jeremyfred
Topic Starter
Hi Folks,
AVG has recently popped up a few trojan alerts, and a trendmicro scan found and cleaned one as well. Additionally, as of late, streaming video has been very choppy for me, on legitimate sites (e.g. hbogo, hulu) that used to run without problems. I'm hoping that y'all can help me out.
Thanks!
-Jeremy
Here is the info from OTL:
OTL logfile created on: 9/9/2012 11:40:59 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\jeremy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.23 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 66.32% Memory free
2.94 Gb Paging File | 2.46 Gb Available in Paging File | 83.70% Paging File free
Paging file location(s): C:\pagefile.sys 1896 3792 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 50.48 Gb Free Space | 45.16% Space Free | Partition Type: NTFS
Computer Name: JF | User Name: jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\jeremy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
PRC - C:\Program Files\Google\Update\1.3.21.115\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.115\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\All Users\Application Data\Boxtools\Toolbox.exe ()
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\jeremy\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\1XConfig.exe (Intel)
PRC - C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
PRC - C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Winamp\winampa.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libaudioenc.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libmpgdec.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libid3tag.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libaacdec.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\imageformats\qgif4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtWebKit4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtGui4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtNetwork4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtCore4.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Boxtools\Toolbox.exe ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Apps\F.lux\flux.exe ()
MOD - C:\WINDOWS\system32\libeay32.dll ()
MOD - C:\WINDOWS\system32\ssleay32.dll ()
MOD - C:\Program Files\Winamp\winampa.exe ()
========== Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (S24EventMonitor) – C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) – C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys ()
DRV - (easytether) – C:\WINDOWS\system32\drivers\easytthr.sys (Mobile Stream)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (WinUsb) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (MDC8021X) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (w29n51) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (tifm) – C:\WINDOWS\system32\drivers\tifm.sys (Texas Instruments)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (w22n51) – C:\WINDOWS\system32\drivers\w22n51.sys (Intel® Corporation)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0D57D5CB-EFB9-4202-8CF5-0207463C1302}
IE - HKCU\..\SearchScopes\{0D57D5CB-EFB9-4202-8CF5-0207463C1302}: "URL" = http://www.google.com/search?q={searchTerm…e=utf8&rlz;=
IE - HKCU\..\SearchScopes\{d6cf3126-41d1-4b46-baa7-6635c2cdd328}: "URL" = http://slirsredirect.search.aol.com/redire…u10aiminstabie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/18 01:05:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/06 01:21:54 | 000,000,000 | —D | M]
[2011/03/02 00:41:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Extensions
[2009/11/13 15:11:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Extensions\[removed]
[2011/03/02 00:41:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions
[2011/03/02 00:41:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/02 00:41:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions\staged-xpis
[2009/03/18 15:40:42 | 000,019,153 | —- | M] () (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions\staged-xpis\{20a82645-c095-46ed-80e3-08825760534b}\MicrosoftDotNetFrameworkAssistant.xpi
[2012/07/08 17:29:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/08 17:29:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/07/08 17:28:39 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
========== Chrome ==========
CHR - homepage: http://lasnet/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://lasnet/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Chrome Toolbox Plugin (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.29_0\plugin/convenience.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Drive = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: Gmail Offline = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.19_0\
CHR - Extension: Google Calendar = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: Chrome Toolbox (by Google) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.32_0\
CHR - Extension: Salon for Chrome = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hdfnaelmdjoicpekggmmafbcdhljalak\0.2010.1102.584_0\
O1 HOSTS File: ([2009/06/20 15:05:11 | 000,307,172 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10574 more lines…
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\Winampa.exe ()
O4 - HKCU..\Run: [Boxoft Tools] C:\Documents and Settings\All Users\Application Data\Boxtools\Boxofttoolbox.exe ()
O4 - HKCU..\Run: [F.lux] C:\Documents and Settings\jeremy\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKCU..\Run: [MusicManager] C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKCU..\Run: [Spotify] C:\Documents and Settings\jeremy\Application Data\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] "C:\Documents and Settings\jeremy\Application Data\Spotify\Data\SpotifyWebHelper.exe" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} http://intel-drv-cdn.systemrequirementslab…reqlab_srlx.cab (System Requirements Lab Class)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB64576A-921D-4028-B831-A7A10C43CF93}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\Sebring: DllName - (c:\WINDOWS\system32\LgNotify.dll) - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/17 23:39:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/09 23:23:03 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\jeremy\Desktop\OTL.exe
[2012/09/06 21:30:39 | 002,002,944 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\jeremy\Desktop\HousecallLauncher.exe
[2012/08/12 18:27:12 | 000,000,000 | —D | C] – C:\Documents and Settings\jeremy\Desktop\torrents
[2012/08/12 15:28:07 | 000,896,400 | —- | C] (BitTorrent, Inc.) – C:\Documents and Settings\jeremy\Desktop\uTorrent.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/09 23:22:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jeremy\Desktop\OTL.exe
[2012/09/09 23:03:03 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-789336058-854245398-1003UA.job
[2012/09/09 23:00:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/09 21:03:09 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-789336058-854245398-1003Core.job
[2012/09/09 21:00:21 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/09 20:27:29 | 057,340,307 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/09/07 00:21:20 | 000,252,347 | —- | M] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\census.cache
[2012/09/07 00:20:52 | 000,167,905 | —- | M] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\ars.cache
[2012/09/06 22:03:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/09/06 22:03:30 | 1323,814,912 | -HS- | M] () – C:\hiberfil.sys
[2012/09/06 21:58:02 | 000,000,492 | —- | M] () – C:\WINDOWS\DCEBOOT.RST
[2012/09/06 21:55:15 | 000,102,400 | —- | M] () – C:\WINDOWS\RegBootClean.exe
[2012/09/06 21:55:14 | 000,022,032 | —- | M] () – C:\WINDOWS\DCEBoot.exe
[2012/09/06 21:31:40 | 000,000,036 | —- | M] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\housecall.guid.cache
[2012/09/06 21:30:23 | 002,002,944 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jeremy\Desktop\HousecallLauncher.exe
[2012/09/05 14:15:26 | 000,002,271 | —- | M] () – C:\Documents and Settings\jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/23 18:23:58 | 000,269,779 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\https___checkin.jetblue.com_B6WebCheckIn_pdfservlet_Boardingpass.pdf_name=B
oardingpass.pdf
[2012/08/23 16:43:06 | 000,287,753 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\petlovemain.gif
[2012/08/18 10:40:01 | 000,000,820 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2012/08/14 07:48:15 | 000,000,803 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\dmv letter.rtf
[2012/08/12 16:09:42 | 000,316,203 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\Cover.jpg
[2012/08/12 15:28:11 | 000,896,400 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\jeremy\Desktop\uTorrent.exe
[2012/08/12 11:30:00 | 000,177,056 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/11 21:36:47 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/06 21:58:02 | 000,000,492 | —- | C] () – C:\WINDOWS\DCEBOOT.RST
[2012/09/06 21:55:14 | 000,102,400 | —- | C] () – C:\WINDOWS\RegBootClean.exe
[2012/09/06 21:55:14 | 000,022,032 | —- | C] () – C:\WINDOWS\DCEBoot.exe
[2012/09/06 21:54:27 | 000,252,347 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\census.cache
[2012/09/06 21:53:37 | 000,167,905 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\ars.cache
[2012/09/06 21:31:40 | 000,000,036 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\housecall.guid.cache
[2012/08/23 18:23:55 | 000,269,779 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\https___checkin.jetblue.com_B6WebCheckIn_pdfservlet_Boardingpass.pdf_name=B
oardingpass.pdf
[2012/08/23 16:43:18 | 000,287,753 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\petlovemain.gif
[2012/08/13 15:37:06 | 000,000,803 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\dmv letter.rtf
[2012/08/12 15:59:45 | 000,316,203 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\Cover.jpg
[2012/06/28 22:14:40 | 000,000,040 | —- | C] () – C:\Documents and Settings\jeremy\Application Data\cdr.ini
[2012/02/23 08:30:19 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/03/02 00:40:57 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/01/24 21:48:27 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2010/12/23 23:09:56 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\getpntid.exe
[2010/10/08 14:12:59 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/09/21 19:40:11 | 000,093,696 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/28 19:03:39 | 000,061,678 | —- | C] () – C:\Documents and Settings\jeremy\Application Data\PFP120JPR.{PB
[2009/06/28 19:03:39 | 000,012,358 | —- | C] () – C:\Documents and Settings\jeremy\Application Data\PFP120JCM.{PB
[2009/06/20 13:45:21 | 000,000,034 | —- | C] () – C:\Documents and Settings\All Users\msrecovery.cfc
========== LOP Check ==========
[2012/09/06 22:34:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Boxtools
[2009/09/02 11:24:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Examsoft
[2009/09/29 13:33:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2011/09/18 01:11:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/29 18:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/31 16:06:23 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Amazon
[2010/10/18 18:46:45 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\CiscoCAA
[2009/11/13 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Flickr
[2009/06/20 13:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Foxit
[2011/01/25 00:44:23 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\ICAClient
[2011/01/13 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Softland
[2012/09/06 22:05:40 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Spotify
[2012/08/23 18:36:54 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\uTorrent
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/12 09:19:07 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: EXPLORER.SCF >
[2004/08/12 09:19:07 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/12 09:19:56 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/29 03:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2010/12/20 07:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\SoftwareDistribution\Download\79810b38397180784856d3f418ff8477\sp3gdr\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3GDR\iexplore.exe
