Oh, for the love of…I've officially determined that McAfee is incapable of dying! Asdfgh! And such!
…But at any rate, here are the transcripts, each in separate posts.
OTL.txt:
OTL logfile created on: 8/13/2012 9:26:06 AM - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Documents and Settings\Family02\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.88 Mb Total Physical Memory | 457.91 Mb Available Physical Memory | 45.16% Memory free
2.38 Gb Paging File | 1.85 Gb Available in Paging File | 77.54% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.05 Gb Total Space | 107.97 Gb Free Space | 76.01% Space Free | Partition Type: NTFS
Computer Name: FAMILY2 | User Name: Family02 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/13 09:21:32 | 000,596,992 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Family02\My Documents\Downloads\OTL (1).exe
PRC - [2012/07/22 20:01:24 | 002,445,880 | —- | M] (Check Point Software Technologies LTD) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2012/07/22 19:29:42 | 000,073,392 | —- | M] (Check Point Software Technologies LTD) – C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012/07/14 09:59:32 | 000,497,320 | —- | M] (Check Point Software Technologies) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012/07/14 09:59:08 | 000,738,984 | —- | M] (Check Point Software Technologies) – C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
PRC - [2012/07/03 12:21:30 | 004,273,976 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/07/03 12:21:29 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/05/04 19:29:46 | 000,161,664 | —- | M] (Oracle Corporation) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
PRC - [2011/02/25 10:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2009/03/05 17:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/02/05 11:14:56 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/12/30 03:09:54 | 000,875,016 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2008/11/13 10:09:44 | 000,065,536 | —- | M] (Prolific) – C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe
PRC - [2008/10/14 14:15:08 | 000,032,768 | —- | M] () – C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
PRC - [2008/07/10 08:23:26 | 002,049,320 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
PRC - [2008/07/10 08:23:26 | 000,053,032 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
PRC - [2008/07/10 08:23:16 | 001,442,088 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
PRC - [2008/07/10 08:23:04 | 001,083,176 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\InCD.exe
PRC - [2008/06/24 15:06:06 | 001,840,424 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008/04/15 20:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 20:54:40 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2012/08/13 02:15:04 | 001,793,024 | —- | M] () – C:\Program Files\Alwil Software\Avast5\defs\12081300\algo.dll
MOD - [2012/08/12 15:05:01 | 001,793,024 | —- | M] () – C:\Program Files\Alwil Software\Avast5\defs\12081201\algo.dll
MOD - [2008/10/14 14:15:08 | 000,032,768 | —- | M] () – C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
MOD - [2003/06/07 01:30:08 | 000,057,344 | —- | M] () – C:\Program Files\Launch Manager\PowerUtl.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - [2012/07/22 20:01:24 | 002,445,880 | —- | M] (Check Point Software Technologies LTD) [Auto | Running] – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe – (vsmon)
SRV - [2012/07/14 09:59:32 | 000,497,320 | —- | M] (Check Point Software Technologies) [Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe – (IswSvc)
SRV - [2012/07/03 12:21:29 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2012/06/05 15:17:44 | 000,160,944 | R— | M] (Skype Technologies) [Disabled | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/05/04 19:29:46 | 000,161,664 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2011/02/28 18:44:14 | 000,183,560 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/02/25 10:46:22 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\BingBar\SeaPort.EXE – (SeaPort)
SRV - [2010/03/21 15:41:00 | 003,532,120 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\system32\GameMon.des – (npggsvc)
SRV - [2009/02/05 11:14:56 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/07/10 08:23:26 | 000,053,032 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe – (NeroRegInCDSrv)
SRV - [2008/07/10 08:23:16 | 001,442,088 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe – (InCDsrv)
SRV - [2008/04/15 20:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts5161ccid.sys – (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts516xIR.sys – (Rts516xIR)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – c:\acernb\int15.sys – (int15.sys)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - [2012/07/22 19:29:44 | 000,526,640 | —- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] – C:\WINDOWS\system32\vsdatant.sys – (Vsdatant)
DRV - [2012/07/14 09:59:44 | 000,027,056 | —- | M] (Check Point Software Technologies) [Kernel | Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys – (ISWKL)
DRV - [2012/07/03 12:21:54 | 000,054,232 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2012/07/03 12:21:53 | 000,721,000 | —- | M] (AVAST Software) [File_System | System | Running] – C:\WINDOWS\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2012/07/03 12:21:53 | 000,353,688 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP)
DRV - [2012/07/03 12:21:53 | 000,097,608 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2)
DRV - [2012/07/03 12:21:53 | 000,035,928 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr)
DRV - [2012/07/03 12:21:53 | 000,021,256 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2012/07/03 12:21:52 | 000,025,256 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2010/02/17 11:25:50 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2010/02/17 11:15:58 | 000,066,632 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 11:15:58 | 000,012,872 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2009/09/16 11:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 11:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 11:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 11:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 11:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdk.sys – (mferkdk)
DRV - [2009/03/02 01:03:46 | 000,038,912 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1c51x86.sys – (L1c)
DRV - [2009/02/25 23:17:52 | 001,344,224 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2009/02/24 04:49:44 | 005,032,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)
DRV - [2009/02/03 02:42:30 | 000,162,816 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/01/02 21:33:54 | 000,145,408 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\M3000KNT.sys – (M3000Srv)
DRV - [2008/08/05 08:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/07/10 08:23:14 | 000,040,488 | —- | M] (Nero AG) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\InCDRm.sys – (incdrm)
DRV - [2008/07/10 08:23:14 | 000,038,952 | —- | M] (Nero AG) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\InCDPass.sys – (InCDPass)
DRV - [2008/07/10 08:23:14 | 000,018,088 | —- | M] (Nero AG) [Recognizer | System | Unknown] – C:\WINDOWS\system32\drivers\InCDrec.sys – (InCDRec)
DRV - [2008/07/10 08:23:04 | 000,128,424 | —- | M] (Nero AG) [File_System | Disabled | Running] – C:\WINDOWS\system32\drivers\InCDfs.sys – (InCDfs)
DRV - [2006/11/02 09:27:36 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2006/01/04 03:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACAW&a;…mp;m=aspire_one
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/accounts/ServiceLogi…mp;ltmplcache=2
IE - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" =
http://www.google.com/search?sourceid=ie7&…1I7ACAW_enUS344
IE - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" =
http://127.0.0.1:4664/search&s;=k6hiU_a…q={searchTerms}
IE - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/07/30 11:15:47 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - homepage:
http://www.gmail.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
http://www.gmail.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: npFFApi (Enabled) = C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: AT_Delbuck = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\neghaibmbjedngldjldidfoobmkkfkle\2\
CHR - Extension: Gmail = C:\Documents and Settings\Family02\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/08/11 18:31:11 | 000,443,305 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15252 more lines…
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Prolific2571_OneButton] C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe (Prolific)
O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-2387590086-3402799377-1653462319-1005\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.systemrequirementslab.co…eqlabdetect.cab (Reg Error: Key error.)
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2}
http://simcity.ea.com/update/EARTPX.cab (EARTPatchX Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {BC18E6DF-BE57-4580-93E8-F228F9A133AA}
http://simcity.ea.com/exchange/lots/telepo…ty4LotTeleX.cab (MaxisSimCity4LotTeleX Control)
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD}
http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab (MaxisSimCity4PatcherX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E03A340A-BB63-4B53-8549-27096FD9F9E9}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.dll) - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Family02\My Documents\My Pictures\untitled.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Family02\My Documents\My Pictures\untitled.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/12 01:07:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/30 11:12:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Check Point
[2012/07/30 11:11:42 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/07/22 19:29:44 | 000,526,640 | —- | C] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys
[2012/07/15 18:27:24 | 000,000,000 | —D | C] – C:\.jagex_cache_32
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/13 09:20:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/13 09:15:28 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/13 09:15:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/08/13 09:14:58 | 1063,198,720 | -HS- | M] () – C:\hiberfil.sys
[2012/08/12 19:58:01 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2387590086-3402799377-1653462319-1005UA.job
[2012/08/12 17:58:01 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2387590086-3402799377-1653462319-1005Core.job
[2012/08/12 17:52:41 | 000,000,512 | —- | M] () – C:\Documents and Settings\Family02\Desktop\MBR.dat
[2012/08/11 18:36:41 | 000,000,318 | -H– | M] () – C:\WINDOWS\tasks\avast! Emergency Update.job
[2012/08/11 18:31:11 | 000,443,305 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/08/11 18:30:08 | 000,443,305 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120811-183111.backup
[2012/08/11 12:07:55 | 000,000,024 | —- | M] () – C:\Documents and Settings\Family02\random.dat
[2012/08/11 11:40:25 | 000,000,024 | —- | M] () – C:\Documents and Settings\Family02\jagexappletviewer.preferences
[2012/08/11 11:39:28 | 000,000,064 | —- | M] () – C:\Documents and Settings\Family02\jagex_cl_runescape_LIVE.dat
[2012/08/09 10:06:28 | 000,002,313 | —- | M] () – C:\Documents and Settings\Family02\Desktop\Google Chrome.lnk
[2012/08/07 11:50:49 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/07/30 21:45:04 | 000,443,125 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120811-183008.backup
[2012/07/30 11:16:32 | 000,415,933 | —- | M] () – C:\WINDOWS\System32\vsconfig.xml
[2012/07/28 14:13:50 | 000,000,069 | —- | M] () – C:\Documents and Settings\Family02\jagex_cl_runescape_LIVE_BETA.dat
[2012/07/28 10:29:57 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/07/28 10:18:23 | 000,000,788 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/28 09:54:12 | 000,443,125 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20120730-214504.backup
[2012/07/22 19:29:44 | 000,526,640 | —- | M] (Check Point Software Technologies LTD) – C:\WINDOWS\System32\vsdatant.sys
[2012/07/21 18:08:03 | 000,120,856 | —- | M] () – C:\Documents and Settings\Family02\My Documents\genVpokedex.ods
[2012/07/15 18:27:47 | 000,000,065 | —- | M] () – C:\Documents and Settings\Family02\jagex_cl_runescape_LIVE1.dat
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/12 17:48:41 | 000,000,512 | —- | C] () – C:\Documents and Settings\Family02\Desktop\MBR.dat
[2012/06/26 11:42:11 | 000,000,069 | —- | C] () – C:\Documents and Settings\Family02\jagex_cl_runescape_LIVE_BETA.dat
[2012/06/26 11:38:07 | 000,000,065 | —- | C] () – C:\Documents and Settings\Family02\jagex_cl_runescape_LIVE1.dat
[2012/06/21 00:29:43 | 000,000,064 | —- | C] () – C:\Documents and Settings\Family02\jagex_cl_runescape_LIVE.dat
[2012/06/21 00:24:13 | 000,000,024 | —- | C] () – C:\Documents and Settings\Family02\jagexappletviewer.preferences
[2012/06/06 23:03:43 | 000,001,580 | —- | C] () – C:\Documents and Settings\Family02\.recently-used.xbel
[2011/11/02 01:52:48 | 000,000,024 | —- | C] () – C:\Documents and Settings\Family02\random.dat
[2011/03/01 08:50:18 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2011/03/01 08:46:57 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/12 20:00:53 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\nvRegDev.dll
[2009/12/26 16:39:40 | 000,000,340 | —- | C] () – C:\Documents and Settings\Family02\Application Data\wklnhst.dat
[2009/10/09 20:15:49 | 000,000,162 | —- | C] () – C:\Documents and Settings\Family02\Application Data\default.pls
[2009/09/09 14:24:18 | 000,001,024 | —- | C] () – C:\Documents and Settings\Family02\.rnd
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
[2008/04/29 11:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe
< MD5 for: SVCHOST.EXE >
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ERDNT\cache\svchost.exe
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/07/01 09:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 08:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 08:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/07/01 09:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe
< %systemroot%\*. /rp /s >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: TOSHIBA MK1655GSX
Partitions: 2
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 7.00GB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 142.00GB
Starting Offset: 7518289920
Hidden sectors: 0
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4CF61E54
< End of report >