Scotty P
Topic Starter
Hi,
I am having a problem with one of the PCs I have. When you do a search or click on links in IE8, most of the time it redirects to some sort of advertisement. It is pretty annoying.
Also I get Popup Ads in the bottom corners of the screen, not in IE Windows but just with little crosses in the corner. They go away when you close them, but soon come back.
Here are my logs:
OTL logfile created on: 13/09/2012 11:10:58 - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\SR Parkin\Desktop\Scanners
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.75 Gb Total Physical Memory | 2.35 Gb Available Physical Memory | 85.49% Memory free
4.59 Gb Paging File | 4.37 Gb Available in Paging File | 95.21% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 82.61 Gb Free Space | 82.61% Space Free | Partition Type: NTFS
Drive D: | 132.88 Gb Total Space | 132.79 Gb Free Space | 99.94% Space Free | Partition Type: NTFS
Drive H: | 7.39 Gb Total Space | 5.75 Gb Free Space | 77.80% Space Free | Partition Type: FAT32
Drive S: | 232.72 Gb Total Space | 213.04 Gb Free Space | 91.55% Space Free | Partition Type: NTFS
Computer Name: RS-01 | User Name: SR Parkin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\SR Parkin\Desktop\Scanners\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll ()
MOD - C:\WINXP\system32\cpwmon2k.dll ()
MOD - C:\WINXP\system32\ssp2ml3.dll ()
========== Services (SafeList) ==========
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (HTCAND32) – System32\Drivers\ANDROIDUSB.sys File not found
DRV - (Changer) – File not found
DRV - (5789) – C:\DOCUME~1\SRPARK~1\LOCALS~1\Temp\5789.sys File not found
DRV - (VIAHdAudAddService) – C:\WINXP\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (nvgts) – C:\WINXP\system32\drivers\nvgts.sys (NVIDIA Corporation)
DRV - (FTDIBUS) – C:\WINXP\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (nvnetbus) – C:\WINXP\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINXP\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (DgiVecp) – C:\WINXP\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (NSHE) – C:\WINXP\system32\drivers\NSHE.SYS (T0r0 2008)
DRV - (AmdPPM) – C:\WINXP\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (Hardlock) – C:\WINXP\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (MTsensor) – C:\WINXP\system32\drivers\ASACPI.sys ()
DRV - (EZUSB) – C:\WINXP\system32\drivers\ezusb.sys (cypress semiconductor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://mail.google.com/mail/u/0/?hl=en&shva=1#inbox
IE - HKCU\..\SearchScopes,DefaultScope = {DFC37C1C-BC1E-4D81-A049-6F8A72543F64}
IE - HKCU\..\SearchScopes\{DFC37C1C-BC1E-4D81-A049-6F8A72543F64}: "URL" = http://www.google.co.uk/search?hl=en&q…erms}&meta=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
O1 HOSTS File: ([2011/08/03 08:50:20 | 000,000,764 | —- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe" File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINXP\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINXP\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - HKLM..\Run: [Seagull Drivers] C:\WINXP\ssdal_nc.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: mamsoft.co.uk ([online] https in Local intranet)
O15 - HKCU\..Trusted Domains: rmdmo.co.uk ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{68C03A3E-EB26-4600-9834-A0EA41CB0A56}: NameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\SR Parkin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/05 13:07:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2012/01/05 08:45:16 | 000,000,122 | RHS- | M] () - H:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell\AutoRun\command - "" = E:\Bin\ASSETUP.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/09/10 08:57:33 | 000,000,000 | —D | C] – S:\Downloads
[2012/09/03 13:48:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/03 13:48:03 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINXP\System32\drivers\mbam.sys
[2012/09/03 13:48:03 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2012/09/03 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\SR Parkin\Desktop\Scanners
[2012/08/31 19:13:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Zeitronix Data Logger
[2012/08/31 19:13:17 | 000,000,000 | —D | C] – C:\Program Files\Zeitronix
[2012/08/24 19:08:53 | 000,000,000 | -HSD | C] – C:\Documents and Settings\SR Parkin\IECompatCache
[2012/08/17 18:45:19 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WINXP\System32\spmsgXP_2k3.dll
[3 S:\*.tmp files -> S:\*.tmp -> ]
[3 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/13 11:12:00 | 000,000,242 | —- | M] () – C:\WINXP\tasks\Scheduled Update for Ask Toolbar.job
[2012/09/13 08:06:38 | 000,276,202 | —- | M] () – C:\WINXP\System32\NvApps.xml
[2012/09/13 08:06:37 | 000,002,206 | —- | M] () – C:\WINXP\System32\wpa.dbl
[2012/09/13 08:06:26 | 000,002,048 | –S- | M] () – C:\WINXP\bootstat.dat
[2012/09/07 14:22:16 | 000,022,562 | —- | M] () – S:\INVOICE-INV2200 FinTurbo.pdf
[2012/09/05 12:46:54 | 000,002,493 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Microsoft Word.lnk
[2012/08/31 19:13:17 | 000,000,804 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Zeitronix Data Logger v3.1.6.lnk
[2012/08/17 18:45:23 | 000,000,000 | -H– | M] () – C:\WINXP\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/08/17 18:45:22 | 000,001,374 | —- | M] () – C:\WINXP\imsins.BAK
[2012/08/17 18:45:22 | 000,000,000 | -H– | M] () – C:\WINXP\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/08/16 15:00:11 | 000,002,491 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Microsoft Excel.lnk
[2012/08/16 07:43:48 | 002,043,088 | —- | M] () – C:\WINXP\System32\FNTCACHE.DAT
[3 S:\*.tmp files -> S:\*.tmp -> ]
[3 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/07 14:21:41 | 000,022,562 | —- | C] () – S:\INVOICE-INV2200 FinTurbo.pdf
[2012/08/31 19:13:17 | 000,000,804 | —- | C] () – C:\Documents and Settings\SR Parkin\Desktop\Zeitronix Data Logger v3.1.6.lnk
[2012/08/17 18:45:23 | 000,000,000 | -H– | C] () – C:\WINXP\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/08/17 18:45:22 | 000,000,000 | -H– | C] () – C:\WINXP\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/02/15 08:48:56 | 000,003,072 | —- | C] () – C:\WINXP\System32\iacenc.dll
[2011/11/05 14:05:21 | 000,000,169 | —- | C] () – C:\WINXP\ETKINST.INI
[2011/08/19 11:06:11 | 000,000,727 | —- | C] () – C:\WINXP\pagebreeze.ini
[2011/08/19 11:06:11 | 000,000,044 | —- | C] () – C:\WINXP\formbreeze.ini
[2011/07/30 10:31:19 | 000,003,584 | —- | C] () – C:\Documents and Settings\SR Parkin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/19 09:25:20 | 000,000,000 | —- | C] () – C:\WINXP\eDrawingOfficeAutomator.INI
[2011/07/19 09:18:43 | 000,022,723 | —- | C] () – C:\WINXP\System32\ssp2ml3.dll
[2011/07/18 20:10:31 | 000,153,088 | —- | C] () – C:\WINXP\System32\UNWISE.EXE
[2011/07/18 20:10:31 | 000,028,672 | —- | C] () – C:\WINXP\System32\hlduinst.exe
[2011/07/18 19:40:39 | 000,087,552 | —- | C] () – C:\WINXP\System32\cpwmon2k.dll
[2011/07/18 19:37:53 | 000,000,370 | —- | C] () – C:\WINXP\ODBC.INI
[2011/07/05 13:56:50 | 000,004,073 | —- | C] () – C:\WINXP\ODBCINST.INI
[2011/07/05 13:55:53 | 002,043,088 | —- | C] () – C:\WINXP\System32\FNTCACHE.DAT
[2011/07/05 13:17:56 | 000,010,084 | R— | C] () – C:\WINXP\System32\drivers\nvphy.bin
[2011/07/05 13:16:30 | 000,254,000 | R— | C] ( ) – C:\WINXP\System32\Audio3D.dll
[2011/07/05 13:16:30 | 000,254,000 | R— | C] ( ) – C:\WINXP\System32\A3D.dll
[2011/07/05 13:13:54 | 000,005,810 | R— | C] () – C:\WINXP\System32\drivers\ASACPI.sys
[2011/07/05 13:13:48 | 000,001,769 | —- | C] () – C:\WINXP\Language_trs.ini
[2011/07/05 13:13:43 | 000,026,638 | —- | C] () – C:\WINXP\Ascd_tmp.ini
[2011/07/05 13:13:43 | 000,010,296 | —- | C] () – C:\WINXP\System32\drivers\ASUSHWIO.SYS
[2011/07/05 13:09:41 | 000,002,048 | –S- | C] () – C:\WINXP\bootstat.dat
[2011/07/05 13:05:32 | 000,021,640 | —- | C] () – C:\WINXP\System32\emptyregdb.dat
[2011/06/30 18:53:20 | 000,061,952 | —- | C] () – C:\WINXP\ssdal_nc.exe
========== LOP Check ==========
[2011/10/25 16:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/11/02 22:32:42 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\CoreFTP
[2011/10/25 16:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\DassaultSystemes
[2011/10/25 16:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\EDrawings
[2011/07/26 13:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\Foxit Software
[2011/07/05 15:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\OpenOffice.org