[2011/12/16 07:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie8\iexplore.exe
[2011/10/31 06:32:32 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=1C5DA2D9EA2A59D0D5C116FA3A5A21AA – C:\WINDOWS\SoftwareDistribution\Download\ae81350a77b7bcb922b221ce92f22f3f\sp3qfe\iexplore.exe
[2010/06/17 11:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2011/10/31 06:46:00 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=2E34CF22B5862AB02786F0819B9FD819 – C:\WINDOWS\SoftwareDistribution\Download\ae81350a77b7bcb922b221ce92f22f3f\sp3gdr\iexplore.exe
[2009/08/27 01:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 04:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 06:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/28 02:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 09:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2011/08/17 07:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2010/10/18 07:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2009/10/28 02:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2011/06/20 07:29:11 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=993F33696EF219C306BF9BBA34D85073 – C:\WINDOWS\SoftwareDistribution\Download\6b6aef8a30b6ddfc7013d6510357896e\sp3gdr\iexplore.exe
[2010/06/17 10:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/02/23 01:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2011/04/21 06:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\ie7updates\KB2586448-IE7\iexplore.exe
[2010/12/20 06:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\SoftwareDistribution\Download\79810b38397180784856d3f418ff8477\sp3qfe\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3QFE\iexplore.exe
[2010/02/23 01:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2011/08/17 06:34:43 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=CB0AFAF9E5C5FE70EC7087E71275DD33 – C:\WINDOWS\$hf_mig$\KB2586448-IE7\SP3QFE\iexplore.exe
[2009/12/18 03:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2010/10/18 06:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/12/16 06:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe
[2011/06/20 06:38:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DE0F15DD275A36C3E67DC1E36F958F3A – C:\WINDOWS\SoftwareDistribution\Download\6b6aef8a30b6ddfc7013d6510357896e\sp3qfe\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2011/02/14 07:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\SoftwareDistribution\Download\854a2ecd85b162f2eb4e0f18a906a0b9\sp3qfe\iexplore.exe
[2011/02/14 08:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\SoftwareDistribution\Download\854a2ecd85b162f2eb4e0f18a906a0b9\sp3gdr\iexplore.exe
[2010/08/25 07:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/12 09:19:56 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2010/08/25 07:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 01:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/09/05 21:44:38 | 000,084,086 | —- | M] () MD5=CDA38180B0952222ACFE5059E60291B7 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/12 09:19:56 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/12 09:28:10 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/12 09:28:09 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SERVICES.LNK >
[2009/02/17 23:39:34 | 000,001,602 | —- | M] () MD5=2E6CF51825804DB4FD6779D4A6F642DA – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/12 09:28:10 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.SBS >
[2009/06/16 03:28:16 | 000,031,314 | —- | M] () MD5=B8897ABC19687D0EF1A1CEBA6E587BBF – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: WINLOGON.EXE >
[2004/08/12 09:33:32 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2009/02/17 23:39:30 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/04/01 13:55:23 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/02/17 23:39:30 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/09/06 22:03:30 | 1323,814,912 | -HS- | M] () – C:\hiberfil.sys
[2009/02/17 23:39:30 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/28 20:34:52 | 000,000,467 | -H– | M] () – C:\IPH.PH
[2009/02/17 23:39:30 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/12 09:25:07 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/20 12:36:48 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/09/06 22:03:29 | 1988,100,096 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/02/17 23:39:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/02/17 19:28:56 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/02/17 19:28:56 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/02/17 19:28:56 | 000,888,832 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
[2009/07/28 16:27:17 | 000,000,000 | —D | M] – C:\Program Files\ExamSoft\SofTest\bak
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/06/20 12:47:43 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/17 23:44:33 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/02/17 23:44:33 | 000,000,079 | —- | M] () – C:\Documents and Settings\jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/06/24 18:01:48 | 000,894,448 | —- | M] (Oracle Corporation) – C:\Documents and Settings\jeremy\Desktop\chromeinstall-7u5.exe
[2012/01/30 01:36:05 | 000,463,080 | —- | M] (CNET Download.com) – C:\Documents and Settings\jeremy\Desktop\cnet2_setupwavtomp3_exe.exe
[2012/02/27 01:39:43 | 000,559,424 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\flux-setup.exe
[2012/09/06 21:30:23 | 002,002,944 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jeremy\Desktop\HousecallLauncher.exe
[2012/01/30 00:46:00 | 000,606,528 | —- | M] (Google Inc.) – C:\Documents and Settings\jeremy\Desktop\musicmanagerinstaller.exe
[2012/09/09 23:22:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jeremy\Desktop\OTL.exe
[2012/04/01 19:37:33 | 014,907,240 | —- | M] (Google Inc.) – C:\Documents and Settings\jeremy\Desktop\picasa39-setup.exe
[2012/01/29 17:12:38 | 011,286,479 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\pwsafe-3.27.exe
[2012/06/28 22:12:34 | 003,655,683 | —- | M] (A-PDF Solution ) – C:\Documents and Settings\jeremy\Desktop\setup(free-ape-to-mp3).exe
[2012/06/24 17:53:14 | 006,955,968 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\jeremy\Desktop\Silverlight.exe
[2012/08/03 17:36:38 | 019,665,520 | —- | M] (Spotify Ltd) – C:\Documents and Settings\jeremy\Desktop\Spotify Installer.exe
[2012/08/12 15:28:11 | 000,896,400 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\jeremy\Desktop\uTorrent.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-08-12 01:37:02
< End of report >
OTL Extras logfile created on: 9/9/2012 11:40:59 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\jeremy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.23 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 66.32% Memory free
2.94 Gb Paging File | 2.46 Gb Available in Paging File | 83.70% Paging File free
Paging file location(s): C:\pagefile.sys 1896 3792 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 50.48 Gb Free Space | 45.16% Space Free | Partition Type: NTFS
Computer Name: JF | User Name: jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe" = C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe:*:Enabled:Application Layer Gateway Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\ExamSoft\SofTest\SoftLnch.exe" = C:\Program Files\ExamSoft\SoftLnch.exe:*:Enabled:SofLaunch
"C:\Program Files\ExamSoft\SofTest\softest.exe" = C:\Program Files\ExamSoft\SofTest.exe:*:Enabled:SofTest
"C:\Program Files\SoulseekNS\slsk.exe" = C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek – ()
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM
"C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe" = C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe:*:Enabled:Flickr Uploadr – (Mozilla Foundation)
"C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe" = C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe:*:Enabled:Application Layer Gateway Service
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\jeremy\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\jeremy\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{18499419-2B80-4C3F-86D3-C6C45CD2062E}" = Samsung ML-1710 Series
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{3378D826-DCF1-4469-A6CA-E38EA43EAF48}" = EasyTether
"{33F1EEC8-93C8-4CC5-9C33-6698A4A627BA}" = TIPCIxx20
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{5380063E-2909-4d72-BFA3-625881F2E78B}" = Intel® PROSet for Wireless
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{7959721D-8268-4565-9E0E-C41A9F4848A9}" = SigmaTel AC97 Audio Drivers
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{96334581-5554-3E5F-8BC9-924C3C3AC5BE}" = Google Talk Plugin
"{9884276A-35B4-461B-827A-4F452C35B4A0}" = SofTest Bar Edition
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}" = Citrix Presentation Server Client
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DDD512C6-2251-4046-8F25-1A5EB355015E}" = Intel® mDriver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"AVG8Uninstall" = AVG Free 8.5
"Boxoft free APE to MP3 (freeware)_is1" = Boxoft free APE to MP3 (freeware)
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.9x Modem
"doPDF 7 printer_is1" = doPDF 7.2 printer
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"Foxit Reader" = Foxit Reader
"Google Updater" = Google Updater
"HTC_WModemDriver" = WModem Driver Installer
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{33F1EEC8-93C8-4CC5-9C33-6698A4A627BA}" = Texas Instruments PCIxx20 drivers.
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"LameACM" = Lame ACM MP3 Codec
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Password Safe" = Password Safe
"Picasa 3" = Picasa 3
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Soulseek2" = SoulSeek 157 NS 13e
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"UltraISO_is1" = UltraISO Premium V9.36
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.3
"WAV to MP3 Encoder" = WAV to MP3 Encoder
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp (remove only)
"Windows XP Service Pack" = Windows XP Service Pack 3
"winusb0200" = Microsoft WinUsb 2.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Flux" = F.lux
"Google Chrome" = Google Chrome
"MusicManager" = Music Manager
"Spotify" = Spotify
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 7/15/2011 11:25:44 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/25/2011 9:39:59 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/25/2011 9:40:00 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/25/2011 9:40:51 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 8/23/2012 7:52:44 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.
Error - 9/5/2012 1:42:16 PM | Computer Name = JF | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.196 on
the Network Card with network address 000E35893D3E.
Error - 9/5/2012 1:42:19 PM | Computer Name = JF | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 000E35893D3E. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 9/5/2012 1:43:10 PM | Computer Name = JF | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 000E35893D3E. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 9/5/2012 1:49:17 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the avg8wd service.
Error - 9/5/2012 1:49:28 PM | Computer Name = JF | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 000E35893D3E. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 9/5/2012 3:43:49 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.
Error - 9/5/2012 3:43:49 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the wscsvc service.
Error - 9/6/2012 8:04:50 AM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.
Error - 9/6/2012 10:05:13 PM | Computer Name = JF | Source = System Error | ID = 1003
Description = Error code 1000008e, parameter1 c0000005, parameter2 bf9568d5, parameter3
f7886c00, parameter4 00000000.
< End of report >
AVG has recently popped up a few trojan alerts, and a trendmicro scan found and cleaned one as well. Additionally, as of late, streaming video has been very choppy for me, on legitimate sites (e.g. hbogo, hulu) that used to run without problems. I'm hoping that y'all can help me out.
Thanks!
-Jeremy
Here is the info from OTL:
OTL logfile created on: 9/9/2012 11:40:59 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\jeremy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.23 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 66.32% Memory free
2.94 Gb Paging File | 2.46 Gb Available in Paging File | 83.70% Paging File free
Paging file location(s): C:\pagefile.sys 1896 3792 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 50.48 Gb Free Space | 45.16% Space Free | Partition Type: NTFS
Computer Name: JF | User Name: jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\jeremy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
PRC - C:\Program Files\Google\Update\1.3.21.115\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.115\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\All Users\Application Data\Boxtools\Toolbox.exe ()
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\jeremy\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\1XConfig.exe (Intel)
PRC - C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
PRC - C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Winamp\winampa.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libaudioenc.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libmpgdec.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libid3tag.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\libaacdec.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\imageformats\qgif4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtWebKit4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtGui4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtNetwork4.dll ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\QtCore4.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Boxtools\Toolbox.exe ()
MOD - C:\Documents and Settings\jeremy\Local Settings\Apps\F.lux\flux.exe ()
MOD - C:\WINDOWS\system32\libeay32.dll ()
MOD - C:\WINDOWS\system32\ssleay32.dll ()
MOD - C:\Program Files\Winamp\winampa.exe ()
========== Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (S24EventMonitor) – C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) – C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys ()
DRV - (easytether) – C:\WINDOWS\system32\drivers\easytthr.sys (Mobile Stream)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (WinUsb) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (MDC8021X) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (w29n51) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (tifm) – C:\WINDOWS\system32\drivers\tifm.sys (Texas Instruments)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (w22n51) – C:\WINDOWS\system32\drivers\w22n51.sys (Intel® Corporation)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0D57D5CB-EFB9-4202-8CF5-0207463C1302}
IE - HKCU\..\SearchScopes\{0D57D5CB-EFB9-4202-8CF5-0207463C1302}: "URL" = http://www.google.com/search?q={searchTerm…e=utf8&rlz;=
IE - HKCU\..\SearchScopes\{d6cf3126-41d1-4b46-baa7-6635c2cdd328}: "URL" = http://slirsredirect.search.aol.com/redire…u10aiminstabie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/18 01:05:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/06 01:21:54 | 000,000,000 | —D | M]
[2011/03/02 00:41:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Extensions
[2009/11/13 15:11:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Extensions\[removed]
[2011/03/02 00:41:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions
[2011/03/02 00:41:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/02 00:41:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions\staged-xpis
[2009/03/18 15:40:42 | 000,019,153 | —- | M] () (No name found) – C:\Documents and Settings\jeremy\Application Data\Mozilla\Firefox\Profiles\9gq6ra0g.default\extensions\staged-xpis\{20a82645-c095-46ed-80e3-08825760534b}\MicrosoftDotNetFrameworkAssistant.xpi
[2012/07/08 17:29:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/08 17:29:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/07/08 17:28:39 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
========== Chrome ==========
CHR - homepage: http://lasnet/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms},
CHR - homepage: http://lasnet/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Chrome Toolbox Plugin (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.29_0\plugin/convenience.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\jeremy\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Drive = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: Gmail Offline = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.19_0\
CHR - Extension: Google Calendar = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: Chrome Toolbox (by Google) = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.32_0\
CHR - Extension: Salon for Chrome = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hdfnaelmdjoicpekggmmafbcdhljalak\0.2010.1102.584_0\
O1 HOSTS File: ([2009/06/20 15:05:11 | 000,307,172 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10574 more lines…
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\Winampa.exe ()
O4 - HKCU..\Run: [Boxoft Tools] C:\Documents and Settings\All Users\Application Data\Boxtools\Boxofttoolbox.exe ()
O4 - HKCU..\Run: [F.lux] C:\Documents and Settings\jeremy\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKCU..\Run: [MusicManager] C:\Documents and Settings\jeremy\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKCU..\Run: [Spotify] C:\Documents and Settings\jeremy\Application Data\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] "C:\Documents and Settings\jeremy\Application Data\Spotify\Data\SpotifyWebHelper.exe" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} http://intel-drv-cdn.systemrequirementslab…reqlab_srlx.cab (System Requirements Lab Class)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB64576A-921D-4028-B831-A7A10C43CF93}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\Sebring: DllName - (c:\WINDOWS\system32\LgNotify.dll) - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/17 23:39:30 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/09 23:23:03 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Documents and Settings\jeremy\Desktop\OTL.exe
[2012/09/06 21:30:39 | 002,002,944 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\jeremy\Desktop\HousecallLauncher.exe
[2012/08/12 18:27:12 | 000,000,000 | —D | C] – C:\Documents and Settings\jeremy\Desktop\torrents
[2012/08/12 15:28:07 | 000,896,400 | —- | C] (BitTorrent, Inc.) – C:\Documents and Settings\jeremy\Desktop\uTorrent.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/09 23:22:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jeremy\Desktop\OTL.exe
[2012/09/09 23:03:03 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-789336058-854245398-1003UA.job
[2012/09/09 23:00:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/09 21:03:09 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-789336058-854245398-1003Core.job
[2012/09/09 21:00:21 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/09 20:27:29 | 057,340,307 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2012/09/07 00:21:20 | 000,252,347 | —- | M] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\census.cache
[2012/09/07 00:20:52 | 000,167,905 | —- | M] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\ars.cache
[2012/09/06 22:03:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/09/06 22:03:30 | 1323,814,912 | -HS- | M] () – C:\hiberfil.sys
[2012/09/06 21:58:02 | 000,000,492 | —- | M] () – C:\WINDOWS\DCEBOOT.RST
[2012/09/06 21:55:15 | 000,102,400 | —- | M] () – C:\WINDOWS\RegBootClean.exe
[2012/09/06 21:55:14 | 000,022,032 | —- | M] () – C:\WINDOWS\DCEBoot.exe
[2012/09/06 21:31:40 | 000,000,036 | —- | M] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\housecall.guid.cache
[2012/09/06 21:30:23 | 002,002,944 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jeremy\Desktop\HousecallLauncher.exe
[2012/09/05 14:15:26 | 000,002,271 | —- | M] () – C:\Documents and Settings\jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/23 18:23:58 | 000,269,779 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\https___checkin.jetblue.com_B6WebCheckIn_pdfservlet_Boardingpass.pdf_name=B
oardingpass.pdf
[2012/08/23 16:43:06 | 000,287,753 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\petlovemain.gif
[2012/08/18 10:40:01 | 000,000,820 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2012/08/14 07:48:15 | 000,000,803 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\dmv letter.rtf
[2012/08/12 16:09:42 | 000,316,203 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\Cover.jpg
[2012/08/12 15:28:11 | 000,896,400 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\jeremy\Desktop\uTorrent.exe
[2012/08/12 11:30:00 | 000,177,056 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/11 21:36:47 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/06 21:58:02 | 000,000,492 | —- | C] () – C:\WINDOWS\DCEBOOT.RST
[2012/09/06 21:55:14 | 000,102,400 | —- | C] () – C:\WINDOWS\RegBootClean.exe
[2012/09/06 21:55:14 | 000,022,032 | —- | C] () – C:\WINDOWS\DCEBoot.exe
[2012/09/06 21:54:27 | 000,252,347 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\census.cache
[2012/09/06 21:53:37 | 000,167,905 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\ars.cache
[2012/09/06 21:31:40 | 000,000,036 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\housecall.guid.cache
[2012/08/23 18:23:55 | 000,269,779 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\https___checkin.jetblue.com_B6WebCheckIn_pdfservlet_Boardingpass.pdf_name=B
oardingpass.pdf
[2012/08/23 16:43:18 | 000,287,753 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\petlovemain.gif
[2012/08/13 15:37:06 | 000,000,803 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\dmv letter.rtf
[2012/08/12 15:59:45 | 000,316,203 | —- | C] () – C:\Documents and Settings\jeremy\Desktop\Cover.jpg
[2012/06/28 22:14:40 | 000,000,040 | —- | C] () – C:\Documents and Settings\jeremy\Application Data\cdr.ini
[2012/02/23 08:30:19 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/03/02 00:40:57 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/01/24 21:48:27 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2010/12/23 23:09:56 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\getpntid.exe
[2010/10/08 14:12:59 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/09/21 19:40:11 | 000,093,696 | —- | C] () – C:\Documents and Settings\jeremy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/28 19:03:39 | 000,061,678 | —- | C] () – C:\Documents and Settings\jeremy\Application Data\PFP120JPR.{PB
[2009/06/28 19:03:39 | 000,012,358 | —- | C] () – C:\Documents and Settings\jeremy\Application Data\PFP120JCM.{PB
[2009/06/20 13:45:21 | 000,000,034 | —- | C] () – C:\Documents and Settings\All Users\msrecovery.cfc
========== LOP Check ==========
[2012/09/06 22:34:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Boxtools
[2009/09/02 11:24:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Examsoft
[2009/09/29 13:33:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Soulseek
[2011/09/18 01:11:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/29 18:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/10/31 16:06:23 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Amazon
[2010/10/18 18:46:45 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\CiscoCAA
[2009/11/13 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Flickr
[2009/06/20 13:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Foxit
[2011/01/25 00:44:23 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\ICAClient
[2011/01/13 19:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Softland
[2012/09/06 22:05:40 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\Spotify
[2012/08/23 18:36:54 | 000,000,000 | —D | M] – C:\Documents and Settings\jeremy\Application Data\uTorrent
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/12 09:19:07 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: EXPLORER.SCF >
[2004/08/12 09:19:07 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/12 09:19:56 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/29 03:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2010/12/20 07:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\SoftwareDistribution\Download\79810b38397180784856d3f418ff8477\sp3gdr\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3GDR\iexplore.exe
[2011/12/16 07:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie8\iexplore.exe
[2011/10/31 06:32:32 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=1C5DA2D9EA2A59D0D5C116FA3A5A21AA – C:\WINDOWS\SoftwareDistribution\Download\ae81350a77b7bcb922b221ce92f22f3f\sp3qfe\iexplore.exe
[2010/06/17 11:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2011/10/31 06:46:00 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=2E34CF22B5862AB02786F0819B9FD819 – C:\WINDOWS\SoftwareDistribution\Download\ae81350a77b7bcb922b221ce92f22f3f\sp3gdr\iexplore.exe
[2009/08/27 01:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 04:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 06:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/28 02:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 09:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2011/08/17 07:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2010/10/18 07:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2009/10/28 02:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2011/06/20 07:29:11 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=993F33696EF219C306BF9BBA34D85073 – C:\WINDOWS\SoftwareDistribution\Download\6b6aef8a30b6ddfc7013d6510357896e\sp3gdr\iexplore.exe
[2010/06/17 10:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/02/23 01:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2011/04/21 06:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\ie7updates\KB2586448-IE7\iexplore.exe
[2010/12/20 06:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\SoftwareDistribution\Download\79810b38397180784856d3f418ff8477\sp3qfe\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\SoftwareDistribution\Download\803badc49670f68514bc104c4297fe82\SP3QFE\iexplore.exe
[2010/02/23 01:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2011/08/17 06:34:43 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=CB0AFAF9E5C5FE70EC7087E71275DD33 – C:\WINDOWS\$hf_mig$\KB2586448-IE7\SP3QFE\iexplore.exe
[2009/12/18 03:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2010/10/18 06:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/12/16 06:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe
[2011/06/20 06:38:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DE0F15DD275A36C3E67DC1E36F958F3A – C:\WINDOWS\SoftwareDistribution\Download\6b6aef8a30b6ddfc7013d6510357896e\sp3qfe\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2011/02/14 07:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\SoftwareDistribution\Download\854a2ecd85b162f2eb4e0f18a906a0b9\sp3qfe\iexplore.exe
[2011/02/14 08:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\SoftwareDistribution\Download\854a2ecd85b162f2eb4e0f18a906a0b9\sp3gdr\iexplore.exe
[2010/08/25 07:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/12 09:19:56 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2010/08/25 07:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/27 01:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/09/05 21:44:38 | 000,084,086 | —- | M] () MD5=CDA38180B0952222ACFE5059E60291B7 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/12 09:19:56 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/12 09:28:10 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/12 09:28:09 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SERVICES.LNK >
[2009/02/17 23:39:34 | 000,001,602 | —- | M] () MD5=2E6CF51825804DB4FD6779D4A6F642DA – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/12 09:28:10 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.SBS >
[2009/06/16 03:28:16 | 000,031,314 | —- | M] () MD5=B8897ABC19687D0EF1A1CEBA6E587BBF – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: WINLOGON.EXE >
[2004/08/12 09:33:32 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2009/02/17 23:39:30 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/04/01 13:55:23 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2009/02/17 23:39:30 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/09/06 22:03:30 | 1323,814,912 | -HS- | M] () – C:\hiberfil.sys
[2009/02/17 23:39:30 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/28 20:34:52 | 000,000,467 | -H– | M] () – C:\IPH.PH
[2009/02/17 23:39:30 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/12 09:25:07 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/20 12:36:48 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/09/06 22:03:29 | 1988,100,096 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/02/17 23:39:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/02/17 19:28:56 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/02/17 19:28:56 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/02/17 19:28:56 | 000,888,832 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
[2009/07/28 16:27:17 | 000,000,000 | —D | M] – C:\Program Files\ExamSoft\SofTest\bak
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/06/20 12:47:43 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/17 23:44:33 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/02/17 23:44:33 | 000,000,079 | —- | M] () – C:\Documents and Settings\jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/06/24 18:01:48 | 000,894,448 | —- | M] (Oracle Corporation) – C:\Documents and Settings\jeremy\Desktop\chromeinstall-7u5.exe
[2012/01/30 01:36:05 | 000,463,080 | —- | M] (CNET Download.com) – C:\Documents and Settings\jeremy\Desktop\cnet2_setupwavtomp3_exe.exe
[2012/02/27 01:39:43 | 000,559,424 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\flux-setup.exe
[2012/09/06 21:30:23 | 002,002,944 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\jeremy\Desktop\HousecallLauncher.exe
[2012/01/30 00:46:00 | 000,606,528 | —- | M] (Google Inc.) – C:\Documents and Settings\jeremy\Desktop\musicmanagerinstaller.exe
[2012/09/09 23:22:59 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Documents and Settings\jeremy\Desktop\OTL.exe
[2012/04/01 19:37:33 | 014,907,240 | —- | M] (Google Inc.) – C:\Documents and Settings\jeremy\Desktop\picasa39-setup.exe
[2012/01/29 17:12:38 | 011,286,479 | —- | M] () – C:\Documents and Settings\jeremy\Desktop\pwsafe-3.27.exe
[2012/06/28 22:12:34 | 003,655,683 | —- | M] (A-PDF Solution ) – C:\Documents and Settings\jeremy\Desktop\setup(free-ape-to-mp3).exe
[2012/06/24 17:53:14 | 006,955,968 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\jeremy\Desktop\Silverlight.exe
[2012/08/03 17:36:38 | 019,665,520 | —- | M] (Spotify Ltd) – C:\Documents and Settings\jeremy\Desktop\Spotify Installer.exe
[2012/08/12 15:28:11 | 000,896,400 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\jeremy\Desktop\uTorrent.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-08-12 01:37:02
< End of report >
OTL Extras logfile created on: 9/9/2012 11:40:59 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\jeremy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.23 Gb Total Physical Memory | 0.82 Gb Available Physical Memory | 66.32% Memory free
2.94 Gb Paging File | 2.46 Gb Available in Paging File | 83.70% Paging File free
Paging file location(s): C:\pagefile.sys 1896 3792 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 50.48 Gb Free Space | 45.16% Space Free | Partition Type: NTFS
Computer Name: JF | User Name: jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe" = C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe:*:Enabled:Application Layer Gateway Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\ExamSoft\SofTest\SoftLnch.exe" = C:\Program Files\ExamSoft\SoftLnch.exe:*:Enabled:SofLaunch
"C:\Program Files\ExamSoft\SofTest\softest.exe" = C:\Program Files\ExamSoft\SofTest.exe:*:Enabled:SofTest
"C:\Program Files\SoulseekNS\slsk.exe" = C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek – ()
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM
"C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\jeremy\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – (Google)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe" = C:\Program Files\Flickr Uploadr\Flickr Uploadr.exe:*:Enabled:Flickr Uploadr – (Mozilla Foundation)
"C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe" = C:\Documents and Settings\jeremy\Local Settings\Temp\0.18785487409230528.exe:*:Enabled:Application Layer Gateway Service
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\jeremy\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\jeremy\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{18499419-2B80-4C3F-86D3-C6C45CD2062E}" = Samsung ML-1710 Series
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{3378D826-DCF1-4469-A6CA-E38EA43EAF48}" = EasyTether
"{33F1EEC8-93C8-4CC5-9C33-6698A4A627BA}" = TIPCIxx20
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{5380063E-2909-4d72-BFA3-625881F2E78B}" = Intel® PROSet for Wireless
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{7959721D-8268-4565-9E0E-C41A9F4848A9}" = SigmaTel AC97 Audio Drivers
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{96334581-5554-3E5F-8BC9-924C3C3AC5BE}" = Google Talk Plugin
"{9884276A-35B4-461B-827A-4F452C35B4A0}" = SofTest Bar Edition
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}" = Citrix Presentation Server Client
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DDD512C6-2251-4046-8F25-1A5EB355015E}" = Intel® mDriver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"AVG8Uninstall" = AVG Free 8.5
"Boxoft free APE to MP3 (freeware)_is1" = Boxoft free APE to MP3 (freeware)
"CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1" = Conexant D480 MDC V.9x Modem
"doPDF 7 printer_is1" = doPDF 7.2 printer
"Flickr Uploadr" = Flickr Uploadr 3.2.1
"Foxit Reader" = Foxit Reader
"Google Updater" = Google Updater
"HTC_WModemDriver" = WModem Driver Installer
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{33F1EEC8-93C8-4CC5-9C33-6698A4A627BA}" = Texas Instruments PCIxx20 drivers.
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"LameACM" = Lame ACM MP3 Codec
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Password Safe" = Password Safe
"Picasa 3" = Picasa 3
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Soulseek2" = SoulSeek 157 NS 13e
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"UltraISO_is1" = UltraISO Premium V9.36
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.0.3
"WAV to MP3 Encoder" = WAV to MP3 Encoder
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp (remove only)
"Windows XP Service Pack" = Windows XP Service Pack 3
"winusb0200" = Microsoft WinUsb 2.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Flux" = F.lux
"Google Chrome" = Google Chrome
"MusicManager" = Music Manager
"Spotify" = Spotify
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 7/15/2011 11:25:44 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/25/2011 9:39:59 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/25/2011 9:40:00 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application PowerDVD.exe, version 5.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/25/2011 9:40:51 PM | Computer Name = JF | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 8/23/2012 7:52:44 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.
Error - 9/5/2012 1:42:16 PM | Computer Name = JF | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.196 on
the Network Card with network address 000E35893D3E.
Error - 9/5/2012 1:42:19 PM | Computer Name = JF | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 000E35893D3E. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 9/5/2012 1:43:10 PM | Computer Name = JF | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 000E35893D3E. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 9/5/2012 1:49:17 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the avg8wd service.
Error - 9/5/2012 1:49:28 PM | Computer Name = JF | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 000E35893D3E. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 9/5/2012 3:43:49 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.
Error - 9/5/2012 3:43:49 PM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the wscsvc service.
Error - 9/6/2012 8:04:50 AM | Computer Name = JF | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the Dnscache service.
Error - 9/6/2012 10:05:13 PM | Computer Name = JF | Source = System Error | ID = 1003
Description = Error code 1000008e, parameter1 c0000005, parameter2 bf9568d5, parameter3
f7886c00, parameter4 00000000.
< End of report >