lavendersage
Topic Starter
I noticed bad changes a few weeks ago. I'd downloaded some free shareware (I know! I know!) and almost immediately thereafter started getting "404 nginx…" service errors when trying to log-in to my yahoo email or gmail.
Then, the other day, I noticed "addedsuccess" when I was trying to google search and was being re-directed.
I researched addedsuccess and then ran FULL scans using:
Ad-Aware
Malwarebytes
Microsoft Security Essentials
Spybot Search and Destroy
Windows Defender (I think)
My computer also has Norton Anti-virus which automatically runs full scans every day.
I haven't seen addedsuccess since and I can once more log-in to gmail and yahoo email but the computer is running ubelievably slowly and some webpages are still sporadically not opening. I can tell there's something still "not quite right".
Below is the OTL txt file. I'll post the Extras.txt file in another post.
OTL.txt
OTL logfile created on: 4/16/2012 4:47:33 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Laurie\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.93 Gb Available Physical Memory | 64.26% Memory free
4.84 Gb Paging File | 3.80 Gb Available in Paging File | 78.61% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.69 Gb Total Space | 27.27 Gb Free Space | 24.42% Space Free | Partition Type: NTFS
Computer Name: LAURIESPAD | User Name: Laurie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Laurie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files\Ad-Aware Antivirus\AdAware.exe (Lavasoft Limited)
PRC - C:\Documents and Settings\Laurie\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\19.6.2.10\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
PRC - C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Documents and Settings\Laurie\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Ad-Aware Antivirus\Engine\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe ()
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe (Motorola)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe (Microsoft Corp.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
PRC - C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
PRC - C:\WINDOWS\system32\KADxMain.exe (Knowles Acoustics)
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\CPdeSrvU.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d96906db18e87ffe2e08f6cda7e2be0f\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\8d886cdc2ca5f0ff97cd1afe8773bb6e\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\56e433394df8d44e43690a855e403555\System.ServiceProcess.ni.dll ()
MOD - C:\Program Files\Ad-Aware Antivirus\ThreatWork.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\a2a14380e8c9149d5b212d0100ef588a\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll ()
MOD - C:\Program Files\Ad-Aware Antivirus\Engine\Definitions\libMachoUniv.dll ()
MOD - C:\Program Files\Ad-Aware Antivirus\Engine\Definitions\libBase64.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files\Ad-Aware Antivirus\Engine\vipre.dll ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\avutil-50.dll ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\libexpat.dll ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\sqlite3.dll ()
MOD - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
MOD - C:\Program Files\Winamp\winampa.exe ()
MOD - C:\WINDOWS\system32\preflib.dll ()
MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
MOD - C:\Program Files\Creative\Sync Manager Unicode\CTSyncRs.crl ()
MOD - C:\WINDOWS\system32\PdeSrvps.dll ()
MOD - C:\Program Files\Dell\QuickSet\preflibcl.dll ()
MOD - C:\WINDOWS\system32\TosCommAPI.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Ad-Aware Service) – C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\19.6.2.10\ccSvcHst.exe (Symantec Corporation)
SRV - (SBAMSvc) – C:\Program Files\Ad-Aware Antivirus\Engine\SBAMSvc.exe (Sunbelt Software)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (MotoConnect Service) – C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (ASFIPmon) – C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (WavxDMgr) – system32\DRIVERS\WavxDMgr.sys File not found
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\NAV\1002000.007\SYMREDRV.SYS File not found
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMFW.SYS File not found
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\NAV\1002000.007\SYMDNS.SYS File not found
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PfModNT.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (motport) – system32\DRIVERS\motport.sys File not found
DRV - (motmodem) – system32\DRIVERS\motmodem.sys File not found
DRV - (MCSTRM) – File not found
DRV - (lbrtfdc) – File not found
DRV - (InCDRm) – system32\drivers\InCDRm.sys File not found
DRV - (InCDPass) – system32\drivers\InCDPass.sys File not found
DRV - (InCDFs) – system32\drivers\InCDFs.sys File not found
DRV - (dsNcAdpt) – system32\DRIVERS\dsNcAdpt.sys File not found
DRV - (Changer) – File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\BASHDefs\20120402.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\IPSDefs\20120413.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\VirusDefs\20120416.001\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\VirusDefs\20120416.001\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\symtdi.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\symefa.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\ironx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\srtspx.sys (Symantec Corporation)
DRV - (ccSet_NAV) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\ccsetx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\symds.sys (Symantec Corporation)
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (sbhips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCLMP) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (motccgp) – C:\WINDOWS\system32\drivers\motccgp.sys (Motorola)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (PBADRV) – C:\WINDOWS\system32\drivers\PBADRV.sys (Dell Inc)
DRV - (motccgpfl) – C:\WINDOWS\system32\drivers\motccgpfl.sys (Motorola)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (MotoSwitchService) – C:\WINDOWS\system32\drivers\motswch.sys (Motorola)
DRV - (WaveFDE) – C:\WINDOWS\system32\drivers\WaveFDE.sys (Windows ® Codename Longhorn DDK provider)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BASFND) – C:\Program Files\Broadcom\ASFIPMon\BASFND.sys (Broadcom Corporation)
DRV - (DXEC01) – C:\WINDOWS\system32\drivers\dxec01.sys (Knowles Acoustics)
DRV - (Jukebox3) – C:\WINDOWS\system32\drivers\ctpdusb.sys (Creative Technology Ltd.)
DRV - (APPDRV) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4081106
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4081106
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4081106
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {8F4AFAEF-0143-40AA-BE7D-346C2C5701D0}
IE - HKCU\..\SearchScopes\{3AA730BE-CFBE-4C8A-B8FB-300CEBE56E93}: "URL" = http://search.yahoo.com/search?p={searchTe…tf-8&fr=ie8
IE - HKCU\..\SearchScopes\{8F4AFAEF-0143-40AA-BE7D-346C2C5701D0}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Documents and Settings\Laurie\My Documents\My Downloads\AmazonMP3Installer\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\IPSFFPlgn\ [2012/03/25 17:57:37 | 000,000,000 | —D | M]
[2012/03/03 01:11:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Laurie\Application Data\Mozilla\Extensions
O1 HOSTS File: ([2011/07/12 22:32:55 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (VideoFileDownload) - {040f45cc-08ca-4bc7-87f7-523bc39df89c} - C:\Program Files\Object\bho_project.dll (InternetEngine)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.6.2.10\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\18.0.1025.142\npchrome_frame.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe (Knowles Acoustics)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [CTSyncU.exe] C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
O4 - HKCU..\Run: [HLBackupScheduler] C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe ()
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\Laurie\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
O4 - Startup: C:\Documents and Settings\Laurie\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Laurie\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: absoluteradio.co.uk ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] http in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1226598793017 (WUWebControl Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1226611868390 (MUWebControl Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} http://xserv.dell.com/DellDriverScanner/DellSystem.CAB (DellSystem.Scanner)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://remote.atlantichealth.org/dana-cach…perSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{40FB8348-2FC6-443F-A970-9777F538D85B}: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\18.0.1025.142\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\gemsafe: DllName - (C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll) - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus)
O24 - Desktop WallPaper: C:\Documents and Settings\Laurie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Laurie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{37913634-b1b9-11dd-b490-002186cd7767}\Shell\AutoRun\command - "" = h6o0re.cmd
O33 - MountPoints2\{37913634-b1b9-11dd-b490-002186cd7767}\Shell\explore\Command - "" = h6o0re.cmd
O33 - MountPoints2\{37913634-b1b9-11dd-b490-002186cd7767}\Shell\open\Command - "" = h6o0re.cmd
O33 - MountPoints2\{f6f4715c-0098-11de-9cf7-002170b48673}\Shell - "" = AutoRun
O33 - MountPoints2\{f6f4715c-0098-11de-9cf7-002170b48673}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6f4715c-0098-11de-9cf7-002170b48673}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/16 16:36:59 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Laurie\Desktop\OTL.exe
[2012/04/15 02:22:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\WeatherBug
[2012/04/14 20:18:30 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Ad-Aware Antivirus
[2012/04/14 17:42:08 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/04/14 17:38:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2012/04/14 17:07:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Local Settings\Application Data\adaware
[2012/04/14 17:07:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2012/04/14 17:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ad-Aware Antivirus
[2012/04/14 17:06:56 | 000,074,968 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2012/04/14 17:06:55 | 000,021,592 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[2012/04/14 17:06:54 | 000,094,040 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbhips.sys
[2012/04/14 17:06:52 | 000,212,568 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbtis.sys
[2012/04/14 17:06:15 | 000,069,208 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFwIm.sys
[2012/04/14 17:06:14 | 000,332,248 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFw.sys
[2012/04/14 17:06:05 | 000,000,000 | —D | C] – C:\Program Files\Ad-Aware Antivirus
[2012/04/14 17:05:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\Ad-Aware Antivirus
[2012/03/30 10:58:20 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/03/24 16:44:55 | 000,000,000 | —D | C] – C:\My Music
[2012/03/24 16:38:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Local Settings\Application Data\MediaMonkey
[2012/03/24 16:38:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\MediaMonkey
[2012/03/24 16:38:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MediaMonkey
[2012/03/24 16:38:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2012/03/24 16:38:02 | 000,000,000 | —D | C] – C:\Program Files\MediaMonkey
[2012/03/24 14:44:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\MusicBee
[2012/03/24 14:38:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Local Settings\Application Data\WinZip
[2012/03/24 14:34:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/03/24 14:34:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2012/03/22 13:24:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2012/03/22 13:24:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2012/03/20 17:29:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2012/03/19 14:19:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FreeRIP
[2011/01/05 16:51:57 | 010,832,208 | —- | C] (Symantec Corporation) – C:\Program Files\nortonsafeweblite.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/16 16:56:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0B5454D1-8BDC-454D-B1DA-59F3A71E2C57}.job
[2012/04/16 16:45:28 | 000,052,202 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2012/04/16 16:37:10 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Laurie\Desktop\OTL.exe
[2012/04/16 16:33:01 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/04/16 10:59:18 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/16 10:56:56 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{5C39155A-A7A8-4325-9E54-C111A8CEEF32}.job
[2012/04/16 10:56:31 | 000,001,617 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware Antivirus.lnk
[2012/04/16 10:54:57 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/04/16 10:54:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/04/16 10:53:59 | 3219,091,456 | -HS- | M] () – C:\hiberfil.sys
[2012/04/15 03:30:01 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/04/14 17:45:27 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/04/14 17:43:15 | 000,626,167 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1306020.00A\Cat.DB
[2012/04/14 17:08:36 | 000,467,780 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/04/14 17:08:36 | 000,080,846 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/04/14 16:48:55 | 000,000,245 | RHS- | M] () – C:\boot.ini
[2012/04/14 13:33:05 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/04/14 13:33:05 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/04/13 14:24:09 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/04/11 23:20:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/11 21:13:46 | 000,008,942 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1306020.00A\VT20120410.034
[2012/04/11 11:34:26 | 000,052,202 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2012/04/11 03:03:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/04/05 11:07:14 | 070,309,384 | —- | M] () – C:\Documents and Settings\Laurie\Desktop\frames.zip
[2012/03/27 23:02:40 | 000,001,887 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK
[2012/03/25 14:13:42 | 000,000,805 | —- | M] () – C:\Documents and Settings\Laurie\Desktop\M4a to MP3 converter.lnk
[2012/03/24 17:25:28 | 000,003,030 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2012/03/24 16:38:14 | 000,000,738 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaMonkey.lnk
[2012/03/24 16:38:12 | 000,000,720 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MediaMonkey.lnk
[2012/03/24 14:40:34 | 000,000,309 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\Desktop.lnk
[2012/03/24 14:36:22 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/03/24 14:36:22 | 000,001,672 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2012/03/24 12:16:37 | 000,000,412 | —- | M] () – C:\WINDOWS\wininit.ini
[2012/03/23 11:09:47 | 000,141,944 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/03/23 11:09:47 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/03/23 11:09:47 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/03/23 11:09:47 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/03/22 13:24:25 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/03/20 00:45:38 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1306020.00A\isolate.ini
[2012/03/19 14:20:33 | 000,001,534 | —- | M] () – C:\Documents and Settings\All Users\Application Data\ss.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/15 11:59:28 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/14 20:23:47 | 000,000,946 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/04/14 17:45:27 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2012/04/14 17:42:47 | 000,001,682 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/14 17:06:59 | 000,001,617 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware Antivirus.lnk
[2012/04/05 11:07:02 | 070,309,384 | —- | C] () – C:\Documents and Settings\Laurie\Desktop\frames.zip
[2012/03/30 10:58:24 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/03/24 16:38:12 | 000,000,738 | —- | C] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaMonkey.lnk
[2012/03/24 16:38:12 | 000,000,720 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MediaMonkey.lnk
[2012/03/24 14:36:22 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/03/24 14:36:22 | 000,001,672 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2012/03/22 13:24:25 | 000,001,878 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/03/19 14:20:33 | 000,001,534 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ss.ini
[2012/03/15 22:28:46 | 000,000,398 | —- | C] () – C:\Documents and Settings\Laurie\Application Data\burnaware.ini
[2012/03/10 18:08:22 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll.bak
[2012/03/10 18:08:22 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2012/03/10 18:08:22 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll.bak
[2012/03/10 18:08:22 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll
[2012/03/03 02:18:37 | 000,715,038 | —- | C] () – C:\WINDOWS\unins000.exe
[2012/03/03 02:18:37 | 000,103,828 | —- | C] () – C:\WINDOWS\unins000.dat
[2012/03/03 01:16:29 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2012/02/23 17:33:39 | 000,003,030 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2012/02/15 21:26:24 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/08/21 19:49:34 | 000,000,108 | -HS- | C] () – C:\WINDOWS\WSYS049.SYS
[2011/01/15 11:35:32 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/10/26 00:07:17 | 000,000,098 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2010/10/25 23:03:20 | 000,038,466 | —- | C] () – C:\Documents and Settings\Laurie\Application Data\Microsoft Excel 97-2003.ADR
[2010/10/25 23:03:13 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/05/24 06:23:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
========== LOP Check ==========
[2012/04/14 17:07:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2012/04/16 10:57:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2012/03/03 02:19:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/03/19 14:19:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeRIP
[2009/04/21 10:11:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2012/03/24 16:38:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2010/10/25 23:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motorola
[2012/03/12 00:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
[2012/03/10 20:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/03/12 00:18:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2012/03/24 14:38:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/05/27 01:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/10 01:39:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/06 08:06:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/03/14 20:42:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\acccore
[2012/04/15 11:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Ad-Aware Antivirus
[2011/01/11 11:10:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Amazon
[2012/03/19 15:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\COWON
[2012/04/16 11:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Dropbox
[2012/03/10 16:32:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\ElevatedDiagnostics
[2012/03/02 21:12:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\InfraRecorder
[2012/03/03 02:05:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Juniper Networks
[2012/03/03 20:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\LimeWire
[2012/04/07 19:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\MediaMonkey
[2008/11/30 15:24:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\MSNInstaller
[2012/03/24 16:02:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\MusicBee
[2009/07/12 12:10:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\SanDisk
[2011/06/18 22:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Tific
[2008/11/06 02:07:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Wave Systems Corp
[2012/04/15 02:22:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\WeatherBug
[2008/11/13 14:09:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Windows Desktop Search
[2008/11/22 20:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Windows Search
[2012/02/11 05:00:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Workrave
[2012/04/15 03:30:01 | 000,000,946 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/03/01 13:01:17 | 000,000,264 | —- | M] () – C:\WINDOWS\Tasks\Defrag.job
[2012/04/16 10:59:18 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/04/16 16:56:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{0B5454D1-8BDC-454D-B1DA-59F3A71E2C57}.job
[2012/04/16 10:56:56 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{5C39155A-A7A8-4325-9E54-C111A8CEEF32}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/04/14 16:48:55 | 000,000,245 | RHS- | M] () – C:\boot.ini
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/11/22 23:47:16 | 000,003,964 | —- | M] () – C:\CTMeasureTiming.ini
[2008/11/06 03:45:33 | 000,004,648 | RH– | M] () – C:\dell.sdr
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/04/16 10:53:59 | 3219,091,456 | -HS- | M] () – C:\hiberfil.sys
[2010/01/07 02:01:23 | 000,002,203 | —- | M] () – C:\hpfr6500.log
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2008/11/18 00:09:28 | 000,000,462 | -H– | M] () – C:\IPH.PH
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/04/16 10:53:58 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/08/05 15:17:17 | 000,003,072 | -HS- | M] () – C:\Thumbs.db
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/04/25 17:29:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/06/27 09:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\zIMFPRNT.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2008/11/29 15:52:13 | 000,001,706 | -H– | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2011/01/05 16:52:04 | 010,832,208 | —- | M] (Symantec Corporation) – C:\Program Files\nortonsafeweblite.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/04/25 05:21:09 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/04/25 05:21:09 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/04/25 05:21:09 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/04/25 17:29:41 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2008/11/06 02:12:20 | 000,014,090 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\msi.log
[2008/11/06 02:06:34 | 000,000,837 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\wave_license.txt
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2008/12/07 00:48:57 | 000,003,072 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/11/13 13:47:53 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/10/16 19:52:22 | 000,000,349 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\Face.url
[2010/11/26 20:16:56 | 000,001,483 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\Search results all-inclusive - TripAdvisor.url
< %USERPROFILE%\Desktop\*.exe >
[2011/06/18 22:25:52 | 002,558,968 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Laurie\Desktop\NPE.exe
[2012/04/16 16:37:10 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Laurie\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-13 14:49:32
< End of report >
Then, the other day, I noticed "addedsuccess" when I was trying to google search and was being re-directed.
I researched addedsuccess and then ran FULL scans using:
Ad-Aware
Malwarebytes
Microsoft Security Essentials
Spybot Search and Destroy
Windows Defender (I think)
My computer also has Norton Anti-virus which automatically runs full scans every day.
I haven't seen addedsuccess since and I can once more log-in to gmail and yahoo email but the computer is running ubelievably slowly and some webpages are still sporadically not opening. I can tell there's something still "not quite right".
Below is the OTL txt file. I'll post the Extras.txt file in another post.
OTL.txt
OTL logfile created on: 4/16/2012 4:47:33 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Laurie\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.93 Gb Available Physical Memory | 64.26% Memory free
4.84 Gb Paging File | 3.80 Gb Available in Paging File | 78.61% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.69 Gb Total Space | 27.27 Gb Free Space | 24.42% Space Free | Partition Type: NTFS
Computer Name: LAURIESPAD | User Name: Laurie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Laurie\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files\Ad-Aware Antivirus\AdAware.exe (Lavasoft Limited)
PRC - C:\Documents and Settings\Laurie\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Norton AntiVirus\Engine\19.6.2.10\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
PRC - C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
PRC - C:\Documents and Settings\Laurie\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Ad-Aware Antivirus\Engine\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe ()
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
PRC - C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe (Motorola)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe (Microsoft Corp.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
PRC - C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
PRC - C:\WINDOWS\system32\KADxMain.exe (Knowles Acoustics)
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\WINDOWS\system32\CPdeSrvU.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d96906db18e87ffe2e08f6cda7e2be0f\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\8d886cdc2ca5f0ff97cd1afe8773bb6e\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\56e433394df8d44e43690a855e403555\System.ServiceProcess.ni.dll ()
MOD - C:\Program Files\Ad-Aware Antivirus\ThreatWork.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\a2a14380e8c9149d5b212d0100ef588a\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll ()
MOD - C:\Program Files\Ad-Aware Antivirus\Engine\Definitions\libMachoUniv.dll ()
MOD - C:\Program Files\Ad-Aware Antivirus\Engine\Definitions\libBase64.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files\Ad-Aware Antivirus\Engine\vipre.dll ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\avutil-50.dll ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\libexpat.dll ()
MOD - C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\sqlite3.dll ()
MOD - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
MOD - C:\Program Files\Winamp\winampa.exe ()
MOD - C:\WINDOWS\system32\preflib.dll ()
MOD - C:\WINDOWS\system32\bcm1xsup.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
MOD - C:\Program Files\Creative\Sync Manager Unicode\CTSyncRs.crl ()
MOD - C:\WINDOWS\system32\PdeSrvps.dll ()
MOD - C:\Program Files\Dell\QuickSet\preflibcl.dll ()
MOD - C:\WINDOWS\system32\TosCommAPI.dll ()
========== Win32 Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Ad-Aware Service) – C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NAV) – C:\Program Files\Norton AntiVirus\Engine\19.6.2.10\ccSvcHst.exe (Symantec Corporation)
SRV - (SBAMSvc) – C:\Program Files\Ad-Aware Antivirus\Engine\SBAMSvc.exe (Sunbelt Software)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (MotoConnect Service) – C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe ()
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (ASFIPmon) – C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (WavxDMgr) – system32\DRIVERS\WavxDMgr.sys File not found
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\NAV\1002000.007\SYMREDRV.SYS File not found
DRV - (SYMNDIS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMNDIS.SYS File not found
DRV - (SYMIDS) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMIDS.SYS File not found
DRV - (SYMFW) – C:\WINDOWS\System32\Drivers\NAV\1008000.029\SYMFW.SYS File not found
DRV - (SYMDNS) – C:\WINDOWS\System32\Drivers\NAV\1002000.007\SYMDNS.SYS File not found
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PfModNT.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (motport) – system32\DRIVERS\motport.sys File not found
DRV - (motmodem) – system32\DRIVERS\motmodem.sys File not found
DRV - (MCSTRM) – File not found
DRV - (lbrtfdc) – File not found
DRV - (InCDRm) – system32\drivers\InCDRm.sys File not found
DRV - (InCDPass) – system32\drivers\InCDPass.sys File not found
DRV - (InCDFs) – system32\drivers\InCDFs.sys File not found
DRV - (dsNcAdpt) – system32\DRIVERS\dsNcAdpt.sys File not found
DRV - (Changer) – File not found
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\BASHDefs\20120402.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\IPSDefs\20120413.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\VirusDefs\20120416.001\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\Definitions\VirusDefs\20120416.001\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\symtdi.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\symefa.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\ironx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\srtspx.sys (Symantec Corporation)
DRV - (ccSet_NAV) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\ccsetx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\NAV\1306020.00A\symds.sys (Symantec Corporation)
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SbFw) – C:\WINDOWS\system32\drivers\SbFw.sys (Sunbelt Software, Inc.)
DRV - (SbTis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software, Inc.)
DRV - (sbhips) – C:\WINDOWS\system32\drivers\sbhips.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCLMP) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (SBFWIMCL) – C:\WINDOWS\system32\drivers\SbFwIm.sys (Sunbelt Software, Inc.)
DRV - (motccgp) – C:\WINDOWS\system32\drivers\motccgp.sys (Motorola)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (PBADRV) – C:\WINDOWS\system32\drivers\PBADRV.sys (Dell Inc)
DRV - (motccgpfl) – C:\WINDOWS\system32\drivers\motccgpfl.sys (Motorola)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (MotoSwitchService) – C:\WINDOWS\system32\drivers\motswch.sys (Motorola)
DRV - (WaveFDE) – C:\WINDOWS\system32\drivers\WaveFDE.sys (Windows ® Codename Longhorn DDK provider)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BASFND) – C:\Program Files\Broadcom\ASFIPMon\BASFND.sys (Broadcom Corporation)
DRV - (DXEC01) – C:\WINDOWS\system32\drivers\dxec01.sys (Knowles Acoustics)
DRV - (Jukebox3) – C:\WINDOWS\system32\drivers\ctpdusb.sys (Creative Technology Ltd.)
DRV - (APPDRV) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4081106
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4081106
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4081106
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {8F4AFAEF-0143-40AA-BE7D-346C2C5701D0}
IE - HKCU\..\SearchScopes\{3AA730BE-CFBE-4C8A-B8FB-300CEBE56E93}: "URL" = http://search.yahoo.com/search?p={searchTe…tf-8&fr=ie8
IE - HKCU\..\SearchScopes\{8F4AFAEF-0143-40AA-BE7D-346C2C5701D0}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Documents and Settings\Laurie\My Documents\My Downloads\AmazonMP3Installer\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.5.1.2\IPSFFPlgn\ [2012/03/25 17:57:37 | 000,000,000 | —D | M]
[2012/03/03 01:11:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Laurie\Application Data\Mozilla\Extensions
O1 HOSTS File: ([2011/07/12 22:32:55 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (VideoFileDownload) - {040f45cc-08ca-4bc7-87f7-523bc39df89c} - C:\Program Files\Object\bho_project.dll (InternetEngine)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\19.6.2.10\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\18.0.1025.142\npchrome_frame.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe (Knowles Acoustics)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [CTSyncU.exe] C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe ()
O4 - HKCU..\Run: [HLBackupScheduler] C:\Program Files\Verizon\VCast Media Manager\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe ()
O4 - HKCU..\Run: [SansaDispatch] C:\Documents and Settings\Laurie\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
O4 - Startup: C:\Documents and Settings\Laurie\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Laurie\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: absoluteradio.co.uk ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: google.com ([www] http in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1226598793017 (WUWebControl Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://www.creative.com/softwareupdate/su/…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1226611868390 (MUWebControl Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} http://xserv.dell.com/DellDriverScanner/DellSystem.CAB (DellSystem.Scanner)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://remote.atlantichealth.org/dana-cach…perSetupSP1.cab (JuniperSetupControlXP Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{40FB8348-2FC6-443F-A970-9777F538D85B}: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\18.0.1025.142\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\gemsafe: DllName - (C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll) - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus)
O24 - Desktop WallPaper: C:\Documents and Settings\Laurie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Laurie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{37913634-b1b9-11dd-b490-002186cd7767}\Shell\AutoRun\command - "" = h6o0re.cmd
O33 - MountPoints2\{37913634-b1b9-11dd-b490-002186cd7767}\Shell\explore\Command - "" = h6o0re.cmd
O33 - MountPoints2\{37913634-b1b9-11dd-b490-002186cd7767}\Shell\open\Command - "" = h6o0re.cmd
O33 - MountPoints2\{f6f4715c-0098-11de-9cf7-002170b48673}\Shell - "" = AutoRun
O33 - MountPoints2\{f6f4715c-0098-11de-9cf7-002170b48673}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6f4715c-0098-11de-9cf7-002170b48673}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/04/16 16:36:59 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Laurie\Desktop\OTL.exe
[2012/04/15 02:22:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\WeatherBug
[2012/04/14 20:18:30 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Ad-Aware Antivirus
[2012/04/14 17:42:08 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/04/14 17:38:29 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2012/04/14 17:07:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Local Settings\Application Data\adaware
[2012/04/14 17:07:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2012/04/14 17:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ad-Aware Antivirus
[2012/04/14 17:06:56 | 000,074,968 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbapifs.sys
[2012/04/14 17:06:55 | 000,021,592 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\sbaphd.sys
[2012/04/14 17:06:54 | 000,094,040 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbhips.sys
[2012/04/14 17:06:52 | 000,212,568 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\sbtis.sys
[2012/04/14 17:06:15 | 000,069,208 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFwIm.sys
[2012/04/14 17:06:14 | 000,332,248 | —- | C] (Sunbelt Software, Inc.) – C:\WINDOWS\System32\drivers\SbFw.sys
[2012/04/14 17:06:05 | 000,000,000 | —D | C] – C:\Program Files\Ad-Aware Antivirus
[2012/04/14 17:05:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\Ad-Aware Antivirus
[2012/03/30 10:58:20 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/03/24 16:44:55 | 000,000,000 | —D | C] – C:\My Music
[2012/03/24 16:38:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Local Settings\Application Data\MediaMonkey
[2012/03/24 16:38:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\MediaMonkey
[2012/03/24 16:38:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MediaMonkey
[2012/03/24 16:38:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2012/03/24 16:38:02 | 000,000,000 | —D | C] – C:\Program Files\MediaMonkey
[2012/03/24 14:44:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Application Data\MusicBee
[2012/03/24 14:38:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Laurie\Local Settings\Application Data\WinZip
[2012/03/24 14:34:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2012/03/24 14:34:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinZip
[2012/03/22 13:24:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2012/03/22 13:24:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2012/03/20 17:29:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2012/03/19 14:19:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FreeRIP
[2011/01/05 16:51:57 | 010,832,208 | —- | C] (Symantec Corporation) – C:\Program Files\nortonsafeweblite.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/04/16 16:56:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0B5454D1-8BDC-454D-B1DA-59F3A71E2C57}.job
[2012/04/16 16:45:28 | 000,052,202 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2012/04/16 16:37:10 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Laurie\Desktop\OTL.exe
[2012/04/16 16:33:01 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/04/16 10:59:18 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/16 10:56:56 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{5C39155A-A7A8-4325-9E54-C111A8CEEF32}.job
[2012/04/16 10:56:31 | 000,001,617 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware Antivirus.lnk
[2012/04/16 10:54:57 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/04/16 10:54:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/04/16 10:53:59 | 3219,091,456 | -HS- | M] () – C:\hiberfil.sys
[2012/04/15 03:30:01 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/04/14 17:45:27 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/04/14 17:43:15 | 000,626,167 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1306020.00A\Cat.DB
[2012/04/14 17:08:36 | 000,467,780 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/04/14 17:08:36 | 000,080,846 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/04/14 16:48:55 | 000,000,245 | RHS- | M] () – C:\boot.ini
[2012/04/14 13:33:05 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/04/14 13:33:05 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/04/13 14:24:09 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/04/11 23:20:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/04/11 21:13:46 | 000,008,942 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1306020.00A\VT20120410.034
[2012/04/11 11:34:26 | 000,052,202 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2012/04/11 03:03:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/04/05 11:07:14 | 070,309,384 | —- | M] () – C:\Documents and Settings\Laurie\Desktop\frames.zip
[2012/03/27 23:02:40 | 000,001,887 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK
[2012/03/25 14:13:42 | 000,000,805 | —- | M] () – C:\Documents and Settings\Laurie\Desktop\M4a to MP3 converter.lnk
[2012/03/24 17:25:28 | 000,003,030 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2012/03/24 16:38:14 | 000,000,738 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaMonkey.lnk
[2012/03/24 16:38:12 | 000,000,720 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MediaMonkey.lnk
[2012/03/24 14:40:34 | 000,000,309 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\Desktop.lnk
[2012/03/24 14:36:22 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/03/24 14:36:22 | 000,001,672 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2012/03/24 12:16:37 | 000,000,412 | —- | M] () – C:\WINDOWS\wininit.ini
[2012/03/23 11:09:47 | 000,141,944 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/03/23 11:09:47 | 000,060,872 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2012/03/23 11:09:47 | 000,007,468 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/03/23 11:09:47 | 000,000,806 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/03/22 13:24:25 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/03/20 00:45:38 | 000,000,172 | —- | M] () – C:\WINDOWS\System32\drivers\NAV\1306020.00A\isolate.ini
[2012/03/19 14:20:33 | 000,001,534 | —- | M] () – C:\Documents and Settings\All Users\Application Data\ss.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/04/15 11:59:28 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/04/14 20:23:47 | 000,000,946 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/04/14 17:45:27 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2012/04/14 17:42:47 | 000,001,682 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/04/14 17:06:59 | 000,001,617 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware Antivirus.lnk
[2012/04/05 11:07:02 | 070,309,384 | —- | C] () – C:\Documents and Settings\Laurie\Desktop\frames.zip
[2012/03/30 10:58:24 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/03/24 16:38:12 | 000,000,738 | —- | C] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\MediaMonkey.lnk
[2012/03/24 16:38:12 | 000,000,720 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MediaMonkey.lnk
[2012/03/24 14:36:22 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2012/03/24 14:36:22 | 000,001,672 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2012/03/22 13:24:25 | 000,001,878 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/03/19 14:20:33 | 000,001,534 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ss.ini
[2012/03/15 22:28:46 | 000,000,398 | —- | C] () – C:\Documents and Settings\Laurie\Application Data\burnaware.ini
[2012/03/10 18:08:22 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll.bak
[2012/03/10 18:08:22 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2012/03/10 18:08:22 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll.bak
[2012/03/10 18:08:22 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll
[2012/03/03 02:18:37 | 000,715,038 | —- | C] () – C:\WINDOWS\unins000.exe
[2012/03/03 02:18:37 | 000,103,828 | —- | C] () – C:\WINDOWS\unins000.dat
[2012/03/03 01:16:29 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2012/02/23 17:33:39 | 000,003,030 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2012/02/15 21:26:24 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/08/21 19:49:34 | 000,000,108 | -HS- | C] () – C:\WINDOWS\WSYS049.SYS
[2011/01/15 11:35:32 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/10/26 00:07:17 | 000,000,098 | —- | C] () – C:\WINDOWS\WirelessFTP.INI
[2010/10/25 23:03:20 | 000,038,466 | —- | C] () – C:\Documents and Settings\Laurie\Application Data\Microsoft Excel 97-2003.ADR
[2010/10/25 23:03:13 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/05/24 06:23:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
========== LOP Check ==========
[2012/04/14 17:07:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection
[2012/04/16 10:57:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2012/03/03 02:19:47 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/03/19 14:19:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeRIP
[2009/04/21 10:11:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2012/03/24 16:38:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2010/10/25 23:35:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motorola
[2012/03/12 00:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
[2012/03/10 20:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/03/12 00:18:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2012/03/24 14:38:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/05/27 01:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/10 01:39:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/06 08:06:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/03/14 20:42:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\acccore
[2012/04/15 11:52:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Ad-Aware Antivirus
[2011/01/11 11:10:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Amazon
[2012/03/19 15:02:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\COWON
[2012/04/16 11:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Dropbox
[2012/03/10 16:32:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\ElevatedDiagnostics
[2012/03/02 21:12:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\InfraRecorder
[2012/03/03 02:05:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Juniper Networks
[2012/03/03 20:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\LimeWire
[2012/04/07 19:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\MediaMonkey
[2008/11/30 15:24:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\MSNInstaller
[2012/03/24 16:02:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\MusicBee
[2009/07/12 12:10:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\SanDisk
[2011/06/18 22:04:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Tific
[2008/11/06 02:07:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Wave Systems Corp
[2012/04/15 02:22:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\WeatherBug
[2008/11/13 14:09:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Windows Desktop Search
[2008/11/22 20:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Windows Search
[2012/02/11 05:00:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Laurie\Application Data\Workrave
[2012/04/15 03:30:01 | 000,000,946 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/03/01 13:01:17 | 000,000,264 | —- | M] () – C:\WINDOWS\Tasks\Defrag.job
[2012/04/16 10:59:18 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/04/16 16:56:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{0B5454D1-8BDC-454D-B1DA-59F3A71E2C57}.job
[2012/04/16 10:56:56 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{5C39155A-A7A8-4325-9E54-C111A8CEEF32}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/04/14 16:48:55 | 000,000,245 | RHS- | M] () – C:\boot.ini
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/11/22 23:47:16 | 000,003,964 | —- | M] () – C:\CTMeasureTiming.ini
[2008/11/06 03:45:33 | 000,004,648 | RH– | M] () – C:\dell.sdr
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 09:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 09:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 09:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 09:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/04/16 10:53:59 | 3219,091,456 | -HS- | M] () – C:\hiberfil.sys
[2010/01/07 02:01:23 | 000,002,203 | —- | M] () – C:\hpfr6500.log
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 09:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 09:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 09:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 09:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 09:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 09:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 09:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 09:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 09:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2008/11/18 00:09:28 | 000,000,462 | -H– | M] () – C:\IPH.PH
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/04/16 10:53:58 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/08/05 15:17:17 | 000,003,072 | -HS- | M] () – C:\Thumbs.db
[2007/11/07 09:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 09:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 09:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/04/25 17:29:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 20:58:12 | 000,030,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2007/06/27 09:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\zIMFPRNT.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2008/11/29 15:52:13 | 000,001,706 | -H– | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2011/01/05 16:52:04 | 010,832,208 | —- | M] (Symantec Corporation) – C:\Program Files\nortonsafeweblite.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/04/25 05:21:09 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/04/25 05:21:09 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/04/25 05:21:09 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/04/25 17:29:41 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
[2008/11/06 02:12:20 | 000,014,090 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\msi.log
[2008/11/06 02:06:34 | 000,000,837 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\wave_license.txt
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2008/12/07 00:48:57 | 000,003,072 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/11/13 13:47:53 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/10/16 19:52:22 | 000,000,349 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\Face.url
[2010/11/26 20:16:56 | 000,001,483 | —- | M] () – C:\Documents and Settings\Laurie\Application Data\Microsoft\Internet Explorer\Quick Launch\Search results all-inclusive - TripAdvisor.url
< %USERPROFILE%\Desktop\*.exe >
[2011/06/18 22:25:52 | 002,558,968 | —- | M] (Symantec Corporation) – C:\Documents and Settings\Laurie\Desktop\NPE.exe
[2012/04/16 16:37:10 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Laurie\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-04-13 14:49:32
< End of report >