This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help analize my Hijack this log [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:51:09 PM, on 2/19/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe
C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe
C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\isuspm.exe
C:\Program Files\Nuance\PDF Viewer Plus\pdfpro7hook.exe
C:\Program Files\Common Files\AOL\1325351862\ee\AOLSoftware.exe
C:\Program Files\real\realplayer\update\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Gamesbar\SearchEngineProtection.exe
C:\WINDOWS\system32\rundll32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\AOL\1325351862\ee\aolupdates.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin\ClickClean.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\PROGRA~1\mcafee\SITEAD~1\saui.exe
C:\Program Files\SIW\siw.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Peggy\My Documents\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111231151040.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\2.0.1.55\oberontb.dll
O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [EaseUs Watch] "C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe"
O4 - HKLM\..\Run: [EaseUs Tray] "C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\\isuspm.exe -scheduler
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PDFProHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfpro7hook.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1325351862\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [EKAIO2StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SearchEngineProtection] C:\Program Files\Gamesbar\SearchEngineProtection.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [KodakHomeCenter] "C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [KodakHomeCenter] "C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Open with PDF Viewer 7 - res://C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
O8 - Extra context menu item: Se&nd to OneNote - res://F:\PROGRA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1317942221062
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://aolsvc.aol.com/onlinegames/luxor/mjolauncher.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EaseUS Agent - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 15392 bytes
Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
OTL
————-
  • Download OTL to your Desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.
Next

GMER Rootkit Scanner
—————
Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. uncheck the following:
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your Desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


In your next reply, please provide the following:
  • OTL log.
  • GMER log.



Regards,

Richard :wavey:
OTL logfile created on: 2/19/2012 10:31:12 PM - Run 1
OTL by OldTimer - Version 3.2.33.0 Folder = C:\Documents and Settings\Peggy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 82.00% Memory free
5.09 Gb Paging File | 4.50 Gb Available in Paging File | 88.29% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 235.85 Gb Free Space | 79.12% Space Free | Partition Type: NTFS
Drive H: | 232.88 Gb Total Space | 161.91 Gb Free Space | 69.52% Space Free | Partition Type: NTFS
Drive P: | 30.56 Gb Total Space | 26.05 Gb Free Space | 85.23% Space Free | Partition Type: NTFS
Drive U: | 465.54 Gb Total Space | 372.21 Gb Free Space | 79.95% Space Free | Partition Type: NTFS
Drive X: | 43.94 Gb Total Space | 30.46 Gb Free Space | 69.32% Space Free | Partition Type: NTFS

Computer Name: HOME-4600 | User Name: Peggy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/19 22:11:46 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
PRC - [2012/01/22 13:35:14 | 000,296,056 | —- | M] (RealNetworks, Inc.) – C:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2011/12/19 16:32:26 | 000,394,672 | —- | M] (Eastman Kodak Company) – C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011/12/10 10:25:36 | 002,756,608 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe
PRC - [2011/11/22 17:18:26 | 001,318,816 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/10/18 14:32:30 | 000,150,856 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2011/10/18 14:28:34 | 000,160,608 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/10/18 14:28:18 | 000,166,288 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/10/09 11:26:19 | 000,684,032 | —- | M] (Roxio) – C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
PRC - [2011/08/05 23:52:46 | 000,744,072 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\TrayNotify.exe
PRC - [2011/08/05 23:52:46 | 000,070,792 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\EuWatch.exe
PRC - [2011/08/05 23:52:46 | 000,060,040 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe
PRC - [2011/07/22 18:13:10 | 000,030,568 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PaperPort\pptd40nt.exe
PRC - [2011/07/22 18:12:04 | 000,138,600 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
PRC - [2011/07/01 00:07:24 | 000,607,592 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PDF Viewer Plus\PdfPro7Hook.exe
PRC - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/05/31 07:22:36 | 000,568,312 | —- | M] (Oberon Media ) – C:\Program Files\GamesBar\SearchEngineProtection.exe
PRC - [2010/05/21 12:40:26 | 000,324,976 | —- | M] (Flexera Software, Inc.) – C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/03/08 01:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1325351862\ee\aolupdates.exe
PRC - [2010/03/08 01:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/05 13:06:56 | 000,057,344 | —- | M] (Creative Technology Ltd) – C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe
PRC - [2006/10/23 06:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
PRC - [2002/10/15 14:37:50 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/17 03:28:58 | 000,169,984 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Automation\2060c6851428e508f673a0dfd819e5fb\Inkjet.Automation.ni.dll
MOD - [2012/02/17 03:28:44 | 000,098,304 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.DeviceSettin#\ad3980c979042cbcf8963a0e82fad500\Inkjet.DeviceSettings.ni.dll
MOD - [2012/02/17 03:28:09 | 000,771,584 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll
MOD - [2012/02/17 03:27:43 | 000,105,472 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Diagnostics\313de9c18ccddcf244989ca8f29b1f97\Inkjet.Diagnostics.ni.dll
MOD - [2012/02/17 03:27:41 | 000,237,056 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Localization\56696b3880309021b174d271ea96ff95\Inkjet.Localization.ni.dll
MOD - [2012/02/17 03:27:35 | 000,283,648 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Utilities\df0efdea1a90f47a74bdef0e44b03ca1\Inkjet.Utilities.ni.dll
MOD - [2012/02/17 03:27:24 | 000,824,320 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Hardware\8c7d08dd02d37cb7fab7a4d0c047d17b\Inkjet.Hardware.ni.dll
MOD - [2012/02/17 03:27:22 | 000,080,896 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Configuration\0664ade269ba04a1c292766bf6bdbfda\Inkjet.Configuration.ni.dll
MOD - [2012/02/17 03:27:19 | 000,180,736 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Statistics\1e8aad9950f2993546a3be08455d86f0\Inkjet.Statistics.ni.dll
MOD - [2012/02/17 03:27:07 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
MOD - [2012/02/17 03:23:54 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
MOD - [2012/02/17 03:23:43 | 012,430,848 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
MOD - [2012/02/17 03:23:08 | 001,587,200 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
MOD - [2012/02/17 03:19:49 | 007,953,408 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
MOD - [2012/01/10 23:51:34 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/05 23:51:58 | 000,064,648 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\TbTapeBrowse.dll
MOD - [2011/08/05 23:51:52 | 000,243,336 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\ExImage.dll
MOD - [2011/08/05 23:51:52 | 000,074,376 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\ExchBackupSize.dll
MOD - [2011/08/05 23:51:50 | 000,069,768 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\EnumTapeDevice.dll
MOD - [2011/08/05 23:51:50 | 000,051,848 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\CodeLog.dll
MOD - [2008/11/25 16:18:00 | 001,291,264 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\libxml2.dll
MOD - [2004/10/05 02:08:00 | 000,055,808 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\zlib1.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/12/19 16:32:26 | 000,394,672 | —- | M] (Eastman Kodak Company) [Auto | Running] – C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe – (Kodak AiO Network Discovery Service)
SRV - [2011/10/18 14:32:30 | 000,150,856 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2011/10/18 14:28:34 | 000,160,608 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV - [2011/10/18 14:28:18 | 000,166,288 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/08/05 23:52:46 | 000,060,040 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Auto | Running] – C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe – (EaseUS Agent)
SRV - [2011/07/22 18:12:04 | 000,138,600 | —- | M] (Nuance Communications, Inc.) [Auto | Running] – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe – (PDFProFiltSrvPP)
SRV - [2011/06/23 14:22:58 | 000,361,712 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2011/06/13 22:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2006/10/23 06:50:35 | 000,046,640 | R— | M] (AOL LLC) [On_Demand | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
SRV - [2002/10/15 14:37:50 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)


========== Driver Services (SafeList) ==========

DRV - [2011/10/15 13:16:16 | 000,464,176 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/10/15 13:16:16 | 000,338,176 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/10/15 13:16:16 | 000,180,816 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/10/15 13:16:16 | 000,121,256 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2011/10/15 13:16:16 | 000,089,792 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/10/15 13:16:16 | 000,087,656 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/10/15 13:16:16 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/10/15 13:16:16 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/10/15 13:16:16 | 000,059,456 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/10/15 13:16:16 | 000,057,600 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/10/09 11:26:21 | 000,242,048 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\cdudf_xp.sys – (cdudf_xp)
DRV - [2011/10/09 11:26:21 | 000,206,464 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\udfreadr_xp.sys – (UdfReadr_xp)
DRV - [2011/10/09 11:26:21 | 000,151,066 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\pwd_2K.sys – (pwd_2k)
DRV - [2011/10/09 11:26:21 | 000,030,694 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Mmc_2k.sys – (mmc_2K)
DRV - [2011/10/09 11:26:21 | 000,025,962 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Dvd_2k.sys – (dvd_2K)
DRV - [2011/10/09 11:26:19 | 000,062,320 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp)
DRV - [2011/10/09 11:26:19 | 000,023,324 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k)
DRV - [2011/08/05 23:52:38 | 000,184,072 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EuFdDisk.sys – (EUFDDISK)
DRV - [2011/08/05 23:52:36 | 000,042,376 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\EUBKMON.sys – (EUBKMON)
DRV - [2011/08/05 23:52:30 | 000,016,008 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\eudskacs.sys – (EUDSKACS)
DRV - [2011/08/05 23:52:28 | 000,038,920 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\eubakup.sys – (EUBAKUP)
DRV - [2011/07/29 12:54:56 | 000,013,192 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv)
DRV - [2011/07/29 12:54:56 | 000,008,456 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv)
DRV - [2010/08/25 18:39:02 | 000,013,064 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\prwntdrv.sys – (prwntdrv)
DRV - [2009/02/26 00:29:58 | 001,142,272 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\P17.sys – (P17)
DRV - [2005/01/10 04:15:30 | 000,106,496 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv)
DRV - [2005/01/10 04:15:24 | 000,138,752 | R— | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k)
DRV - [2003/08/29 03:59:24 | 001,101,696 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMSM.sys – (BCMModem)
DRV - [2002/10/15 14:32:16 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/22 07:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 7A 9B 7C 2E EF CC 01 [binary data]
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://accounts.google.com/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3D2%26view%3Dcm%26fs%3D1%26tf%3D1%26to%26su%3DShareaholic%2Bhas%2Bbeen%2Bsuccessfully%2Binstalled.%26body%3DLink%3A%2Bhttp%3A%2F%2Fwww.shareaholic.com%2Ftools%2Ffirefox%2Fwelcome%2F3.0.1%2B%28via%2Bshareaholic.com%29%250D%250A%250D%250A&bsv;=llya694le36z&scc;=1
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: P:\ITUNES\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: C:\Program Files\EpicPlay\npEpicHost.dll ( )
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Viewer Plus\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/07 05:50:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/02/19 13:34:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/01/22 13:36:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/09 19:27:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/10/22 06:07:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Extensions
[2012/02/18 13:45:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Firefox\Profiles\reev6mht.default\extensions
[2011/10/22 06:07:39 | 000,000,000 | —D | M] (EpicPlay Games) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Firefox\Profiles\reev6mht.default\extensions\[removed]
[2011/10/09 19:27:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\PEGGY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\REEV6MHT.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\PEGGY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\REEV6MHT.DEFAULT\EXTENSIONS\[removed]
[2012/02/19 13:34:26 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/02/07 05:50:57 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/10/07 08:32:34 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/29 00:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/28 18:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/18 13:09:46 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/01/26 19:01:32 | 000,001,467 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober46392171.xml
[2011/12/21 10:42:07 | 000,001,467 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober615774250.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Mixesoft Click&Clean; Plug-In (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin/npccch32.dll
CHR - plugin: Bitdefender QuickScan (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin/npqscan.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: EpicPlay NPAPI Display Host (Enabled) = C:\Program Files\EpicPlay\npEpicHost.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: DocuCom PDF Plus (Enabled) = C:\Program Files\Nuance\PDF Viewer Plus\bin\nppdf.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Magic Actions for YouTube\u2122 = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\4.7_0\
CHR - Extension: Turn Off the Lights = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.0.0.53_0\
CHR - Extension: YouTube = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.122.1_0\
CHR - Extension: Click&Clean; = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\
CHR - Extension: LastPass = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.90.2_0\
CHR - Extension: Print = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idfnpgjblkahngbondojabhffkkdekbd\2.0.2.1_0\
CHR - Extension: Picnik = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\inmnggcpelemfookhlhkdfbechcdadfp\1.0.6_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Yidio = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kenklnagphgeldfpobjachbgpimaopbf\1.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: Google Mail Checker = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
CHR - Extension: Quick Note = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.2.9_0\
CHR - Extension: Ghostery = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\2.4.0_0\
CHR - Extension: Facebook Notifications = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: Google Chrome to Phone Extension = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
CHR - Extension: Google Reader = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: EpicPlay = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\plccnhhjonaiagjelpfkclblmlppjcik\

O1 HOSTS File: ([2002/09/03 13:39:21 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111231151040.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (GamesBarBHO Class) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\2.0.1.55\oberontb.dll (Oberon Media Ltd.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EaseUs Tray] C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EaseUs Watch] C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PDFProHook] C:\Program Files\Nuance\PDF Viewer Plus\PdfPro7Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [SearchEngineProtection] C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://F:\PROGRA~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with PDF Viewer 7 - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - res://F:\PROGRA~1\Office14\ONBttnIE.dll/105 File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1317942221062 (MUWebControl Class)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://aolsvc.aol.com/onlinegames/luxor/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACC14ECB-787B-4C4F-B8EF-F64D987637F7}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Peggy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Peggy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/10/06 14:55:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/09/03 12:36:02 | 000,000,000 | —- | M] () - H:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell\AutoRun\command - "" = F:\StartClickFreeBackup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/19 22:00:23 | 000,583,680 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
[2012/02/19 13:35:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/02/19 12:59:29 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Peggy\Recent
[2012/02/19 12:32:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\Unused Desktop Shortcuts
[2012/02/19 11:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Local Settings\Application Data\FixItCenter
[2012/02/19 11:25:24 | 000,000,000 | —D | C] – C:\WINDOWS\MATS
[2012/02/19 11:25:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Fix it Center
[2012/02/18 13:15:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\ElevatedDiagnostics
[2012/02/18 13:14:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/02/18 13:13:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012/02/09 05:28:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote
[2012/02/08 04:16:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\image001
[2012/02/07 04:58:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\ATT00001
[2012/02/05 00:10:51 | 000,000,000 | —D | C] – C:\EaseUs
[2012/01/26 19:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\Oberon Media
[2012/01/26 19:01:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GamesBar
[2012/01/26 19:01:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2012/01/26 19:01:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Oberon Media
[2012/01/26 19:01:35 | 000,000,000 | —D | C] – C:\Program Files\GamesBar
[2012/01/23 13:54:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\RealNetworks
[2012/01/22 17:15:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\2011 10-01 Atlanta trip
[2012/01/22 17:15:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\2011 Florida Trip
[2012/01/22 17:15:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\2011 Holly Springs, MS
[2012/01/22 17:15:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\polyphemus
[2012/01/22 13:36:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2012/01/22 13:35:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2012/01/22 13:35:26 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2012/01/21 14:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Local Settings\Application Data\WMTools Downloaded Files
[2011/10/06 15:40:47 | 000,065,536 | R— | C] ( ) – C:\WINDOWS\System32\A3d.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/19 22:11:46 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
[2012/02/19 22:06:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-630328440-839522115-1003UA.job
[2012/02/19 22:02:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/19 18:07:45 | 000,000,249 | RHS- | M] () – C:\boot.ini
[2012/02/19 17:18:20 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C391DD8A-B008-4850-A2C9-0E127992F41B}.job
[2012/02/19 17:02:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/19 16:41:21 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/19 13:30:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/19 11:42:40 | 000,000,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/02/19 10:45:19 | 000,000,630 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\SIW.lnk
[2012/02/19 02:07:19 | 000,004,096 | -HS- | M] () – C:\{D4418025-3B61-43A0-B914-A709F4BCE5B1}.CBM
[2012/02/19 02:06:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-630328440-839522115-1003Core.job
[2012/02/19 01:00:10 | 000,306,176 | -HS- | M] () – C:\EUMONBMP.SYS
[2012/02/18 09:39:25 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2012/02/18 09:39:25 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2012/02/17 05:49:22 | 000,082,337 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Brown'sLanding.jpg
[2012/02/17 03:35:11 | 000,477,152 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/17 03:18:11 | 000,543,072 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/17 03:18:11 | 000,096,684 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/16 20:09:12 | 000,002,304 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Google Chrome.lnk
[2012/02/16 20:09:12 | 000,002,282 | —- | M] () – C:\Documents and Settings\Peggy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/16 05:17:38 | 000,536,442 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Redstart-2.jpg
[2012/02/14 06:39:52 | 002,607,361 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Machine_delivered_to_SA_without_instructions.wmv
[2012/02/09 05:28:04 | 000,015,561 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote.zip
[2012/02/08 04:16:45 | 000,432,996 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\image001.zip
[2012/02/07 04:58:10 | 000,018,944 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/07 04:58:01 | 001,924,016 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\ATT00001.zip
[2012/02/04 10:02:02 | 000,008,192 | -HS- | M] () – C:\ESLOADLX
[2012/02/04 10:01:57 | 000,194,388 | -HS- | M] () – C:\ESLDR
[2012/01/31 11:40:32 | 000,000,096 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\PP11Thumbs.ptn2
[2012/01/31 11:31:35 | 000,157,899 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\PP11Thumbs.ptn
[2012/01/31 11:31:35 | 000,000,374 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\maxdesk.ini2
[2012/01/26 06:11:25 | 000,002,459 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Microsoft Excel 2010.lnk
[2012/01/23 16:11:45 | 000,002,501 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Microsoft Word 2010.lnk
[2012/01/23 12:57:13 | 000,001,615 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2012/01/22 23:22:12 | 000,000,552 | —- | M] () – C:\WINDOWS\WM7.INI
[2012/01/22 23:21:46 | 000,000,702 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\wm7.lnk
[2012/01/22 18:43:17 | 000,000,059 | —- | M] () – C:\WINDOWS\webdial.ini
[2012/01/22 17:22:07 | 000,001,495 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Windows Explorer.lnk
[2012/01/22 13:35:26 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2012/01/22 05:50:43 | 007,012,352 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Hiver.pps
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/19 11:25:29 | 000,000,746 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/02/19 11:25:29 | 000,000,740 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/02/18 09:39:25 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2012/02/18 09:39:25 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2012/02/17 05:49:21 | 000,082,337 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Brown'sLanding.jpg
[2012/02/16 08:03:50 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/16 08:03:50 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/16 05:17:34 | 000,536,442 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Redstart-2.jpg
[2012/02/14 06:39:32 | 002,607,361 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Machine_delivered_to_SA_without_instructions.wmv
[2012/02/09 05:28:03 | 000,015,561 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote.zip
[2012/02/08 04:16:41 | 000,432,996 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\image001.zip
[2012/02/07 04:57:46 | 001,924,016 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\ATT00001.zip
[2012/02/05 03:51:58 | 000,004,096 | -HS- | C] () – C:\{D4418025-3B61-43A0-B914-A709F4BCE5B1}.CBM
[2012/02/04 22:38:42 | 000,306,176 | -HS- | C] () – C:\EUMONBMP.SYS
[2012/01/22 18:56:18 | 000,000,702 | —- | C] () – C:\Documents and Settings\Peggy\Desktop\wm7.lnk
[2012/01/22 18:43:17 | 000,000,059 | —- | C] () – C:\WINDOWS\webdial.ini
[2012/01/22 05:49:50 | 007,012,352 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Hiver.pps
[2012/01/21 16:14:42 | 000,001,615 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2011/12/31 12:41:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/12/31 11:08:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/12/24 14:16:01 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2011/10/13 22:12:50 | 000,109,300 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/10/09 23:47:14 | 000,000,552 | —- | C] () – C:\WINDOWS\WM7.INI
[2011/10/09 19:03:24 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2011/10/09 11:29:58 | 000,000,103 | —- | C] () – C:\WINDOWS\WININIT.INI
[2011/10/08 21:44:58 | 000,042,376 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/10/07 23:37:33 | 000,098,696 | —- | C] () – C:\WINDOWS\System32\setupprwdrv03.exe
[2011/10/07 23:37:33 | 000,013,064 | —- | C] () – C:\WINDOWS\System32\prwntdrv.sys
[2011/10/07 23:22:23 | 000,019,840 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2011/10/07 23:22:22 | 002,469,760 | —- | C] () – C:\WINDOWS\System32\BootMan.exe
[2011/10/07 23:22:22 | 000,086,408 | —- | C] () – C:\WINDOWS\System32\setupempdrv03.exe
[2011/10/07 23:22:21 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2011/10/07 23:22:21 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2011/10/07 10:54:10 | 000,018,944 | —- | C] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/06 23:09:19 | 010,080,316 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1417001333-630328440-839522115-1003-0.dat
[2011/10/06 23:09:17 | 000,379,550 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/10/06 21:00:22 | 000,000,299 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2011/10/06 18:14:59 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\P17.dll
[2011/10/06 18:14:59 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\P17CPI.dll
[2011/10/06 15:39:13 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2011/10/06 14:57:42 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/10/06 14:53:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/10/06 09:47:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/10/06 09:46:32 | 000,477,152 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/08/05 13:35:30 | 000,001,056 | —- | C] () – C:\WINDOWS\System32\EKaio2WiaCoInst.ini
[2011/07/22 17:32:34 | 000,034,326 | —- | C] () – C:\WINDOWS\MAXLINK.INI

========== LOP Check ==========

[2011/10/09 23:52:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AlawarWrapper
[2011/10/22 06:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2011/10/06 18:27:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2011/10/07 22:30:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2012/02/19 11:16:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2012/01/11 01:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2011/10/06 23:16:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2012/01/26 19:04:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2011/10/09 20:25:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/12/21 10:42:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2011/10/08 18:21:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OfficeGuardianV2
[2011/10/07 22:14:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2011/11/29 19:32:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2011/10/09 20:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/31 10:42:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2012/02/19 19:28:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2011/12/31 11:19:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/10/06 23:24:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2011/10/06 21:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zeon
[2011/10/13 21:57:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/01/14 06:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Temp
[2011/10/31 17:37:48 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Nuance
[2011/10/07 20:43:20 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Temp
[2012/01/15 06:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Temp
[2012/02/12 22:51:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\.oit
[2011/12/24 14:16:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Aisle 5 Games, Inc
[2011/10/07 23:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Auslogics
[2011/12/24 16:58:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\BloodTies
[2011/10/07 22:14:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\DriverCure
[2012/02/19 11:23:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\ElevatedDiagnostics
[2011/10/06 21:43:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Nuance
[2012/01/26 19:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Oberon Media
[2011/10/06 23:24:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\OpenCandy
[2011/10/06 19:03:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Skinux
[2011/10/06 19:57:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Temp
[2011/10/06 21:44:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Peggy\Application Data\Zeon
[2012/02/19 17:18:20 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{C391DD8A-B008-4850-A2C9-0E127992F41B}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/03 23:56:50 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/13 18:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 18:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/03 23:56:58 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/03 23:56:58 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 18:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 18:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/03 23:56:58 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 18:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 18:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
[C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 -> Junction
[C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\v4.0_4.0.0.0__31bf3856ad364e35] -> C:\WINDOWS\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 220 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:FD9CE1F3

< End of report >
Thanks Richard Extras next post.
OTL Extras logfile created on: 2/19/2012 10:14:27 PM - Run 1
OTL by OldTimer - Version 3.2.33.0 Folder = C:\Documents and Settings\Peggy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.70 Gb Available Physical Memory | 83.04% Memory free
5.09 Gb Paging File | 4.52 Gb Available in Paging File | 88.68% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 235.88 Gb Free Space | 79.13% Space Free | Partition Type: NTFS
Drive H: | 232.88 Gb Total Space | 161.91 Gb Free Space | 69.52% Space Free | Partition Type: NTFS
Drive P: | 30.56 Gb Total Space | 26.05 Gb Free Space | 85.23% Space Free | Partition Type: NTFS
Drive U: | 465.54 Gb Total Space | 372.21 Gb Free Space | 79.95% Space Free | Partition Type: NTFS
Drive X: | 43.94 Gb Total Space | 30.46 Gb Free Space | 69.32% Space Free | Partition Type: NTFS

Computer Name: HOME-4600 | User Name: Peggy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5353:UDP" = 5353:UDP:*:Enabled:Bonjour Port 5353
"9322:TCP" = 9322:TCP:*:Enabled:EKDiscovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0 – (CyberLink Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:Kodak EasyShare Software
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe" = C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0 – (CyberLink Corp.)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"F:\Program Files\Office14\ONENOTE.EXE" = F:\Program Files\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote
"C:\Program Files\Logitech\Vid HD\Vid.exe" = C:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD – (Logitech Inc.)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"P:\ITUNES\iTunes.exe" = P:\ITUNES\iTunes.exe:*:Enabled:iTunes
"C:\Program Files\Common Files\AOL\acs\AOLDial.exe" = C:\Program Files\Common Files\AOL\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer – (America Online)
"C:\Program Files\Common Files\AOL\acs\AOLacsd.exe" = C:\Program Files\Common Files\AOL\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service – (AOL LLC)
"C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\waol.exe" = C:\Program Files\AOL Desktop 9.7\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" = C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe:*:Enabled:Kodak.AiO.HomeCenter – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\Kodak.Statistics.exe" = C:\Program Files\Kodak\AiO\Center\Kodak.Statistics.exe:*:Enabled:Kodak.AiO.Statistics – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe" = C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe:*:Enabled:Kodak.AiO.SetupUtility – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Firmware\KodakAiOUpdater.exe" = C:\Program Files\Kodak\AiO\Firmware\KodakAiOUpdater.exe:*:Enabled:Kodak.AiO.FwUpdater – (Eastman Kodak Company)
"C:\Documents and Settings\All Users\Application Data\Kodak\Installer\Setup.exe" = C:\Documents and Settings\All Users\Application Data\Kodak\Installer\Setup.exe:*:Enabled:Kodak.AiO.Installer – (Eastman Kodak Company)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam
"{042A6F10-F770-4886-A502-B795DCF2D3B5}" = Nuance PDF Viewer Plus
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1E0D8F69-A6AB-4934-9B2D-159D9F97BA4A}" = ParetoLogic DriverCure
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG Power Tools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2928F0D5-DABC-4637-A6B3-740629075555}" = RocketFish 5.1 PCI Sound Card
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = LG CyberLink PowerDVD
"{2C0A655C-61E7-428A-8ED2-23A3D20E7DD2}" = Data Lifeguard Tools
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = BACS
"{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater
"{52357C6C-FE7F-4E8C-B045-EDE5146A1F9C}" = PaperPort Anywhere 1.1.4269.39023 powered by OfficeDrop
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.77
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048
"{5E453519-60F6-4A4D-A0BF-16663F9B3536}" = Safari
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update
"{6D3BD056-5434-4473-A995-01965DEF1786}" = Nuance PaperPort 14
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7E482AF6-AA1F-4CC5-BA13-0536675F5744}" = ASPCA TriMini Reminder by We-Care.com v5.0.2.1
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A35C2323-3CEA-405C-9569-EF5DDE930B2F}" = PrintMaster
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2011.10.29
"{ADD5DB49-72CF-11D8-9D75-000129760D75}" = LG CyberLink PowerBackup
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = LG CyberLink PowerProducer
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = B57Inst
"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials
"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D5F881C2-B134-474E-AA60-B25DD218AE0D}" = Crash Analysis Tool
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Software
"{E5C1F2BF-9E5F-4A80-87B5-2C5ECC16560C}" = birdJam Maker
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BFGC" = Big Fish Games: Game Manager
"CCleaner" = CCleaner
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 9.1.0 Home Edition
"EASEUS Partition Recovery_is1" = EASEUS Partition Recovery 5.0.1
"EaseUS Todo Backup Free 3.0_is1" = EaseUS Todo Backup Free 3.0
"GamesBar" = GamesBar [removed]
"ie8" = Windows Internet Explorer 8
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG Power Tools
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = LG CyberLink PowerDVD
"InstallShield_{468190DA-FB4C-45BA-8E40-4B165FF1A939}" = Broadcom Advanced Control Suite
"InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = LG CyberLink PowerProducer
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Driver Installer
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint
"Logitech Vid" = Logitech Vid HD
"McAfee Virtual Technician" = McAfee Virtual Technician
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Midnight Mysteries Salem Witch Trials" = Midnight Mysteries Salem Witch Trials
"Midnight Mysteries The Edgar Allan Poe Conspiracy" = Midnight Mysteries The Edgar Allan Poe Conspiracy
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"MSC" = McAfee AntiVirus Plus
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 15.0" = RealPlayer
"Shockwave" = Shockwave
"The Print Shop 6.0" = The Print Shop®
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"Tweak UI 2.10" = Tweak UI
"ViewpointMediaPlayer" = Viewpoint Media Player
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BloodTies" = BloodTies
"Google Chrome" = Google Chrome
"Interpol" = Interpol

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/19/2012 9:25:53 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/19/2012 9:25:53 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3639515

Error - 2/19/2012 9:25:53 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3639515

Error - 2/19/2012 11:52:56 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/19/2012 11:52:56 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4703390

Error - 2/19/2012 11:52:56 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4703390

Error - 2/19/2012 11:52:58 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/19/2012 11:52:58 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4705343

Error - 2/19/2012 11:52:58 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4705343

Error - 2/20/2012 12:04:29 AM | Computer Name = HOME-4600 | Source = ESENT | ID = 623
Description = wuaueng.dll (4636) SUS20ClientDataStore: The version store for this
instance (0) has reached its maximum size of 8Mb. It is likely that a long-running
transaction is preventing cleanup of the version store and causing it to build
up in size. Updates will be rejected until the long-running transaction has been
completely committed or rolled back. Possible long-running transaction: SessionId:
0x025903C0 Session-context: 0x00000000 Session-context ThreadId: 0x00001138

[ System Events ]
Error - 2/12/2012 10:40:00 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/12/2012 10:52:00 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/12/2012 11:04:00 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/12/2012 11:16:00 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/12/2012 11:28:00 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/12/2012 11:40:01 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/12/2012 11:52:01 PM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/13/2012 12:04:01 AM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/13/2012 12:16:01 AM | Computer Name = HOME-4600 | Source = DCOM | ID = 10010
Description = The server {548E275F-0290-40E7-B454-738B0C61DE60} did not register
with DCOM within the required timeout.

Error - 2/19/2012 3:30:41 PM | Computer Name = HOME-4600 | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer PaperPort Image Printer share
name Printer3.


< End of report >
GMER next reply
Thanks for the information :thumbup:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O3 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: internet ([]about in Trusted sites)
    O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\Shell\AutoRun\command - "" = F:\StartClickFreeBackup.exe
    @Alternate Data Stream - 220 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:FD9CE1F3
      
    :Commands
    [purity] 
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done.
  • When the computer has rebooted, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date/time of the tool run.
  • Copy and paste the contents of that report in your next reply.
Next

Reconfigure Windows XP to show hidden files and folders:
  • Click Start and open My Computer.
  • Select the Tools menu and click Folder Options then select the View tab.
  • Under the Hidden files and folders heading select "Show hidden files and folders".
  • Uncheck the "Hide protected operating system files (recommended)" option.
  • Uncheck the "Hide file extensions for known file types" option.
  • Click Yes to confirm then click OK.
Next

Please go to VirusTotal.
  • Click Choose File and browse to the file listed below in bold and click Scan it!.