[2012/09/13 11:12:00 | 000,000,242 | —- | M] () – C:\WINXP\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/14 10:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\explorer.exe
[2008/04/14 10:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-0D300D8F.PF >
[2012/08/29 07:55:20 | 000,081,356 | —- | M] () MD5=28A69FB3DCA7E7388BE15E1C934A8580 – C:\WINXP\Prefetch\EXPLORER.EXE-0D300D8F.pf
< MD5 for: EXPLORER.SCF >
[2008/04/14 10:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINXP\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2010/09/16 11:27:16 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINXP\Help\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2010/09/16 11:27:16 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2010/09/16 11:27:16 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINXP\system32\dllcache\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2010/09/16 11:27:34 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2010/09/16 11:27:34 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/09/13 11:03:38 | 000,108,296 | —- | M] () MD5=F81DE174A3E4FA5F8FEAADF4B00161F5 – C:\WINXP\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2008/04/14 10:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINXP\Help\iexplore.hlp
< MD5 for: SERVICES >
[2008/04/14 10:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINXP\system32\drivers\etc\services
< MD5 for: SERVICES.EXE >
[2010/09/16 14:11:07 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\system32\dllcache\services.exe
[2010/09/16 14:11:07 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\system32\services.exe
< MD5 for: SERVICES.LNK >
[2011/07/05 13:07:54 | 000,001,590 | —- | M] () MD5=2C6B5A5D07DE7EB0663A9590CE904AC9 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2008/04/14 10:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINXP\system32\services.msc
< MD5 for: WINLOGON.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 10:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\dllcache\winlogon.exe
[2008/04/14 10:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2011/07/05 13:07:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/05 13:03:36 | 000,000,207 | -HS- | M] () – C:\boot.ini
[2011/07/05 13:07:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/05/23 16:14:47 | 000,454,078 | —- | M] () – C:\Etka7.txt
[2011/10/19 09:11:30 | 000,001,466 | —- | M] () – C:\FONTLOG.TXT
[2011/07/05 13:07:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/07/05 13:07:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/09/13 08:06:23 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINXP\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINXP\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINXP\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINXP\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2011/07/05 13:07:27 | 000,000,067 | -HS- | M] () – C:\WINXP\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 17:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/01/11 06:16:58 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINXP\system32\spool\prtprocs\w32x86\ssp2mpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2012/02/06 09:24:46 | 000,108,789 | —- | M] () – C:\WINXP\system32\Cover mount.JPG
[3 C:\WINXP\system32\*.tmp files -> C:\WINXP\system32\*.tmp -> ]
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2011/07/05 13:55:20 | 000,094,208 | —- | M] () – C:\WINXP\System32\config\default.sav
[2011/07/05 13:55:20 | 001,089,536 | —- | M] () – C:\WINXP\System32\config\software.sav
[2011/07/05 13:55:20 | 000,917,504 | —- | M] () – C:\WINXP\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/07/05 13:07:54 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/05 13:11:50 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\SR Parkin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/07/05 13:11:50 | 000,000,079 | —- | M] () – C:\Documents and Settings\SR Parkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-12 18:01:48
< End of report >
I am having a problem with one of the PCs I have. When you do a search or click on links in IE8, most of the time it redirects to some sort of advertisement. It is pretty annoying.
Also I get Popup Ads in the bottom corners of the screen, not in IE Windows but just with little crosses in the corner. They go away when you close them, but soon come back.
Here are my logs:
OTL logfile created on: 13/09/2012 11:10:58 - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\SR Parkin\Desktop\Scanners
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.75 Gb Total Physical Memory | 2.35 Gb Available Physical Memory | 85.49% Memory free
4.59 Gb Paging File | 4.37 Gb Available in Paging File | 95.21% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 82.61 Gb Free Space | 82.61% Space Free | Partition Type: NTFS
Drive D: | 132.88 Gb Total Space | 132.79 Gb Free Space | 99.94% Space Free | Partition Type: NTFS
Drive H: | 7.39 Gb Total Space | 5.75 Gb Free Space | 77.80% Space Free | Partition Type: FAT32
Drive S: | 232.72 Gb Total Space | 213.04 Gb Free Space | 91.55% Space Free | Partition Type: NTFS
Computer Name: RS-01 | User Name: SR Parkin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\SR Parkin\Desktop\Scanners\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll ()
MOD - C:\WINXP\system32\cpwmon2k.dll ()
MOD - C:\WINXP\system32\ssp2ml3.dll ()
========== Services (SafeList) ==========
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (HTCAND32) – System32\Drivers\ANDROIDUSB.sys File not found
DRV - (Changer) – File not found
DRV - (5789) – C:\DOCUME~1\SRPARK~1\LOCALS~1\Temp\5789.sys File not found
DRV - (VIAHdAudAddService) – C:\WINXP\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (nvgts) – C:\WINXP\system32\drivers\nvgts.sys (NVIDIA Corporation)
DRV - (FTDIBUS) – C:\WINXP\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (nvnetbus) – C:\WINXP\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINXP\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (DgiVecp) – C:\WINXP\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (NSHE) – C:\WINXP\system32\drivers\NSHE.SYS (T0r0 2008)
DRV - (AmdPPM) – C:\WINXP\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (Hardlock) – C:\WINXP\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (MTsensor) – C:\WINXP\system32\drivers\ASACPI.sys ()
DRV - (EZUSB) – C:\WINXP\system32\drivers\ezusb.sys (cypress semiconductor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://mail.google.com/mail/u/0/?hl=en&shva=1#inbox
IE - HKCU\..\SearchScopes,DefaultScope = {DFC37C1C-BC1E-4D81-A049-6F8A72543F64}
IE - HKCU\..\SearchScopes\{DFC37C1C-BC1E-4D81-A049-6F8A72543F64}: "URL" = http://www.google.co.uk/search?hl=en&q…erms}&meta=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
O1 HOSTS File: ([2011/08/03 08:50:20 | 000,000,764 | —- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe" File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINXP\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINXP\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - HKLM..\Run: [Seagull Drivers] C:\WINXP\ssdal_nc.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: mamsoft.co.uk ([online] https in Local intranet)
O15 - HKCU\..Trusted Domains: rmdmo.co.uk ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{68C03A3E-EB26-4600-9834-A0EA41CB0A56}: NameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\SR Parkin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/05 13:07:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2012/01/05 08:45:16 | 000,000,122 | RHS- | M] () - H:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell\AutoRun\command - "" = E:\Bin\ASSETUP.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/09/10 08:57:33 | 000,000,000 | —D | C] – S:\Downloads
[2012/09/03 13:48:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/03 13:48:03 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINXP\System32\drivers\mbam.sys
[2012/09/03 13:48:03 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2012/09/03 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\SR Parkin\Desktop\Scanners
[2012/08/31 19:13:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Zeitronix Data Logger
[2012/08/31 19:13:17 | 000,000,000 | —D | C] – C:\Program Files\Zeitronix
[2012/08/24 19:08:53 | 000,000,000 | -HSD | C] – C:\Documents and Settings\SR Parkin\IECompatCache
[2012/08/17 18:45:19 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WINXP\System32\spmsgXP_2k3.dll
[3 S:\*.tmp files -> S:\*.tmp -> ]
[3 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/13 11:12:00 | 000,000,242 | —- | M] () – C:\WINXP\tasks\Scheduled Update for Ask Toolbar.job
[2012/09/13 08:06:38 | 000,276,202 | —- | M] () – C:\WINXP\System32\NvApps.xml
[2012/09/13 08:06:37 | 000,002,206 | —- | M] () – C:\WINXP\System32\wpa.dbl
[2012/09/13 08:06:26 | 000,002,048 | –S- | M] () – C:\WINXP\bootstat.dat
[2012/09/07 14:22:16 | 000,022,562 | —- | M] () – S:\INVOICE-INV2200 FinTurbo.pdf
[2012/09/05 12:46:54 | 000,002,493 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Microsoft Word.lnk
[2012/08/31 19:13:17 | 000,000,804 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Zeitronix Data Logger v3.1.6.lnk
[2012/08/17 18:45:23 | 000,000,000 | -H– | M] () – C:\WINXP\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/08/17 18:45:22 | 000,001,374 | —- | M] () – C:\WINXP\imsins.BAK
[2012/08/17 18:45:22 | 000,000,000 | -H– | M] () – C:\WINXP\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/08/16 15:00:11 | 000,002,491 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Microsoft Excel.lnk
[2012/08/16 07:43:48 | 002,043,088 | —- | M] () – C:\WINXP\System32\FNTCACHE.DAT
[3 S:\*.tmp files -> S:\*.tmp -> ]
[3 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/07 14:21:41 | 000,022,562 | —- | C] () – S:\INVOICE-INV2200 FinTurbo.pdf
[2012/08/31 19:13:17 | 000,000,804 | —- | C] () – C:\Documents and Settings\SR Parkin\Desktop\Zeitronix Data Logger v3.1.6.lnk
[2012/08/17 18:45:23 | 000,000,000 | -H– | C] () – C:\WINXP\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/08/17 18:45:22 | 000,000,000 | -H– | C] () – C:\WINXP\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/02/15 08:48:56 | 000,003,072 | —- | C] () – C:\WINXP\System32\iacenc.dll
[2011/11/05 14:05:21 | 000,000,169 | —- | C] () – C:\WINXP\ETKINST.INI
[2011/08/19 11:06:11 | 000,000,727 | —- | C] () – C:\WINXP\pagebreeze.ini
[2011/08/19 11:06:11 | 000,000,044 | —- | C] () – C:\WINXP\formbreeze.ini
[2011/07/30 10:31:19 | 000,003,584 | —- | C] () – C:\Documents and Settings\SR Parkin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/19 09:25:20 | 000,000,000 | —- | C] () – C:\WINXP\eDrawingOfficeAutomator.INI
[2011/07/19 09:18:43 | 000,022,723 | —- | C] () – C:\WINXP\System32\ssp2ml3.dll
[2011/07/18 20:10:31 | 000,153,088 | —- | C] () – C:\WINXP\System32\UNWISE.EXE
[2011/07/18 20:10:31 | 000,028,672 | —- | C] () – C:\WINXP\System32\hlduinst.exe
[2011/07/18 19:40:39 | 000,087,552 | —- | C] () – C:\WINXP\System32\cpwmon2k.dll
[2011/07/18 19:37:53 | 000,000,370 | —- | C] () – C:\WINXP\ODBC.INI
[2011/07/05 13:56:50 | 000,004,073 | —- | C] () – C:\WINXP\ODBCINST.INI
[2011/07/05 13:55:53 | 002,043,088 | —- | C] () – C:\WINXP\System32\FNTCACHE.DAT
[2011/07/05 13:17:56 | 000,010,084 | R— | C] () – C:\WINXP\System32\drivers\nvphy.bin
[2011/07/05 13:16:30 | 000,254,000 | R— | C] ( ) – C:\WINXP\System32\Audio3D.dll
[2011/07/05 13:16:30 | 000,254,000 | R— | C] ( ) – C:\WINXP\System32\A3D.dll
[2011/07/05 13:13:54 | 000,005,810 | R— | C] () – C:\WINXP\System32\drivers\ASACPI.sys
[2011/07/05 13:13:48 | 000,001,769 | —- | C] () – C:\WINXP\Language_trs.ini
[2011/07/05 13:13:43 | 000,026,638 | —- | C] () – C:\WINXP\Ascd_tmp.ini
[2011/07/05 13:13:43 | 000,010,296 | —- | C] () – C:\WINXP\System32\drivers\ASUSHWIO.SYS
[2011/07/05 13:09:41 | 000,002,048 | –S- | C] () – C:\WINXP\bootstat.dat
[2011/07/05 13:05:32 | 000,021,640 | —- | C] () – C:\WINXP\System32\emptyregdb.dat
[2011/06/30 18:53:20 | 000,061,952 | —- | C] () – C:\WINXP\ssdal_nc.exe
========== LOP Check ==========
[2011/10/25 16:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/11/02 22:32:42 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\CoreFTP
[2011/10/25 16:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\DassaultSystemes
[2011/10/25 16:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\EDrawings
[2011/07/26 13:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\Foxit Software
[2011/07/05 15:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\OpenOffice.org
[2012/09/13 11:12:00 | 000,000,242 | —- | M] () – C:\WINXP\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/14 10:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\explorer.exe
[2008/04/14 10:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-0D300D8F.PF >
[2012/08/29 07:55:20 | 000,081,356 | —- | M] () MD5=28A69FB3DCA7E7388BE15E1C934A8580 – C:\WINXP\Prefetch\EXPLORER.EXE-0D300D8F.pf
< MD5 for: EXPLORER.SCF >
[2008/04/14 10:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINXP\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2010/09/16 11:27:16 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINXP\Help\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2010/09/16 11:27:16 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2010/09/16 11:27:16 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINXP\system32\dllcache\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2010/09/16 11:27:34 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2010/09/16 11:27:34 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/09/13 11:03:38 | 000,108,296 | —- | M] () MD5=F81DE174A3E4FA5F8FEAADF4B00161F5 – C:\WINXP\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2008/04/14 10:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINXP\Help\iexplore.hlp
< MD5 for: SERVICES >
[2008/04/14 10:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINXP\system32\drivers\etc\services
< MD5 for: SERVICES.EXE >
[2010/09/16 14:11:07 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\system32\dllcache\services.exe
[2010/09/16 14:11:07 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\system32\services.exe
< MD5 for: SERVICES.LNK >
[2011/07/05 13:07:54 | 000,001,590 | —- | M] () MD5=2C6B5A5D07DE7EB0663A9590CE904AC9 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2008/04/14 10:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINXP\system32\services.msc
< MD5 for: WINLOGON.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 10:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\dllcache\winlogon.exe
[2008/04/14 10:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2011/07/05 13:07:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/05 13:03:36 | 000,000,207 | -HS- | M] () – C:\boot.ini
[2011/07/05 13:07:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/05/23 16:14:47 | 000,454,078 | —- | M] () – C:\Etka7.txt
[2011/10/19 09:11:30 | 000,001,466 | —- | M] () – C:\FONTLOG.TXT
[2011/07/05 13:07:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/07/05 13:07:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/09/13 08:06:23 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINXP\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINXP\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINXP\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINXP\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2011/07/05 13:07:27 | 000,000,067 | -HS- | M] () – C:\WINXP\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 17:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/01/11 06:16:58 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINXP\system32\spool\prtprocs\w32x86\ssp2mpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
[2012/02/06 09:24:46 | 000,108,789 | —- | M] () – C:\WINXP\system32\Cover mount.JPG
[3 C:\WINXP\system32\*.tmp files -> C:\WINXP\system32\*.tmp -> ]
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2011/07/05 13:55:20 | 000,094,208 | —- | M] () – C:\WINXP\System32\config\default.sav
[2011/07/05 13:55:20 | 001,089,536 | —- | M] () – C:\WINXP\System32\config\software.sav
[2011/07/05 13:55:20 | 000,917,504 | —- | M] () – C:\WINXP\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/07/05 13:07:54 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/05 13:11:50 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\SR Parkin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/07/05 13:11:50 | 000,000,079 | —- | M] () – C:\Documents and Settings\SR Parkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-12 18:01:48
< End of report >