joshthegoat
Topic Starter
My computer has been getting google redirects on a regular basis. Once redirected, if I hit "back" about 4 times it gets me back to the original page I wanted to go to.
Here's the OTL.txt paste
OTL logfile created on: 12/31/2011 4:21:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Operator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.06% Memory free
3.85 Gb Paging File | 3.01 Gb Available in Paging File | 78.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 224.61 Gb Free Space | 75.35% Space Free | Partition Type: NTFS
Computer Name: NEOBOX | User Name: Operator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Operator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\uagqecsvc.exe (Microsoft ® Corporation)
PRC - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Cisco\Cisco HostScan\bin\ciscod.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Symantec\VIP Access Client\VIPAppService.exe (Symantec Corporation)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe (IDT, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Java\jre6\bin\jp2iexp.dll ()
MOD - C:\Program Files\Java\jre6\bin\jp2native.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\WINDOWS\system32\quartz.dll ()
========== Win32 Services (SafeList) ==========
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (uagqecsvc) – C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\uagqecsvc.exe (Microsoft ® Corporation)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (ciscod.exe) – C:\Program Files\Cisco\Cisco HostScan\bin\ciscod.exe (Cisco Systems, Inc.)
SRV - (VIPAppService) – C:\Program Files\Symantec\VIP Access Client\VIPAppService.exe (Symantec Corporation)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PLFlash DeviceIoControl Service) – C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (STacSV) – c:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe (IDT, Inc.)
========== Driver Services (SafeList) ==========
DRV - (catchme) – File not found
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (acsmux) – C:\WINDOWS\system32\drivers\acsmux.sys (Cisco Systems, Inc.)
DRV - (acsint) – C:\WINDOWS\system32\drivers\acsint.sys (Cisco Systems, Inc.)
DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) – C:\WINDOWS\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) – C:\WINDOWS\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\l151x86.sys (Atheros Communications, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (RTL85n86) – C:\WINDOWS\system32\drivers\RTL85n86.sys (Realtek)
DRV - (AmdTools) – C:\WINDOWS\system32\drivers\AmdTools.sys (AMD, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://us.etrade.com/e/t/user/login
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr;=&q;=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl;=en&ie;=UTF-8&q;=%s&btnG;=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l;=55α=%s&S;=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip;=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 49
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.496
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/05/15 22:14:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Symantec\VIP Access Client\ [2011/11/15 10:05:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/31 13:07:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/31 13:07:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/11/22 19:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/05/15 22:14:40 | 000,000,000 | —D | M]
[2009/11/18 17:46:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Operator\Application Data\Mozilla\Extensions
[2011/12/29 00:47:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\pltn1dws.default\extensions
[2010/08/22 00:47:19 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\pltn1dws.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2011/12/31 10:58:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/31 10:58:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\OPERATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PLTN1DWS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/27 21:17:10 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/06/21 17:39:18 | 000,034,376 | —- | M] () – C:\Program Files\mozilla firefox\plugins\logging.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/27 21:17:07 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/27 21:17:07 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/12/31 00:54:19 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [AttachmentWipermailadc.fmi.com] C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\AttachmentWiper.exeBatchRun\run.bat ()
O4 - Startup: C:\Documents and Settings\Operator\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Operator\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Operator\Start Menu\Programs\Startup\JMicron Button Manager.lnk = C:\Program Files\JMicron\JMBtnMgr.EXE (JMicron Technology Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33704B0F-9EB7-434B-B752-EA6CFFB87423} http://babyjoancam.viewnetcam.com/JpegInst.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.6.0.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A2A8145-77D0-4161-9819-B56481B30B4B}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87C853CB-5E40-4847-9422-C7C7EB90F223}: DhcpNameServer = 192.168.10.1 [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1179609-0B0F-4589-9F58-942E0FE88BD0}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/25 17:25:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/31 16:20:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/12/31 13:16:31 | 000,000,000 | —D | C] – C:\ComboFix
[2011/12/31 11:03:25 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Operator\Recent
[2011/12/31 10:58:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/12/31 10:58:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/31 10:58:16 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 10:58:16 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 10:58:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 10:58:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/12/31 10:56:24 | 000,910,112 | —- | C] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/30 17:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\Wak
[2011/12/30 17:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\Myy
[2011/12/30 14:45:17 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/30 13:03:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\.minecraft
[2011/12/29 01:09:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/12/29 01:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/12/29 00:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Local Settings\Application Data\Temp
[2011/12/29 00:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/12/29 00:56:40 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/12/29 00:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Local Settings\Application Data\Google
[2011/12/29 00:55:47 | 000,000,000 | —D | C] – C:\Program Files\Downloads
[2011/12/28 18:12:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/23 16:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/23 15:25:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/23 15:25:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/31 16:25:14 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/31 16:20:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/12/31 16:06:01 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/31 15:09:14 | 000,000,394 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Operator Logon.job
[2011/12/31 14:15:47 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/31 14:15:41 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/31 14:15:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/31 13:14:30 | 004,358,797 | R— | M] (Swearware) – C:\Documents and Settings\Operator\Desktop\ComboFix.exe
[2011/12/31 13:05:22 | 000,270,142 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/31 10:56:23 | 000,910,112 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/31 00:54:19 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/30 17:43:34 | 000,017,522 | -HS- | M] () – C:\Documents and Settings\Operator\Local Settings\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 17:43:34 | 000,017,522 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 14:45:37 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/30 13:15:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/29 01:09:37 | 000,001,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/29 01:09:37 | 000,001,798 | —- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 00:58:53 | 000,000,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/28 22:31:01 | 000,000,752 | —- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\iexplore.exe.lnk
[2011/12/28 18:50:52 | 000,000,752 | —- | M] () – C:\Documents and Settings\Operator\Desktop\iexplore.exe.lnk
[2011/12/28 18:26:38 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/28 17:59:16 | 000,017,544 | -HS- | M] () – C:\Documents and Settings\Operator\Local Settings\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/28 17:59:16 | 000,017,544 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/24 12:34:31 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\n6JNdr64.dat
[2011/12/24 12:34:31 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ssY84kwL.com.b
[2011/12/23 11:54:08 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/12/18 23:35:22 | 000,001,732 | -H– | M] () – C:\Documents and Settings\Operator\My Documents\Default.rdp
[2011/12/18 10:10:33 | 000,083,360 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIRfsClientNP.dll
[2011/12/18 10:10:32 | 000,087,424 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIinit.dll
[2011/12/18 10:10:32 | 000,030,592 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIport.dll
[2011/12/18 10:08:11 | 000,356,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/10 11:43:38 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/12/05 21:55:59 | 000,000,172 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Google.url
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/31 13:05:22 | 000,270,142 | —- | C] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/30 17:41:28 | 000,017,522 | -HS- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 17:41:28 | 000,017,522 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/29 01:09:37 | 000,001,820 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/29 01:09:37 | 000,001,798 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 00:56:44 | 000,000,890 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 00:56:44 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/28 22:31:01 | 000,000,752 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\iexplore.exe.lnk
[2011/12/28 18:50:52 | 000,000,752 | —- | C] () – C:\Documents and Settings\Operator\Desktop\iexplore.exe.lnk
[2011/12/28 18:26:38 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/24 12:34:31 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ssY84kwL.com.b
[2011/12/24 10:19:36 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\n6JNdr64.dat
[2011/12/23 15:26:54 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/23 15:13:49 | 000,017,544 | -HS- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/23 15:13:49 | 000,017,544 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/11/24 13:26:42 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/24 12:39:20 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/24 12:39:20 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/24 12:39:20 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/24 12:39:20 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/24 12:39:20 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/21 07:13:48 | 000,139,128 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/07/21 07:13:48 | 000,138,056 | —- | C] () – C:\Documents and Settings\Operator\Application Data\PnkBstrK.sys
[2011/07/21 07:13:23 | 000,215,128 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/07/21 07:13:21 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2011/07/21 07:13:21 | 000,075,064 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/05/15 22:05:56 | 000,205,918 | —- | C] () – C:\WINDOWS\hpoins46.dat
[2011/05/15 22:05:56 | 000,000,601 | —- | C] () – C:\WINDOWS\hpomdl46.dat
[2010/06/11 02:40:10 | 000,000,707 | —- | C] () – C:\Documents and Settings\Operator\Application Data\myMPQ.ini
[2010/02/28 13:40:03 | 000,004,430 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft Excel 97-2003.NOT
[2010/02/28 13:38:17 | 000,038,260 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft Excel 97-2003.ADR
[2009/12/30 22:00:31 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/21 20:27:20 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/21 18:25:29 | 000,043,520 | —- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/18 13:09:50 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2009/12/18 13:09:49 | 000,196,565 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2009/12/18 13:09:49 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2009/11/26 12:44:05 | 000,078,712 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/18 17:46:12 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/20 13:40:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/08/25 17:53:42 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2008/08/25 17:37:41 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2008/08/25 17:37:33 | 003,107,788 | R— | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/08/25 17:27:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/08/25 17:22:36 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/25 12:11:03 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/08/25 12:09:58 | 000,356,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/07/16 13:35:28 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 02:55:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/21 16:51:16 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2007/08/21 14:36:12 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2007/06/24 20:14:55 | 000,008,336 | —- | C] () – C:\WINDOWS\UN060501.INI
[2006/12/31 04:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 05:00:00 | 000,465,398 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 05:00:00 | 000,079,540 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 05:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/09/25 22:30:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/11/15 10:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco
[2011/03/20 11:56:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/02/05 15:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/12/31 00:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/11/24 12:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/02/28 12:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/08/27 12:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/26 12:37:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/30 13:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\.minecraft
[2011/06/04 16:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Audacity
[2011/11/06 11:01:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\AVG
[2011/12/31 13:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Dropbox
[2011/02/10 09:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\ICAClient
[2011/05/15 21:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Leadertech
[2011/12/31 13:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Myy
[2011/07/20 21:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\SystemRequirementsLab
[2010/03/10 01:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\TechSmith
[2011/09/11 23:22:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Thunderbird
[2011/12/31 11:03:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Wak
[2008/08/25 18:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Windows Desktop Search
[2010/01/01 13:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Windows Search
[2011/12/31 15:09:14 | 000,000,394 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On Operator Logon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/11/25 15:14:12 | 000,001,024 | —- | M] () – C:\.rnd
[2008/08/25 17:25:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/11/24 12:46:43 | 000,000,339 | —- | M] () – C:\Boot.bak
[2011/12/30 14:45:37 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/12/31 15:09:18 | 000,018,805 | —- | M] () – C:\ComboFix.txt
[2008/08/25 17:25:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/11/24 19:00:37 | 006,430,218 | —- | M] () – C:\immudebug.log
[2008/08/25 17:25:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/08/25 17:25:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 19:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 21:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/31 14:15:29 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/08/25 17:24:54 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/10/21 14:29:40 | 000,320,512 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp101.dll
[2011/12/18 10:10:33 | 000,052,096 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/08/25 12:09:18 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/08/25 12:09:18 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/08/25 12:09:18 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/25 17:25:21 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/25 17:29:35 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/23 16:27:45 | 003,511,776 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Operator\Desktop\ccsetup312.exe
[2011/12/31 13:14:30 | 004,358,797 | R— | M] (Swearware) – C:\Documents and Settings\Operator\Desktop\ComboFix.exe
[2011/12/31 10:56:23 | 000,910,112 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/31 13:05:22 | 000,270,142 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/31 16:20:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/11/06 22:01:53 | 002,167,144 | —- | M] (SolidQuest Inc. ) – C:\Documents and Settings\Operator\Desktop\RegTeck_setup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-31 16:56:03
========== Alternate Data Streams ==========
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
Here's the OTL.txt paste
OTL logfile created on: 12/31/2011 4:21:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Operator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.06% Memory free
3.85 Gb Paging File | 3.01 Gb Available in Paging File | 78.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 224.61 Gb Free Space | 75.35% Space Free | Partition Type: NTFS
Computer Name: NEOBOX | User Name: Operator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Operator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\uagqecsvc.exe (Microsoft ® Corporation)
PRC - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Cisco\Cisco HostScan\bin\ciscod.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Symantec\VIP Access Client\VIPAppService.exe (Symantec Corporation)
PRC - C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe (IDT, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Java\jre6\bin\jp2iexp.dll ()
MOD - C:\Program Files\Java\jre6\bin\jp2native.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\WINDOWS\system32\quartz.dll ()
========== Win32 Services (SafeList) ==========
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) – File not found
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (uagqecsvc) – C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\uagqecsvc.exe (Microsoft ® Corporation)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (ciscod.exe) – C:\Program Files\Cisco\Cisco HostScan\bin\ciscod.exe (Cisco Systems, Inc.)
SRV - (VIPAppService) – C:\Program Files\Symantec\VIP Access Client\VIPAppService.exe (Symantec Corporation)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (PLFlash DeviceIoControl Service) – C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (STacSV) – c:\Program Files\IDT\ECSXPV_5762_010208\WDM\stacsv.exe (IDT, Inc.)
========== Driver Services (SafeList) ==========
DRV - (catchme) – File not found
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (acsmux) – C:\WINDOWS\system32\drivers\acsmux.sys (Cisco Systems, Inc.)
DRV - (acsint) – C:\WINDOWS\system32\drivers\acsint.sys (Cisco Systems, Inc.)
DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidEqd) – C:\WINDOWS\system32\drivers\LHidEqd.sys (Logitech, Inc.)
DRV - (LEqdUsb) – C:\WINDOWS\system32\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}) – C:\Program Files\CyberLink\PowerDVD8\000.fcl (CyberLink Corp.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (AtcL001) – C:\WINDOWS\system32\drivers\l151x86.sys (Atheros Communications, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (IDT, Inc.)
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (RTL85n86) – C:\WINDOWS\system32\drivers\RTL85n86.sys (Realtek)
DRV - (AmdTools) – C:\WINDOWS\system32\drivers\AmdTools.sys (AMD, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://us.etrade.com/e/t/user/login
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\CNNSI, = search.sportsillustrated.cnn.com/pages/search.jsp?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Dictionary, = dictionary.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Google, = google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleGroups, = groups-beta.google.com/groups?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleImages, = images.google.com/images?hl=en&lr;=&q;=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GoogleNews, = news.google.com/news?tab=gn&hl;=en&ie;=UTF-8&q;=%s&btnG;=Search+News
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KB, = support.microsoft.com/search/default.aspx?query=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\KBDLL, = support.microsoft.com/dllhelp/default.aspx?dlltype=file&l;=55α=%s&S;=1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Movies, = fandango.com/my_box_office.asp?searchby=2&txtCityZip;=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Thesaurus, = thesaurus.reference.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Weather, = weather.com/weather/local/%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Yahoo, = search.yahoo.com/search?p=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 49
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.496
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/05/15 22:14:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Symantec\VIP Access Client\ [2011/11/15 10:05:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/31 13:07:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/31 13:07:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/11/22 19:44:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/05/15 22:14:40 | 000,000,000 | —D | M]
[2009/11/18 17:46:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Operator\Application Data\Mozilla\Extensions
[2011/12/29 00:47:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\pltn1dws.default\extensions
[2010/08/22 00:47:19 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\pltn1dws.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2011/12/31 10:58:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/12/31 10:58:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\OPERATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\PLTN1DWS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/27 21:17:10 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/06/21 17:39:18 | 000,034,376 | —- | M] () – C:\Program Files\mozilla firefox\plugins\logging.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/27 21:17:07 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/27 21:17:07 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/12/31 00:54:19 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [AttachmentWipermailadc.fmi.com] C:\Documents and Settings\Operator\Forefront UAG Remote Access Agent\mailadcfmicom\exchangena1\AttachmentWiper.exeBatchRun\run.bat ()
O4 - Startup: C:\Documents and Settings\Operator\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Operator\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Operator\Start Menu\Programs\Startup\JMicron Button Manager.lnk = C:\Program Files\JMicron\JMBtnMgr.EXE (JMicron Technology Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33704B0F-9EB7-434B-B752-EA6CFFB87423} http://babyjoancam.viewnetcam.com/JpegInst.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.6.0.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A2A8145-77D0-4161-9819-B56481B30B4B}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{87C853CB-5E40-4847-9422-C7C7EB90F223}: DhcpNameServer = 192.168.10.1 [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1179609-0B0F-4589-9F58-942E0FE88BD0}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/25 17:25:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk /r \??\J:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/31 16:20:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/12/31 13:16:31 | 000,000,000 | —D | C] – C:\ComboFix
[2011/12/31 11:03:25 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Operator\Recent
[2011/12/31 10:58:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/12/31 10:58:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/12/31 10:58:16 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/12/31 10:58:16 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/12/31 10:58:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/12/31 10:58:16 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/12/31 10:56:24 | 000,910,112 | —- | C] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/30 17:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\Wak
[2011/12/30 17:41:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\Myy
[2011/12/30 14:45:17 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/30 13:03:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Application Data\.minecraft
[2011/12/29 01:09:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/12/29 01:01:00 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2011/12/29 00:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Local Settings\Application Data\Temp
[2011/12/29 00:56:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/12/29 00:56:40 | 000,000,000 | —D | C] – C:\Program Files\Google
[2011/12/29 00:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Operator\Local Settings\Application Data\Google
[2011/12/29 00:55:47 | 000,000,000 | —D | C] – C:\Program Files\Downloads
[2011/12/28 18:12:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/12/23 16:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/23 15:25:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/23 15:25:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/31 16:25:14 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/12/31 16:20:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/12/31 16:06:01 | 000,000,890 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/31 15:09:14 | 000,000,394 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On Operator Logon.job
[2011/12/31 14:15:47 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/31 14:15:41 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/31 14:15:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/31 13:14:30 | 004,358,797 | R— | M] (Swearware) – C:\Documents and Settings\Operator\Desktop\ComboFix.exe
[2011/12/31 13:05:22 | 000,270,142 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/31 10:56:23 | 000,910,112 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/31 00:54:19 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/12/30 17:43:34 | 000,017,522 | -HS- | M] () – C:\Documents and Settings\Operator\Local Settings\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 17:43:34 | 000,017,522 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 14:45:37 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/30 13:15:06 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/29 01:09:37 | 000,001,820 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/29 01:09:37 | 000,001,798 | —- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 00:58:53 | 000,000,689 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/28 22:31:01 | 000,000,752 | —- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\iexplore.exe.lnk
[2011/12/28 18:50:52 | 000,000,752 | —- | M] () – C:\Documents and Settings\Operator\Desktop\iexplore.exe.lnk
[2011/12/28 18:26:38 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/28 17:59:16 | 000,017,544 | -HS- | M] () – C:\Documents and Settings\Operator\Local Settings\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/28 17:59:16 | 000,017,544 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/24 12:34:31 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\n6JNdr64.dat
[2011/12/24 12:34:31 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\ssY84kwL.com.b
[2011/12/23 11:54:08 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/12/18 23:35:22 | 000,001,732 | -H– | M] () – C:\Documents and Settings\Operator\My Documents\Default.rdp
[2011/12/18 10:10:33 | 000,083,360 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIRfsClientNP.dll
[2011/12/18 10:10:32 | 000,087,424 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIinit.dll
[2011/12/18 10:10:32 | 000,030,592 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIport.dll
[2011/12/18 10:08:11 | 000,356,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/10 15:24:06 | 000,020,464 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/10 11:43:38 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/12/05 21:55:59 | 000,000,172 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Google.url
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/31 13:05:22 | 000,270,142 | —- | C] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/30 17:41:28 | 000,017,522 | -HS- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/30 17:41:28 | 000,017,522 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0acvb08ox6mn2nsaj30an408524o3j3323il45np56i23
[2011/12/29 01:09:37 | 000,001,820 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/29 01:09:37 | 000,001,798 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/29 00:56:44 | 000,000,890 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 00:56:44 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/28 22:31:01 | 000,000,752 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\iexplore.exe.lnk
[2011/12/28 18:50:52 | 000,000,752 | —- | C] () – C:\Documents and Settings\Operator\Desktop\iexplore.exe.lnk
[2011/12/28 18:26:38 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/24 12:34:31 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\ssY84kwL.com.b
[2011/12/24 10:19:36 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\n6JNdr64.dat
[2011/12/23 15:26:54 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/23 15:13:49 | 000,017,544 | -HS- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/12/23 15:13:49 | 000,017,544 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\cbfaqy7j5cfo4uyi0jiy1e541n7i
[2011/11/24 13:26:42 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/24 12:39:20 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/24 12:39:20 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/24 12:39:20 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/24 12:39:20 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/24 12:39:20 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/21 07:13:48 | 000,139,128 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/07/21 07:13:48 | 000,138,056 | —- | C] () – C:\Documents and Settings\Operator\Application Data\PnkBstrK.sys
[2011/07/21 07:13:23 | 000,215,128 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/07/21 07:13:21 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2011/07/21 07:13:21 | 000,075,064 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/05/15 22:05:56 | 000,205,918 | —- | C] () – C:\WINDOWS\hpoins46.dat
[2011/05/15 22:05:56 | 000,000,601 | —- | C] () – C:\WINDOWS\hpomdl46.dat
[2010/06/11 02:40:10 | 000,000,707 | —- | C] () – C:\Documents and Settings\Operator\Application Data\myMPQ.ini
[2010/02/28 13:40:03 | 000,004,430 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft Excel 97-2003.NOT
[2010/02/28 13:38:17 | 000,038,260 | —- | C] () – C:\Documents and Settings\Operator\Application Data\Microsoft Excel 97-2003.ADR
[2009/12/30 22:00:31 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/21 20:27:20 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/12/21 18:25:29 | 000,043,520 | —- | C] () – C:\Documents and Settings\Operator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/18 13:09:50 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2009/12/18 13:09:49 | 000,196,565 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2009/12/18 13:09:49 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2009/11/26 12:44:05 | 000,078,712 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/18 17:46:12 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/20 13:40:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/08/25 17:53:42 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2008/08/25 17:37:41 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2008/08/25 17:37:33 | 003,107,788 | R— | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/08/25 17:27:04 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/08/25 17:22:36 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/08/25 12:11:03 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/08/25 12:09:58 | 000,356,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/07/16 13:35:28 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/05/26 20:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 20:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/14 02:55:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2007/09/27 09:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/21 16:51:16 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2007/08/21 14:36:12 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2007/06/24 20:14:55 | 000,008,336 | —- | C] () – C:\WINDOWS\UN060501.INI
[2006/12/31 04:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2001/08/23 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 05:00:00 | 000,465,398 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 05:00:00 | 000,079,540 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 05:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/09/25 22:30:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/11/15 10:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cisco
[2011/03/20 11:56:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/02/05 15:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/12/31 00:17:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2011/11/24 12:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2010/02/28 12:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/08/27 12:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/26 12:37:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/30 13:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\.minecraft
[2011/06/04 16:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Audacity
[2011/11/06 11:01:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\AVG
[2011/12/31 13:03:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Dropbox
[2011/02/10 09:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\ICAClient
[2011/05/15 21:21:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Leadertech
[2011/12/31 13:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Myy
[2011/07/20 21:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\SystemRequirementsLab
[2010/03/10 01:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\TechSmith
[2011/09/11 23:22:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Thunderbird
[2011/12/31 11:03:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Wak
[2008/08/25 18:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Windows Desktop Search
[2010/01/01 13:47:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Operator\Application Data\Windows Search
[2011/12/31 15:09:14 | 000,000,394 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup 2011 Integrator Start On Operator Logon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/11/25 15:14:12 | 000,001,024 | —- | M] () – C:\.rnd
[2008/08/25 17:25:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/11/24 12:46:43 | 000,000,339 | —- | M] () – C:\Boot.bak
[2011/12/30 14:45:37 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/12/31 15:09:18 | 000,018,805 | —- | M] () – C:\ComboFix.txt
[2008/08/25 17:25:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/11/24 19:00:37 | 006,430,218 | —- | M] () – C:\immudebug.log
[2008/08/25 17:25:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/08/25 17:25:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 19:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 21:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/31 14:15:29 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/08/25 17:24:54 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/10/21 14:29:40 | 000,320,512 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpfpp101.dll
[2011/12/18 10:10:33 | 000,052,096 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/08/25 12:09:18 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/08/25 12:09:18 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/08/25 12:09:18 | 000,917,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/25 17:25:21 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/08/25 17:29:35 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Operator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/23 16:27:45 | 003,511,776 | —- | M] (Piriform Ltd) – C:\Documents and Settings\Operator\Desktop\ccsetup312.exe
[2011/12/31 13:14:30 | 004,358,797 | R— | M] (Swearware) – C:\Documents and Settings\Operator\Desktop\ComboFix.exe
[2011/12/31 10:56:23 | 000,910,112 | —- | M] (Sun Microsystems, Inc.) – C:\Documents and Settings\Operator\Desktop\jxpiinstall.exe
[2011/12/31 13:05:22 | 000,270,142 | —- | M] () – C:\Documents and Settings\Operator\Desktop\Minecraft.exe
[2011/12/31 16:20:12 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Operator\Desktop\OTL.exe
[2011/11/06 22:01:53 | 002,167,144 | —- | M] (SolidQuest Inc. ) – C:\Documents and Settings\Operator\Desktop\RegTeck_setup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-31 16:56:03
========== Alternate Data Streams ==========
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >