This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Firefox proxy settings keep changing. [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let's try a few things:

  • Type about:config into the address bar of Firefox
  • Click I'll be careful, I promise!
  • In the filter box, type proxy
  • Double-click network.proxy.type, enter 0 for its value, and then hit OK
—-

Tea Timer may be the culprit here. Have you manually gone into Firefox after Tea Timer has been disabled and manually reset the proxy? Here's how:

Open up Firefox
  • go to Tools and select the Options button:
  • Click on the Advanced button then the Network tab then Setttings
  • By default, the No Proxy option should be selected.
  • If it is set to anything else > reset it to No Proxy
  • then click on the OK button at the bottom of the window:
  • Click on the OK button again to close the Options window:
—-

If you think you haven't properly disabled Tea Timer, please uninstall it, reset Firefox to defaults, and then reinstall. Please repeat this for any other anti-virus program or firewall you have running.
network.proxy.type is already set to 0. i have to reset the proxy settings back to no proxy from manual every time i open firefox.
If you haven't already, show hidden files and folders:

  • Show hidden files/folders

    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Yes to confirm.
    • Click OK.
  • user.js

    • Ensure that Firefox is not running
    • Open Notepad (WindowsKey + R to open a run box, then type "notepad")
    • Copy the line inside the code box below…

      user_pref("network.proxy.type", 0);
    • … and paste it into the document within notepad and then go to File > Save As…
    • In the Save As dialog box, navigate to C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\hk5tj3jo.default
    • In "Save as Type", you must select "All Files"
    • For File name, type in user.js and then hit Save
    • Open up Firefox and let me know whether the problem persists
i just went ahead and deleted firefox along with all my previous settings, bookmarks etc. etc. and downloaded it again. The issue seems to be fixed at this time and the proxy settings remain on "use system proxy settings" instead of starting on manual every time. What should I do now?
  • Viewpoint

    I noticed you have Viewpoint Manager Service on your computer. While it is not malware, it is considered foistware because it is installed without the user's consent. I would recommend you remove it. For more information, please go here.

  • Java is out of date

    • Click Start, click Control Panel, and then double-click Add or Remove Programs.
    • Find any instances of "Java" and Remove them.
    • Reboot your computer.
    • Go here for the latest Java release.
    • Under "Java Platform, Standard Edition", Download JRE 7.
    • Accept the license agreement.
    • Download the executable for Windows x86 Offline and save it to your desktop.
    • Double-click jre-7-windows-i586.exe on your desktop and install it.
    • After installing, you can delete jre-7-windows-i586.exe from your desktop.
    • Now let's clear Java's cache.
      • Click Start > Control Panel
      • Double-click the Java icon (you must be in Classic View, which you can switch to on the left tasks pane, if necessary)
      • Under the General tab, click Settings under Temporary Internet Files.
      • Choose to Delete Files.
      • Check all boxes.
      • Click OK.
    • If you weren't prompted to reboot, please do so.
  • OTL

    • Launch OTL.exe.
    • Check the following.
      • Scan all users.
      • Standard Output.
      • Lop check.
      • Purity check.
    • Under Extra Registry section, select Use SafeList
    • Click the Run Scan button and wait for the scan to finish (usually about 10-15 minutes).
    • When finished it will produce a log.
      • OTL.txt (open on your desktop)
    • Please post me this log
—-

Are there any outstanding issues?
OTL logfile created on: 1/17/2012 11:15:58 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.73 Mb Total Physical Memory | 512.56 Mb Available Physical Memory | 50.51% Memory free
1.88 Gb Paging File | 1.44 Gb Available in Paging File | 76.65% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 21.47 Gb Free Space | 57.61% Space Free | Partition Type: NTFS

Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/17 23:14:37 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\desktop\OTL.exe
PRC - [2012/01/17 23:02:48 | 000,161,664 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011/12/21 01:24:51 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINNT\explorer.exe
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINNT\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/12/21 01:24:51 | 002,124,760 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/11/28 21:24:24 | 008,527,008 | —- | M] () – C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
MOD - [2008/04/13 18:11:59 | 000,014,336 | —- | M] () – C:\WINNT\system32\msdmo.dll
MOD - [2008/04/13 18:11:51 | 000,059,904 | —- | M] () – C:\WINNT\system32\devenum.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (wuauserv)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - File not found [Disabled | Stopped] – – (AOLService)
SRV - File not found [Disabled | Stopped] – – (AOL ACS)
SRV - File not found [Disabled | Stopped] – – (ACDaemon)
SRV - File not found [Disabled | Stopped] – – (aawservice)
SRV - [2012/01/17 23:02:48 | 000,161,664 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/05/20 14:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2009/11/29 21:24:28 | 000,603,904 | —- | M] (TuneUp Software) [Disabled | Stopped] – C:\WINNT\system32\TUProgSt.exe – (TuneUp.ProgramStatisticsSvc)
SRV - [2009/01/27 12:26:42 | 000,398,336 | —- | M] (Ares Development Group) [On_Demand | Stopped] – C:\Program Files\Ares\chatServer.exe – (AresChatServer)
SRV - [2008/11/09 14:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [On_Demand | Stopped] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2004/10/15 16:24:42 | 000,206,048 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINNT\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - [2010/05/20 14:27:24 | 000,030,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\nx6000.sys – (MSHUSBVideo)
DRV - [2010/03/15 20:28:27 | 000,095,024 | —- | M] (Sunbelt Software) [Kernel | System | Running] – C:\WINNT\system32\drivers\SBREDrv.sys – (SBRE)
DRV - [2010/02/11 06:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\WINNT\system32\drivers\tcpip6.sys – (Tcpip6)
DRV - [2007/10/11 05:20:56 | 000,000,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\atwpkt2.sys – (ATWPKT2)
DRV - [2007/10/02 16:45:04 | 004,109,376 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\alcxwdm.sys – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/03 23:41:39 | 000,013,776 | —- | M] (Smart Link) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\recagent.sys – (RecAgent)
DRV - [2004/05/13 18:01:23 | 000,028,352 | —- | M] (MusicMatch, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\System32\drivers\MxlW2k.sys – (MxlW2k)
DRV - [2003/05/20 12:23:10 | 000,210,592 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\mtlmnt5.sys – (Mtlmnt5)
DRV - [2003/05/20 12:21:44 | 001,295,472 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\mtlstrm.sys – (Mtlstrm)
DRV - [2003/05/20 12:19:24 | 000,085,688 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\slnthal.sys – (SlNtHal)
DRV - [2003/05/19 14:30:02 | 000,169,120 | —- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINNT\system32\drivers\ntmtlfax.sys – (NtMtlFax)
DRV - [2003/05/13 09:58:34 | 000,521,408 | —- | M] ( ) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slntamr.sys – (Slntamr)
DRV - [2003/01/16 23:19:32 | 000,039,348 | —- | M] (Vireo Software) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\slwdmsup.sys – (SlWdmSup)
DRV - [2003/01/10 16:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINNT\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/09/10 05:06:00 | 000,025,244 | —- | M] (Adaptec) [Kernel | Auto | Running] – C:\WINNT\System32\drivers\aspi32.sys – (Aspi32)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://my.aol.com/?ncid=aolmas00050000000002 [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINNT\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@yverinfo.yahoo.com/YahooVersionInfoPlugin;version=1.0.0.1: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/17 21:33:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/17 23:04:20 | 000,000,000 | —D | M]

[2012/01/17 21:34:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2012/01/17 21:59:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\qaydy8da.default\extensions
[2012/01/17 21:33:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\QAYDY8DA.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\QAYDY8DA.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\QAYDY8DA.DEFAULT\EXTENSIONS\[removed]
[2011/12/21 01:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/12/20 22:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/20 22:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: AOL Media Playback Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/01/10 18:19:38 | 000,000,027 | —- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINNT\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINNT\System32\narrator.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1199318644546 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire http://download.games.yahoo.com/games/clients/y/mjst4_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC7BC81B-A70D-4700-8CBA-E1D77637A0FA}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINNT\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/17 23:14:28 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/17 23:12:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts
[2012/01/17 23:06:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Sun
[2012/01/17 23:04:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/01/17 23:04:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/01/17 23:04:20 | 000,637,848 | —- | C] (Oracle Corporation) – C:\WINNT\System32\npdeployJava1.dll
[2012/01/17 23:04:20 | 000,567,184 | —- | C] (Oracle Corporation) – C:\WINNT\System32\deployJava1.dll
[2012/01/17 23:04:20 | 000,223,112 | —- | C] (Oracle Corporation) – C:\WINNT\System32\javaws.exe
[2012/01/17 23:04:20 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINNT\System32\javaw.exe
[2012/01/17 23:04:20 | 000,173,960 | —- | C] (Oracle Corporation) – C:\WINNT\System32\java.exe
[2012/01/17 23:04:20 | 000,141,312 | —- | C] (Oracle Corporation) – C:\WINNT\System32\javacpl.cpl
[2012/01/17 20:18:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/01/16 23:39:39 | 000,000,000 | —D | C] – C:\_OTL
[2012/01/13 22:23:04 | 000,000,000 | —D | C] – C:\c1d7fc001171605dddde
[2012/01/13 21:15:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Aunt Wanda
[2012/01/13 17:32:39 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/01/09 18:04:49 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/01/09 18:01:05 | 000,518,144 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2012/01/09 18:01:05 | 000,406,528 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2012/01/09 18:01:05 | 000,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2012/01/09 18:01:05 | 000,060,416 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2012/01/09 18:00:02 | 000,000,000 | —D | C] – C:\WINNT\ERDNT
[2012/01/09 17:59:53 | 000,000,000 | —D | C] – C:\Qoobox
[2012/01/08 21:58:32 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/01/04 21:37:25 | 000,222,080 | —- | C] (Microsoft Corporation) – C:\WINNT\System32\MpSigStub.exe
[2012/01/03 04:40:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/01/03 04:36:11 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2008/06/01 17:56:09 | 001,030,144 | —- | C] (Microsoft Corporation) – C:\Program Files\dbghelp.dll
[2008/06/01 17:56:09 | 000,626,688 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcr80.dll
[2008/06/01 17:56:09 | 000,548,864 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcp80.dll
[2008/06/01 17:56:09 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Program Files\msvcm80.dll
[2003/07/01 19:02:45 | 000,014,976 | —- | C] ( ) – C:\WINNT\System32\drivers\winddx.sys
[1979/12/31 23:00:00 | 001,295,472 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlstrm.sys
[1979/12/31 23:00:00 | 000,521,408 | —- | C] ( ) – C:\WINNT\System32\drivers\slntamr.sys
[1979/12/31 23:00:00 | 000,210,592 | —- | C] ( ) – C:\WINNT\System32\drivers\mtlmnt5.sys
[1979/12/31 23:00:00 | 000,169,120 | —- | C] ( ) – C:\WINNT\System32\drivers\ntmtlfax.sys
[1979/12/31 23:00:00 | 000,085,688 | —- | C] ( ) – C:\WINNT\System32\drivers\slnthal.sys
[1979/12/31 23:00:00 | 000,045,056 | —- | C] ( ) – C:\WINNT\System32\slserv.exe

========== Files - Modified Within 30 Days ==========

[2012/01/17 23:26:08 | 000,000,390 | -H– | M] () – C:\WINNT\tasks\MpIdleTask.job
[2012/01/17 23:17:21 | 000,000,978 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003UA.job
[2012/01/17 23:14:59 | 000,000,424 | -H– | M] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/17 23:14:37 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/01/17 23:11:51 | 000,001,158 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2012/01/17 23:09:16 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2012/01/17 23:02:44 | 000,223,112 | —- | M] (Oracle Corporation) – C:\WINNT\System32\javaws.exe
[2012/01/17 23:02:43 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINNT\System32\javaw.exe
[2012/01/17 23:02:42 | 000,173,960 | —- | M] (Oracle Corporation) – C:\WINNT\System32\java.exe
[2012/01/17 23:02:42 | 000,141,312 | —- | M] (Oracle Corporation) – C:\WINNT\System32\javacpl.cpl
[2012/01/17 23:02:41 | 000,637,848 | —- | M] (Oracle Corporation) – C:\WINNT\System32\npdeployJava1.dll
[2012/01/17 23:02:40 | 000,567,184 | —- | M] (Oracle Corporation) – C:\WINNT\System32\deployJava1.dll
[2012/01/17 21:33:52 | 000,000,742 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/17 20:19:45 | 000,001,945 | —- | M] () – C:\WINNT\epplauncher.mif
[2012/01/17 04:17:00 | 000,000,926 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-4096060120-124127034-945509873-1003Core.job
[2012/01/10 18:19:38 | 000,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2012/01/09 18:05:00 | 000,000,323 | RHS- | M] () – C:\boot.ini
[2012/01/07 05:22:05 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/07 05:22:04 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2012/01/04 22:00:56 | 000,000,207 | —- | M] () – C:\Boot.bak
[2012/01/03 13:40:54 | 000,433,414 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2012/01/03 13:40:54 | 000,068,244 | —- | M] () – C:\WINNT\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2012/01/17 21:33:52 | 000,000,742 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/17 21:33:51 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/01/17 20:40:51 | 000,000,390 | -H– | C] () – C:\WINNT\tasks\MpIdleTask.job
[2012/01/17 20:24:04 | 000,000,424 | -H– | C] () – C:\WINNT\tasks\MP Scheduled Scan.job
[2012/01/17 20:18:36 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/01/10 23:21:23 | 000,002,307 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/01/09 18:05:00 | 000,000,207 | —- | C] () – C:\Boot.bak
[2012/01/09 18:04:56 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/01/09 18:01:05 | 000,256,000 | —- | C] () – C:\WINNT\PEV.exe
[2012/01/09 18:01:05 | 000,208,896 | —- | C] () – C:\WINNT\MBR.exe
[2012/01/09 18:01:05 | 000,098,816 | —- | C] () – C:\WINNT\sed.exe
[2012/01/09 18:01:05 | 000,080,412 | —- | C] () – C:\WINNT\grep.exe
[2012/01/09 18:01:05 | 000,068,096 | —- | C] () – C:\WINNT\zip.exe
[2012/01/04 21:33:04 | 000,001,945 | —- | C] () – C:\WINNT\epplauncher.mif
[2010/07/31 15:14:26 | 000,212,400 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/04/30 19:37:32 | 000,256,368 | —- | C] () – C:\Program Files\WinRAR.chm
[2010/04/30 19:37:32 | 000,141,824 | —- | C] () – C:\Program Files\RarExt.dll
[2010/04/30 19:37:32 | 000,052,224 | —- | C] () – C:\Program Files\RarExt64.dll
[2010/04/30 19:37:32 | 000,000,495 | —- | C] () – C:\Program Files\File_Id.diz
[2010/01/09 21:27:08 | 000,000,056 | -H– | C] () – C:\WINNT\System32\ezsidmv.dat
[2008/08/31 19:13:08 | 000,073,220 | —- | C] () – C:\WINNT\System32\EPPICPrinterDB.dat
[2008/08/31 19:13:08 | 000,000,097 | —- | C] () – C:\WINNT\System32\PICSDK.ini
[2008/08/31 19:13:07 | 000,031,053 | —- | C] () – C:\WINNT\System32\EPPICPattern131.dat
[2008/08/31 19:13:07 | 000,029,114 | —- | C] () – C:\WINNT\System32\EPPICPattern1.dat
[2008/08/31 19:13:07 | 000,027,417 | —- | C] () – C:\WINNT\System32\EPPICPattern121.dat
[2008/08/31 19:13:07 | 000,021,021 | —- | C] () – C:\WINNT\System32\EPPICPattern3.dat
[2008/08/31 19:13:07 | 000,015,670 | —- | C] () – C:\WINNT\System32\EPPICPattern5.dat
[2008/08/31 19:13:07 | 000,013,280 | —- | C] () – C:\WINNT\System32\EPPICPattern2.dat
[2008/08/31 19:13:07 | 000,010,673 | —- | C] () – C:\WINNT\System32\EPPICPattern4.dat
[2008/08/31 19:13:07 | 000,004,943 | —- | C] () – C:\WINNT\System32\EPPICPattern6.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_PT.dat
[2008/08/31 19:13:07 | 000,001,140 | —- | C] () – C:\WINNT\System32\EPPICPresetData_BP.dat
[2008/08/31 19:13:07 | 000,001,137 | —- | C] () – C:\WINNT\System32\EPPICPresetData_ES.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_FR.dat
[2008/08/31 19:13:07 | 000,001,130 | —- | C] () – C:\WINNT\System32\EPPICPresetData_CF.dat
[2008/08/31 19:13:07 | 000,001,104 | —- | C] () – C:\WINNT\System32\EPPICPresetData_EN.dat
[2008/08/31 19:11:38 | 000,000,044 | —- | C] () – C:\WINNT\EPSNX400.ini
[2008/06/19 23:32:00 | 000,001,160 | —- | C] () – C:\WINNT\mozver.dat
[2008/06/02 17:23:38 | 000,021,312 | —- | C] () – C:\WINNT\choice.exe
[2008/06/01 17:56:28 | 000,018,464 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox.dat
[2008/06/01 17:56:28 | 000,001,056 | -HS- | C] () – C:\WINNT\System32\drivers\fidbox2.dat
[2008/05/16 13:59:02 | 000,000,374 | —- | C] () – C:\WINNT\wininit.ini
[2008/03/11 16:20:45 | 000,000,121 | —- | C] () – C:\WINNT\winzipsp.ini
[2008/02/08 02:00:14 | 000,000,080 | —- | C] () – C:\WINNT\SuperUtil.ini
[2008/02/08 01:51:36 | 000,000,000 | —- | C] () – C:\WINNT\System32\suupdate.dat
[2008/02/08 01:51:35 | 000,000,000 | —- | C] () – C:\WINNT\System32\mssurun.dat
[2007/12/05 03:08:52 | 001,446,464 | —- | C] () – C:\Program Files\Silverlight.exe
[2007/10/20 19:08:23 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys
[2007/10/20 18:25:18 | 000,049,152 | —- | C] () – C:\WINNT\System32\ChCfg.exe
[2007/10/20 18:23:14 | 000,147,456 | —- | C] () – C:\WINNT\System32\RtlCPAPI.dll
[2007/10/18 00:00:21 | 000,055,949 | —- | C] () – C:\WINNT\System32\x264-uninstall.exe
[2007/10/11 05:20:56 | 000,000,000 | —- | C] () – C:\WINNT\System32\drivers\atwpkt2.sys
[2007/03/02 16:03:53 | 000,001,763 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/12 22:02:29 | 000,000,116 | —- | C] () – C:\WINNT\NeroDigital.ini
[2007/01/15 01:25:20 | 000,000,079 | —- | C] () – C:\WINNT\xptools.ini
[2007/01/15 01:21:58 | 000,000,120 | —- | C] () – C:\WINNT\System32\bn.dll
[2007/01/08 18:20:12 | 000,014,848 | —- | C] () – C:\WINNT\System32\BASSMOD.dll
[2006/12/18 03:43:12 | 000,000,022 | —- | C] () – C:\Program Files\zipnew.dat
[2006/12/18 03:43:12 | 000,000,020 | —- | C] () – C:\Program Files\rarnew.dat
[2006/12/18 03:42:56 | 001,039,360 | —- | C] () – C:\Program Files\WinRAR.exe
[2006/12/18 03:42:56 | 000,378,880 | —- | C] () – C:\Program Files\Rar.exe
[2006/12/18 03:42:56 | 000,246,272 | —- | C] () – C:\Program Files\UnRAR.exe
[2006/12/18 03:42:56 | 000,092,672 | —- | C] () – C:\Program Files\Default.SFX
[2006/12/18 03:42:56 | 000,074,240 | —- | C] () – C:\Program Files\Zip.SFX
[2006/12/18 03:42:56 | 000,069,632 | —- | C] () – C:\Program Files\WinCon.SFX
[2006/12/18 03:42:56 | 000,045,056 | —- | C] () – C:\Program Files\RarExtLoader.exe
[2006/12/18 03:42:55 | 000,003,271 | —- | C] () – C:\Program Files\Order.htm
[2006/12/18 03:42:55 | 000,001,088 | —- | C] () – C:\Program Files\RarFiles.lst
[2006/12/18 03:42:55 | 000,001,063 | —- | C] () – C:\Program Files\Descript.ion
[2006/12/18 03:42:55 | 000,000,639 | —- | C] () – C:\Program Files\Uninstall.lst
[2006/11/07 20:52:05 | 000,000,044 | —- | C] () – C:\WINNT\liveup.ini
[2006/08/12 22:09:45 | 000,004,096 | —- | C] () – C:\WINNT\d3dx.dat
[2006/07/16 17:08:08 | 000,000,627 | —- | C] () – C:\Program Files\playlist.xml
[2006/03/23 19:13:53 | 000,052,490 | —- | C] () – C:\WINNT\DcArt32presets.ini
[2006/03/05 01:46:11 | 000,001,610 | —- | C] () – C:\WINNT\GPlrLanc.dat
[2005/12/13 17:30:33 | 000,122,535 | —- | C] () – C:\WINNT\RSEDNClientUninstaller.exe
[2005/11/22 00:41:22 | 000,000,784 | —- | C] () – C:\Documents and Settings\Owner\Application Data\mpauth.dat
[2005/09/26 18:27:37 | 000,000,028 | —- | C] () – C:\WINNT\Systems.ini
[2005/08/31 18:05:37 | 000,000,075 | —- | C] () – C:\WINNT\System32\sysogg.dll
[2005/07/09 06:00:53 | 000,000,008 | —- | C] () – C:\WINNT\System32\wtl.dat
[2005/07/09 05:25:40 | 000,000,004 | —- | C] () – C:\WINNT\System32\micr0st.dll
[2005/07/09 05:16:13 | 000,129,024 | —- | C] () – C:\WINNT\UNWISE.EXE
[2005/05/20 21:35:09 | 000,000,056 | RHS- | C] () – C:\WINNT\System32\566097EC98.sys
[2005/03/21 20:59:40 | 000,000,715 | —- | C] () – C:\WINNT\aolback.exe.lnk
[2005/03/21 20:53:31 | 000,000,335 | —- | C] () – C:\WINNT\nsreg.dat
[2005/02/18 16:53:48 | 000,000,000 | —- | C] () – C:\WINNT\impborl.dll
[2005/02/08 14:42:45 | 000,000,092 | —- | C] () – C:\Program Files\play.rbn.rm&proto;=rtsp
[2005/01/13 22:23:53 | 000,001,131 | —- | C] () – C:\WINNT\System32\vh.dat
[2005/01/04 16:19:13 | 000,001,100 | —- | C] () – C:\WINNT\dhstatus.dat
[2004/12/15 08:22:09 | 000,149,504 | —- | C] () – C:\WINNT\System32\UNWISE.EXE
[2004/10/31 18:32:17 | 000,001,100 | —- | C] () – C:\WINNT\checkip.dat
[2004/10/31 18:29:50 | 000,001,393 | —- | C] () – C:\WINNT\ipconfig.dat
[2004/09/25 22:23:36 | 000,004,569 | —- | C] () – C:\WINNT\System32\secupd.dat
[2004/08/29 21:52:13 | 000,131,072 | —- | C] () – C:\WINNT\System32\SpoonUninstall.exe
[2004/08/25 17:53:06 | 000,000,032 | —- | C] () – C:\WINNT\easecdripper.ini
[2004/08/25 17:28:05 | 000,003,082 | —- | C] () – C:\WINNT\System32\affv6628p4now.sys
[2004/08/17 01:56:38 | 000,122,880 | —- | C] () – C:\WINNT\UnGins.exe
[2004/08/13 03:53:41 | 000,000,014 | —- | C] () – C:\WINNT\msoffice.ini
[2004/07/21 21:54:24 | 000,001,125 | —- | C] () – C:\WINNT\winamp.ini
[2004/05/26 14:42:25 | 000,000,048 | —- | C] () – C:\WINNT\upth.ini
[2004/05/26 14:42:25 | 000,000,028 | —- | C] () – C:\WINNT\atid.ini
[2004/02/11 07:50:12 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2004/02/07 14:41:59 | 000,082,944 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/22 12:00:28 | 000,012,635 | —- | C] () – C:\WINNT\System32\DAntivirus.ini
[2003/10/25 14:37:35 | 000,067,857 | —- | C] () – C:\WINNT\cdPlayer.ini
[2003/10/22 10:05:08 | 000,000,030 | —- | C] () – C:\WINNT\Morphexe.INI
[2003/10/08 13:34:26 | 000,121,440 | —- | C] () – C:\WINNT\System32\MSDRMCtrl.dll
[2003/08/27 18:06:58 | 000,000,027 | —- | C] () – C:\WINNT\UP9ASP.INI
[2003/08/27 17:33:30 | 000,006,550 | —- | C] () – C:\WINNT\jautoexp.dat
[2003/08/27 16:45:53 | 000,065,536 | —- | C] () – C:\WINNT\System32\YCRWin32.dll
[2003/08/27 14:24:03 | 000,000,242 | —- | C] () – C:\WINNT\qwimp.ini
[2003/08/26 16:10:20 | 000,000,120 | —- | C] () – C:\WINNT\SIERRA.INI
[2003/08/23 13:49:22 | 000,000,396 | —- | C] () – C:\WINNT\intuprof.ini
[2003/08/23 13:48:46 | 000,000,880 | —- | C] () – C:\WINNT\QUICKEN.INI
[2003/08/22 20:05:57 | 000,002,241 | —- | C] () – C:\WINNT\hpdj5600.ini
[2003/08/22 20:05:25 | 000,000,414 | —- | C] () – C:\WINNT\hpbvspst.ini
[2003/07/16 14:22:18 | 000,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINNT\patchw32.dll
[2003/07/01 19:23:27 | 000,000,000 | —- | C] () – C:\WINNT\System32\a3d.dll
[2003/07/01 19:10:07 | 000,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2003/07/01 19:07:33 | 000,282,624 | —- | C] () – C:\WINNT\System32\PCDrSystemInformation.dll
[2003/07/01 19:05:00 | 000,094,208 | —- | C] () – C:\WINNT\System32\PCDrKernelModeServices.dll
[2003/07/01 19:05:00 | 000,077,824 | —- | C] () – C:\WINNT\System32\ProgressTrace.dll
[2003/07/01 19:03:46 | 000,000,561 | —- | C] () – C:\WINNT\System32\OEMINFO.INI
[2003/07/01 19:02:45 | 000,466,944 | —- | C] () – C:\WINNT\System32\SLLights.dll
[2003/07/01 19:02:45 | 000,376,832 | —- | C] () – C:\WINNT\System32\slmh.exe
[2003/07/01 19:02:45 | 000,167,936 | —- | C] () – C:\WINNT\System32\minirec.exe
[2003/07/01 19:02:45 | 000,151,552 | —- | C] () – C:\WINNT\System32\amr_cpl.dll
[2003/07/01 19:02:45 | 000,061,440 | —- | C] () – C:\WINNT\SmCfg.exe
[2003/05/16 11:56:01 | 000,000,770 | —- | C] () – C:\WINNT\orun32.ini
[2003/05/16 10:34:34 | 000,002,048 | –S- | C] () – C:\WINNT\bootstat.dat
[2003/05/16 10:26:45 | 000,021,640 | —- | C] () – C:\WINNT\System32\emptyregdb.dat
[2003/05/16 10:20:03 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/05/16 10:18:53 | 000,221,632 | —- | C] () – C:\WINNT\System32\FNTCACHE.DAT
[2003/03/27 15:28:44 | 000,004,955 | —- | C] () – C:\WINNT\System32\DProg.ini
[2002/10/15 16:54:04 | 000,153,088 | —- | C] () – C:\WINNT\System32\unrar.dll
[2002/10/06 12:42:58 | 000,237,568 | —- | C] () – C:\WINNT\System32\OggDS.dll
[2002/10/04 17:04:26 | 000,921,600 | —- | C] () – C:\WINNT\System32\VorbisEnc.dll
[2002/10/04 17:04:26 | 000,188,416 | —- | C] () – C:\WINNT\System32\vorbis.dll
[2002/10/04 17:04:18 | 000,045,056 | —- | C] () – C:\WINNT\System32\ogg.dll
[2002/09/06 10:36:16 | 000,233,472 | —- | C] () – C:\WINNT\System32\lame_enc.dll
[2002/05/15 18:38:40 | 000,091,136 | —- | C] () – C:\WINNT\System32\mp4fil32.dll
[2002/05/04 08:19:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\avisynthEx.dll
[2002/04/19 09:23:26 | 000,106,137 | —- | C] () – C:\WINNT\System32\libpostproc.dll
[2001/08/29 18:57:40 | 000,155,648 | —- | C] () – C:\WINNT\System32\addurl41.DLL
[2001/07/10 13:43:16 | 000,018,432 | —- | C] () – C:\WINNT\System32\winwatch.DLL
[2001/06/22 06:06:02 | 000,167,936 | —- | C] () – C:\WINNT\System32\MPEG2DEC.dll
[2000/09/08 16:53:50 | 000,073,839 | —- | C] () – C:\WINNT\System32\KodakOneTouch.dll
[1979/12/31 23:00:00 | 013,107,200 | —- | C] () – C:\WINNT\System32\oembios.bin
[1979/12/31 23:00:00 | 000,673,088 | —- | C] () – C:\WINNT\System32\mlang.dat
[1979/12/31 23:00:00 | 000,433,414 | —- | C] () – C:\WINNT\System32\perfh009.dat
[1979/12/31 23:00:00 | 000,272,128 | —- | C] () – C:\WINNT\System32\perfi009.dat
[1979/12/31 23:00:00 | 000,218,003 | —- | C] () – C:\WINNT\System32\dssec.dat
[1979/12/31 23:00:00 | 000,188,416 | —- | C] () – C:\WINNT\System32\slextspk.dll
[1979/12/31 23:00:00 | 000,159,744 | —- | C] () – C:\WINNT\System32\SLGen.dll
[1979/12/31 23:00:00 | 000,068,244 | —- | C] () – C:\WINNT\System32\perfc009.dat
[1979/12/31 23:00:00 | 000,049,152 | —- | C] () – C:\WINNT\System32\coinst.dll
[1979/12/31 23:00:00 | 000,046,258 | —- | C] () – C:\WINNT\System32\mib.bin
[1979/12/31 23:00:00 | 000,028,626 | —- | C] () – C:\WINNT\System32\perfd009.dat
[1979/12/31 23:00:00 | 000,024,576 | —- | C] () – C:\WINNT\slrundll.exe
[1979/12/31 23:00:00 | 000,005,114 | —- | C] () – C:\WINNT\System32\oembios.dat
[1979/12/31 23:00:00 | 000,001,804 | —- | C] () – C:\WINNT\System32\dcache.bin
[1979/12/31 23:00:00 | 000,000,741 | —- | C] () – C:\WINNT\System32\noise.dat

========== LOP Check ==========

[2010/06/11 18:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Applications
[2010/07/21 19:57:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/08/31 21:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2007/01/06 14:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/08/09 17:00:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/05/10 22:09:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2009/12/07 18:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2010/07/07 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/11/06 19:22:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/01/03 05:06:09 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2009/10/18 21:27:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/07 18:04:51 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2003/07/01 19:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\InterTrust
[2009/12/07 19:00:01 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\TuneUp Software
[2007/01/04 23:35:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Azureus
[2010/06/21 16:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DC++
[2008/09/05 16:57:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eBookPro6
[2010/07/07 21:12:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GlarySoft
[2003/08/05 22:50:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/08/31 21:25:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leader Technologies
[2008/08/31 19:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2010/02/16 23:56:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\minimem
[2011/09/05 15:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/05/09 07:48:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCToolsFirewallPlus
[2008/08/15 02:17:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PhotoParade
[2009/11/28 20:36:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Playrix Entertainment
[2009/10/19 00:35:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SharePod
[2009/01/04 23:43:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skinux
[2009/05/02 11:38:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Skunk Studios
[2011/05/09 07:47:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spam Monitor
[2009/11/29 21:02:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sudden Games
[2009/04/15 01:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Systweak
[2009/09/26 16:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TikisLab
[2005/12/15 03:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuneUp Software
[2008/02/12 04:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Uniblue
[2011/06/29 14:26:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wal-Mart Digital Photo Viewer
[2007/10/07 11:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens
[2006/08/12 22:14:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Wildfire
[2012/01/17 23:14:59 | 000,000,424 | -H– | M] () – C:\WINNT\Tasks\MP Scheduled Scan.job
[2012/01/17 23:26:08 | 000,000,390 | -H– | M] () – C:\WINNT\Tasks\MpIdleTask.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Program Files\play.rbn.rm&proto;=rtsp:SummaryInformation

< End of report >
The OTL scan also created this Extras.Txt log too?




OTL Extras logfile created on: 1/17/2012 11:15:58 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.73 Mb Total Physical Memory | 512.56 Mb Available Physical Memory | 50.51% Memory free
1.88 Gb Paging File | 1.44 Gb Available in Paging File | 76.65% Paging File free
Paging file location(s): C:\pagefile.sys 1000 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 21.47 Gb Free Space | 57.61% Space Free | Partition Type: NTFS

Computer Name: YOUR-3B54ED6EDD | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2234:TCP" = 2234:TCP:*:Enabled:Soulseek
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"9420:TCP" = 9420:TCP:*:Enabled:RSP
"1035:TCP" = 1035:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application – (www.sopcast.com)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys" = C:\Documents and Settings\Owner\Application Data\PnkBstrK.sys:*:Enabled:PnkBstrK.sys – ()
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares – (Ares Development Group)
"C:\Program Files\SoulseekNS\slsk.exe" = C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek – ()
"C:\WINNT\system32\spool\drivers\w32x86\3\E_DUPA30.EXE" = C:\WINNT\system32\spool\drivers\w32x86\3\E_DUPA30.EXE:*:Enabled:EPSON Driver Update – (SEIKO EPSON CORPORATION)
"C:\WINNT\system32\mmc.exe" = C:\WINNT\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver – (www.sopcast.com)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1CB92574-96F2-467B-B793-5CEB35C40C29}" = Image Resizer Powertoy for Windows XP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217002FF}" = Java™ 7 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5FC7AB5C-61FC-42DF-A923-5139BCF10D42}" = Microsoft LifeCam
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7169B8E4-2632-46B1-AA5F-167CB5FE5029}" = Symantec Network Drivers Update
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7EE9DE0D-9228-4C33-B80E-FDD1773600DF}" = Microsoft Works Suite Add-in for Microsoft Word
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management client
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Ares" = Ares 2.1.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"EPSON Scanner" = EPSON Scan
"EPSON Stylus NX400 Series" = EPSON Stylus NX400 Series Printer Uninstall
"hp print screen utility" = hp print screen utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InterActual Player" = InterActual Player
"IrfanView" = IrfanView (remove only)
"LTCM Client" = LTCM Client
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoParade.exe" = PhotoParade Player
"Portraits" = Portraits Screen Saver
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 12.0" = RealPlayer
"RSNet EDN" = Red Swoosh EDN Client (lol remove only)
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON NX400 User's Guide
"SLAMRMO" = Smart Link 56K Modem
"SopCast" = SopCast 3.2.4
"Soulseek2" = SoulSeek 157 NS 13c
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"Works2003Setup" = Microsoft Works 2003 Setup Launcher
"X264 H.264/AVC Video Codec" = X264 H.264/AVC Video Codec (remove only)
"Yahoo! Software Update" = Yahoo! Software Update
"yBook_is1" = yBook

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-4096060120-124127034-945509873-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/21/2011 1:44:31 AM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

Error - 2/21/2011 1:44:33 AM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/25/2011 10:54:55 PM | Computer Name = YOUR-3B54ED6EDD | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 2/25/2011 10:55:30 PM | Computer Name = YOUR-3B54ED6EDD | Source = Application Error | ID = 1000
Description = Faulting application applesyncnotifier.exe, version 1.6.72.0, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.

[ System Events ]
Error - 1/18/2012 12:48:46 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/18/2012 12:48:46 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 1/18/2012 12:51:09 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/18/2012 12:51:09 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%126

Error - 1/18/2012 12:52:31 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7022
Description = The MSCamSvc service hung on starting.

Error - 1/18/2012 12:52:31 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SuperMounter TfFsMon TFSysMon

Error - 1/18/2012 1:09:35 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2

Error - 1/18/2012 1:09:35 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%126

Error - 1/18/2012 1:10:58 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7022
Description = The MSCamSvc service hung on starting.

Error - 1/18/2012 1:10:58 AM | Computer Name = YOUR-3B54ED6EDD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SuperMounter TfFsMon TFSysMon

[ TuneUp Events ]
Error - 2/12/2010 8:59:58 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/16/2010 12:42:08 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/16/2010 12:45:32 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/17/2010 2:03:32 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/17/2010 10:23:36 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 2/28/2010 9:07:54 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 3/2/2010 4:58:56 PM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 4/18/2010 2:45:02 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:45:02', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','3340',0)

Error - 4/18/2010 2:47:06 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:47:06', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','3080',0)

Error - 4/18/2010 2:50:22 AM | Computer Name = YOUR-3B54ED6EDD | Source = TuneUp Program Statistics | ID = 131840
Description = SQL Error: near "anti": syntax error; when executing SQL: INSERT INTO
ActiveApps (Started, Exe, ProcID, Resumed) VALUES ('2010-04-18 01:50:22', '\device\harddiskvolume1\program
files\malwarebytes' anti-malware\mbam.exe','2620',0)


< End of report >
Hi WyandotteWyno,

I deem your system ALL-CLEAN! :thumbup: However, given one of the infections was a backdoor trojan, I still strongly urge you to change any passwords you use. As I mentioned earlier, there is no guarantee with this type of infection that your computer will be clean, even if the logs appear to indicate otherwise.

Please carry out the following clean-up procedure before departing and post one last reply confirming your machine is in proper working order so that we may close the thread.

  • Uninstalling ComboFix

    • Click Start > Run (or WindowsKey + R)
    • In the Run box, type combofix /uninstall (there is a space between "combofix" and "/uninstall") and then click OK.
    • A message will pop up shortly after confirming its removal.
  • OTL Clean-Up

    • Start OTL.exe.
    • Close all other programs apart from OTL as this step will require a reboot.
    • On the OTL main screen, press the CLEANUP button.
    • Say Yes to the prompt and then allow the program to reboot your computer.
  • Adobe Reader is out of date

    The latest version of Adobe Reader can be downloaded here.

  • Other information you should know before you leave:

    SpywareBlaster
    • If you use Internet Explorer, SpywareBlaster provides excellent additional protection.
    • SpywareBlaster prevents the installation of ActiveX-based spyware and other potentially unwanted programs.
    • Download it for free here.
    Web of Trust
    • WOT is a browsing tool that helps you determine the safety of unknown websites.
    • It places color-coded symbols next to URLs.
    • Green - Go
    • Yellow - Caution
    • Red - Stop
  • You can download it here.
Secunia Online Software Inspector
  • This is a nice little Java applet that will determine if any software on your computer is out of date.
  • Check it out here.
Other tips
  • Please go here for more valuable security tips.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI