Exploit:JAVA Detected by MSE [Solved]
33 min read
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
We’ll run some more scans to be sure there isn’t anything else lurkingDo I need to do more
Usually from having outdated programs installed.how did I get them?
===================================================
Download and run OTL
- download OTL to your desktop.
- double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- when the window appears, underneath Output at the top change it to Minimal Output.
- check the boxes beside LOP Check and Purity Check.
- under Custom Scan paste this in
netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
%appdata%\Microsoft\Windows\Start Menu\*.* /s
%programdata%\Microsoft\Windows\Start Menu\*.* /s
- click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
- when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- you may need two posts to fit them both in.
Run aswMBR
- download aswMBR.exe to your desktop.
- double click the aswMBR.exe to run it
- if asked, accept the AVAST virus definition download
- click the "Scan" button to start scan
- on completion of the scan click Save log, save it to your desktop and post in your next reply
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
OTL logfile created on: 2/8/2012 5:53:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Leonard Roe\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.25 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 66.31% Memory free
1.49 Gb Paging File | 1.15 Gb Available in Paging File | 76.80% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 12.63 Gb Free Space | 37.48% Space Free | Partition Type: NTFS
Computer Name: DG1BWS51 | User Name: Leonard Roe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\ArcSoft\Media Card Companion\ustor.dll ()
MOD - C:\Program Files\Dell\Media Experience\DirWatcher.dll ()
MOD - C:\Program Files\Sonic\RecordNow!\shlext.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\FPXLIB.DLL ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NPF) – C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (PD1030VID) – C:\WINDOWS\SYSTEM32\DRIVERS\p1030vid.sys (Creative Technology Ltd.)
DRV - (C21ndisXP) – C:\WINDOWS\SYSTEM32\DRIVERS\C21ndisXP.sys (Com21, Inc)
DRV - (QV2KUX) – C:\WINDOWS\SYSTEM32\DRIVERS\qv2kux.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:0.6.0.13
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100211.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/17 21:22:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/11 03:29:42 | 000,000,000 | —D | M]
[2008/10/28 10:34:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Extensions
[2011/09/06 11:25:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions
[2009/09/14 11:14:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 12:16:33 | 000,000,000 | —D | M] (Speed Dial) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/02/13 16:33:31 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/13 09:18:27 | 000,000,000 | —D | M] ("AutoPager") – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2010/02/04 12:16:29 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2011/10/20 17:00:25 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/03 17:33:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/15 17:25:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/20 17:00:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/05/03 17:32:53 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/03 04:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/11 16:48:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.11_0\
CHR - Extension: YouTube = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Autocomplete = on = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ecpgkdflcnofdbbkiggklcfmgbnbabhh\1.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/05/03 12:52:18 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: auctiva.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: rubylane.com ([www] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157106795703 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} http://www.ipernity.com/E/Applets/Uploader…oader4.cab?v4.7 (Image Uploader Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{060AEA6E-F159-4837-8F62-2717DBE4A491}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{675F733C-F963-4B18-885E-DBA958852641}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\VIO\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\SYSTEM32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2012/02/08 14:46:33 | 004,733,440 | —- | C] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:40 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/02/06 17:31:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Leonard Roe\Recent
[2012/01/11 19:19:16 | 004,448,256 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
========== Files - Modified Within 30 Days ==========
[2012/02/08 17:47:00 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/08 17:23:00 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006UA.job
[2012/02/08 14:47:19 | 004,733,440 | —- | M] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/02/08 05:23:00 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006Core.job
[2012/02/07 21:45:21 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8DD95D15-9132-4CA1-8998-B4F91695AF3E}.job
[2012/02/07 19:47:00 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/05 02:16:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/02 20:45:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/31 17:59:01 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/01/31 17:57:54 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2012/01/31 17:57:52 | 1340,133,376 | -HS- | M] () – C:\hiberfil.sys
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2012/01/27 20:53:46 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/11 19:19:16 | 004,448,256 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2012/01/11 03:29:44 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/11 03:07:34 | 000,445,762 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2012/01/11 03:07:34 | 000,072,556 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
========== Files Created - No Company Name ==========
[2012/01/27 20:53:46 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/11 03:29:44 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/11 03:29:43 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2010/03/09 13:54:08 | 000,150,240 | —- | C] () – C:\WINDOWS\System32\drivers\MLTCAP.sys
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/03/01 09:01:16 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2009/01/09 11:49:53 | 000,054,088 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/04/16 02:56:28 | 000,000,135 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\fusioncache.dat
[2008/04/04 13:35:41 | 000,000,086 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/06 15:19:24 | 000,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2006/12/11 11:46:20 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/12/11 11:46:20 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2006/11/10 03:24:30 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2006/10/05 11:45:27 | 000,000,325 | —- | C] () – C:\WINDOWS\PSTUDIO.INI
[2006/09/25 12:57:55 | 000,002,301 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/01 05:43:25 | 000,000,064 | —- | C] () – C:\WINDOWS\sysdat.dll
[2005/02/03 03:36:23 | 000,000,347 | —- | C] () – C:\WINDOWS\ulead32.ini
[2005/02/02 01:07:36 | 000,014,211 | R— | C] () – C:\WINDOWS\twacker.ini
[2005/01/21 18:24:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/08 18:14:22 | 000,373,760 | —- | C] () – C:\WINDOWS\System32\xnmba450.dll
[2004/11/08 18:14:22 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\xnmhb450.dll
[2004/11/08 18:14:22 | 000,066,048 | —- | C] () – C:\WINDOWS\System32\xnmte450.dll
[2004/11/08 18:14:22 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\xnmhn450.dll
[2004/11/08 18:14:16 | 000,004,036 | —- | C] () – C:\WINDOWS\System32\apcctr.ini
[2004/10/22 20:58:40 | 000,028,775 | —- | C] () – C:\WINDOWS\javaw.exe
[2004/10/22 17:10:52 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\mcrtl32(2)(2).dll
[2004/10/22 17:10:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/10/22 12:29:54 | 000,000,329 | —- | C] () – C:\WINDOWS\dellstat.ini
[2004/10/17 20:54:01 | 000,006,656 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/10/17 20:50:15 | 000,061,678 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JPR.{PB
[2004/10/17 20:50:15 | 000,012,358 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JCM.{PB
[2004/10/17 17:32:09 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/10/17 13:56:37 | 000,000,738 | —- | C] () – C:\WINDOWS\ahd3.ini
[2004/10/16 15:43:04 | 000,000,154 | —- | C] () – C:\WINDOWS\PCStudy.ini
[2004/10/16 12:43:17 | 000,002,272 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2004/10/16 12:39:38 | 000,000,012 | —- | C] () – C:\WINDOWS\XBIBLEST.INI
[2004/10/10 16:08:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/10 16:03:24 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/10/10 15:58:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/10/10 15:58:37 | 000,000,304 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/10/10 15:49:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/10/10 15:48:28 | 000,445,762 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/10/10 15:48:28 | 000,072,556 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/10/10 15:36:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 13:08:08 | 000,262,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 10:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 16:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 15:09:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/02/10 14:08:00 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 14:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== LOP Check ==========
[2009/02/19 10:55:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2007/12/09 14:06:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/09/20 12:55:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/09 13:40:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2004/10/10 16:00:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/15 21:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/28 15:23:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\ElevatedDiagnostics
[2007/09/12 16:47:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Flickr
[2007/12/09 16:14:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\GetRightToGo
[2008/12/19 20:06:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\ieSpell
[2004/10/14 20:30:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Leadertech
[2009/06/04 12:16:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Listing & Factory 2008
[2009/06/04 12:26:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Listing Factory 2008
[2005/01/27 09:34:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\MSNInstaller
[2010/03/09 13:40:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Ulead Systems
[2008/08/12 08:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Uniblue
[2007/07/12 07:52:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Leonard Roe\Application Data\Viewpoint
[2012/02/05 02:16:01 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/02/07 21:45:21 | 000,000,436 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{8DD95D15-9132-4CA1-8998-B4F91695AF3E}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/09/04 16:35:14 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/01/30 19:08:02 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2004/11/28 18:20:32 | 000,000,211 | —- | M] () – C:\BOOT.PCP
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/10/10 15:39:56 | 000,003,569 | RH– | M] () – C:\DELL.SDR
[2012/01/31 17:57:52 | 1340,133,376 | -HS- | M] () – C:\hiberfil.sys
[2004/08/10 13:14:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2007/12/09 16:16:01 | 000,000,164 | —- | M] () – C:\install.dat
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2011/05/03 17:08:48 | 000,026,502 | —- | M] () – C:\JavaRa.log
[2010/05/08 00:46:56 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/22 08:47:41 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2012/02/07 17:08:00 | 415,236,096 | -HS- | M] () – C:\pagefile.sys
[2004/10/10 16:00:28 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2004/10/30 00:08:38 | 000,073,258 | —- | M] () – C:\ymsgr_grayorange_040816.zip
[2007/01/11 15:52:37 | 000,000,146 | —- | M] () – C:\YServer.txt
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/07/29 08:27:40 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\DLBCPP5C.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/01/28 11:00:00 | 000,049,152 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\IMFPRINT.DLL
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2004/05/18 10:50:58 | 000,000,204 | —- | M] () – C:\Documents and Settings\All Users\Favorites\My Yahoo!.url
[2004/05/18 10:49:54 | 000,000,213 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo! Bookmarks.url
[2004/05/18 17:26:04 | 000,000,208 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo! Mail.url
[2004/05/18 17:13:06 | 000,000,207 | —- | M] () – C:\Documents and Settings\All Users\Favorites\Yahoo!.url
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/22 08:54:07 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/09/09 14:27:44 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2011/05/03 04:09:13 | 000,000,222 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\FREE eBay Auction Management, Auction Templates, Auction Tools, and Unlimited Image Hosting.url
[2011/04/30 20:16:32 | 000,000,264 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\gun - Google Search.url
[2010/12/10 09:16:35 | 000,000,207 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\GunBroker.com - All Selling.url
[2011/05/03 03:30:13 | 000,004,143 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\iGoogle.url
[2011/04/30 21:14:18 | 000,105,514 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\My eBay Summary.url
[2010/07/29 00:04:38 | 000,000,175 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\NYCTREEMAN - Hatena Haiku.url
[2010/09/18 00:52:08 | 000,000,212 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\Open Forum Listen Online (MP3).url
[2010/09/16 10:16:35 | 000,000,184 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\Postcrossing - Postcards Traveling The World.url
[2011/08/04 11:02:36 | 000,000,300 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\USPS - USPS - Calculate Postage.url
[2009/05/19 20:05:53 | 000,000,207 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\WABC-AM Radio.url
[2011/04/21 10:53:54 | 000,000,262 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\Welcome - PayPal.url
[2011/05/03 03:55:23 | 000,014,647 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\Welcome to Flickr!.url
[2011/04/28 20:02:23 | 000,000,164 | —- | M] () – C:\Documents and Settings\Leonard Roe\Application Data\Microsoft\Internet Explorer\Quick Launch\What is my IP address, country, operating system, browser Arul John.url
< %USERPROFILE%\Desktop\*.exe >
[2012/02/08 14:47:19 | 004,733,440 | —- | M] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2009/12/19 09:08:59 | 008,086,544 | —- | M] (Mozilla) – C:\Documents and Settings\Leonard Roe\Desktop\Firefox Setup 3.5.6.exe
[2011/05/13 13:12:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Leonard Roe\Desktop\HiJackThis.exe
[2006/11/18 16:53:49 | 001,410,680 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\install_flash_player.exe
[2011/05/03 03:45:49 | 000,036,864 | —- | M] (Appleoddity) – C:\Documents and Settings\Leonard Roe\Desktop\JavaMSIFix.exe
[2012/02/08 14:45:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[1998/09/20 12:01:00 | 000,005,870 | R— | M] () – C:\WINDOWS\DEFAULT.SRC
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
[2011/10/07 19:29:50 | 000,000,698 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-31 07:33:59
< %appdata%\Microsoft\Windows\Start Menu\*.* /s >
Invalid Environment Variable: programdata
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\BOOT.PCP:SummaryInformation
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 2/8/2012 5:53:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Leonard Roe\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.25 Gb Total Physical Memory | 0.83 Gb Available Physical Memory | 66.31% Memory free
1.49 Gb Paging File | 1.15 Gb Available in Paging File | 76.80% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 12.63 Gb Free Space | 37.48% Space Free | Partition Type: NTFS
Computer Name: DG1BWS51 | User Name: Leonard Roe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Disabled:Winamp – (Nullsoft, Inc.)
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk – (Google)
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{21BCE515-D5A3-11D4-8E33-0010B53EC668}" = Ulead Photo Express 4.0 My Custom Edition
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 29
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4F1DA6BF-3614-48A1-9970-9E90F646789E}" = Ulead VideoStudio 8.0 SE VCD
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DEF17DA-2FBD-457F-8550-68A116B7ACD9}" = WOT for Internet Explorer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{976EA7B1-7562-483D-88DA-4323D263B7CD}" = DiMAGE Viewer
"{99E67091-D392-4031-AD2A-E9547F3615F8}" = KONICA_MINOLTA DiMAGE remote camera driver
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.4
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.0
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEC2A5B9-CE19-4F2E-9C8F-F310C0EAB993}" = ArcSoft Media Card Companion
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"Adobe Acrobat Reader 3.0" = Adobe Acrobat Reader 3.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"CCleaner" = CCleaner
"Creative PC-CAM Center" = Creative PC-CAM Center
"Creative WebCam Monitor" = Creative WebCam Monitor
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Photo Printer 720" = Dell Photo Printer 720
"DellSupport" = Dell Support 5.0.0 (630)
"ERUNT_is1" = ERUNT 1.1j
"HijackThis" = HijackThis 2.0.2
"HP-LaserJet 1020 series" = LaserJet 1020 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ieSpell" = ieSpell 2.2.0 (build 647)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"PowerChute plus" = PowerChute plus 5.2.1
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"RegistryBooster 2_is1" = Uniblue RegistryBooster 2
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 4.1.1
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Customizations" = Yahoo! extras
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"ymb" = Yahoo! Mail Quick Select Tool (PhotoMail)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/1/2012 2:59:48 AM | Computer Name = DG1BWS51 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 1/1/2012 3:17:01 PM | Computer Name = DG1BWS51 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19170, fault address 0x00067978.
Error - 1/1/2012 3:17:20 PM | Computer Name = DG1BWS51 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/11/2012 4:14:53 AM | Computer Name = DG1BWS51 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 1/13/2012 5:01:04 AM | Computer Name = DG1BWS51 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/13/2012 5:01:04 AM | Computer Name = DG1BWS51 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/13/2012 5:01:09 AM | Computer Name = DG1BWS51 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.
Error - 1/13/2012 5:01:12 AM | Computer Name = DG1BWS51 | Source = Application Hang | ID = 1001
Description = Fault bucket 1180947459.
Error - 1/22/2012 3:01:38 AM | Computer Name = DG1BWS51 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 2/5/2012 3:20:12 AM | Computer Name = DG1BWS51 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
[ System Events ]
Error - 12/28/2011 4:38:18 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00132048AB74 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
Error - 12/28/2011 4:38:50 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 00132048AB74.
Error - 1/24/2012 1:53:29 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00132048AB74 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
Error - 1/24/2012 1:54:02 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 00132048AB74.
Error - 1/24/2012 1:54:50 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 00132048AB74.
Error - 1/24/2012 1:58:22 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00132048AB74 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
Error - 1/24/2012 1:59:01 PM | Computer Name = DG1BWS51 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 00132048AB74.
Error - 1/30/2012 3:54:03 PM | Computer Name = DG1BWS51 | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.
Error - 2/8/2012 2:11:00 AM | Computer Name = DG1BWS51 | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.
Error - 2/8/2012 6:54:38 PM | Computer Name = DG1BWS51 | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.
< End of report >
aswMBR version 0.9.9.1532 Copyright© 2011 AVAST Software
Run date: 2012-02-08 18:01:11
—————————–
18:01:11.343 OS Version: Windows 5.1.2600 Service Pack 3
18:01:11.343 Number of processors: 1 586 0x304
18:01:11.343 ComputerName: DG1BWS51 UserName:
18:01:12.046 Initialize success
18:03:05.578 AVAST engine defs: 12020801
18:03:34.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
18:03:34.937 Disk 0 Vendor: ST340014A 8.16 Size: 38146MB BusType: 3
18:03:34.984 Disk 0 MBR read successfully
18:03:34.984 Disk 0 MBR scan
18:03:35.109 Disk 0 unknown MBR code
18:03:35.124 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 47 MB offset 63
18:03:35.312 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 34506 MB offset 96390
18:03:35.374 Disk 0 Partition 3 00 DB CP/M / CTOS MSWIN4.1 3584 MB offset 70766325
18:03:35.421 Disk 0 scanning sectors +78108030
18:03:35.593 Disk 0 scanning C:\WINDOWS\system32\drivers
18:04:21.734 Service scanning
18:04:23.531 Service MpKslfb3b155f c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D2432415-A600-433D-BF17-906C3B318446}\MpKslfb3b155f.sys **LOCKED** 32
18:04:24.312 Modules scanning
18:05:35.656 Disk 0 trace - called modules:
18:05:35.718 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
18:05:35.749 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a3da030]
18:05:35.765 3 CLASSPNP.SYS[f76b7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a38eb00]
18:05:36.812 AVAST engine scan C:\WINDOWS
18:06:06.593 AVAST engine scan C:\WINDOWS\system32
18:14:51.187 AVAST engine scan C:\WINDOWS\system32\drivers
18:15:53.999 AVAST engine scan C:\Documents and Settings\Leonard Roe
19:31:26.437 AVAST engine scan C:\Documents and Settings\All Users
19:38:38.796 Scan finished successfully
19:39:13.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Leonard Roe\Desktop\MBR.dat"
19:39:13.359 The log file has been saved successfully to "C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.txt"
There is no malware showing in these logs, just some things that need to be looked at more and some that need tidied up.
Run OTL
- Double click on the icon to run it.
- Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services :OTL FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (Reg Error: Key error.) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) :Commands [purity] [emptytemp] [Reboot]
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot when it is done
- Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Run Malwarebytes’ Anti-Malware
I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
- start Malwarebytes-Anti-Malware and update it, (“Update” tab}
- once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
- when the scan is complete, click OK, then Show Results to view the results.
- be sure that everything is checked, and click Remove Selected.
- when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
- the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- copy and paste the contents of that report in your next reply and exit MBAM.
===============================================
Run Farbar Service Scanner
Please download Farbar Service Scanner
- make sure "Include All Files" option remains checked
- press Scan
- it will create a log (FSS.txt) in the same directory the tool is run
- please copy and paste the log to your reply.
OTL fix log
New OTL log
Mbam.txt
FSS.txt
Thanks
Satchfan
I still have MBAM, will check for update first as you say.
by the way… I hardly use Firefox anymore, and I see a bunch of weird junk in there like
"FF - prefs.js..extensions.enabledItems: [removed]:1.5.1" (no idea what the heck that is)
And I seem to have JAVA difficulties a lot, especially in chrome, not so much in IE, but some sites the JAVA takes a bunch of time to set up
So if you see ANY carp** in my computer that you think is a waste of time and space, or possibly risky, let me know and I'll scrub them right out.
I would love to clean the old girl out, but I don't like removing things I don't understand.
I'll run these scans as soon as I get back, and thanks again :/
Christopher Beard is a Mozilla employee, (I think!), and Personas offers over 30,000 different designs to personalize your browser! . The ID is [removed]"FF - prefs.js..extensions.enabledItems: [removed]:1.5.1" (no idea what the heck that is
I'll run these scans as soon as I get back
Regarding Java and rubbish on your machine, it's not as bad as some, so we should be able to deal with it just fine..
Satchfan
OTL logfile created on: 2/10/2012 3:57:33 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Leonard Roe\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.25 Gb Total Physical Memory | 0.81 Gb Available Physical Memory | 65.23% Memory free
1.48 Gb Paging File | 1.23 Gb Available in Paging File | 82.78% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 13.03 Gb Free Space | 38.66% Space Free | Partition Type: NTFS
Drive E: | 977.19 Mb Total Space | 942.58 Mb Free Space | 96.46% Space Free | Partition Type: FAT
Computer Name: DG1BWS51 | User Name: Leonard Roe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\ArcSoft\Media Card Companion\ustor.dll ()
MOD - C:\Program Files\Dell\Media Experience\DirWatcher.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\FPXLIB.DLL ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL ()
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NPF) – C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (PD1030VID) – C:\WINDOWS\SYSTEM32\DRIVERS\p1030vid.sys (Creative Technology Ltd.)
DRV - (C21ndisXP) – C:\WINDOWS\SYSTEM32\DRIVERS\C21ndisXP.sys (Com21, Inc)
DRV - (QV2KUX) – C:\WINDOWS\SYSTEM32\DRIVERS\qv2kux.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:0.6.0.13
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100211.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/17 21:22:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/11 03:29:42 | 000,000,000 | —D | M]
[2008/10/28 10:34:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Extensions
[2011/09/06 11:25:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions
[2009/09/14 11:14:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 12:16:33 | 000,000,000 | —D | M] (Speed Dial) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/02/13 16:33:31 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/13 09:18:27 | 000,000,000 | —D | M] ("AutoPager") – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2010/02/04 12:16:29 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2011/10/20 17:00:25 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/03 17:33:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/15 17:25:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/10/20 17:00:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/05/03 17:32:53 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/10/03 04:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/11 16:48:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.11_0\
CHR - Extension: YouTube = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Autocomplete = on = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ecpgkdflcnofdbbkiggklcfmgbnbabhh\1.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/05/03 12:52:18 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: auctiva.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: rubylane.com ([www] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157106795703 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} http://www.ipernity.com/E/Applets/Uploader…oader4.cab?v4.7 (Image Uploader Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{060AEA6E-F159-4837-8F62-2717DBE4A491}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{675F733C-F963-4B18-885E-DBA958852641}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/10 15:46:02 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/08 14:46:33 | 004,733,440 | —- | C] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:40 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/02/06 17:31:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Leonard Roe\Recent
[2012/01/11 19:19:16 | 004,448,256 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
========== Files - Modified Within 30 Days ==========
[2012/02/10 15:55:24 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/10 15:54:55 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8DD95D15-9132-4CA1-8998-B4F91695AF3E}.job
[2012/02/10 15:50:59 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/02/10 15:50:13 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/10 15:50:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2012/02/10 15:50:03 | 1340,133,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/10 15:47:01 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/10 15:23:00 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006UA.job
[2012/02/10 05:23:00 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006Core.job
[2012/02/10 02:29:33 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 20:45:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/08 14:47:19 | 004,733,440 | —- | M] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2012/01/11 19:19:16 | 004,448,256 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
========== Files Created - No Company Name ==========
[2012/01/27 20:53:46 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2010/03/09 13:54:08 | 000,150,240 | —- | C] () – C:\WINDOWS\System32\drivers\MLTCAP.sys
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/03/01 09:01:16 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2009/01/09 11:49:53 | 000,054,088 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/04/16 02:56:28 | 000,000,135 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\fusioncache.dat
[2008/04/04 13:35:41 | 000,000,086 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/06 15:19:24 | 000,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2006/12/11 11:46:20 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/12/11 11:46:20 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2006/11/10 03:24:30 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2006/10/05 11:45:27 | 000,000,325 | —- | C] () – C:\WINDOWS\PSTUDIO.INI
[2006/09/25 12:57:55 | 000,002,301 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/01 05:43:25 | 000,000,064 | —- | C] () – C:\WINDOWS\sysdat.dll
[2005/02/03 03:36:23 | 000,000,347 | —- | C] () – C:\WINDOWS\ulead32.ini
[2005/02/02 01:07:36 | 000,014,211 | R— | C] () – C:\WINDOWS\twacker.ini
[2005/01/21 18:24:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/08 18:14:22 | 000,373,760 | —- | C] () – C:\WINDOWS\System32\xnmba450.dll
[2004/11/08 18:14:22 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\xnmhb450.dll
[2004/11/08 18:14:22 | 000,066,048 | —- | C] () – C:\WINDOWS\System32\xnmte450.dll
[2004/11/08 18:14:22 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\xnmhn450.dll
[2004/11/08 18:14:16 | 000,004,036 | —- | C] () – C:\WINDOWS\System32\apcctr.ini
[2004/10/22 20:58:40 | 000,028,775 | —- | C] () – C:\WINDOWS\javaw.exe
[2004/10/22 17:10:52 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\mcrtl32(2)(2).dll
[2004/10/22 17:10:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/10/22 12:29:54 | 000,000,329 | —- | C] () – C:\WINDOWS\dellstat.ini
[2004/10/17 20:54:01 | 000,006,656 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/10/17 20:50:15 | 000,061,678 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JPR.{PB
[2004/10/17 20:50:15 | 000,012,358 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JCM.{PB
[2004/10/17 17:32:09 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/10/17 13:56:37 | 000,000,738 | —- | C] () – C:\WINDOWS\ahd3.ini
[2004/10/16 15:43:04 | 000,000,154 | —- | C] () – C:\WINDOWS\PCStudy.ini
[2004/10/16 12:43:17 | 000,002,272 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2004/10/16 12:39:38 | 000,000,012 | —- | C] () – C:\WINDOWS\XBIBLEST.INI
[2004/10/10 16:08:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/10 16:03:24 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/10/10 15:58:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/10/10 15:58:37 | 000,000,304 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/10/10 15:49:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/10/10 15:48:28 | 000,445,762 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/10/10 15:48:28 | 000,072,556 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/10/10 15:36:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 13:08:08 | 000,262,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 10:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 16:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 15:09:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/02/10 14:08:00 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 14:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\BOOT.PCP:SummaryInformation
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI