIA PhysX
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATT-PRT22" = ATT-PRT22
"BitTorrent" = BitTorrent
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Diablo II" = Diablo II
"DriverCD" = DriverCD
"DVDFab 8 Qt_is1" = DVDFab 8.1.0.5 (04/07/2011) Qt
"F5 Networks Client Components" = BIG-IP Edge Client Components (All Users)
"HP Photo & Imaging" = HP Image Zone 4.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{9E67BFA7-2A1C-4439-95CE-D6ACD3E85073}" = Peachtree Accounting 2011
"Integration Services" = Sage Integration Services
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PFPortChecker" = PFPortChecker 1.0.36
"Portforward Static IP Address" = Portforward Static IP Address 1.0.44
"RealAlt_is1" = Real Alternative 2.0.2
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WRUNINST" = Webroot SecureAnywhere
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:18:38 AM, on 12/20/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17095)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
E:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\GIGABYTE\GEST\gest.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\WINDOWS\system32\svchost.exe
E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\Documents and Settings\Patricia\Desktop\OTL.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Core Temp\Core Temp.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patricia\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.240.133.193 www.google-analytics.com.
O1 - Hosts: 216.240.133.193 ad-emea.doubleclick.net.
O1 - Hosts: 216.240.133.193 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Programs\Office\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - F:\Programs\Office\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SecurDisc] E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PeachtreePrefetcher.exe] E:\Programs\Sage\Peachtree\PeachtreePrefetcher.exe /configfile:peachtreeprefetcher.winstart.config
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [InCD] E:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\RUN.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WRSVC] "C:\Program Files\Webroot\WRSA.exe" -ul
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Core Temp] "C:\Program Files\Core Temp\Core Temp.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil11c_Plugin.exe -update plugin
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\Programs\Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - F:\Programs\Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} (OPSWAT AntiViruses Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} (F5 Networks VPN Manager) - https://vpn.na.sage.com/vdesk/terminal/urxv…0,2011,104,2321
O16 - DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} (OPSWAT FireWalls Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} (F5 Networks Dynamic Application Tunnel Control) - https://vpn.na.sage.com/vdesk/terminal/f5tu…0,2011,104,2309
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://vpn.na.sage.com/vdesk/terminal/Inst…,2010,1020,1507
O16 - DPF: {49EC7987-E331-44E3-B170-748B58A268B9} (OPSWAT ProcessesScanner Class) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O16 - DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} (F5 Networks Policy Agent Host Class) - https://vpn.na.sage.com/vdesk/terminal/f5In…,2010,1020,1407
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://vpn.na.sage.com/vdesk/terminal/urxs…,2010,1020,1428
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://vpn.na.sage.com/vdesk/terminal/urxh…00,2011,124,911
O16 - DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} (F5 Networks OS Policy Agent) - https://vpn.na.sage.com/policy/download_bin…,2010,1020,1432
O16 - DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} (F5 Networks OPSWAT Helper Control) - https://vpn.na.sage.com/vdesk/terminal/f5op…1,2011,603,1126
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - E:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Peachtree SmartPosting 2011 - Sage Software, Inc. - E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
O23 - Service: Pervasive PSQL Workgroup Engine (psqlWGE) - Pervasive Software Inc. - C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
O23 - Service: WRSVC - Webroot - C:\Program Files\Webroot\WRSA.exe
–
End of file - 11703 bytes
DDS
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:21:52.10 on Tue 12/20/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2476 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
.
============== Running Processes ===============
.
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
E:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
E:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\GIGABYTE\GEST\gest.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\WRSA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Pervasive Software\PSQL\bin\w3dbsmgr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
E:\Programs\Sage\Peachtree\SmartPostingService2011.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Core Temp\Core Temp.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\ping.exe
C:\Documents and Settings\Patricia\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - f:\programs\office\office14\GROOVEEX.DLL
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - f:\programs\office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Core Temp] "c:\program files\core temp\Core Temp.exe"
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11c_Plugin.exe -update plugin
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SecurDisc] e:\program files\nero\nero 7\incd\NBHGui.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [PeachtreePrefetcher.exe] e:\programs\sage\peachtree\PeachtreePrefetcher.exe /configfile:peachtreeprefetcher.winstart.config
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [InCD] e:\program files\nero\nero 7\incd\InCD.exe
mRun: [GEST] c:\program files\gigabyte\gest\RUN.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WRSVC] "c:\program files\webroot\WRSA.exe" -ul
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.872
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
uPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
mPolicies-explorer: NoViewOnDrive = 0 (0x0)
mPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
mPolicies-explorer: NoWindowsUpdate = 0 (0x0)
mPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
dPolicies-explorer: NoViewOnDrive = 0 (0x0)
dPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
dPolicies-explorer: NoWindowsUpdate = 0 (0x0)
dPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\programs\office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - f:\programs\office\office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
DPF: {195538FD-1C39-44B1-A7C3-5D7137A8A8F1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://vpn.na.sage.com/vdesk/terminal/urxvpn.cab#version=7000,2011,104,2321
DPF: {30CF9713-6614-4556-B5F5-66F8C7F9DEF1} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vpn.na.sage.com/vdesk/terminal/f5tunsrv.cab#version=7000,2011,104,2309
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vpn.na.sage.com/vdesk/terminal/InstallerControl.cab#version=7000,2010,1020,1507
DPF: {49EC7987-E331-44E3-B170-748B58A268B9} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
DPF: {57C76689-F052-487B-A19F-855AFDDF28EE} - hxxps://vpn.na.sage.com/vdesk/terminal/f5InspectionHost.cab#version=7000,2010,1020,1407
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vpn.na.sage.com/vdesk/terminal/urxshost.cab#version=7000,2010,1020,1428
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vpn.na.sage.com/vdesk/terminal/urxhost.cab#version=7000,2011,124,911
DPF: {E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D} - hxxps://vpn.na.sage.com/policy/download_binary.php/win32/f5syschk.cab#Version=7000,2010,1020,1432
DPF: {EBDC91CB-F23F-477D-B152-3F7243760D04} - hxxps://vpn.na.sage.com/vdesk/terminal/f5opswati.cab#Version=7001,2011,603,1126
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - f:\programs\office\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 216.240.133.193 www.google-analytics.com.
Hosts: 216.240.133.193 ad-emea.doubleclick.net.
Hosts: 216.240.133.193 www.statcounter.com.
Hosts: 69.72.252.254 www.google-analytics.com.
Hosts: 69.72.252.254 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\patricia\applic~1\mozilla\firefox\profiles\wkqja21d.default\
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: e:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: f:\programs\office\office14\NPAUTHZ.DLL
FF - plugin: f:\programs\office\office14\NPSPWRAP.DLL
FF - plugin: f:\programs\real alternative\browser\plugins\nppl3260.dll
FF - plugin: f:\programs\real alternative\browser\plugins\nprpjplug.dll
FF - plugin: i:\programs\divx\divx web player\npdivx32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [2011-12-18 107336]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl4eb7697b;MpKsl4eb7697b;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\MpKsl4eb7697b.sys [2011-12-20 29904]
R2 Peachtree SmartPosting 2011;Peachtree SmartPosting 2011;e:\programs\sage\peachtree\SmartPostingService2011.exe [2010-9-13 43848]
R2 psqlWGE;Pervasive PSQL Workgroup Engine;c:\program files\pervasive software\psql\bin\w3dbsmgr.exe [2008-6-6 435496]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2012\TuneUpUtilitiesService32.exe [2011-12-14 1514304]
R2 WRSVC;WRSVC;c:\program files\webroot\WRSA.exe [2011-12-18 637208]
R3 ALSysIO;ALSysIO;\??\c:\docume~1\patricia\locals~1\temp\alsysio.sys –> c:\docume~1\patricia\locals~1\temp\ALSysIO.sys [?]
R3 GEST Service;GEST Service for program management.;c:\program files\gigabyte\gest\GSvr.exe [2010-4-26 47624]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2012\TuneUpUtilitiesDriver32.sys [2011-11-8 10064]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [2010-6-11 35448]
S0 pIclxoGw;pIclxoGw;c:\windows\system32\drivers\pIclxoGw.sys [2011-12-20 107336]
S1 MpKsl05309e57;MpKsl05309e57;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c584baa6-e20e-44be-9141-61d6417b9b42}\mpksl05309e57.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c584baa6-e20e-44be-9141-61d6417b9b42}\MpKsl05309e57.sys [?]
S1 MpKsl2714a0e1;MpKsl2714a0e1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdbb7fc4-3c2a-4e0b-80ad-4e490922cee0}\mpksl2714a0e1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{bdbb7fc4-3c2a-4e0b-80ad-4e490922cee0}\MpKsl2714a0e1.sys [?]
S1 MpKsl2f23e610;MpKsl2f23e610;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\mpksl2f23e610.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\MpKsl2f23e610.sys [?]
S1 MpKsl354afefd;MpKsl354afefd;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01751214-b360-4f2b-a0f5-14a514a2d6ed}\mpksl354afefd.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01751214-b360-4f2b-a0f5-14a514a2d6ed}\MpKsl354afefd.sys [?]
S1 MpKsl6d86a591;MpKsl6d86a591;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32aa8df5-fbc5-4db8-a871-71feadde419f}\mpksl6d86a591.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32aa8df5-fbc5-4db8-a871-71feadde419f}\MpKsl6d86a591.sys [?]
S1 MpKsl7990e691;MpKsl7990e691;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{803f0683-2921-4ba4-b339-847eb250ceb5}\mpksl7990e691.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{803f0683-2921-4ba4-b339-847eb250ceb5}\MpKsl7990e691.sys [?]
S1 MpKsl836b7f90;MpKsl836b7f90;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{29d607b1-73f8-4c69-b41d-cc62685ab812}\mpksl836b7f90.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{29d607b1-73f8-4c69-b41d-cc62685ab812}\MpKsl836b7f90.sys [?]
S1 MpKsl88e6af3b;MpKsl88e6af3b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e8c76270-ac80-4a45-9ace-65c7af84bc87}\mpksl88e6af3b.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e8c76270-ac80-4a45-9ace-65c7af84bc87}\MpKsl88e6af3b.sys [?]
S1 MpKsl944debed;MpKsl944debed;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4dbb258c-2bde-43d7-9caa-61ba55584da1}\mpksl944debed.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4dbb258c-2bde-43d7-9caa-61ba55584da1}\MpKsl944debed.sys [?]
S1 MpKsl99c0f781;MpKsl99c0f781;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f8af1b56-0c99-4ac0-b79f-fb5d0c0c8140}\mpksl99c0f781.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f8af1b56-0c99-4ac0-b79f-fb5d0c0c8140}\MpKsl99c0f781.sys [?]
S1 MpKslaae793a0;MpKslaae793a0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\mpkslaae793a0.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f58cebd7-eacf-4d02-9d28-00e891847310}\MpKslaae793a0.sys [?]
S1 MpKslcbd862da;MpKslcbd862da;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042caf0a-ea2f-4642-bd5c-d436c09b9add}\mpkslcbd862da.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{042caf0a-ea2f-4642-bd5c-d436c09b9add}\MpKslcbd862da.sys [?]
S1 MpKslce097d11;MpKslce097d11;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a1b535f4-7bf2-4167-8573-7720aa6f42d6}\mpkslce097d11.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a1b535f4-7bf2-4167-8573-7720aa6f42d6}\MpKslce097d11.sys [?]
S1 MpKsld45cf3e6;MpKsld45cf3e6;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab8b7ebc-2b9e-4937-8142-4be51f0ebf69}\mpksld45cf3e6.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab8b7ebc-2b9e-4937-8142-4be51f0ebf69}\MpKsld45cf3e6.sys [?]
S1 MpKsldaa75e46;MpKsldaa75e46;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f17962e0-8376-4980-9ad4-622c9950922f}\mpksldaa75e46.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{f17962e0-8376-4980-9ad4-622c9950922f}\MpKsldaa75e46.sys [?]
S1 MpKsle7be0667;MpKsle7be0667;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17c6adc8-1ee4-4a18-bce9-821f136857ed}\mpksle7be0667.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17c6adc8-1ee4-4a18-bce9-821f136857ed}\MpKsle7be0667.sys [?]
S1 MpKslecb2ba95;MpKslecb2ba95;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb483246-1cd6-4db2-896f-12372ff095cf}\mpkslecb2ba95.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fb483246-1cd6-4db2-896f-12372ff095cf}\MpKslecb2ba95.sys [?]
S2 NeroRegInCDSrv;Nero Registry InCD Service;e:\program files\nero\nero 7\incd\nbhregincdsrv.exe –> e:\program files\nero\nero 7\incd\NBHRegInCDSrv.exe [?]
S3 esgiguard;esgiguard;\??\c:\program files\enigma software group\spyhunter\esgiguard.sys –> c:\program files\enigma software group\spyhunter\esgiguard.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2010-12-12 10744]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-4-17 22216]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;f:\programs\office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-4 50704]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S4 MBAMService;MBAMService;f:\programs\malwarebytes' anti-malware\mbamservice.exe [2011-4-17 366152]
.
=============== File Associations ===============
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
=============== Created Last 30 ================
.
2011-12-20 14:40:43 107336 —-a-w- c:\windows\system32\drivers\pIclxoGw.sys
2011-12-20 13:58:44 28992 —-a-w- c:\windows\system32\uxtuneup.dll
2011-12-20 13:36:01 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\MpKsl4eb7697b.sys
2011-12-20 13:35:59 56200 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\offreg.dll
2011-12-20 13:34:51 162816 —-a-w- c:\windows\system32\drivers\BineenXt.sys
2011-12-20 01:31:05 162816 —-a-w- c:\windows\system32\drivers\srvlnASy.sys
2011-12-19 21:16:33 6823496 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{7ebda840-a36e-474a-a355-8831d9343538}\mpengine.dll
2011-12-19 04:27:36 162816 —-a-w- c:\windows\system32\drivers\xocVqFMR.sys
2011-12-19 04:27:22 162816 —-a-w- c:\windows\system32\drivers\odcgeLCR.sys
2011-12-19 00:33:24 162816 —-a-w- c:\windows\system32\drivers\VGlxxmhq.sys
2011-12-18 21:17:39 162816 —-a-w- c:\windows\system32\drivers\tftUsCuh.sys
2011-12-18 21:12:40 162816 —-a-w- c:\windows\system32\drivers\UtNACVPB.sys
2011-12-18 20:58:51 162816 —-a-w- c:\windows\system32\drivers\tkGBMHJb.sys
2011-12-18 20:56:34 141272 —-a-w- c:\windows\system32\WRusr.dll
2011-12-18 20:56:34 107336 —-a-w- c:\windows\system32\drivers\WRkrn.sys
2011-12-18 20:56:32 ——– d—–w- c:\program files\Webroot
2011-12-18 20:56:30 ——– d—–w- c:\docume~1\alluse~1\applic~1\WRData
2011-12-10 15:09:11 ——– d—–w- c:\program files\common files\DivX Shared
2011-12-04 15:31:30 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2011-12-04 15:30:56 ——– d—–w- c:\docume~1\patricia\applic~1\TuneUp Software
2011-12-04 15:30:34 ——– d—–w- c:\program files\TuneUp Utilities 2012
2011-12-04 15:29:11 ——– d—–w- c:\docume~1\alluse~1\applic~1\TuneUp Software
2011-12-04 15:28:39 ——– d-sh–w- c:\docume~1\alluse~1\applic~1\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-12-04 14:11:18 41680 —-a-w- c:\windows\system32\drivers\ubxxitam.sys
2011-12-04 14:09:55 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-04 14:09:55 281104 —-a-w- c:\windows\system32\wpcap.dll
2011-12-04 14:09:55 100880 —-a-w- c:\windows\system32\Packet.dll
2011-12-03 22:05:01 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-12-03 22:05:01 ——– d—–w- c:\windows\system32\wbem\Repository
2011-12-03 19:49:17 ——– d—–w- c:\docume~1\patricia\applic~1\Malwarebytes
.
==================== Find3M ====================
.
2011-12-20 13:36:10 16608 —-a-w- c:\windows\gdrv.sys
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-23 17:08:43 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 -c–a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 -c–a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 -c–a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 10:22:06.64 ===============
——————————————————————————–