OTL logfile created on: 2/19/2012 10:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.33.0 Folder = C:\Documents and Settings\Peggy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 82.00% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.29% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 235.85 Gb Free Space | 79.12% Space Free | Partition Type: NTFS
Drive H: | 232.88 Gb Total Space | 161.91 Gb Free Space | 69.52% Space Free | Partition Type: NTFS
Drive P: | 30.56 Gb Total Space | 26.05 Gb Free Space | 85.23% Space Free | Partition Type: NTFS
Drive U: | 465.54 Gb Total Space | 372.21 Gb Free Space | 79.95% Space Free | Partition Type: NTFS
Drive X: | 43.94 Gb Total Space | 30.46 Gb Free Space | 69.32% Space Free | Partition Type: NTFS
Computer Name: HOME-4600 | User Name: Peggy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/19 22:11:46 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
PRC - [2012/01/22 13:35:14 | 000,296,056 | —- | M] (RealNetworks, Inc.) – C:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2011/12/19 16:32:26 | 000,394,672 | —- | M] (Eastman Kodak Company) – C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011/12/10 10:25:36 | 002,756,608 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe
PRC - [2011/11/22 17:18:26 | 001,318,816 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/10/18 14:32:30 | 000,150,856 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2011/10/18 14:28:34 | 000,160,608 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/10/18 14:28:18 | 000,166,288 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/10/09 11:26:19 | 000,684,032 | —- | M] (Roxio) – C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
PRC - [2011/08/05 23:52:46 | 000,744,072 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\TrayNotify.exe
PRC - [2011/08/05 23:52:46 | 000,070,792 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\EuWatch.exe
PRC - [2011/08/05 23:52:46 | 000,060,040 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe
PRC - [2011/07/22 18:13:10 | 000,030,568 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PaperPort\pptd40nt.exe
PRC - [2011/07/22 18:12:04 | 000,138,600 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
PRC - [2011/07/01 00:07:24 | 000,607,592 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PDF Viewer Plus\PdfPro7Hook.exe
PRC - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/05/31 07:22:36 | 000,568,312 | —- | M] (Oberon Media ) – C:\Program Files\GamesBar\SearchEngineProtection.exe
PRC - [2010/05/21 12:40:26 | 000,324,976 | —- | M] (Flexera Software, Inc.) – C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/03/08 01:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1325351862\ee\aolupdates.exe
PRC - [2010/03/08 01:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/05 13:06:56 | 000,057,344 | —- | M] (Creative Technology Ltd) – C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe
PRC - [2006/10/23 06:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
PRC - [2002/10/15 14:37:50 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/17 03:28:58 | 000,169,984 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Automation\2060c6851428e508f673a0dfd819e5fb\Inkjet.Automation.ni.dll
MOD - [2012/02/17 03:28:44 | 000,098,304 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.DeviceSettin#\ad3980c979042cbcf8963a0e82fad500\Inkjet.DeviceSettings.ni.dll
MOD - [2012/02/17 03:28:09 | 000,771,584 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll
MOD - [2012/02/17 03:27:43 | 000,105,472 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Diagnostics\313de9c18ccddcf244989ca8f29b1f97\Inkjet.Diagnostics.ni.dll
MOD - [2012/02/17 03:27:41 | 000,237,056 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Localization\56696b3880309021b174d271ea96ff95\Inkjet.Localization.ni.dll
MOD - [2012/02/17 03:27:35 | 000,283,648 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Utilities\df0efdea1a90f47a74bdef0e44b03ca1\Inkjet.Utilities.ni.dll
MOD - [2012/02/17 03:27:24 | 000,824,320 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Hardware\8c7d08dd02d37cb7fab7a4d0c047d17b\Inkjet.Hardware.ni.dll
MOD - [2012/02/17 03:27:22 | 000,080,896 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Configuration\0664ade269ba04a1c292766bf6bdbfda\Inkjet.Configuration.ni.dll
MOD - [2012/02/17 03:27:19 | 000,180,736 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Statistics\1e8aad9950f2993546a3be08455d86f0\Inkjet.Statistics.ni.dll
MOD - [2012/02/17 03:27:07 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
MOD - [2012/02/17 03:23:54 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
MOD - [2012/02/17 03:23:43 | 012,430,848 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
MOD - [2012/02/17 03:23:08 | 001,587,200 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
MOD - [2012/02/17 03:19:49 | 007,953,408 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
MOD - [2012/01/10 23:51:34 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/05 23:51:58 | 000,064,648 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\TbTapeBrowse.dll
MOD - [2011/08/05 23:51:52 | 000,243,336 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\ExImage.dll
MOD - [2011/08/05 23:51:52 | 000,074,376 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\ExchBackupSize.dll
MOD - [2011/08/05 23:51:50 | 000,069,768 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\EnumTapeDevice.dll
MOD - [2011/08/05 23:51:50 | 000,051,848 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\CodeLog.dll
MOD - [2008/11/25 16:18:00 | 001,291,264 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\libxml2.dll
MOD - [2004/10/05 02:08:00 | 000,055,808 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\zlib1.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/12/19 16:32:26 | 000,394,672 | —- | M] (Eastman Kodak Company) [Auto | Running] – C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe – (Kodak AiO Network Discovery Service)
SRV - [2011/10/18 14:32:30 | 000,150,856 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2011/10/18 14:28:34 | 000,160,608 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV - [2011/10/18 14:28:18 | 000,166,288 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/08/05 23:52:46 | 000,060,040 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Auto | Running] – C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe – (EaseUS Agent)
SRV - [2011/07/22 18:12:04 | 000,138,600 | —- | M] (Nuance Communications, Inc.) [Auto | Running] – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe – (PDFProFiltSrvPP)
SRV - [2011/06/23 14:22:58 | 000,361,712 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2011/06/13 22:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2006/10/23 06:50:35 | 000,046,640 | R— | M] (AOL LLC) [On_Demand | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
SRV - [2002/10/15 14:37:50 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
========== Driver Services (SafeList) ==========
DRV - [2011/10/15 13:16:16 | 000,464,176 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/10/15 13:16:16 | 000,338,176 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/10/15 13:16:16 | 000,180,816 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/10/15 13:16:16 | 000,121,256 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2011/10/15 13:16:16 | 000,089,792 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/10/15 13:16:16 | 000,087,656 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/10/15 13:16:16 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/10/15 13:16:16 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/10/15 13:16:16 | 000,059,456 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/10/15 13:16:16 | 000,057,600 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/10/09 11:26:21 | 000,242,048 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\cdudf_xp.sys – (cdudf_xp)
DRV - [2011/10/09 11:26:21 | 000,206,464 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\udfreadr_xp.sys – (UdfReadr_xp)
DRV - [2011/10/09 11:26:21 | 000,151,066 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\pwd_2K.sys – (pwd_2k)
DRV - [2011/10/09 11:26:21 | 000,030,694 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Mmc_2k.sys – (mmc_2K)
DRV - [2011/10/09 11:26:21 | 000,025,962 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Dvd_2k.sys – (dvd_2K)
DRV - [2011/10/09 11:26:19 | 000,062,320 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp)
DRV - [2011/10/09 11:26:19 | 000,023,324 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k)
DRV - [2011/08/05 23:52:38 | 000,184,072 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EuFdDisk.sys – (EUFDDISK)
DRV - [2011/08/05 23:52:36 | 000,042,376 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\EUBKMON.sys – (EUBKMON)
DRV - [2011/08/05 23:52:30 | 000,016,008 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\eudskacs.sys – (EUDSKACS)
DRV - [2011/08/05 23:52:28 | 000,038,920 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\eubakup.sys – (EUBAKUP)
DRV - [2011/07/29 12:54:56 | 000,013,192 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv)
DRV - [2011/07/29 12:54:56 | 000,008,456 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv)
DRV - [2010/08/25 18:39:02 | 000,013,064 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\prwntdrv.sys – (prwntdrv)
DRV - [2009/02/26 00:29:58 | 001,142,272 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\P17.sys – (P17)
DRV - [2005/01/10 04:15:30 | 000,106,496 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv)
DRV - [2005/01/10 04:15:24 | 000,138,752 | R— | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k)
DRV - [2003/08/29 03:59:24 | 001,101,696 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMSM.sys – (BCMModem)
DRV - [2002/10/15 14:32:16 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/22 07:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 7A 9B 7C 2E EF CC 01 [binary data]
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
https://accounts.google.com/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3D2%26view%3Dcm%26fs%3D1%26tf%3D1%26to%26su%3DShareaholic%2Bhas%2Bbeen%2Bsuccessfully%2Binstalled.%26body%3DLink%3A%2Bhttp%3A%2F%2Fwww.shareaholic.com%2Ftools%2Ffirefox%2Fwelcome%2F3.0.1%2B%28via%2Bshareaholic.com%29%250D%250A%250D%250A&bsv;=llya694le36z&scc;=1
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: P:\ITUNES\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: C:\Program Files\EpicPlay\npEpicHost.dll ( )
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Viewer Plus\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/07 05:50:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/02/19 13:34:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/01/22 13:36:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/09 19:27:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/10/22 06:07:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Extensions
[2012/02/18 13:45:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Firefox\Profiles\reev6mht.default\extensions
[2011/10/22 06:07:39 | 000,000,000 | —D | M] (EpicPlay Games) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Firefox\Profiles\reev6mht.default\extensions\[removed]
[2011/10/09 19:27:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\PEGGY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\REEV6MHT.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\PEGGY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\REEV6MHT.DEFAULT\EXTENSIONS\[removed]
[2012/02/19 13:34:26 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/02/07 05:50:57 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/10/07 08:32:34 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/29 00:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/28 18:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/18 13:09:46 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/01/26 19:01:32 | 000,001,467 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober46392171.xml
[2011/12/21 10:42:07 | 000,001,467 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober615774250.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Mixesoft Click&Clean; Plug-In (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin/npccch32.dll
CHR - plugin: Bitdefender QuickScan (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin/npqscan.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: EpicPlay NPAPI Display Host (Enabled) = C:\Program Files\EpicPlay\npEpicHost.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: DocuCom PDF Plus (Enabled) = C:\Program Files\Nuance\PDF Viewer Plus\bin\nppdf.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Magic Actions for YouTube\u2122 = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\4.7_0\
CHR - Extension: Turn Off the Lights = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.0.0.53_0\
CHR - Extension: YouTube = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\
CHR - Extension: Click&Clean; = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\
CHR - Extension: LastPass = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.90.2_0\
CHR - Extension: Print = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idfnpgjblkahngbondojabhffkkdekbd\2.0.2.1_0\
CHR - Extension: Picnik = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\inmnggcpelemfookhlhkdfbechcdadfp\1.0.6_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Yidio = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kenklnagphgeldfpobjachbgpimaopbf\1.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: Google Mail Checker = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
CHR - Extension: Quick Note = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.2.9_0\
CHR - Extension: Ghostery = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\2.4.0_0\
CHR - Extension: Facebook Notifications = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: Google Chrome to Phone Extension = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
CHR - Extension: Google Reader = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: EpicPlay = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\plccnhhjonaiagjelpfkclblmlppjcik\
O1 HOSTS File: ([2002/09/03 13:39:21 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111231151040.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (GamesBarBHO Class) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\2.0.1.55\oberontb.dll (Oberon Media Ltd.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EaseUs Tray] C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EaseUs Watch] C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDFProHook] C:\Program Files\Nuance\PDF Viewer Plus\PdfPro7Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [SearchEngineProtection] C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://F:\PROGRA~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with PDF Viewer 7 - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - res://F:\PROGRA~1\Office14\ONBttnIE.dll/105 File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1317942221062 (MUWebControl Class)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A}
http://aolsvc.aol.com/onlinegames/luxor/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACC14ECB-787B-4C4F-B8EF-F64D987637F7}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Peggy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Peggy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/10/06 14:55:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/09/03 12:36:02 | 000,000,000 | —- | M] () - H:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell\AutoRun\command - "" = F:\StartClickFreeBackup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/19 22:00:23 | 000,583,680 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
[2012/02/19 13:35:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/02/19 12:59:29 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Peggy\Recent
[2012/02/19 12:32:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\Unused Desktop Shortcuts
[2012/02/19 11:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Local Settings\Application Data\FixItCenter
[2012/02/19 11:25:24 | 000,000,000 | —D | C] – C:\WINDOWS\MATS
[2012/02/19 11:25:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Fix it Center
[2012/02/18 13:15:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\ElevatedDiagnostics
[2012/02/18 13:14:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/02/18 13:13:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012/02/09 05:28:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote
[2012/02/08 04:16:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\image001
[2012/02/07 04:58:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\ATT00001
[2012/02/05 00:10:51 | 000,000,000 | —D | C] – C:\EaseUs
[2012/01/26 19:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\Oberon Media
[2012/01/26 19:01:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GamesBar
[2012/01/26 19:01:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2012/01/26 19:01:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Oberon Media
[2012/01/26 19:01:35 | 000,000,000 | —D | C] – C:\Program Files\GamesBar
[2012/01/23 13:54:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\RealNetworks
[2012/01/22 17:15:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\2011 10-01 Atlanta trip
[2012/01/22 17:15:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\2011 Florida Trip
[2012/01/22 17:15:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\2011 Holly Springs, MS
[2012/01/22 17:15:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\polyphemus
[2012/01/22 13:36:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2012/01/22 13:35:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2012/01/22 13:35:26 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2012/01/21 14:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Local Settings\Application Data\WMTools Downloaded Files
[2011/10/06 15:40:47 | 000,065,536 | R— | C] ( ) – C:\WINDOWS\System32\A3d.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/19 22:11:46 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
[2012/02/19 22:06:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-630328440-839522115-1003UA.job
[2012/02/19 22:02:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/19 18:07:45 | 000,000,249 | RHS- | M] () – C:\boot.ini
[2012/02/19 17:18:20 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C391DD8A-B008-4850-A2C9-0E127992F41B}.job
[2012/02/19 17:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/19 16:41:21 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/19 13:30:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/19 11:42:40 | 000,000,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/02/19 10:45:19 | 000,000,630 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\SIW.lnk
[2012/02/19 02:07:19 | 000,004,096 | -HS- | M] () – C:\{D4418025-3B61-43A0-B914-A709F4BCE5B1}.CBM
[2012/02/19 02:06:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-630328440-839522115-1003Core.job
[2012/02/19 01:00:10 | 000,306,176 | -HS- | M] () – C:\EUMONBMP.SYS
[2012/02/18 09:39:25 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2012/02/18 09:39:25 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2012/02/17 05:49:22 | 000,082,337 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Brown'sLanding.jpg
[2012/02/17 03:35:11 | 000,477,152 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/17 03:18:11 | 000,543,072 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/17 03:18:11 | 000,096,684 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/16 20:09:12 | 000,002,304 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Google Chrome.lnk
[2012/02/16 20:09:12 | 000,002,282 | —- | M] () – C:\Documents and Settings\Peggy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/16 05:17:38 | 000,536,442 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Redstart-2.jpg
[2012/02/14 06:39:52 | 002,607,361 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Machine_delivered_to_SA_without_instructions.wmv
[2012/02/09 05:28:04 | 000,015,561 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote.zip
[2012/02/08 04:16:45 | 000,432,996 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\image001.zip
[2012/02/07 04:58:10 | 000,018,944 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/07 04:58:01 | 001,924,016 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\ATT00001.zip
[2012/02/04 10:02:02 | 000,008,192 | -HS- | M] () – C:\ESLOADLX
[2012/02/04 10:01:57 | 000,194,388 | -HS- | M] () – C:\ESLDR
[2012/01/31 11:40:32 | 000,000,096 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\PP11Thumbs.ptn2
[2012/01/31 11:31:35 | 000,157,899 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\PP11Thumbs.ptn
[2012/01/31 11:31:35 | 000,000,374 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\maxdesk.ini2
[2012/01/26 06:11:25 | 000,002,459 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Microsoft Excel 2010.lnk
[2012/01/23 16:11:45 | 000,002,501 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Microsoft Word 2010.lnk
[2012/01/23 12:57:13 | 000,001,615 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2012/01/22 23:22:12 | 000,000,552 | —- | M] () – C:\WINDOWS\WM7.INI
[2012/01/22 23:21:46 | 000,000,702 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\wm7.lnk
[2012/01/22 18:43:17 | 000,000,059 | —- | M] () – C:\WINDOWS\webdial.ini
[2012/01/22 17:22:07 | 000,001,495 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Windows Explorer.lnk
[2012/01/22 13:35:26 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2012/01/22 05:50:43 | 007,012,352 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Hiver.pps
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/19 11:25:29 | 000,000,746 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/02/19 11:25:29 | 000,000,740 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/02/18 09:39:25 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2012/02/18 09:39:25 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2012/02/17 05:49:21 | 000,082,337 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Brown'sLanding.jpg
[2012/02/16 08:03:50 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/16 08:03:50 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/16 05:17:34 | 000,536,442 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Redstart-2.jpg
[2012/02/14 06:39:32 | 002,607,361 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Machine_delivered_to_SA_without_instructions.wmv
[2012/02/09 05:28:03 | 000,015,561 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote.zip
[2012/02/08 04:16:41 | 000,432,996 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\image001.zip
[2012/02/07 04:57:46 | 001,924,016 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\ATT00001.zip
[2012/02/05 03:51:58 | 000,004,096 | -HS- | C] () – C:\{D4418025-3B61-43A0-B914-A709F4BCE5B1}.CBM
[2012/02/04 22:38:42 | 000,306,176 | -HS- | C] () – C:\EUMONBMP.SYS
[2012/01/22 18:56:18 | 000,000,702 | —- | C] () – C:\Documents and Settings\Peggy\Desktop\wm7.lnk
[2012/01/22 18:43:17 | 000,000,059 | —- | C] () – C:\WINDOWS\webdial.ini
[2012/01/22 05:49:50 | 007,012,352 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Hiver.pps
[2012/01/21 16:14:42 | 000,001,615 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2011/12/31 12:41:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/12/31 11:08:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/12/24 14:16:01 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2011/10/13 22:12:50 | 000,109,300 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/10/09 23:47:14 | 000,000,552 | —- | C] () – C:\WINDOWS\WM7.INI
[2011/10/09 19:03:24 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2011/10/09 11:29:58 | 000,000,103 | —- | C] () – C:\WINDOWS\WININIT.INI
[2011/10/08 21:44:58 | 000,042,376 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/10/07 23:37:33 | 000,098,696 | —- | C] () – C:\WINDOWS\System32\setupprwdrv03.exe
[2011/10/07 23:37:33 | 000,013,064 | —- | C] () – C:\WINDOWS\System32\prwntdrv.sys
[2011/10/07 23:22:23 | 000,019,840 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2011/10/07 23:22:22 | 002,469,760 | —- | C] () – C:\WINDOWS\System32\BootMan.exe
[2011/10/07 23:22:22 | 000,086,408 | —- | C] () – C:\WINDOWS\System32\setupempdrv03.exe
[2011/10/07 23:22:21 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2011/10/07 23:22:21 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2011/10/07 10:54:10 | 000,018,944 | —- | C] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/06 23:09:19 | 010,080,316 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1417001333-630328440-839522115-1003-0.dat
[2011/10/06 23:09:17 | 000,379,550 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/10/06 21:00:22 | 000,000,299 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2011/10/06 18:14:59 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\P17.dll
[2011/10/06 18:14:59 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\P17CPI.dll
[2011/10/06 15:39:13 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2011/10/06 14:57:42 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/10/06 14:53:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/10/06 09:47:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/10/06 09:46:32 | 000,477,152 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/08/05 13:35:30 | 000,001,056 | —- | C] () – C:\WINDOWS\System32\EKaio2WiaCoInst.ini
[2011/07/22 17:32:34 | 000,034,326 | —- | C] () – C:\WINDOWS\MAXLINK.INI
========== LOP Check ==========
[2011/10/09 23:52:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AlawarWrapper
[2011/10/22 06:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/10/06 18:27:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2011/10/07 22:30:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2012/02/19 11:16:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2012/01/11 01:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2011/10/06 23:16:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2012/01/26 19:04:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2011/10/09 20:25:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/12/21 10:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2011/10/08 18:21:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OfficeGuardianV2
[2011/10/07 22:14:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/11/29 19:32:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2011/10/09 20:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/31 10:42:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/02/19 19:28:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2011/12/31 11:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/10/06 23:24:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2011/10/06 21:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zeon
[2011/10/13 21:57:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/01/14 06:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Temp
[2011/10/31 17:37:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Nuance
[2011/10/07 20:43:20 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Temp
[2012/01/15 06:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Temp
[2012/02/12 22:51:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\.oit
[2011/12/24 14:16:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Aisle 5 Games, Inc
[2011/10/07 23:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Auslogics
[2011/12/24 16:58:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\BloodTies
[2011/10/07 22:14:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\DriverCure
[2012/02/19 11:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\ElevatedDiagnostics
[2011/10/06 21:43:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Nuance
[2012/01/26 19:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Oberon Media
[2011/10/06 23:24:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\OpenCandy
[2011/10/06 19:03:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Skinux
[2011/10/06 19:57:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Temp
[2011/10/06 21:44:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Zeon
[2012/02/19 17:18:20 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C391DD8A-B008-4850-A2C9-0E127992F41B}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SVCHOST.EXE >
[2008/04/13 18:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 18:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/03 23:56:58 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >
[2004/08/03 23:56:58 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 18:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 18:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/03 23:56:58 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 18:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 18:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
[C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 -> Junction
[C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35] -> C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 220 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:FD9CE1F3
< End of report >
Thanks Richard Extras next post.