This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Exploit:JAVA Detected by MSE [Solved]

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here's the second OTL scan


OTL logfile created on: 2/12/2012 11:45:04 AM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Leonard Roe\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.68 Gb Available Physical Memory | 54.55% Memory free
1.48 Gb Paging File | 1.08 Gb Available in Paging File | 72.86% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 12.43 Gb Free Space | 36.88% Space Free | Partition Type: NTFS

Computer Name: DG1BWS51 | User Name: Leonard Roe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avutil-51.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avformat-53.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avcodec-53.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\gcswf32.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\ustor.dll ()
MOD - C:\Program Files\Dell\Media Experience\DirWatcher.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\FPXLIB.DLL ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKsl51de008b) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{295D80E9-CFC8-4155-A86F-2FCD9DBD3083}\MpKsl51de008b.sys (Microsoft Corporation)
DRV - (NPF) – C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (PD1030VID) – C:\WINDOWS\SYSTEM32\DRIVERS\p1030vid.sys (Creative Technology Ltd.)
DRV - (C21ndisXP) – C:\WINDOWS\SYSTEM32\DRIVERS\C21ndisXP.sys (Com21, Inc)
DRV - (QV2KUX) – C:\WINDOWS\SYSTEM32\DRIVERS\qv2kux.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:0.6.0.13
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100211.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/17 21:22:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/11 10:37:06 | 000,000,000 | —D | M]

[2008/10/28 10:34:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Extensions
[2011/09/06 11:25:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions
[2009/09/14 11:14:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 12:16:33 | 000,000,000 | —D | M] (Speed Dial) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/02/13 16:33:31 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/13 09:18:27 | 000,000,000 | —D | M] ("AutoPager") – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2010/02/04 12:16:29 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2012/02/11 11:34:56 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/03 17:33:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/15 17:25:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/02/11 11:34:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/02/11 11:34:24 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/07/11 16:48:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.11_0\
CHR - Extension: YouTube = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Autocomplete = on = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ecpgkdflcnofdbbkiggklcfmgbnbabhh\1.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/05/03 12:52:18 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: auctiva.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: rubylane.com ([www] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157106795703 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} http://www.ipernity.com/E/Applets/Uploader…oader4.cab?v4.7 (Image Uploader Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{060AEA6E-F159-4837-8F62-2717DBE4A491}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{675F733C-F963-4B18-885E-DBA958852641}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/11 11:50:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Solid State Networks
[2012/02/11 11:35:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/02/11 11:34:53 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/11 11:34:53 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/11 11:34:53 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/11 11:34:53 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/10 15:46:02 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/08 14:46:33 | 004,733,440 | —- | C] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:40 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/02/06 17:31:30 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Leonard Roe\Recent

========== Files - Modified Within 30 Days ==========

[2012/02/12 11:47:12 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/12 11:44:20 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/12 11:39:39 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/02/12 11:39:12 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/12 11:39:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2012/02/12 11:39:03 | 1340,133,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/12 11:23:00 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006UA.job
[2012/02/12 11:01:04 | 000,139,264 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\SystemLook.exe
[2012/02/12 05:23:00 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006Core.job
[2012/02/11 18:30:06 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8DD95D15-9132-4CA1-8998-B4F91695AF3E}.job
[2012/02/11 12:15:39 | 000,879,700 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\SecurityCheck.exe
[2012/02/11 11:55:37 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/02/11 11:34:15 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/11 11:34:15 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/11 11:34:15 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/11 11:34:15 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/11 11:34:13 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/10 16:14:00 | 000,008,628 | -H– | M] () – C:\WINDOWS\System32\ZSHP1020.GID
[2012/02/10 16:07:00 | 000,336,319 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\FSS.exe
[2012/02/10 02:29:33 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 20:45:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/08 14:47:19 | 004,733,440 | —- | M] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2012/02/12 11:01:10 | 000,139,264 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\SystemLook.exe
[2012/02/11 12:15:30 | 000,879,700 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\SecurityCheck.exe
[2012/02/11 11:55:37 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/02/11 11:55:36 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/02/10 16:06:52 | 000,336,319 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\FSS.exe
[2012/01/27 20:53:46 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2010/03/09 13:54:08 | 000,150,240 | —- | C] () – C:\WINDOWS\System32\drivers\MLTCAP.sys
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/03/01 09:01:16 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2009/01/09 11:49:53 | 000,054,088 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/04/16 02:56:28 | 000,000,135 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\fusioncache.dat
[2008/04/04 13:35:41 | 000,000,086 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/06 15:19:24 | 000,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2006/12/11 11:46:20 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/12/11 11:46:20 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2006/11/10 03:24:30 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2006/10/05 11:45:27 | 000,000,325 | —- | C] () – C:\WINDOWS\PSTUDIO.INI
[2006/09/25 12:57:55 | 000,002,301 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/01 05:43:25 | 000,000,064 | —- | C] () – C:\WINDOWS\sysdat.dll
[2005/02/03 03:36:23 | 000,000,347 | —- | C] () – C:\WINDOWS\ulead32.ini
[2005/02/02 01:07:36 | 000,014,211 | R— | C] () – C:\WINDOWS\twacker.ini
[2005/01/21 18:24:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/08 18:14:22 | 000,373,760 | —- | C] () – C:\WINDOWS\System32\xnmba450.dll
[2004/11/08 18:14:22 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\xnmhb450.dll
[2004/11/08 18:14:22 | 000,066,048 | —- | C] () – C:\WINDOWS\System32\xnmte450.dll
[2004/11/08 18:14:22 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\xnmhn450.dll
[2004/11/08 18:14:16 | 000,004,036 | —- | C] () – C:\WINDOWS\System32\apcctr.ini
[2004/10/22 17:10:52 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\mcrtl32(2)(2).dll
[2004/10/22 17:10:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/10/22 12:29:54 | 000,000,329 | —- | C] () – C:\WINDOWS\dellstat.ini
[2004/10/17 20:54:01 | 000,006,656 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/10/17 20:50:15 | 000,061,678 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JPR.{PB
[2004/10/17 20:50:15 | 000,012,358 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JCM.{PB
[2004/10/17 17:32:09 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/10/17 13:56:37 | 000,000,738 | —- | C] () – C:\WINDOWS\ahd3.ini
[2004/10/16 15:43:04 | 000,000,154 | —- | C] () – C:\WINDOWS\PCStudy.ini
[2004/10/16 12:39:38 | 000,000,012 | —- | C] () – C:\WINDOWS\XBIBLEST.INI
[2004/10/10 16:08:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/10 16:03:24 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/10/10 15:58:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/10/10 15:58:37 | 000,000,304 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/10/10 15:49:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/10/10 15:48:28 | 000,445,762 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/10/10 15:48:28 | 000,072,556 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/10/10 15:36:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 13:08:08 | 000,262,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 10:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 16:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 15:09:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/02/10 14:08:00 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 14:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\BOOT.PCP:SummaryInformation
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
and here's the look log: SystemLook 30.07.11 by jpshortstuff Log created at 11:52 on 12/02/2012 by Leonard Roe Administrator - Elevation successful ========== filefind ========== Searching for "*Java*" C:\JavaRa.log –a—- 26502 bytes [02:27 03/05/2011] [22:08 03/05/2011] 40583A19A52F01D0EE14DD4BC6588354 C:\Documents and Settings\Default User\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}\Java 2 Runtime Environment, SE v1.4.2_03.msi –a—- 9946112 bytes [00:06 15/10/2004] [20:56 10/10/2004] B19C74B2CF628B940EDAD835793E0182 C:\Documents and Settings\Leonard Roe\Desktop\JavaMSIFix.exe –a—- 36864 bytes [03:46 03/05/2011] [08:45 03/05/2011] E96768A413C55FEA2E5644DCD6BC5FCC C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}\Java 2 Runtime Environment, SE v1.4.2_03.msi –a—- 9946112 bytes [00:07 15/10/2004] [20:56 10/10/2004] B19C74B2CF628B940EDAD835793E0182 C:\I386\ADCJAVAS.INC –a—- 629 bytes [18:26 16/10/2004] [10:00 04/08/2004] 49B9878B48D6614A5D76C7B07AE00F25 C:\I386\ADOJAVAS.INC –a—- 14610 bytes [18:26 16/10/2004] [10:00 04/08/2004] 398FD657D8EA0BD77325E6BAEEA25090 C:\I386\Java 2 Runtime Environment, SE v1.4.2_03.msi –a—- 9946112 bytes [18:29 16/10/2004] [20:56 10/10/2004] B19C74B2CF628B940EDAD835793E0182 C:\I386\java.exe –a—- 24681 bytes [18:33 16/10/2004] [21:36 19/11/2003] 43576DCAB6039640930EBA1E5E5E2FD8 C:\I386\javaw.exe –a—- 28779 bytes [18:33 16/10/2004] [21:36 19/11/2003] FF597046F03D19CF6FF9C2A1428F8B7C C:\Program Files\Common Files\Apple\Apple Application Support\JavaScriptCore.dll –a—- 1334632 bytes [12:22 27/09/2011] [12:22 27/09/2011] 565072DF3953ADB81D0EAA658C71A7C8 C:\Program Files\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\JavaScriptFormatter.js –a—- 27954 bytes [02:56 25/06/2011] [02:56 25/06/2011] 33FCB40ED26BB3E0901C452AC9831DBD C:\Program Files\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\SourceJavaScriptTokenizer.js –a—- 99401 bytes [02:56 25/06/2011] [02:56 25/06/2011] 5B79151C26EF71DA88EC317B1A60FA0C C:\Program Files\Common Files\Apple\Apple Application Support\WebKit.resources\inspector\SourceJavaScriptTokenizer.re2js –a—- 9340 bytes [02:56 25/06/2011] [02:56 25/06/2011] CF2FB3689F892BEF6A2D3E319A69C734 C:\Program Files\Common Files\System\ADO\ADOJAVAS.INC –a—- 14610 bytes [10:00 04/08/2004] [10:00 04/08/2004] 398FD657D8EA0BD77325E6BAEEA25090 C:\Program Files\Common Files\System\MSADC\ADCJAVAS.INC –a—- 629 bytes [10:00 04/08/2004] [10:00 04/08/2004] 49B9878B48D6614A5D76C7B07AE00F25 C:\Program Files\Java\jre6\bin\deployJava1.dll –a—- 472808 bytes [16:34 11/02/2012] [16:34 11/02/2012] CCB1CD9C87E247A52248A6B0E16EDE6B C:\Program Files\Java\jre6\bin\java-rmi.exe –a—- 34080 bytes [16:34 11/02/2012] [16:34 11/02/2012] BDBCE90CE74990DF3B2C7C8484DDE146 C:\Program Files\Java\jre6\bin\java.dll –a—- 126976 bytes [16:34 11/02/2012] [16:34 11/02/2012] 9B3173EB1B50FF10686D01FE3DD22839 C:\Program Files\Java\jre6\bin\java.exe –a—- 149280 bytes [16:34 11/02/2012] [16:34 11/02/2012] DD798E7D8F45FD2BB73150EABBB39E9F C:\Program Files\Java\jre6\bin\javacpl.cpl –a—- 73728 bytes [16:34 11/02/2012] [16:34 11/02/2012] B27F09888C419B476EC6DAA8086260DE C:\Program Files\Java\jre6\bin\javacpl.exe –a—- 59168 bytes [16:34 11/02/2012] [16:34 11/02/2012] FA71E60855B37C3C26D9EBBB52A0C3DE C:\Program Files\Java\jre6\bin\javaw.exe –a—- 149280 bytes [16:34 11/02/2012] [16:34 11/02/2012] F0003BBE2DDBC6A86BCD8BB3E59A459E C:\Program Files\Java\jre6\bin\javaws.exe –a—- 157472 bytes [16:34 11/02/2012] [16:34 11/02/2012] 7030C9615C98953C481553671DD7B9E5 C:\Program Files\Java\jre6\bin\java_crw_demo.dll –a—- 14336 bytes [16:34 11/02/2012] [16:34 11/02/2012] 803F360CD842CD46AF594FC2C7A6126E C:\Program Files\Java\jre6\bin\npdeployJava1.dll –a—- 476904 bytes [16:34 11/02/2012] [16:34 11/02/2012] FF030B5F429A1A8C18821E4595599C1F C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll –a—- 476904 bytes [16:34 11/02/2012] [16:34 11/02/2012] FF030B5F429A1A8C18821E4595599C1F C:\Program Files\Java\jre6\lib\javaws.jar –a—- 830299 bytes [16:34 11/02/2012] [16:34 11/02/2012] E0BD6E74C4AA126E3800C392C3DAF8A6 C:\Program Files\Java\jre6\lib\ext\QTJava.zip –a—- 935850 bytes [19:28 24/10/2011] [19:28 24/10/2011] FBF75758DCAC6AA563CBB082F4975517 C:\Program Files\Java\jre6\lib\security\java.policy –a—- 2253 bytes [16:34 11/02/2012] [16:34 11/02/2012] 6B20D44D047BF8DD858C71E91937E412 C:\Program Files\Java\jre6\lib\security\java.security –a—- 11113 bytes [16:34 11/02/2012] [16:34 11/02/2012] E1DE33C5513A20EA99C35870053E5DFC C:\Program Files\Java\jre6\lib\security\javaws.policy –a—- 109 bytes [16:34 11/02/2012] [16:34 11/02/2012] E8B8FB9FCB3A6113C03672FDD276B830 C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\java.dll –a—- 102511 bytes [01:58 23/10/2004] [12:05 02/05/2003] 6265DB24EA0FAF1CD7E9EE6B7669FEDA C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\java.exe –a—- 24677 bytes [01:58 23/10/2004] [12:05 02/05/2003] 870C3E34EE7E2C88F4D0DBDF91D7EBBF C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\javaw.exe –a—- 28775 bytes [01:58 23/10/2004] [12:05 02/05/2003] E8F6AE4E55929DAA0EAE4B09B447B817 C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\NPJava11.dll –a—- 61556 bytes [01:58 23/10/2004] [12:05 02/05/2003] 199BF10FD2551A8C72519F220FD7EF16 C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\NPJava12.dll –a—- 61556 bytes [01:58 23/10/2004] [12:05 02/05/2003] 2DBB44DC68A0BB39EADF9035D2E0A0A3 C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\NPJava13.dll –a—- 61556 bytes [01:58 23/10/2004] [12:05 02/05/2003] F44756A6720C3CB58145428033C0F3CB C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\NPJava32.dll –a—- 61556 bytes [01:58 23/10/2004] [12:05 02/05/2003] 57B0B08803D7911134F6A5CAE383528A C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\security\java.policy –a—- 2223 bytes [01:58 23/10/2004] [12:05 02/05/2003] 84BF34FCB8600DF9F36AE39F8768ED27 C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\security\java.security –a—- 6871 bytes [01:58 23/10/2004] [12:05 02/05/2003] 8C485324337B6AB3CA5935F6E6DC1D4B C:\Program Files\QuickTime\QTSystem\QTJava.zip –a—- 935850 bytes [19:28 24/10/2011] [19:28 24/10/2011] FBF75758DCAC6AA563CBB082F4975517 C:\Program Files\QuickTime\QTSystem\QTJavaNative.dll –a—- 493416 bytes [20:02 24/10/2011] [20:02 24/10/2011] D59CC1523B37E436366E54AB09041636 C:\Program Files\QuickTime\QTSystem\QuickTimeJavaExtras.qtx –a—- 5120 bytes [19:28 24/10/2011] [19:28 24/10/2011] C923F46B7CAC86684958BF5A239D530F C:\WINDOWS\Prefetch\JAVA.EXE-32FD225F.pf –a—- 8242 bytes [17:02 11/02/2012] [17:02 11/02/2012] 3ADC0444257823C60B7435F90D4FA516 C:\WINDOWS\Prefetch\JAVAW.EXE-392A4E93.pf –a—- 107030 bytes [08:30 11/01/2012] [17:02 11/02/2012] 58A9ACB6709DA731443C475AD1BA15A5 C:\WINDOWS\Prefetch\JAVAWS.EXE-078C20EA.pf –a—- 12314 bytes [08:30 11/01/2012] [17:02 11/02/2012] F2AD67DE59B03A126A24B4E5983BC3F7 C:\WINDOWS\ServicePackFiles\i386\adcjavas.inc ——- 629 bytes [11:40 22/08/2008] [10:00 04/08/2004] 49B9878B48D6614A5D76C7B07AE00F25 C:\WINDOWS\ServicePackFiles\i386\adojavas.inc ——- 14610 bytes [11:40 22/08/2008] [10:00 04/08/2004] 398FD657D8EA0BD77325E6BAEEA25090 C:\WINDOWS\SYSTEM32\deployJava1.dll –a—- 472808 bytes [03:25 16/04/2010] [16:34 11/02/2012] CCB1CD9C87E247A52248A6B0E16EDE6B C:\WINDOWS\SYSTEM32\java.exe –a—- 149280 bytes [16:34 11/02/2012] [16:34 11/02/2012] DD798E7D8F45FD2BB73150EABBB39E9F C:\WINDOWS\SYSTEM32\javacpl.cpl –a—- 73728 bytes [16:34 11/02/2012] [16:34 11/02/2012] B27F09888C419B476EC6DAA8086260DE C:\WINDOWS\SYSTEM32\javaw.exe –a—- 149280 bytes [16:34 11/02/2012] [16:34 11/02/2012] F0003BBE2DDBC6A86BCD8BB3E59A459E C:\WINDOWS\SYSTEM32\javaws.exe –a—- 157472 bytes [16:34 11/02/2012] [16:34 11/02/2012] 7030C9615C98953C481553671DD7B9E5 C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}\Java 2 Runtime Environment, SE v1.4.2_03.msi –a—- 9946112 bytes [00:06 15/10/2004] [20:56 10/10/2004] B19C74B2CF628B940EDAD835793E0182 C:\_OTL\MovedFiles\02122012_113647\C_Program Files\Mozilla Firefox\plugins\npdeployJava1.dll –a—- 476904 bytes [03:25 16/04/2010] [16:34 11/02/2012] FF030B5F429A1A8C18821E4595599C1F C:\_OTL\MovedFiles\02122012_113647\C_WINDOWS\javaw.exe –a—- 28775 bytes [01:58 23/10/2004] [01:58 23/10/2004] E8F6AE4E55929DAA0EAE4B09B447B817 ========== Regfind ========== Searching for "*Java*" No data found. ========== folderfind ========== Searching for "*Java*" C:\Documents and Settings\Administrator\Application Data\Sun\Java d—— [00:42 08/11/2005] C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\javaws d—— [00:42 08/11/2005] C:\Documents and Settings\All Users\Application Data\Sun\Java d—— [06:41 27/01/2010] C:\Documents and Settings\All Users\Application Data\Sun\Java\Java Update d—— [06:41 27/01/2010] C:\Documents and Settings\Default User\Application Data\Sun\Java d—— [00:06 15/10/2004] C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\javaws d—— [00:06 15/10/2004] C:\Documents and Settings\Leonard Roe\Application Data\Adobe\Acrobat\8.0\JavaScripts d—— [16:56 02/03/2007] C:\Documents and Settings\Leonard Roe\Application Data\Adobe\Acrobat\9.0\JavaScripts d—— [17:19 16/05/2009] C:\Documents and Settings\Leonard Roe\Application Data\Sun\Java d—— [00:07 15/10/2004] C:\Documents and Settings\Leonard Roe\Application Data\Sun\Java\Deployment\javaws d—— [00:07 15/10/2004] C:\Program Files\Java d—— [22:32 03/05/2011] C:\Program Files\JavaSoft d—— [01:58 23/10/2004] C:\Program Files\Adobe\Reader 10.0\Reader\Javascripts d—— [16:55 11/02/2012] C:\Program Files\Adobe\Reader 8.0\Reader\Javascripts d—— [23:09 18/05/2009] C:\Program Files\Adobe\Reader 9.0\Reader\Javascripts d—— [22:24 15/05/2009] C:\Program Files\Common Files\Java d—— [16:35 11/02/2012] C:\Program Files\Common Files\Apple\Apple Application Support\JavaScriptCore.resources d—— [00:18 07/04/2010] C:\Program Files\Common Files\Java\Java Update d—— [16:35 11/02/2012] C:\WINDOWS\JAVA d—— [20:34 10/10/2004] C:\WINDOWS\Sun\Java d—— [20:29 24/10/2004] C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java d—— [00:06 15/10/2004] C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java\Deployment\javaws d—— [00:06 15/10/2004] -= EOF =-

I'm confused about some of these problems with Adobe and Java…do they have to be installed on each browser separately? or just on the computer?

Read How do I enable Java in my web browser?

You can go here for all the information you need regarding Java:

You only need one version of Adobe Reader on your computer as it is only used for reading PDF files, not for viewing web pages.

===============================================

Clear all your temporary files

Download ATF Cleaner
  • double-click ATF-Cleaner.exe (on your desktop) to run the program.
  • under Main choose: Select All
  • click the Empty Selected button.
If you use Firefox browser
  • click Firefox at the top and choose: Select All
  • click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • click Opera at the top and choose: Select All
  • click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

For Technical Support, double-click the e-mail address located at the bottom of each menu

===============================================

We’ll use OTL to get rid of the old program folders.

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Program Files\JavaSoft
    C:\Documents and Settings\Administrator\Application Data\Sun
    C:\Documents and Settings\All Users\Application Data\Sun
    C:\Documents and Settings\Default User\Application Data\Sun
    C:\Documents and Settings\Leonard Roe\Application Data\Sun
    C:\Program Files\Adobe\Reader 8.0
    C:\Program Files\Adobe\Reader 9.0
    C:\WINDOWS\JAVA
    C:\WINDOWS\Sun
    C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Logs to include in the next post:

OTL fix log
New OTL log


Please tell me if you have any remaining problems.

Satchfan
OTL run fix log…….. All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Pacific folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Indian folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Europe folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Etc folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Australia folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Atlantic folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Asia folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Antarctica folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\America\North_Dakota folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\America\Kentucky folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\America\Indiana folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\America folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi\Africa folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\zi folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\security folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\images\cursors folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\images folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\im folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\i386 folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\fonts folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\ext folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\cmm folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib\applet folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\lib folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin\client folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1\bin folder moved successfully. C:\Program Files\JavaSoft\JRE1.4\1.4.1 folder moved successfully. C:\Program Files\JavaSoft\JRE1.4 folder moved successfully. C:\Program Files\JavaSoft folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\javaws\cache folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\javaws folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Sun\Java folder moved successfully. C:\Documents and Settings\Administrator\Application Data\Sun folder moved successfully. C:\Documents and Settings\All Users\Application Data\Sun\Java\Java Update folder moved successfully. C:\Documents and Settings\All Users\Application Data\Sun\Java folder moved successfully. C:\Documents and Settings\All Users\Application Data\Sun folder moved successfully. C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\javaws\cache folder moved successfully. C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment\javaws folder moved successfully. C:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment folder moved successfully. C:\Documents and Settings\Default User\Application Data\Sun\Java folder moved successfully. C:\Documents and Settings\Default User\Application Data\Sun folder moved successfully. File\Folder C:\Documents and Settings\Leonard Roe\Application Data\Sun not found. C:\Program Files\Adobe\Reader 8.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A81300000003} folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Setup Files folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\Linguistics\Providers\Proximity folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\Linguistics\Providers folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\Linguistics\LanguageNames folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\Linguistics folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\Font\PFM folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\Font folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource\CMap folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Resource folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\Tracker folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\SPPlugins folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins3d\prc folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins3d folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\VDKHome\ENU folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\VDKHome folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Multimedia\MPP folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Multimedia folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\ImageViewer\en_US folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\ImageViewer folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Annotations\Stamps\ENU folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Annotations\Stamps folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\Annotations folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\AcroForm\PMP folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins\AcroForm folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\plug_ins folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\Optional folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\Legal\en_US folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\Legal folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\Javascripts folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\IDTemplates\ENU folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\IDTemplates folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\HowTo\ENU\Images folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\HowTo\ENU folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\HowTo folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\Browser folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\BeyondReader\ENU\Onramp folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\BeyondReader\ENU folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\BeyondReader folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\AMT folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\AIR folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\adobe_epic\eula\en_US folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\adobe_epic\eula folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader\adobe_epic folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Reader folder moved successfully. C:\Program Files\Adobe\Reader 8.0\Esl folder moved successfully. C:\Program Files\Adobe\Reader 8.0 folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-1033-7B44-A91000000001} folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Setup Files folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport\Unicode\Mappings\win folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport\Unicode\Mappings\Mac folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport\Unicode\Mappings\Adobe folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport\Unicode\Mappings folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport\Unicode\ICU folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport\Unicode folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\TypeSupport folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\SaslPrep folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\Linguistics\Providers\Proximity\11.00 folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\Linguistics\Providers\Proximity folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\Linguistics\Providers folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\Linguistics\LanguageNames2 folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\Linguistics folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\Font folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource\CMap folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Resource folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\Tracker folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins3d\prc folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins3d folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\VDKHome\ENU folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\VDKHome folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia\MPP folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Multimedia folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annotations\Stamps\ENU folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annotations\Stamps folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annotations folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\AcroForm\PMP folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\AcroForm folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\Optional folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\Legal\ENU folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\Legal folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\Javascripts folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\IDTemplates\ENU folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\IDTemplates folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\DocSettings\Redaction\ENU folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\DocSettings\Redaction folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\DocSettings folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader\Browser folder moved successfully. C:\Program Files\Adobe\Reader 9.0\Reader folder moved successfully. C:\Program Files\Adobe\Reader 9.0 folder moved successfully. C:\WINDOWS\JAVA\TRUSTLIB folder moved successfully. C:\WINDOWS\JAVA\CLASSES folder moved successfully. C:\WINDOWS\JAVA folder moved successfully. C:\WINDOWS\Sun\Java\Deployment folder moved successfully. C:\WINDOWS\Sun\Java folder moved successfully. C:\WINDOWS\Sun folder moved successfully. C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache folder moved successfully. C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java\Deployment\javaws folder moved successfully. C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java\Deployment folder moved successfully. C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java folder moved successfully. C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Leonard Roe ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 376899 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 46852076 bytes ->Google Chrome cache emptied: 8999972 bytes ->Flash cache emptied: 470 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32835 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Owner %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 54.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 02142012_021138 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
OTL log………


OTL logfile created on: 2/14/2012 2:20:26 AM - Run 5
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Leonard Roe\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.70 Gb Available Physical Memory | 56.08% Memory free
1.48 Gb Paging File | 1.10 Gb Available in Paging File | 74.49% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 12.45 Gb Free Space | 36.95% Space Free | Partition Type: NTFS

Computer Name: DG1BWS51 | User Name: Leonard Roe | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avutil-51.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avformat-53.dll ()
MOD - C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\avcodec-53.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\ustor.dll ()
MOD - C:\Program Files\Dell\Media Experience\DirWatcher.dll ()
MOD - C:\Program Files\ArcSoft\Media Card Companion\FPXLIB.DLL ()
MOD - C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (NPF) – C:\WINDOWS\SYSTEM32\DRIVERS\npf.sys (CACE Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (PD1030VID) – C:\WINDOWS\SYSTEM32\DRIVERS\p1030vid.sys (Creative Technology Ltd.)
DRV - (C21ndisXP) – C:\WINDOWS\SYSTEM32\DRIVERS\C21ndisXP.sys (Com21, Inc)
DRV - (QV2KUX) – C:\WINDOWS\SYSTEM32\DRIVERS\qv2kux.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:0.6.0.13
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100211.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: {64161300-e22b-11db-8314-0800200c9a66}:0.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2088: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/17 21:22:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/11 10:37:06 | 000,000,000 | —D | M]

[2008/10/28 10:34:42 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Extensions
[2012/02/13 18:18:05 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions
[2009/09/14 11:14:07 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/04 12:16:33 | 000,000,000 | —D | M] (Speed Dial) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}
[2010/02/13 16:33:31 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/13 09:18:27 | 000,000,000 | —D | M] ("AutoPager") – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2010/02/04 12:16:29 | 000,000,000 | —D | M] (Personas) – C:\Documents and Settings\Leonard Roe\Application Data\Mozilla\Firefox\Profiles\62hh1b1j.default\extensions\[removed]
[2012/02/12 15:20:01 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/03 17:33:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/15 17:25:56 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/02/11 11:34:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/02/11 11:34:24 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/07/11 16:48:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\Application\17.0.963.46\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.11_0\
CHR - Extension: YouTube = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Autocomplete = on = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ecpgkdflcnofdbbkiggklcfmgbnbabhh\1.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/05/03 12:52:18 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe (Arcsoft, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Check &Spelling; - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/10/10 09:40:35 | 000,000,000 | —D | M]
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: auctiva.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([mail] https in Trusted sites)
O15 - HKCU\..Trusted Domains: hotmail.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: rubylane.com ([www] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1157106795703 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} http://www.auctiva.com/hostedimages/active…oad/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} http://www.ipernity.com/E/Applets/Uploader…oader4.cab?v4.7 (Image Uploader Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{060AEA6E-F159-4837-8F62-2717DBE4A491}: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{675F733C-F963-4B18-885E-DBA958852641}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/14 01:52:08 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Leonard Roe\Recent
[2012/02/13 10:32:57 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Leonard Roe\Desktop\ATF_Cleaner.exe
[2012/02/11 11:50:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\Solid State Networks
[2012/02/11 11:35:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/02/11 11:34:53 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/11 11:34:53 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/11 11:34:53 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/11 11:34:53 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/10 15:46:02 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/08 14:46:33 | 004,733,440 | —- | C] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:40 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2012/02/14 02:23:11 | 000,001,006 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006UA.job
[2012/02/14 02:19:10 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/14 02:14:51 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/02/14 02:13:36 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/14 02:13:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2012/02/14 02:13:08 | 1340,133,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/14 01:47:00 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/13 23:11:00 | 000,000,436 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{8DD95D15-9132-4CA1-8998-B4F91695AF3E}.job
[2012/02/13 10:32:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Leonard Roe\Desktop\ATF_Cleaner.exe
[2012/02/13 05:23:00 | 000,000,954 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1502690784-542892451-2706031008-1006Core.job
[2012/02/12 11:01:04 | 000,139,264 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\SystemLook.exe
[2012/02/11 12:15:39 | 000,879,700 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\SecurityCheck.exe
[2012/02/11 11:55:37 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/02/11 11:34:15 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/11 11:34:15 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/11 11:34:15 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/02/11 11:34:15 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2012/02/11 11:34:13 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2012/02/10 16:14:00 | 000,008,628 | -H– | M] () – C:\WINDOWS\System32\ZSHP1020.GID
[2012/02/10 16:07:00 | 000,336,319 | —- | M] () – C:\Documents and Settings\Leonard Roe\Desktop\FSS.exe
[2012/02/10 02:29:33 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 20:45:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/08 14:47:19 | 004,733,440 | —- | M] (AVAST Software) – C:\Documents and Settings\Leonard Roe\Desktop\aswMBR.exe
[2012/02/08 14:45:25 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Leonard Roe\Desktop\OTL.exe
[2012/01/31 07:44:05 | 000,237,072 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2012/02/12 11:01:10 | 000,139,264 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\SystemLook.exe
[2012/02/11 12:15:30 | 000,879,700 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\SecurityCheck.exe
[2012/02/11 11:55:37 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/02/11 11:55:36 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/02/10 16:06:52 | 000,336,319 | —- | C] () – C:\Documents and Settings\Leonard Roe\Desktop\FSS.exe
[2012/01/27 20:53:46 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2010/03/09 13:54:08 | 000,150,240 | —- | C] () – C:\WINDOWS\System32\drivers\MLTCAP.sys
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/03/01 09:01:16 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2009/01/09 11:49:53 | 000,054,088 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2008/04/16 02:56:28 | 000,000,135 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\fusioncache.dat
[2008/04/04 13:35:41 | 000,000,086 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/02/06 15:19:24 | 000,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2006/12/11 11:46:20 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\ZSHP1020.EXE
[2006/12/11 11:46:20 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2006/11/10 03:24:30 | 000,000,444 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2006/10/05 11:45:27 | 000,000,325 | —- | C] () – C:\WINDOWS\PSTUDIO.INI
[2006/09/25 12:57:55 | 000,002,301 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/09/01 05:43:25 | 000,000,064 | —- | C] () – C:\WINDOWS\sysdat.dll
[2005/02/03 03:36:23 | 000,000,347 | —- | C] () – C:\WINDOWS\ulead32.ini
[2005/02/02 01:07:36 | 000,014,211 | R— | C] () – C:\WINDOWS\twacker.ini
[2005/01/21 18:24:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/08 18:14:22 | 000,373,760 | —- | C] () – C:\WINDOWS\System32\xnmba450.dll
[2004/11/08 18:14:22 | 000,086,528 | —- | C] () – C:\WINDOWS\System32\xnmhb450.dll
[2004/11/08 18:14:22 | 000,066,048 | —- | C] () – C:\WINDOWS\System32\xnmte450.dll
[2004/11/08 18:14:22 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\xnmhn450.dll
[2004/11/08 18:14:16 | 000,004,036 | —- | C] () – C:\WINDOWS\System32\apcctr.ini
[2004/10/22 17:10:52 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\mcrtl32(2)(2).dll
[2004/10/22 17:10:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/10/22 12:29:54 | 000,000,329 | —- | C] () – C:\WINDOWS\dellstat.ini
[2004/10/17 20:54:01 | 000,006,656 | —- | C] () – C:\Documents and Settings\Leonard Roe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/10/17 20:50:15 | 000,061,678 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JPR.{PB
[2004/10/17 20:50:15 | 000,012,358 | —- | C] () – C:\Documents and Settings\Leonard Roe\Application Data\PFP120JCM.{PB
[2004/10/17 17:32:09 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/10/17 13:56:37 | 000,000,738 | —- | C] () – C:\WINDOWS\ahd3.ini
[2004/10/16 15:43:04 | 000,000,154 | —- | C] () – C:\WINDOWS\PCStudy.ini
[2004/10/16 12:39:38 | 000,000,012 | —- | C] () – C:\WINDOWS\XBIBLEST.INI
[2004/10/10 16:08:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/10/10 16:03:24 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/10/10 15:58:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/10/10 15:58:37 | 000,000,304 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/10/10 15:49:14 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/10/10 15:48:28 | 000,445,762 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/10/10 15:48:28 | 000,072,556 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/10/10 15:36:06 | 000,000,520 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,780 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/10 13:08:08 | 000,262,232 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 13:03:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 13:02:16 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 10:08:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 10:08:26 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2004/08/04 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 16:01:02 | 000,045,056 | —- | C] () – C:\WINDOWS\SETPWRCG.EXE
[2004/05/26 15:09:26 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/02/10 14:08:00 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2002/11/13 14:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\BOOT.PCP:SummaryInformation
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
As it is not installed, it’s doing no harm but you can just delete the folder:• right-click on the Start button and click on Explore
• in the left window, click on the + sign to the left of (C:)
• also in the left window, scroll down until you see Program Files and click on it
• in the right window, right-click on the Adobe program you want removed and choose Delete.
Please let me know if you have any remaining problems.

Satchfan
No problems that I know of…. That bit of Adobe Flash that is outdated is a plugin extra of some kind. I just remembered that when I was watching some video on a news website, it requested I allow the Adobe plugin to view it. Should I remove that as well? Other than that, I can't think of anything unless you see something else that should be cleaned. The computer seems to be working fine, I ran a full MSE scan last night which was clean. :thumbup:
PS I have no "Explore" on my start menu I have Search for files and folders but not sure if that's going to get me where you're directing me…I'll take a look and see correction….I do when I "right click" :smack:
Sorry for the delay - I was waiting for another answer from you.

That bit of Adobe Flash that is outdated is a plugin extra of some kind.

I just remembered that when I was watching some video on a news website, it requested I allow the Adobe plugin to view it.

Should I remove that as well?

Yes, I mentioned before that you can uninstall Adobe Flash Player 10.2.159.1 in the same way as you did with Java and Reader.

Go here and download the latest version.

===================================================

Well done Ebayvictim, you’ve done a good job and your computer appears to be clean. :thumbup:

We need to tidy up by removing the tools that have been used.

Uninstall OTL
  • double-click OTL.exe
  • click the CleanUp! button.
  • select Yes when the Begin cleanup Process? prompt appears.
  • if you are prompted to reboot during the cleanup, select Yes.
  • the tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

You can delete any other files/programs we’ve used that are still on your desktop by right-clicking on them and choosing Delete.

===================================================

Create a Restore Point
  • click Start, Run
  • copy and paste the following:

    %SystemRoot%\System32\restore\rstrui.exe
  • press OK
  • choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create
  • when the confirmation screen shows that the restore point has been created, click Close.
Remove old restore points
  • go to Start, Programs, Accessories, System tools, Disk Cleanup
  • when the Disc Cleanup dialog box appears, click OK
  • when it finishes running, a box with tabs will appear, select the ”More options” tab
  • on this tab you will find a section for System Restore
  • if you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.
===================================================

Firewall

You're using the Windows Firewall which is not adequate protection. The main reason you should use a third-party firewall over the Windows XP Firewall is because Windows Firewall only stops incoming signals from accessing your computer. However, it will not stop Outgoing signals (possibly ones that could intrude your privacy) from sending information to the Internet or to other networks. That means if malware happens to compromise your PC again, it will be able to SEND OUT out your credit card data and any other personal information.

I suggest you install a more robust third party firewall that filters both incoming and outgoing traffic.

Download and install one of the following freeware firewalls from below:

Sygate Personal Firewall Free Edition:
Zone Alarm Free:
Comodo Personal Firewall:

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

When you have done that:

Disable Windows firewall:
  • click on Start, Settings and then Control Panel
  • click on the Security Center icon.
  • click on the Windows Firewall icon
  • click Off (not recommended) and then click OK.
You should take the time to read Understanding and Using Firewalls

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes.

If there are no remaining problems and I don't hear back from you, I'll assume that all is well and close this thread in 24 hours.

Safe computing

Satchfan
Thank you very much :)

Just one thing I'm a little confused about regarding Windows Firewall …

I was under the impression that Microsoft Security Essentials was all I needed

Can I have one of those firewalls you suggest running at the same time as M.S.E?

I will follow the other instructions now.
OK, that's good enough for me.

Thanks again!

This is the best computer help site, I've sent a lot of people here over the last couple years

I just got a little money from ebay, so I'll make a donation from paypal tonignt :thumbup:

Lenny

This is the best computer help site, I've sent a lot of people here over the last couple years

I just got a little money from ebay, so I'll make a donation from paypal tonignt

Thanks Lenny and glad we could help :thumbup:

Take care

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI