Saguin
Topic Starter
My old topic
Sorry I was gone for a while and couldn't get back to finishing the issue as posted in the link.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:34:57 AM, on 9/24/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
E:\homework\HiJackThis(1).exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Constant Guard Protection Suite (COM) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe /s
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x081b -f video -m logitech -d 13.31.1044.0 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x081b -f video -m logitech -d 13.31.1044.0 (User 'Default user')
O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
O4 - Global Startup: Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1311645391250
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GIDLogonXP - GIDLogonXP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CGPS Service (IDVaultSvc) - White Sky, Inc. - C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\nlssrv32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
–
End of file - 6537 bytes
MBAM log:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Database version: v2012.09.24.03
Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.6001.18702
Anna :: P-EE951AC334294 [limited]
10/16/2012 8:15:30 PM
mbam-log-2012-10-16 (20-15-30).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 286066
Time elapsed: 14 minute(s), 43 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
OTL.txt
OTL logfile created on: 10/16/2012 8:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
988.42 Mb Total Physical Memory | 736.63 Mb Available Physical Memory | 74.53% Memory free
2.32 Gb Paging File | 2.21 Gb Available in Paging File | 95.39% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.62 Gb Free Space | 88.31% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 284.81 Mb Free Space | 29.89% Space Free | Partition Type: FAT
Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\homework\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (IDVaultSvc) – C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
SRV - (BCUService) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120921.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120919.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}: "URL" = http://search.yahoo.com/search?p={searchTe…m&type=IEBD
IE - HKCU\..\SearchScopes\{3725716F-C2A9-4c1e-968D-23988B72A3A6}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver=5
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: [removed]:0.79.1
FF - prefs.js..extensions.enabledAddons: {84625510-7e5d-11e0-a411-0800200c9a66}:1.15
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:[removed] - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.12.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.0.68 - 1
FF - prefs.js..extensions.enabledItems: [removed]:0.79.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120302
FF - prefs.js..extensions.enabledItems: {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}:1.8.81
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/16 04:22:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_12_1 [2012/10/13 10:59:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\Documents and Settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/24 05:13:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/08/14 00:48:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions
[2012/10/16 04:47:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions
[2011/09/12 01:22:39 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/20 12:07:31 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2011/11/19 22:19:38 | 000,000,000 | —D | M] (OptimizeGoogle) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\[removed]
[2012/10/16 04:47:06 | 000,672,576 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
[2012/09/01 00:49:14 | 000,036,056 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi
[2011/07/28 02:05:20 | 000,002,468 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\safesearch.xml
[2012/10/11 05:41:29 | 000,002,112 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\wot-safe-search.xml
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/13 10:59:42 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\COFFPLGN_2011_7_12_1
[2012/02/16 04:22:31 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN
[2012/09/24 05:13:01 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/24 05:12:57 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/24 05:12:57 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Constant Guard Protection Suite (COM)) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll (WhiteSky)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_4_402_265_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311645391250 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB065480-E775-4735-BD9F-CE0EDD8DCA77}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/24 23:41:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[2012/10/14 22:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/10/13 10:56:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Tific
[2012/10/13 10:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Symantec
[2012/10/11 00:15:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Identities
[2012/10/04 07:00:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\Videos
[2012/10/04 06:52:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\150RACH_
[2012/10/04 06:51:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\149RACH_
[2012/09/24 05:12:53 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/09/23 21:53:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2012/09/23 12:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/09/23 12:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/09/18 08:42:00 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2012/09/18 04:37:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Apple Computer
[2012/09/18 03:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Apple Computer
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/16 04:43:36 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/16 04:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/15 14:49:57 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/15 04:36:10 | 000,000,229 | -HS- | M] () – C:\boot.ini
[2012/10/14 11:55:54 | 000,009,099 | —- | M] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/13 11:01:19 | 000,000,757 | —- | M] () – C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk
[2012/10/13 10:59:40 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/10/11 18:34:21 | 000,078,728 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | M] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | M] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | M] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:57 | 000,068,084 | —- | M] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:45 | 000,172,017 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:45 | 000,251,184 | —- | M] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:42 | 007,415,240 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 22:34:34 | 000,013,824 | —- | M] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/08 04:03:40 | 000,026,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:53 | 001,015,501 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:30 | 000,096,473 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:41 | 000,390,682 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:51 | 000,901,150 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/07 05:49:56 | 000,296,448 | —- | M] () – C:\WINDOWS\Xenofex.ini
[2012/10/06 11:28:13 | 000,044,368 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | M] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:09 | 000,300,130 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:16 | 000,158,402 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:25 | 000,121,741 | —- | M] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:57 | 000,126,771 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:07 | 002,265,284 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:43 | 000,147,280 | —- | M] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:44 | 001,021,823 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:47 | 001,001,913 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:40:01 | 000,004,953 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | M] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/09/26 17:36:23 | 000,062,714 | —- | M] () – C:\Documents and Settings\Anna\Desktop\8026423591_628bfa58b7_z.jpg
[2012/09/26 09:27:49 | 000,028,453 | —- | M] () – C:\Documents and Settings\Anna\Desktop\8026450828_467bdd0035_z.jpg
[2012/09/25 04:29:46 | 000,083,149 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo9_r1_1280.jpg
[2012/09/25 04:29:39 | 000,076,508 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo8_r1_1280.jpg
[2012/09/25 04:29:33 | 000,087,232 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo4_1280.jpg
[2012/09/25 04:29:23 | 000,049,920 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo5_1280.jpg
[2012/09/25 04:29:17 | 000,056,304 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo11_r1_400.jpg
[2012/09/25 04:29:12 | 000,063,386 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo10_r1_1280.jpg
[2012/09/25 04:29:00 | 000,062,693 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo2_1280.jpg
[2012/09/25 04:28:49 | 000,047,413 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo1_1280.jpg
[2012/09/25 04:28:38 | 000,072,730 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo3_400.jpg
[2012/09/24 03:03:24 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/09/22 23:00:12 | 000,018,521 | —- | M] () – C:\Documents and Settings\Anna\Desktop\time_will_tell6-hg-wells-warehouse-13-30505216-624-352.jpg
[2012/09/22 11:08:38 | 000,036,432 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Season-3-Episode-4-claudia-donovan-allison-scagliotti-24055598-595-395.jpg
[2012/09/21 17:48:53 | 000,120,484 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Helena_Image.jpg
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/14 11:55:54 | 000,009,099 | —- | C] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/11 18:34:21 | 000,078,728 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | C] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | C] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | C] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:56 | 000,068,084 | —- | C] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:44 | 000,172,017 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:44 | 000,251,184 | —- | C] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:40 | 007,415,240 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 04:03:39 | 000,026,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:52 | 001,015,501 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:29 | 000,096,473 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:40 | 000,390,682 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:50 | 000,901,150 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/06 11:28:13 | 000,044,368 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | C] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:08 | 000,300,130 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:15 | 000,158,402 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:24 | 000,121,741 | —- | C] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:56 | 000,126,771 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:06 | 002,265,284 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:42 | 000,147,280 | —- | C] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:43 | 001,021,823 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:46 | 001,001,913 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:39:12 | 000,004,953 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | C] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/09/26 17:36:22 | 000,062,714 | —- | C] () – C:\Documents and Settings\Anna\Desktop\8026423591_628bfa58b7_z.jpg
[2012/09/26 09:19:16 | 000,028,453 | —- | C] () – C:\Documents and Settings\Anna\Desktop\8026450828_467bdd0035_z.jpg
[2012/09/25 04:29:46 | 000,083,149 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo9_r1_1280.jpg
[2012/09/25 04:29:39 | 000,076,508 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo8_r1_1280.jpg
[2012/09/25 04:29:32 | 000,087,232 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo4_1280.jpg
[2012/09/25 04:29:23 | 000,049,920 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo5_1280.jpg
[2012/09/25 04:29:17 | 000,056,304 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo11_r1_400.jpg
[2012/09/25 04:29:12 | 000,063,386 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo10_r1_1280.jpg
[2012/09/25 04:29:00 | 000,062,693 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo2_1280.jpg
[2012/09/25 04:28:49 | 000,047,413 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo1_1280.jpg
[2012/09/25 04:28:37 | 000,072,730 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo3_400.jpg
[2012/09/22 23:00:00 | 000,018,521 | —- | C] () – C:\Documents and Settings\Anna\Desktop\time_will_tell6-hg-wells-warehouse-13-30505216-624-352.jpg
[2012/09/22 11:08:34 | 000,036,432 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Season-3-Episode-4-claudia-donovan-allison-scagliotti-24055598-595-395.jpg
[2012/09/21 17:48:51 | 000,120,484 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Helena_Image.jpg
[2012/08/23 01:42:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\libgcc_s_dw2-1.dll
[2012/08/23 01:39:11 | 000,015,960 | —- | C] () – C:\WINDOWS\System32\mingwm10.dll
[2012/08/23 01:16:34 | 004,325,376 | —- | C] () – C:\WINDOWS\System32\QtGui4.dll
[2012/08/21 03:18:29 | 000,317,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/04/29 14:41:54 | 000,296,448 | —- | C] () – C:\WINDOWS\Xenofex.ini
[2012/03/25 11:41:34 | 000,000,060 | —- | C] () – C:\Documents and Settings\Anna\jagex_cl_runescape_LIVE.dat
[2012/03/25 11:41:34 | 000,000,024 | —- | C] () – C:\Documents and Settings\Anna\random.dat
[2012/02/15 07:07:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/15 03:43:33 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2011/10/11 11:56:04 | 000,013,824 | —- | C] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/28 19:45:39 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/27 00:54:01 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/26 00:22:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/25 01:09:37 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/07/25 01:08:47 | 000,004,096 | R— | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/07/25 01:08:43 | 000,982,224 | R— | C] () – C:\WINDOWS\System32\igkrng500.bin
[2011/07/25 01:08:43 | 000,439,336 | R— | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2011/07/25 00:59:32 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/07/25 00:59:32 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/07/24 23:49:09 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/07/24 23:35:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/07/24 18:21:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/07/24 18:18:57 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 01:07:02 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/04/01 01:07:02 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/04/01 01:06:56 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/04/01 00:56:00 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
========== ZeroAccess Check ==========
[2011/07/25 01:02:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/08/23 16:10:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alien Skin
[2011/10/15 03:37:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2011/07/25 23:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/07/25 23:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\White Sky, Inc
[2012/08/23 03:53:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Alien Skin
[2012/08/20 12:07:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Dropbox
[2011/10/15 03:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\HotSync
[2012/09/24 01:26:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\ID Vault
[2011/08/19 22:01:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Leadertech
[2012/08/21 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Oracle
[2012/06/27 08:23:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Philipp Winterberg
[2012/10/13 10:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Tific
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 08:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2004/08/04 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >
[2004/08/04 08:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/04 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true >
========== Drive Information ==========
Physical Drives
—————
Error accessing drive info (0)
Error accessing drive info (0)
Partitions
—————
Error accessing partition info (0)
Error accessing partition info (0)
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
< End of report >
Extras.txt
OTL Extras logfile created on: 10/16/2012 8:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
988.42 Mb Total Physical Memory | 736.63 Mb Available Physical Memory | 74.53% Memory free
2.32 Gb Paging File | 2.21 Gb Available in Paging File | 95.39% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.62 Gb Free Space | 88.31% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 284.81 Mb Free Space | 29.89% Space Free | Partition Type: FAT
Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0904.1
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1B141C01-6491-45C1-BF2F-3FE6BF1FFE7C}_is1" = Colour Studio 2.0 Demo
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F474DDA-6E88-4176-9411-D22CF54B730B}_is1" = Chromagic version 1.1
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{6022299E-440C-43DA-825F-B58BCCB570B9}_is1" = Fotomatic version 1.4
"{607616CE-076C-49C7-A2E8-E6A6AB21053B}_is1" = Colour Surprise version 1.0
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{839CA7E5-5956-487D-8138-682907C5D576}_is1" = The Works version 3.2
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9191979D-821C-4EA8-B021-2DA1D859A7C5}" = GuardedID
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E1C7EF5E-3A7B-4ED4-A48B-F70F1B36EAB4}" = Corel Paint Shop Pro Photo XI
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Alien Skin Exposure 4" = Alien Skin Exposure 4
"CleanUp!" = CleanUp!
"Enable S3 for USB Device" = Enable S3 for USB Device
"ID Vault" = Constant Guard Protection Suite
"ie8" = Windows Internet Explorer 8
"InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"Little Ink Pot's Chalkaholic Plugin_is1" = Chalkaholic Plugin v 1.1
"Little Ink Pot's Thredgeholder Plugin_is1" = Thredgeholder Plugin v 1.1
"Little Ink Pot's Xpose Plugin_is1" = Xpose Plugin v 1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"N360" = Norton Security Suite
"virtualPhotographer_is1" = virtualPhotographer 1.5.6
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.20 (32-bit)
"Xenofex 1.0" = Xenofex 1.0
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/11/2012 10:07:21 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning MainModule.FileName; failed Only part
of a ReadProcessMemory or WriteProcessMemory request was completed at System.Diagnostics.NtProcessManager.GetModuleInfos(Int32
processId, Boolean firstModuleOnly) at System.Diagnostics.NtProcessManager.GetFirstModuleInfo(Int32
processId) at System.Diagnostics.Process.get_MainModule() at .?. ()
Error - 9/15/2012 8:21:35 AM | Computer Name = P-EE951AC334294 | Source = .NET Runtime | ID = 1023
Description = .NET Runtime version 2.0.50727.3634 - Fatal Execution Engine Error
(7A0BC6A6) (80131506)
Error - 9/17/2012 5:55:28 PM | Computer Name = P-EE951AC334294 | Source = GIDTB | ID = 6000
Description = An error caused the driver not to respond. If this is a new installation,
retry the installation with Anti-Malware software disabled. Current license number:
(null)
Error - 9/23/2012 3:29:34 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = Display Flag Error Call was canceled by the message filter. (Exception
from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
Error - 9/23/2012 3:29:34 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = Interaction with the desktop is required. Enable desktop interaction
flag in Properties->Log On.
Error - 9/24/2012 12:58:05 AM | Computer Name = P-EE951AC334294 | Source = GIDTB | ID = 6000
Description = An error caused the driver not to respond. If this is a new installation,
retry the installation with Anti-Malware software disabled. Current license number:
(null)
Error - 9/29/2012 12:48:01 AM | Computer Name = P-EE951AC334294 | Source = MsiInstaller | ID = 1008
Description = The installation of C:\Documents and Settings\Anna\Application Data\Sun\Java\jre1.7.0_07\jre1.7.0_07-c.msi
is not permitted due to an error in software restriction policy processing. The
object cannot be trusted.
Error - 10/1/2012 1:08:56 AM | Computer Name = P-EE951AC334294 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 10/7/2012 6:47:36 PM | Computer Name = P-EE951AC334294 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 10/16/2012 8:33:13 PM | Computer Name = P-EE951AC334294 | Source = MsiInstaller | ID = 1008
Description = The installation of E:\homework\HiJackThis.msi is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.
[ System Events ]
Error - 10/16/2012 6:27:27 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 10/16/2012 6:53:44 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:10:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 10/16/2012 8:10:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:10:59 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 10/16/2012 8:32:08 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:32:13 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:37:17 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 10/16/2012 8:39:59 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 10/16/2012 8:40:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
< End of report >
GMER.txt
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-10-16 20:48:52
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Anna\LOCALS~1\Temp\kfldakod.sys
—- Kernel code sections - GMER 1.0.15 —-
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[332] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 001A3D48
.text C:\WINDOWS\System32\svchost.exe[332] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 001A4672
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 001A46D3
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 001A4743
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!IsWindowVisible 7E429E3D 5 Bytes JMP 001A4776
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!MessageBoxIndirectW 7E4664D5 6 Bytes [33, C0, 40, C2, 04, 00] {XOR EAX, EAX; INC EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[332] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 001A48DC
.text C:\WINDOWS\System32\svchost.exe[332] ole32.dll!CoGetClassObject 77515205 5 Bytes JMP 001A48B2
.text C:\WINDOWS\System32\svchost.exe[332] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 001A45D4
—- Devices - GMER 1.0.15 —-
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-4 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T1L0-c 85E642E2
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Sorry I was gone for a while and couldn't get back to finishing the issue as posted in the link.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:34:57 AM, on 9/24/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
E:\homework\HiJackThis(1).exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Constant Guard Protection Suite (COM) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coIEPlg.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe /s
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x081b -f video -m logitech -d 13.31.1044.0 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x081b -f video -m logitech -d 13.31.1044.0 (User 'Default user')
O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe
O4 - Global Startup: Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1311645391250
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GIDLogonXP - GIDLogonXP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CGPS Service (IDVaultSvc) - White Sky, Inc. - C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\nlssrv32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
–
End of file - 6537 bytes
MBAM log:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Database version: v2012.09.24.03
Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.6001.18702
Anna :: P-EE951AC334294 [limited]
10/16/2012 8:15:30 PM
mbam-log-2012-10-16 (20-15-30).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 286066
Time elapsed: 14 minute(s), 43 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
OTL.txt
OTL logfile created on: 10/16/2012 8:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
988.42 Mb Total Physical Memory | 736.63 Mb Available Physical Memory | 74.53% Memory free
2.32 Gb Paging File | 2.21 Gb Available in Paging File | 95.39% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.62 Gb Free Space | 88.31% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 284.81 Mb Free Space | 29.89% Space Free | Partition Type: FAT
Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\homework\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (IDVaultSvc) – C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe (White Sky, Inc.)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (JavaQuickStarterService) – C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe (Oracle Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
SRV - (BCUService) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (ProtexisLicensing) – C:\WINDOWS\system32\PSIService.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20120923.008\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20120921.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20120919.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (GIDv2) – C:\WINDOWS\System32\drivers\gidv2.sys (StrikeForce Technologies, Inc.)
DRV - (SYMTDI) – C:\WINDOWS\system32\drivers\N360\0502020.003\symtdi.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\N360\0502020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0502020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0502020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0502020.003\ironx86.sys (Symantec Corporation)
DRV - (RTL8192su) – C:\WINDOWS\system32\drivers\RTL8192su.sys (Realtek Semiconductor Corporation )
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{0A65ED42-75AD-4bbe-8E8B-EF542DC9B1AD}: "URL" = http://search.yahoo.com/search?p={searchTe…m&type=IEBD
IE - HKCU\..\SearchScopes\{3725716F-C2A9-4c1e-968D-23988B72A3A6}: "URL" = http://www.google.com/custom?client=pub-37…q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…eo=US&ver=5
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/firefox"
FF - prefs.js..extensions.enabledAddons: [removed]:0.79.1
FF - prefs.js..extensions.enabledAddons: {84625510-7e5d-11e0-a411-0800200c9a66}:1.15
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:[removed] - 1
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2011.7.12.1
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:10.1.0.68 - 1
FF - prefs.js..extensions.enabledItems: [removed]:0.79.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120302
FF - prefs.js..extensions.enabledItems: {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}:1.8.81
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2012/02/16 04:22:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_12_1 [2012/10/13 10:59:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\Documents and Settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.2.0.28\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/24 05:13:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/08/14 00:48:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Extensions
[2012/10/16 04:47:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions
[2011/09/12 01:22:39 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/20 12:07:31 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}(2)
[2011/11/19 22:19:38 | 000,000,000 | —D | M] (OptimizeGoogle) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\[removed]
[2012/10/16 04:47:06 | 000,672,576 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi
[2012/09/01 00:49:14 | 000,036,056 | —- | M] () (No name found) – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi
[2011/07/28 02:05:20 | 000,002,468 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\safesearch.xml
[2012/10/11 05:41:29 | 000,002,112 | —- | M] () – C:\Documents and Settings\Anna\Application Data\Mozilla\Firefox\Profiles\jomfg8s5.default\searchplugins\wot-safe-search.xml
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/24 05:12:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/10/13 10:59:42 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\COFFPLGN_2011_7_12_1
[2012/02/16 04:22:31 | 000,000,000 | —D | M] (Symantec Intrusion Prevention) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPLGN
[2012/09/24 05:13:01 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/24 05:12:57 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/24 05:12:57 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Constant Guard Protection Suite (COM)) - {B84CDBE7-1B46-494B-A188-01D4C52DEB61} - C:\Documents and Settings\All Users\Application Data\White Sky, Inc\ID Vault\IEBHO1.1.730.1\NativeBHO.dll (WhiteSky)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.2.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [GIDDesktop] C:\Program Files\SFT\GuardedID\gidd.exe (StrikeForce Technologies Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_4_402_265_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Constant Guard.lnk = C:\Program Files\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk = C:\Program Files\Palm\register.exe (Palm/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1311645391250 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AB065480-E775-4735-BD9F-CE0EDD8DCA77}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GIDLogonXP: DllName - (GIDLogonXP.dll) - C:\WINDOWS\System32\GIDLogonXP.dll (StrikeForce Technologies Inc)
O24 - Desktop WallPaper: C:\WINDOWS\Coffee Bean.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Coffee Bean.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/24 23:41:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[2012/10/14 22:46:22 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2012/10/13 10:56:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Tific
[2012/10/13 10:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Symantec
[2012/10/11 00:15:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Identities
[2012/10/04 07:00:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\Videos
[2012/10/04 06:52:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\150RACH_
[2012/10/04 06:51:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\My Documents\149RACH_
[2012/09/24 05:12:53 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/09/23 21:53:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2012/09/23 12:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/09/23 12:23:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/09/18 08:42:00 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2012/09/18 04:37:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Application Data\Apple Computer
[2012/09/18 03:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Anna\Local Settings\Application Data\Apple Computer
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/16 04:43:36 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/10/16 04:43:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/10/15 14:49:57 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/10/15 04:36:10 | 000,000,229 | -HS- | M] () – C:\boot.ini
[2012/10/14 11:55:54 | 000,009,099 | —- | M] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/13 11:01:19 | 000,000,757 | —- | M] () – C:\Documents and Settings\Anna\Start Menu\Programs\Startup\Palm Registration.lnk
[2012/10/13 10:59:40 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2012/10/11 18:34:21 | 000,078,728 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | M] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | M] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | M] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | M] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:57 | 000,068,084 | —- | M] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:45 | 000,172,017 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | M] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:45 | 000,251,184 | —- | M] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:42 | 007,415,240 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 22:34:34 | 000,013,824 | —- | M] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/08 04:03:40 | 000,026,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:53 | 001,015,501 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:30 | 000,096,473 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:41 | 000,390,682 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:51 | 000,901,150 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | M] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/07 05:49:56 | 000,296,448 | —- | M] () – C:\WINDOWS\Xenofex.ini
[2012/10/06 11:28:13 | 000,044,368 | —- | M] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | M] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | M] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:09 | 000,300,130 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:16 | 000,158,402 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | M] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:25 | 000,121,741 | —- | M] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:57 | 000,126,771 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:07 | 002,265,284 | —- | M] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:43 | 000,147,280 | —- | M] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:44 | 001,021,823 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:47 | 001,001,913 | —- | M] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:40:01 | 000,004,953 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | M] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/09/26 17:36:23 | 000,062,714 | —- | M] () – C:\Documents and Settings\Anna\Desktop\8026423591_628bfa58b7_z.jpg
[2012/09/26 09:27:49 | 000,028,453 | —- | M] () – C:\Documents and Settings\Anna\Desktop\8026450828_467bdd0035_z.jpg
[2012/09/25 04:29:46 | 000,083,149 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo9_r1_1280.jpg
[2012/09/25 04:29:39 | 000,076,508 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo8_r1_1280.jpg
[2012/09/25 04:29:33 | 000,087,232 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo4_1280.jpg
[2012/09/25 04:29:23 | 000,049,920 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo5_1280.jpg
[2012/09/25 04:29:17 | 000,056,304 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo11_r1_400.jpg
[2012/09/25 04:29:12 | 000,063,386 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo10_r1_1280.jpg
[2012/09/25 04:29:00 | 000,062,693 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo2_1280.jpg
[2012/09/25 04:28:49 | 000,047,413 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo1_1280.jpg
[2012/09/25 04:28:38 | 000,072,730 | —- | M] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo3_400.jpg
[2012/09/24 03:03:24 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/09/22 23:00:12 | 000,018,521 | —- | M] () – C:\Documents and Settings\Anna\Desktop\time_will_tell6-hg-wells-warehouse-13-30505216-624-352.jpg
[2012/09/22 11:08:38 | 000,036,432 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Season-3-Episode-4-claudia-donovan-allison-scagliotti-24055598-595-395.jpg
[2012/09/21 17:48:53 | 000,120,484 | —- | M] () – C:\Documents and Settings\Anna\Desktop\Helena_Image.jpg
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/14 11:55:54 | 000,009,099 | —- | C] () – C:\Documents and Settings\Anna\Desktop\red.jpg
[2012/10/11 18:34:21 | 000,078,728 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lol.jpg
[2012/10/11 18:29:48 | 000,042,537 | —- | C] () – C:\Documents and Settings\Anna\My Documents\4.gif
[2012/10/11 18:27:34 | 000,041,302 | —- | C] () – C:\Documents and Settings\Anna\My Documents\3.gif
[2012/10/11 18:26:51 | 000,056,421 | —- | C] () – C:\Documents and Settings\Anna\My Documents\2.gif
[2012/10/11 18:26:35 | 000,042,342 | —- | C] () – C:\Documents and Settings\Anna\My Documents\1.gif
[2012/10/11 00:12:56 | 000,068,084 | —- | C] () – C:\Documents and Settings\Anna\Desktop\11-grand-central-station-_1.jpg
[2012/10/09 22:44:22 | 000,091,822 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Daniel-Del-Orfano_The-Long-Goodbye.jpg
[2012/10/09 22:18:44 | 000,172,017 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Warehouse_Pan.jpg
[2012/10/09 22:02:09 | 000,173,991 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshineresized.jpg
[2012/10/09 22:01:00 | 000,521,013 | —- | C] () – C:\Documents and Settings\Anna\Desktop\sunshine.jpg
[2012/10/09 21:58:44 | 000,251,184 | —- | C] () – C:\Documents and Settings\Anna\Desktop\meowmeow.jpg
[2012/10/09 21:12:40 | 007,415,240 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image3.pspimage
[2012/10/08 04:03:39 | 000,026,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maj9qwPy3N1rd50lho1_500.jpg
[2012/10/07 23:15:52 | 001,015,501 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_maktuytrHx1qi989qo1_250.gif
[2012/10/07 23:14:39 | 000,123,962 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o2_500.jpg
[2012/10/07 23:14:29 | 000,096,473 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamawcULP81r1cpy3o1_500.jpg
[2012/10/07 23:14:14 | 000,025,051 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mambo1f4gs1qlx7xzo1_500.jpg
[2012/10/07 23:13:45 | 000,430,022 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mamgy7OZjZ1qg0b67.gif
[2012/10/07 23:11:20 | 000,508,905 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lfs7m8hRKa1qbxoeqo1_500.gif
[2012/10/07 23:10:28 | 000,159,719 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lty1gm3EC71r5avb2o1_500.jpg
[2012/10/07 23:07:40 | 000,390,682 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavv3oPDSA1r384au.gif
[2012/10/07 23:07:10 | 000,510,894 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_mavvz6Rxkf1qeef72.gif
[2012/10/07 23:04:05 | 000,495,726 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lrow55omdm1qeq4tyo3_r1_250.gif
[2012/10/07 22:53:30 | 000,789,712 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co1_500.gif
[2012/10/07 22:53:21 | 000,926,183 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m88yczhtoE1rqfz4co3_500.gif
[2012/10/07 20:46:32 | 000,447,437 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb664rjOXz1r384au.gif
[2012/10/07 13:15:50 | 000,901,150 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.pspimage
[2012/10/07 13:15:25 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarnsworth.jpg
[2012/10/07 08:26:51 | 000,115,234 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.png
[2012/10/07 08:26:38 | 000,044,207 | —- | C] () – C:\Documents and Settings\Anna\Desktop\fbendless wonder.jpg
[2012/10/06 11:28:13 | 000,044,368 | —- | C] () – C:\Documents and Settings\Anna\Desktop\rachelfarns.jpg
[2012/10/06 11:27:56 | 000,045,807 | —- | C] () – C:\Documents and Settings\Anna\Desktop\HGfarns.jpg
[2012/10/06 11:01:59 | 000,334,205 | —- | C] () – C:\Documents and Settings\Anna\Desktop\w13_s2e3-vet-pete-myka.jpg
[2012/10/06 08:30:35 | 000,129,632 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth .jpg
[2012/10/06 08:13:13 | 001,019,590 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m6yyhxFkqr1qbu8fp.gif
[2012/10/06 08:11:49 | 001,022,541 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m70t42zmEZ1qzjk2so7_400.gif
[2012/10/06 08:11:17 | 000,865,642 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m4sexrqh5j1rqfz4co1_500.gif
[2012/10/06 08:10:08 | 000,300,130 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_m8ry6lovov1qacf3wo1_r1_500.png
[2012/10/06 07:37:15 | 000,158,402 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mb4aoxU4AI1r1cpy3o1_500.jpg
[2012/10/06 04:16:18 | 000,081,583 | —- | C] () – C:\Documents and Settings\Anna\Desktop\lovelovelove.jpg
[2012/10/06 02:35:24 | 000,121,741 | —- | C] () – C:\Documents and Settings\Anna\Desktop\return-of-hg-wells.jpg
[2012/10/06 01:31:37 | 000,016,283 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Carnival Queen Make-Up.JPG
[2012/10/05 22:54:56 | 000,126,771 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth-idealhero-4.jpg
[2012/10/05 21:56:06 | 002,265,284 | —- | C] () – C:\Documents and Settings\Anna\Desktop\farnsworth empty.pspimage
[2012/10/05 21:08:01 | 001,351,669 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Farnsworth.pspimage
[2012/10/04 05:24:42 | 000,147,280 | —- | C] () – C:\Documents and Settings\Anna\Desktop\525917_10151183062704449_1697597416_n.jpg
[2012/10/01 23:12:43 | 001,021,823 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_lz94cuXDVL1qde33io1_500.gif
[2012/10/01 23:11:46 | 001,001,913 | —- | C] () – C:\Documents and Settings\Anna\My Documents\tumblr_m45rfvwyl91qde33io1_500.gif
[2012/09/30 19:39:12 | 000,004,953 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Drusie.rtf
[2012/09/28 15:14:58 | 000,075,924 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Incorrect answer.jpg
[2012/09/28 13:37:34 | 000,262,346 | —- | C] () – C:\Documents and Settings\Anna\Desktop\wallpaper_cast_03_1920_129011579697.jpg
[2012/09/28 12:31:40 | 000,036,673 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image72.jpg
[2012/09/28 12:15:15 | 000,037,178 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Image7.jpg
[2012/09/26 17:36:22 | 000,062,714 | —- | C] () – C:\Documents and Settings\Anna\Desktop\8026423591_628bfa58b7_z.jpg
[2012/09/26 09:19:16 | 000,028,453 | —- | C] () – C:\Documents and Settings\Anna\Desktop\8026450828_467bdd0035_z.jpg
[2012/09/25 04:29:46 | 000,083,149 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo9_r1_1280.jpg
[2012/09/25 04:29:39 | 000,076,508 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo8_r1_1280.jpg
[2012/09/25 04:29:32 | 000,087,232 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo4_1280.jpg
[2012/09/25 04:29:23 | 000,049,920 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo5_1280.jpg
[2012/09/25 04:29:17 | 000,056,304 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo11_r1_400.jpg
[2012/09/25 04:29:12 | 000,063,386 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo10_r1_1280.jpg
[2012/09/25 04:29:00 | 000,062,693 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo2_1280.jpg
[2012/09/25 04:28:49 | 000,047,413 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo1_1280.jpg
[2012/09/25 04:28:37 | 000,072,730 | —- | C] () – C:\Documents and Settings\Anna\Desktop\tumblr_mav976AE9n1qfw6kdo3_400.jpg
[2012/09/22 23:00:00 | 000,018,521 | —- | C] () – C:\Documents and Settings\Anna\Desktop\time_will_tell6-hg-wells-warehouse-13-30505216-624-352.jpg
[2012/09/22 11:08:34 | 000,036,432 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Season-3-Episode-4-claudia-donovan-allison-scagliotti-24055598-595-395.jpg
[2012/09/21 17:48:51 | 000,120,484 | —- | C] () – C:\Documents and Settings\Anna\Desktop\Helena_Image.jpg
[2012/08/23 01:42:11 | 000,107,520 | —- | C] () – C:\WINDOWS\System32\libgcc_s_dw2-1.dll
[2012/08/23 01:39:11 | 000,015,960 | —- | C] () – C:\WINDOWS\System32\mingwm10.dll
[2012/08/23 01:16:34 | 004,325,376 | —- | C] () – C:\WINDOWS\System32\QtGui4.dll
[2012/08/21 03:18:29 | 000,317,288 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/04/29 14:41:54 | 000,296,448 | —- | C] () – C:\WINDOWS\Xenofex.ini
[2012/03/25 11:41:34 | 000,000,060 | —- | C] () – C:\Documents and Settings\Anna\jagex_cl_runescape_LIVE.dat
[2012/03/25 11:41:34 | 000,000,024 | —- | C] () – C:\Documents and Settings\Anna\random.dat
[2012/02/15 07:07:54 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/15 03:43:33 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2011/10/11 11:56:04 | 000,013,824 | —- | C] () – C:\Documents and Settings\Anna\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/28 19:45:39 | 000,000,952 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2011/07/27 00:54:01 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/07/26 00:22:07 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/07/25 01:09:37 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/07/25 01:08:47 | 000,004,096 | R— | C] ( ) – C:\WINDOWS\System32\IGFXDEVLib.dll
[2011/07/25 01:08:43 | 000,982,224 | R— | C] () – C:\WINDOWS\System32\igkrng500.bin
[2011/07/25 01:08:43 | 000,439,336 | R— | C] () – C:\WINDOWS\System32\igcompkrng500.bin
[2011/07/25 00:59:32 | 000,207,400 | R— | C] () – C:\WINDOWS\GSetup.exe
[2011/07/25 00:59:32 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2011/07/24 23:49:09 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/07/24 23:35:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/07/24 18:21:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/07/24 18:18:57 | 000,095,072 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 01:07:02 | 010,920,984 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2011/04/01 01:07:02 | 000,104,472 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2011/04/01 01:06:56 | 000,336,408 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2011/04/01 00:56:00 | 000,028,418 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
========== ZeroAccess Check ==========
[2011/07/25 01:02:50 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/08/23 16:10:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alien Skin
[2011/10/15 03:37:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2011/07/25 23:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/07/25 23:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\White Sky, Inc
[2012/08/23 03:53:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Alien Skin
[2012/08/20 12:07:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Dropbox
[2011/10/15 03:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\HotSync
[2012/09/24 01:26:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\ID Vault
[2011/08/19 22:01:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Leadertech
[2012/08/21 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Oracle
[2012/06/27 08:23:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Philipp Winterberg
[2012/10/13 10:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Anna\Application Data\Tific
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 08:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
< MD5 for: SVCHOST.EXE >
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 20:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2004/08/04 08:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
< MD5 for: USERINIT.EXE >
[2004/08/04 08:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2004/08/04 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true >
========== Drive Information ==========
Physical Drives
—————
Error accessing drive info (0)
Error accessing drive info (0)
Partitions
—————
Error accessing partition info (0)
Error accessing partition info (0)
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction
< End of report >
Extras.txt
OTL Extras logfile created on: 10/16/2012 8:36:11 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\homework
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
988.42 Mb Total Physical Memory | 736.63 Mb Available Physical Memory | 74.53% Memory free
2.32 Gb Paging File | 2.21 Gb Available in Paging File | 95.39% Paging File free
Paging file location(s): C:\pagefile.sys 1476 2952 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.62 Gb Free Space | 88.31% Space Free | Partition Type: NTFS
Drive E: | 953.00 Mb Total Space | 284.81 Mb Free Space | 29.89% Space Free | Partition Type: FAT
Computer Name: P-EE951AC334294 | User Name: Anna | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0904.1
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1B141C01-6491-45C1-BF2F-3FE6BF1FFE7C}_is1" = Colour Studio 2.0 Demo
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java™ 7 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F474DDA-6E88-4176-9411-D22CF54B730B}_is1" = Chromagic version 1.1
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{6022299E-440C-43DA-825F-B58BCCB570B9}_is1" = Fotomatic version 1.4
"{607616CE-076C-49C7-A2E8-E6A6AB21053B}_is1" = Colour Surprise version 1.0
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{839CA7E5-5956-487D-8138-682907C5D576}_is1" = The Works version 3.2
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{9191979D-821C-4EA8-B021-2DA1D859A7C5}" = GuardedID
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E1C7EF5E-3A7B-4ED4-A48B-F70F1B36EAB4}" = Corel Paint Shop Pro Photo XI
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Alien Skin Exposure 4" = Alien Skin Exposure 4
"CleanUp!" = CleanUp!
"Enable S3 for USB Device" = Enable S3 for USB Device
"ID Vault" = Constant Guard Protection Suite
"ie8" = Windows Internet Explorer 8
"InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}" = Belkin F7D1101 Basic Wireless USB Adapter
"Little Ink Pot's Chalkaholic Plugin_is1" = Chalkaholic Plugin v 1.1
"Little Ink Pot's Thredgeholder Plugin_is1" = Thredgeholder Plugin v 1.1
"Little Ink Pot's Xpose Plugin_is1" = Xpose Plugin v 1.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"N360" = Norton Security Suite
"virtualPhotographer_is1" = virtualPhotographer 1.5.6
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.20 (32-bit)
"Xenofex 1.0" = Xenofex 1.0
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/11/2012 10:07:21 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = IsStrikeForceAlreadyRunning MainModule.FileName; failed Only part
of a ReadProcessMemory or WriteProcessMemory request was completed at System.Diagnostics.NtProcessManager.GetModuleInfos(Int32
processId, Boolean firstModuleOnly) at System.Diagnostics.NtProcessManager.GetFirstModuleInfo(Int32
processId) at System.Diagnostics.Process.get_MainModule() at .?. ()
Error - 9/15/2012 8:21:35 AM | Computer Name = P-EE951AC334294 | Source = .NET Runtime | ID = 1023
Description = .NET Runtime version 2.0.50727.3634 - Fatal Execution Engine Error
(7A0BC6A6) (80131506)
Error - 9/17/2012 5:55:28 PM | Computer Name = P-EE951AC334294 | Source = GIDTB | ID = 6000
Description = An error caused the driver not to respond. If this is a new installation,
retry the installation with Anti-Malware software disabled. Current license number:
(null)
Error - 9/23/2012 3:29:34 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = Display Flag Error Call was canceled by the message filter. (Exception
from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))
Error - 9/23/2012 3:29:34 PM | Computer Name = P-EE951AC334294 | Source = IDVault | ID = 0
Description = Interaction with the desktop is required. Enable desktop interaction
flag in Properties->Log On.
Error - 9/24/2012 12:58:05 AM | Computer Name = P-EE951AC334294 | Source = GIDTB | ID = 6000
Description = An error caused the driver not to respond. If this is a new installation,
retry the installation with Anti-Malware software disabled. Current license number:
(null)
Error - 9/29/2012 12:48:01 AM | Computer Name = P-EE951AC334294 | Source = MsiInstaller | ID = 1008
Description = The installation of C:\Documents and Settings\Anna\Application Data\Sun\Java\jre1.7.0_07\jre1.7.0_07-c.msi
is not permitted due to an error in software restriction policy processing. The
object cannot be trusted.
Error - 10/1/2012 1:08:56 AM | Computer Name = P-EE951AC334294 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 10/7/2012 6:47:36 PM | Computer Name = P-EE951AC334294 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 10/16/2012 8:33:13 PM | Computer Name = P-EE951AC334294 | Source = MsiInstaller | ID = 1008
Description = The installation of E:\homework\HiJackThis.msi is not permitted due
to an error in software restriction policy processing. The object cannot be trusted.
[ System Events ]
Error - 10/16/2012 6:27:27 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 10/16/2012 6:53:44 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:10:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 10/16/2012 8:10:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:10:59 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 10/16/2012 8:32:08 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:32:13 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 10/16/2012 8:37:17 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 10/16/2012 8:39:59 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
Error - 10/16/2012 8:40:29 PM | Computer Name = P-EE951AC334294 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
< End of report >
GMER.txt
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-10-16 20:48:52
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Anna\LOCALS~1\Temp\kfldakod.sys
—- Kernel code sections - GMER 1.0.15 —-
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[332] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 001A3D48
.text C:\WINDOWS\System32\svchost.exe[332] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 001A4672
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 001A46D3
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 001A4743
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!IsWindowVisible 7E429E3D 5 Bytes JMP 001A4776
.text C:\WINDOWS\System32\svchost.exe[332] USER32.dll!MessageBoxIndirectW 7E4664D5 6 Bytes [33, C0, 40, C2, 04, 00] {XOR EAX, EAX; INC EAX; RET 0x4}
.text C:\WINDOWS\System32\svchost.exe[332] ole32.dll!CoCreateInstance 774FF1BC 5 Bytes JMP 001A48DC
.text C:\WINDOWS\System32\svchost.exe[332] ole32.dll!CoGetClassObject 77515205 5 Bytes JMP 001A48B2
.text C:\WINDOWS\System32\svchost.exe[332] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 001A45D4
—- Devices - GMER 1.0.15 —-
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-4 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 85E642E2
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T1L0-c 85E642E2
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)