    C:\ESLDR

  • There might be a short wait.
  • Select Reanalyse file and post back with the results of the scan.
  • Do the same for:

    C:\ESLOADLX
In your next reply, please provide the following:
  • OTL log.
  • VirusTotal results.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Richard, I am at work for the rest of the week out of town I have a territory away from home. When I get home on Friday I will complete your request. Only at my home computer Friday thru Sunday sometimes on Monday. Don't give up on me!!! Thanks! :D
All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry key HKEY_USERS\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internet\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4cc2c8ea-f0fb-11e0-93b9-00038a000015}\ not found. File F:\StartClickFreeBackup.exe not found. ADS C:\Documents and Settings\All Users\Application Data\Temp:FD9CE1F3 deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users ->Flash cache emptied: 43 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 70272 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 634842 bytes User: Peggy ->Temp folder emptied: 14487211 bytes ->Temporary Internet Files folder emptied: 82399501 bytes ->FireFox cache emptied: 48914452 bytes ->Google Chrome cache emptied: 48950380 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 8205456 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1145933 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 573 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 103172928 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33924 bytes RecycleBin emptied: 62898674 bytes Total Files Cleaned = 354.00 mb OTL by OldTimer - Version 3.2.33.0 log created on 02242012_210520 Files\Folders moved on Reboot… C:\Documents and Settings\Peggy\Local Settings\Temp\CMLS–2012-02-24–21-05-34.log moved successfully. Registry entries deleted on Reboot… Per your request Richard!
SHA256: 7d4589979677277d01b2094089397afc31d4b8296cfcbecd42ce4c9f34b2b15a File name: ESLDR Detection ratio: 1 / 43 Analysis date: 2012-02-25 03:17:13 UTC ( 1 minute ago ) 00 Antivirus Result Update AhnLab-V3 - 20120224 AntiVir - 20120224 Antiy-AVL - 20120225 Avast - 20120224 AVG - 20120225 BitDefender - 20120225 ByteHero - 20120222 CAT-QuickHeal - 20120224 ClamAV - 20120225 Commtouch - 20120224 Comodo - 20120225 DrWeb - 20120225 Emsisoft - 20120225 eSafe - 20120223 eTrust-Vet - 20120225 F-Prot - 20120224 F-Secure - 20120224 Fortinet - 20120223 GData - 20120225 Ikarus - 20120224 Jiangmin - 20120224 K7AntiVirus - 20120222 Kaspersky - 20120225 McAfee - 20120225 McAfee-GW-Edition Heuristic.BehavesLike.Exploit.CodeExec.EOOJ 20120225 Microsoft - 20120224 NOD32 - 20120225 Norman - 20120224 nProtect - 20120224 Panda - 20120224 PCTools - 20120224 Prevx - 20120225 Rising - 20120224 Sophos - 20120225 SUPERAntiSpyware - 20120223 Symantec - 20120225 TheHacker - 20120224 TrendMicro - 20120224 TrendMicro-HouseCall - 20120225 VBA32 - 20120224 VIPRE - 20120224 ViRobot - 20120224 VirusBuster - 20120224 Comments Additional information ssdeep 3072:exm1NJrXqqbg6F9a23iW3EG5o0Nuhnq+OlxFaWDFkNMq2H+jLhKEOaA63NHov:eIzkqFa23iMEG C0R+O/FImrc9Ua/NIv TrID Unknown! First seen by VirusTotal 2011-07-15 02:55:11 UTC ( 7 months, 2 weeks ago ) Last seen by VirusTotal 2012-02-25 03:17:13 UTC ( 1 minute ago ) File names (max. 25) ESLDR EASEUSLD.LDR ESLDR e450c697aa8c4a95d0de7dd427b70206 Blog | Twitter | [removed] | Google groups | TOS & Privacy Policy Esldr request!
SHA256: 89cd05a112694c0ad9898746e24b386551d79270859f69004e56fad0c91d81e5 File name: ESLOADLX Detection ratio: 0 / 43 Analysis date: 2012-02-25 03:23:50 UTC ( 1 minute ago ) 00 Antivirus Result Update AhnLab-V3 - 20120224 AntiVir - 20120224 Antiy-AVL - 20120225 Avast - 20120224 AVG - 20120225 BitDefender - 20120225 ByteHero - 20120222 CAT-QuickHeal - 20120224 ClamAV - 20120225 Commtouch - 20120224 Comodo - 20120225 DrWeb - 20120225 Emsisoft - 20120225 eSafe - 20120223 eTrust-Vet - 20120225 F-Prot - 20120224 F-Secure - 20120224 Fortinet - 20120223 GData - 20120225 Ikarus - 20120224 Jiangmin - 20120224 K7AntiVirus - 20120222 Kaspersky - 20120225 McAfee - 20120225 McAfee-GW-Edition - 20120225 Microsoft - 20120224 NOD32 - 20120225 Norman - 20120224 nProtect - 20120224 Panda - 20120224 PCTools - 20120224 Prevx - 20120225 Rising - 20120224 Sophos - 20120225 SUPERAntiSpyware - 20120223 Symantec - 20120225 TheHacker - 20120224 TrendMicro - 20120224 TrendMicro-HouseCall - 20120225 VBA32 - 20120224 VIPRE - 20120224 ViRobot - 20120225 VirusBuster - 20120224 Comments Additional information No comments Per your request ESLOADLX
I already sent the virus total results and below is the OTL Log per your request. Computer seams to be faster but I just got home tonight and have not had much time to check it out and see if the CPU usage is spiking to 100%. The drive still sounds like it is doing something but maybe its just louder than my previous drive. I will update how its running better in my next reply. What about the hidden file changes is it okay to leave them where I set them for Virus Total?


OTL logfile created on: 2/24/2012 9:31:31 PM - Run 2
OTL by OldTimer - Version 3.2.33.0 Folder = C:\Documents and Settings\Peggy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.66 Gb Available Physical Memory | 81.98% Memory free
5.09 Gb Paging File | 4.15 Gb Available in Paging File | 81.42% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.09 Gb Total Space | 235.96 Gb Free Space | 79.16% Space Free | Partition Type: NTFS
Drive H: | 232.88 Gb Total Space | 161.91 Gb Free Space | 69.52% Space Free | Partition Type: NTFS
Drive P: | 30.56 Gb Total Space | 26.05 Gb Free Space | 85.23% Space Free | Partition Type: NTFS
Drive U: | 465.54 Gb Total Space | 372.21 Gb Free Space | 79.95% Space Free | Partition Type: NTFS
Drive X: | 43.94 Gb Total Space | 30.44 Gb Free Space | 69.28% Space Free | Partition Type: NTFS

Computer Name: HOME-4600 | User Name: Peggy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/19 22:11:46 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
PRC - [2012/02/18 14:06:05 | 000,876,032 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin\ClickClean.exe
PRC - [2012/02/18 07:59:28 | 000,282,648 | —- | M] (McAfee, Inc.) – c:\Program Files\McAfee\SiteAdvisor\saUI.exe
PRC - [2012/02/14 23:03:37 | 001,049,072 | —- | M] (Google Inc.) – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2012/01/22 13:35:14 | 000,296,056 | —- | M] (RealNetworks, Inc.) – C:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2011/12/19 16:32:26 | 000,394,672 | —- | M] (Eastman Kodak Company) – C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011/12/10 10:25:36 | 002,756,608 | —- | M] (Eastman Kodak Company) – C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe
PRC - [2011/11/22 17:18:26 | 001,318,816 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/10/18 14:32:30 | 000,150,856 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2011/10/18 14:28:34 | 000,160,608 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/10/18 14:28:18 | 000,166,288 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/10/09 11:26:19 | 000,684,032 | —- | M] (Roxio) – C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
PRC - [2011/10/06 21:01:07 | 000,557,056 | —- | M] (BitLeader) – C:\Program Files\lg_fwupdate\fwupdate.exe
PRC - [2011/08/05 23:52:46 | 000,744,072 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\TrayNotify.exe
PRC - [2011/08/05 23:52:46 | 000,070,792 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\EuWatch.exe
PRC - [2011/08/05 23:52:46 | 000,060,040 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) – C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe
PRC - [2011/07/22 18:13:10 | 000,030,568 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PaperPort\pptd40nt.exe
PRC - [2011/07/22 18:12:04 | 000,138,600 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
PRC - [2011/07/01 00:07:24 | 000,607,592 | —- | M] (Nuance Communications, Inc.) – C:\Program Files\Nuance\PDF Viewer Plus\PdfPro7Hook.exe
PRC - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/10/27 18:17:52 | 000,207,424 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/05/31 07:22:36 | 000,568,312 | —- | M] (Oberon Media ) – C:\Program Files\GamesBar\SearchEngineProtection.exe
PRC - [2010/05/21 12:40:26 | 000,324,976 | —- | M] (Flexera Software, Inc.) – C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/03/08 01:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1325351862\ee\aolupdates.exe
PRC - [2010/03/08 01:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe
PRC - [2009/04/15 22:52:06 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/05 13:06:56 | 000,057,344 | —- | M] (Creative Technology Ltd) – C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe
PRC - [2003/05/16 08:50:00 | 000,019,968 | —- | M] (Logitech Inc.) – C:\WINDOWS\LOGI_MWX.EXE
PRC - [2002/10/15 14:37:50 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/18 14:06:05 | 000,876,032 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin\ClickClean.exe
MOD - [2012/02/17 03:28:58 | 000,169,984 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Automation\2060c6851428e508f673a0dfd819e5fb\Inkjet.Automation.ni.dll
MOD - [2012/02/17 03:28:44 | 000,098,304 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.DeviceSettin#\ad3980c979042cbcf8963a0e82fad500\Inkjet.DeviceSettings.ni.dll
MOD - [2012/02/17 03:28:09 | 000,771,584 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll
MOD - [2012/02/17 03:27:43 | 000,105,472 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Diagnostics\313de9c18ccddcf244989ca8f29b1f97\Inkjet.Diagnostics.ni.dll
MOD - [2012/02/17 03:27:41 | 000,237,056 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Localization\56696b3880309021b174d271ea96ff95\Inkjet.Localization.ni.dll
MOD - [2012/02/17 03:27:35 | 000,283,648 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Utilities\df0efdea1a90f47a74bdef0e44b03ca1\Inkjet.Utilities.ni.dll
MOD - [2012/02/17 03:27:24 | 000,824,320 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Hardware\8c7d08dd02d37cb7fab7a4d0c047d17b\Inkjet.Hardware.ni.dll
MOD - [2012/02/17 03:27:22 | 000,080,896 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Configuration\0664ade269ba04a1c292766bf6bdbfda\Inkjet.Configuration.ni.dll
MOD - [2012/02/17 03:27:19 | 000,180,736 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Inkjet.Statistics\1e8aad9950f2993546a3be08455d86f0\Inkjet.Statistics.ni.dll
MOD - [2012/02/17 03:27:07 | 000,971,264 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
MOD - [2012/02/17 03:23:54 | 005,450,752 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
MOD - [2012/02/17 03:23:43 | 012,430,848 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
MOD - [2012/02/17 03:23:08 | 001,587,200 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
MOD - [2012/02/17 03:19:49 | 007,953,408 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
MOD - [2012/02/14 23:03:36 | 000,429,040 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\ppgooglenaclpluginchrome.dll
MOD - [2012/02/14 23:03:34 | 003,772,912 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\pdf.dll
MOD - [2012/02/14 23:02:10 | 000,122,880 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\avutil-51.dll
MOD - [2012/02/14 23:02:08 | 000,220,672 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\avformat-53.dll
MOD - [2012/02/14 23:02:07 | 001,747,456 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\avcodec-53.dll
MOD - [2012/01/10 23:51:34 | 011,490,816 | —- | M] () – C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/05 23:51:58 | 000,064,648 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\TbTapeBrowse.dll
MOD - [2011/08/05 23:51:52 | 000,243,336 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\ExImage.dll
MOD - [2011/08/05 23:51:52 | 000,074,376 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\ExchBackupSize.dll
MOD - [2011/08/05 23:51:50 | 000,069,768 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\EnumTapeDevice.dll
MOD - [2011/08/05 23:51:50 | 000,051,848 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\CodeLog.dll
MOD - [2009/02/26 00:39:00 | 000,065,536 | R— | M] () – C:\WINDOWS\system32\P17.dll
MOD - [2008/11/25 16:18:00 | 001,291,264 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\libxml2.dll
MOD - [2004/10/05 02:08:00 | 000,055,808 | —- | M] () – C:\Program Files\EASEUS\Todo Backup\bin\zlib1.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/12/19 16:32:26 | 000,394,672 | —- | M] (Eastman Kodak Company) [Auto | Running] – C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe – (Kodak AiO Network Discovery Service)
SRV - [2011/10/18 14:32:30 | 000,150,856 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2011/10/18 14:28:34 | 000,160,608 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV - [2011/10/18 14:28:18 | 000,166,288 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/08/05 23:52:46 | 000,060,040 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Auto | Running] – C:\Program Files\EASEUS\Todo Backup\bin\Agent.exe – (EaseUS Agent)
SRV - [2011/07/22 18:12:04 | 000,138,600 | —- | M] (Nuance Communications, Inc.) [Auto | Running] – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe – (PDFProFiltSrvPP)
SRV - [2011/06/23 14:22:58 | 000,361,712 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2011/06/13 22:09:22 | 000,267,568 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Fix it Center\Matsvc.exe – (MatSvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2011/01/27 17:28:14 | 000,214,904 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McAfee SiteAdvisor Service)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [Auto | Running] – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2006/10/23 06:50:35 | 000,046,640 | R— | M] (AOL LLC) [On_Demand | Stopped] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
SRV - [2003/03/03 12:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
SRV - [2002/10/15 14:37:50 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)


========== Driver Services (SafeList) ==========

DRV - [2011/10/15 13:16:16 | 000,464,176 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/10/15 13:16:16 | 000,338,176 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/10/15 13:16:16 | 000,180,816 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/10/15 13:16:16 | 000,121,256 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2011/10/15 13:16:16 | 000,089,792 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/10/15 13:16:16 | 000,087,656 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/10/15 13:16:16 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/10/15 13:16:16 | 000,083,856 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/10/15 13:16:16 | 000,059,456 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/10/15 13:16:16 | 000,057,600 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/10/09 11:26:21 | 000,242,048 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\cdudf_xp.sys – (cdudf_xp)
DRV - [2011/10/09 11:26:21 | 000,206,464 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\System32\drivers\udfreadr_xp.sys – (UdfReadr_xp)
DRV - [2011/10/09 11:26:21 | 000,151,066 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\pwd_2K.sys – (pwd_2k)
DRV - [2011/10/09 11:26:21 | 000,030,694 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Mmc_2k.sys – (mmc_2K)
DRV - [2011/10/09 11:26:21 | 000,025,962 | —- | M] (Roxio) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\Dvd_2k.sys – (dvd_2K)
DRV - [2011/10/09 11:26:19 | 000,062,320 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp)
DRV - [2011/10/09 11:26:19 | 000,023,324 | —- | M] (Roxio) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k)
DRV - [2011/08/05 23:52:38 | 000,184,072 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\EuFdDisk.sys – (EUFDDISK)
DRV - [2011/08/05 23:52:36 | 000,042,376 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\EUBKMON.sys – (EUBKMON)
DRV - [2011/08/05 23:52:30 | 000,016,008 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\eudskacs.sys – (EUDSKACS)
DRV - [2011/08/05 23:52:28 | 000,038,920 | —- | M] (CHENGDU YIWO Tech Development Co., Ltd) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\eubakup.sys – (EUBAKUP)
DRV - [2011/07/29 12:54:56 | 000,013,192 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv)
DRV - [2011/07/29 12:54:56 | 000,008,456 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv)
DRV - [2010/08/25 18:39:02 | 000,013,064 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\prwntdrv.sys – (prwntdrv)
DRV - [2009/02/26 00:29:58 | 001,142,272 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\P17.sys – (P17)
DRV - [2005/01/10 04:15:30 | 000,106,496 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv)
DRV - [2005/01/10 04:15:24 | 000,138,752 | R— | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k)
DRV - [2003/08/29 03:59:24 | 001,101,696 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMSM.sys – (BCMModem)
DRV - [2002/10/15 14:32:16 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/22 07:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6E CC 2A 26 97 F0 CC 01 [binary data]
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1417001333-630328440-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://accounts.google.com/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3D2%26view%3Dcm%26fs%3D1%26tf%3D1%26to%26su%3DShareaholic%2Bhas%2Bbeen%2Bsuccessfully%2Binstalled.%26body%3DLink%3A%2Bhttp%3A%2F%2Fwww.shareaholic.com%2Ftools%2Ffirefox%2Fwelcome%2F3.0.1%2B%28via%2Bshareaholic.com%29%250D%250A%250D%250A&bsv;=llya694le36z&scc;=1
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: P:\ITUNES\Mozilla Plugins\npitunes.dll File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: C:\Program Files\EpicPlay\npEpicHost.dll ( )
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Viewer Plus\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/23 15:09:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/02/24 21:12:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/01/22 13:36:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/09 19:27:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/10/22 06:07:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Extensions
[2012/02/18 13:45:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Firefox\Profiles\reev6mht.default\extensions
[2011/10/22 06:07:39 | 000,000,000 | —D | M] (EpicPlay Games) – C:\Documents and Settings\Peggy\Application Data\Mozilla\Firefox\Profiles\reev6mht.default\extensions\[removed]
[2011/10/09 19:27:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
() (No name found) – C:\DOCUMENTS AND SETTINGS\PEGGY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\REEV6MHT.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\PEGGY\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\REEV6MHT.DEFAULT\EXTENSIONS\[removed]
[2012/02/24 21:12:20 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/02/23 15:09:19 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/10/07 08:32:34 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/29 00:53:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/09/28 18:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/18 13:09:46 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/01/26 19:01:32 | 000,001,467 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober46392171.xml
[2011/12/21 10:42:07 | 000,001,467 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\WebSearchober615774250.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Mixesoft Click&Clean; Plug-In (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin/npccch32.dll
CHR - plugin: Bitdefender QuickScan (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\plugin/npqscan.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: EpicPlay NPAPI Display Host (Enabled) = C:\Program Files\EpicPlay\npEpicHost.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: DocuCom PDF Plus (Enabled) = C:\Program Files\Nuance\PDF Viewer Plus\bin\nppdf.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Magic Actions for YouTube\u2122 = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\4.7_0\
CHR - Extension: Turn Off the Lights = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.0.0.53_0\
CHR - Extension: YouTube = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: Click&Clean; = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.3.0_0\
CHR - Extension: LastPass = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.90.2_0\
CHR - Extension: Print = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idfnpgjblkahngbondojabhffkkdekbd\2.0.2.1_0\
CHR - Extension: Picnik = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\inmnggcpelemfookhlhkdfbechcdadfp\1.0.6_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Yidio = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kenklnagphgeldfpobjachbgpimaopbf\1.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: Google Mail Checker = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
CHR - Extension: Quick Note = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.2.9_0\
CHR - Extension: Ghostery = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\2.4.0_0\
CHR - Extension: Facebook Notifications = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: Google Chrome to Phone Extension = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
CHR - Extension: Google Reader = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm\4.2_0\
CHR - Extension: Gmail = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: EpicPlay = C:\Documents and Settings\Peggy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\plccnhhjonaiagjelpfkclblmlppjcik\

O1 HOSTS File: ([2002/09/03 13:39:21 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111231151040.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (GamesBarBHO Class) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\2.0.1.55\oberontb.dll (Oberon Media Ltd.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\RocketFish\RF5.1\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EaseUs Tray] C:\Program Files\EaseUS\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EaseUs Watch] C:\Program Files\EaseUS\Todo Backup\bin\EuWatch.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [EKAIO2StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1325351862\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [iTunesHelper] "P:\ITUNES\iTunesHelper.exe" File not found
O4 - HKLM..\Run: [LGODDFU] C:\Program Files\lg_fwupdate\fwupdate.exe (BitLeader)
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [P17Helper] C:\WINDOWS\System32\P17.dll ()
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFProHook] C:\Program Files\Nuance\PDF Viewer Plus\PdfPro7Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [DW6] File not found
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [SearchEngineProtection] C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
O4 - HKU\S-1-5-21-1417001333-630328440-839522115-1003..\Run: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKU\.DEFAULT..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - HKU\S-1-5-18..\RunOnce: [KodakHomeCenter] C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\pmremind.exe (Broderbund Properties LLC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk = File not found
O4 - Startup: C:\Documents and Settings\Peggy\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://F:\PROGRA~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with PDF Viewer 7 - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - res://F:\PROGRA~1\Office14\ONBttnIE.dll/105 File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-1417001333-630328440-839522115-1003\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1317942221062 (MUWebControl Class)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://aolsvc.aol.com/onlinegames/luxor/mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACC14ECB-787B-4C4F-B8EF-F64D987637F7}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Peggy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Peggy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/10/06 14:55:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/09/03 12:36:02 | 000,000,000 | —- | M] () - H:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/24 21:14:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2012/02/24 21:05:20 | 000,000,000 | —D | C] – C:\_OTL
[2012/02/19 22:00:23 | 000,583,680 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
[2012/02/19 12:59:29 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Peggy\Recent
[2012/02/19 12:32:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Desktop\Unused Desktop Shortcuts
[2012/02/19 11:41:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Local Settings\Application Data\FixItCenter
[2012/02/19 11:25:24 | 000,000,000 | —D | C] – C:\WINDOWS\MATS
[2012/02/19 11:25:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Fix it Center
[2012/02/18 13:15:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\ElevatedDiagnostics
[2012/02/18 13:14:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2012/02/18 13:13:37 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012/02/09 05:28:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote
[2012/02/08 04:16:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\image001
[2012/02/07 04:58:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\My Documents\ATT00001
[2012/02/05 00:10:51 | 000,000,000 | —D | C] – C:\EaseUs
[2012/01/26 19:01:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Peggy\Application Data\Oberon Media
[2012/01/26 19:01:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GamesBar
[2012/01/26 19:01:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2012/01/26 19:01:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Oberon Media
[2012/01/26 19:01:35 | 000,000,000 | —D | C] – C:\Program Files\GamesBar
[2011/10/06 15:40:47 | 000,065,536 | R— | C] ( ) – C:\WINDOWS\System32\A3d.dll

========== Files - Modified Within 30 Days ==========

[2012/02/24 21:30:04 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{C391DD8A-B008-4850-A2C9-0E127992F41B}.job
[2012/02/24 21:09:38 | 000,000,337 | —- | M] () – C:\WINDOWS\lgfwup.ini
[2012/02/24 21:09:02 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/24 21:08:29 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/24 21:08:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/24 21:06:01 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-630328440-839522115-1003UA.job
[2012/02/24 21:02:01 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/23 02:06:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-630328440-839522115-1003Core.job
[2012/02/22 12:56:06 | 000,958,808 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Sapsucker.jpg
[2012/02/22 11:50:06 | 000,000,249 | RHS- | M] () – C:\boot.ini
[2012/02/20 07:26:24 | 000,061,355 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\New Compressed (zipped) Folder.zip
[2012/02/19 22:54:18 | 000,302,592 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\ub1kpfhw.exe
[2012/02/19 22:51:43 | 000,302,592 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\2bt4o3ld.exe
[2012/02/19 22:11:46 | 000,583,680 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Peggy\Desktop\OTL.exe
[2012/02/19 11:42:40 | 000,000,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/02/19 10:45:19 | 000,000,630 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\SIW.lnk
[2012/02/19 02:07:19 | 000,004,096 | -HS- | M] () – C:\{D4418025-3B61-43A0-B914-A709F4BCE5B1}.CBM
[2012/02/19 01:00:10 | 000,306,176 | -HS- | M] () – C:\EUMONBMP.SYS
[2012/02/18 09:39:25 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2012/02/18 09:39:25 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2012/02/17 05:49:22 | 000,082,337 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Brown'sLanding.jpg
[2012/02/17 03:35:11 | 000,477,152 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/17 03:18:11 | 000,543,072 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/02/17 03:18:11 | 000,096,684 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/02/16 20:09:12 | 000,002,304 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Google Chrome.lnk
[2012/02/16 20:09:12 | 000,002,282 | —- | M] () – C:\Documents and Settings\Peggy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/16 05:17:38 | 000,536,442 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Redstart-2.jpg
[2012/02/14 06:39:52 | 002,607,361 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\Machine_delivered_to_SA_without_instructions.wmv
[2012/02/09 05:28:04 | 000,015,561 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote.zip
[2012/02/08 04:16:45 | 000,432,996 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\image001.zip
[2012/02/07 04:58:10 | 000,018,944 | —- | M] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/07 04:58:01 | 001,924,016 | —- | M] () – C:\Documents and Settings\Peggy\My Documents\ATT00001.zip
[2012/02/04 10:02:02 | 000,008,192 | -HS- | M] () – C:\ESLOADLX
[2012/02/04 10:01:57 | 000,194,388 | -HS- | M] () – C:\ESLDR
[2012/01/31 11:40:32 | 000,000,096 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\PP11Thumbs.ptn2
[2012/01/31 11:31:35 | 000,157,899 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\PP11Thumbs.ptn
[2012/01/31 11:31:35 | 000,000,374 | -H– | M] () – C:\Documents and Settings\Peggy\My Documents\maxdesk.ini2
[2012/01/26 06:11:25 | 000,002,459 | —- | M] () – C:\Documents and Settings\Peggy\Desktop\Microsoft Excel 2010.lnk

========== Files Created - No Company Name ==========

[2012/02/22 12:55:58 | 000,958,808 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Sapsucker.jpg
[2012/02/22 11:50:13 | 000,001,837 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
[2012/02/22 11:50:13 | 000,001,465 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
[2012/02/22 11:50:13 | 000,000,599 | —- | C] () – C:\Documents and Settings\Peggy\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/02/20 07:26:05 | 000,061,355 | —- | C] () – C:\Documents and Settings\Peggy\Desktop\New Compressed (zipped) Folder.zip
[2012/02/19 22:54:47 | 000,302,592 | —- | C] () – C:\Documents and Settings\Peggy\Desktop\ub1kpfhw.exe
[2012/02/19 22:51:55 | 000,302,592 | —- | C] () – C:\Documents and Settings\Peggy\Desktop\2bt4o3ld.exe
[2012/02/19 11:25:29 | 000,000,746 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Fix it Center.lnk
[2012/02/19 11:25:29 | 000,000,740 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Fix it Center.lnk
[2012/02/18 09:39:25 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2012/02/18 09:39:25 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2012/02/17 05:49:21 | 000,082,337 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Brown'sLanding.jpg
[2012/02/16 08:03:50 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/02/16 08:03:50 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2012/02/16 05:17:34 | 000,536,442 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Redstart-2.jpg
[2012/02/14 06:39:32 | 002,607,361 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\Machine_delivered_to_SA_without_instructions.wmv
[2012/02/09 05:28:03 | 000,015,561 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\GillilandHomequote.zip
[2012/02/08 04:16:41 | 000,432,996 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\image001.zip
[2012/02/07 04:57:46 | 001,924,016 | —- | C] () – C:\Documents and Settings\Peggy\My Documents\ATT00001.zip
[2012/02/05 03:51:58 | 000,004,096 | -HS- | C] () – C:\{D4418025-3B61-43A0-B914-A709F4BCE5B1}.CBM
[2012/02/04 22:38:42 | 000,306,176 | -HS- | C] () – C:\EUMONBMP.SYS
[2012/01/22 18:43:17 | 000,000,059 | —- | C] () – C:\WINDOWS\webdial.ini
[2011/12/31 12:41:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2011/12/31 11:08:40 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/12/24 14:16:01 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2011/10/13 22:12:50 | 000,109,300 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2011/10/09 23:47:14 | 000,000,552 | —- | C] () – C:\WINDOWS\WM7.INI
[2011/10/09 19:03:24 | 000,001,743 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2011/10/09 11:29:58 | 000,000,103 | —- | C] () – C:\WINDOWS\WININIT.INI
[2011/10/08 21:44:58 | 000,042,376 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/10/07 23:37:33 | 000,098,696 | —- | C] () – C:\WINDOWS\System32\setupprwdrv03.exe
[2011/10/07 23:37:33 | 000,013,064 | —- | C] () – C:\WINDOWS\System32\prwntdrv.sys
[2011/10/07 23:22:23 | 000,019,840 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2011/10/07 23:22:22 | 002,469,760 | —- | C] () – C:\WINDOWS\System32\BootMan.exe
[2011/10/07 23:22:22 | 000,086,408 | —- | C] () – C:\WINDOWS\System32\setupempdrv03.exe
[2011/10/07 23:22:21 | 000,013,192 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2011/10/07 23:22:21 | 000,008,456 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2011/10/07 10:54:10 | 000,018,944 | —- | C] () – C:\Documents and Settings\Peggy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/06 23:09:19 | 010,080,316 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1417001333-630328440-839522115-1003-0.dat
[2011/10/06 23:09:17 | 000,379,550 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/10/06 21:00:22 | 000,000,337 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2011/10/06 18:14:59 | 000,065,536 | R— | C] () – C:\WINDOWS\System32\P17.dll
[2011/10/06 18:14:59 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\P17CPI.dll
[2011/10/06 15:39:13 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2011/10/06 14:57:42 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/10/06 14:53:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/10/06 09:47:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/10/06 09:46:32 | 000,477,152 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/08/05 13:35:30 | 000,001,056 | —- | C] () – C:\WINDOWS\System32\EKaio2WiaCoInst.ini
[2011/07/22 17:32:34 | 000,034,326 | —- | C] () – C:\WINDOWS\MAXLINK.INI

< End of report >
Richard, My computer is much more responsive! It loads web pages and videos much quicker. Even on you tube where i normally get frustrated because of all the interrupts it is much improved. I watched the trend page on performance under Task manager and never saw it spike to 100 percent like it was before except for one instance when i had Google chrome web page up, I don't know what you did but it is greatly appreciated. I guess my paid subscription to McAfee is not doing to well!
Welcome back! :)

Yes, you can leave the hidden file changes for now :thumbup:

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

Error - 2/19/2012 9:25:53 PM | Computer Name = HOME-4600 | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second


I think that Bonjour Service could be the cause for the high CPU usage. Apple’s Bonjour Service (mDNSResponder.exe) searches for and reminds you of software updates.

It starts automatically everytime when Windows boot up and can consume your computer’s CPU resources.

If you would like to remove Bonjour Service, follow these steps:
  • Click on Start > Control Panel.
  • Click on Add or Remove Programs.
  • Select the following from the list:


    Bonjour

  • Click the Remove button.
If you ever need to use it in the future, you can download and reinstall Bonjour for Windows from Apple’s official website.

Next

Questionable Toolbar/Plugin Uninstall:

Do you use all those toolbars and browser plugins that are installed?

GamesBar is an Adware toolbar.

WeCareReminder is an open to debate browser plugin.

If you would like to remove the Toolbar(s)/Plugin(s), follow these steps:
  • Click on Start > Control Panel.
  • Click on Add or Remove Programs.
  • Select the following from the list:


    GamesBar 2.0.1.55
    ASPCA TriMini Reminder by We-Care.com v5.0.2.1

  • Click the Remove button.
Next

MALWAREBYTES' ANTI-MALWARE
——————————————-
Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your Desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Next

ESET ONLINE SCANNER
—————————-
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the green ESET Online Scanner button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps):
    • Click on Download to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the esetsmartinstaller_enu.exe icon on your desktop.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check Scan archives.
  • Ensure that the option "Remove found threats" is Unchecked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats.
  • Push Export to text file…, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    Note - when ESET doesn't find any threats, no report will be created.
  • Push the Back button.
  • Push Finish.
In your next reply, please provide the following:
  • MBAM log.
  • ESET log.
  • Update on how your PC is running.



Regards,

Richard :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI