nicolo
Topic Starter
Windows XP machine has a ton of adwares running before and I removed a lot of them. I'm not certain if there is anything else that is hidden. Boot up time seems bogged down. Can anyone help?
—————
OTL logfile created on: 11/30/2012 11:16:43 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\YOUNG ONE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.86 Mb Total Physical Memory | 481.32 Mb Available Physical Memory | 47.47% Memory free
2.38 Gb Paging File | 1.64 Gb Available in Paging File | 68.83% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 145.00 Gb Total Space | 81.00 Gb Free Space | 55.86% Space Free | Partition Type: NTFS
Computer Name: JAMES-91746AC0C | User Name: YOUNG ONE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AOL\DataMask by AOL\pl.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\ep.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\epservice.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\dps.exe (AOL)
PRC - C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - c:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\TeamViewer_Desktop.exe (TeamViewer GmbH)
PRC - C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files\SentryBay\Update\SentryBayUpdate.exe (AOL)
PRC - C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\WINXP\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\WINXP\system32\mmc.exe (Microsoft Corporation)
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
PRC - C:\WINXP\system32\dfrgntfs.exe (Microsoft Corp. and Executive Software International, Inc.)
PRC - C:\WINXP\system32\HPZipm12.exe (HP)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AOL\DataMask by AOL\libxmlsec.dll ()
MOD - C:\Program Files\AOL\DataMask by AOL\libxmlsec-mscrypto.dll ()
MOD - C:\Program Files\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\AOL\DataMask by AOL\libxml2.dll ()
MOD - C:\WINXP\system32\msdmo.dll ()
MOD - C:\WINXP\system32\devenum.dll ()
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (EntryProtect) – C:\Program Files\AOL\DataMask by AOL\epservice.exe (AOL)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\822\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (sbupdate) – C:\Program Files\SentryBay\Update\SentryBayUpdate.exe (AOL)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (mfevtp) – C:\WINXP\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
SRV - (Pml Driver HPZ12) – C:\WINXP\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mfeavfk01) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (SWDUMon) – C:\WINXP\system32\drivers\SWDUMon.sys ()
DRV - (epfilter) – C:\WINXP\system32\drivers\epfilter.sys (SentryBay)
DRV - (MBAMProtector) – C:\WINXP\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ASCTRM) – C:\WINXP\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (mfehidk) – C:\WINXP\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINXP\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINXP\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINXP\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINXP\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINXP\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINXP\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINXP\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINXP\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINXP\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (motccgpfl) – C:\WINXP\system32\drivers\motccgpfl.sys (Motorola)
DRV - (motccgp) – C:\WINXP\system32\drivers\motccgp.sys (Motorola)
DRV - (MPE) – C:\WINXP\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (motport) – C:\WINXP\system32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\WINXP\system32\drivers\motmodem.sys (Motorola)
DRV - (emAudio) – C:\WINXP\system32\drivers\emAudio.sys (Pinnacle Systems GmbH)
DRV - (STHDA) – C:\WINXP\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DCamUSBEMPIA) – C:\WINXP\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINXP\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINXP\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (MarvinBus) – C:\WINXP\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (bvrp_pci) – C:\WINXP\system32\drivers\bvrp_pci.sys ()
DRV - (HSFHWBS2) – C:\WINXP\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINXP\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINXP\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (wanatw) – C:\WINXP\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – C:\WINXP\system32\drivers\omci.sys (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/
IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=15-11-2012
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aol.com/?ncid=customie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - HKCU\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…0000019d17406b1
IE - HKCU\..\SearchScopes\{40267B06-090D-4211-B671-4647C071C5C8}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=15-11-2012
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://search.coupons.com/search.asp?p=df&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@update.sentrybay.com/SentryBay Update;version=8: C:\Program Files\SentryBay\Update\1.0.0.7621\npSentryBayOneClick8.dll (AOL)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/11/30 22:33:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AOL\DataMask by AOL\ffext [2012/11/14 15:42:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/28 07:52:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/11/24 05:44:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Extensions
[2012/11/25 05:53:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions
[2012/11/25 05:53:12 | 000,000,000 | —D | M] (ProxTube - Unblock YouTube) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions\[removed]
[2012/11/24 00:43:09 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/20 01:17:52 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/20 01:17:14 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/20 01:17:14 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bjaehcnihbogidpfieaepehilfecnodk\4.2.0.7869_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kochbcmingebnmbcpbbpfpmipakoipge\4.2.0.8207_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.20.90_0\crossrider
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.20.90_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\.bak
O1 HOSTS File: ([2012/04/12 08:33:06 | 000,000,947 | —- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DataMask by AOL) - {3955aa73-8c60-4a9b-acdb-0c2edb1b6748} - C:\Program Files\AOL\DataMask by AOL\epbho32.dll (AOL)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20120709150211.dll (McAfee, Inc.)
O2 - BHO: (Price Check by AOL) - {D25B97E9-62B2-40CE-BECF-E43A7B879072} - C:\Program Files\Price Check by AOL\aolpricecheck.dll (AOL Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome\Application\24.0.1312.27\npchrome_frame.dll (Google Inc.)
O2 - BHO: (TBSB07898 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O2 - BHO: (DataMask by AOL) - {ff507020-a257-4527-a222-b6f5732e55ee} - C:\Program Files\AOL\DataMask by AOL\plbho32.dll (AOL)
O3 - HKLM\..\Toolbar: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Data Protection Suite] C:\Program Files\AOL\DataMask by AOL\dps.exe (AOL)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [PhishLock] C:\Program Files\AOL\DataMask by AOL\pl.exe (AOL)
O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found
O4 - Startup: C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.3.0…xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3523D06-520B-4086-8151-9C5A7784F32F}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome\Application\24.0.1312.27\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\822\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\822\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop Components:0 () - http://www.carmd.com/Content/Images/Home/b…at-is-CarMD.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/08/05 00:12:32 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINXP\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.mjpg - pvmjpg30.dll File not found
Drivers32: wave1 - C:\WINXP\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/11/30 22:28:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:18:14 | 003,902,728 | —- | C] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
[2012/11/30 21:27:19 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\TeamViewer
[2012/11/28 07:51:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\QuickTime
[2012/11/28 06:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Staples Easy Button
[2012/11/28 06:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Staples Easy Button
[2012/11/28 06:44:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Staples Easy Button
[2012/11/28 06:44:54 | 000,000,000 | —D | C] – C:\Program Files\Staples Easy Button
[2012/11/25 14:58:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/11/25 14:47:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Norton PC Checkup 3.0
[2012/11/25 14:47:12 | 000,000,000 | —D | C] – C:\Program Files\Norton PC Checkup 3.0
[2012/11/25 14:47:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Norton
[2012/11/25 04:56:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\UAB
[2012/11/25 04:56:22 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\PC_Drivers_Headquarters
[2012/11/25 04:56:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Driver Restore
[2012/11/25 04:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\PCCUStubInstaller
[2012/11/25 04:53:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Driver Restore
[2012/11/25 04:53:14 | 000,000,000 | —D | C] – C:\Program Files\Driver Restore
[2012/11/24 05:43:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Mozilla
[2012/11/24 05:43:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla
[2012/11/24 00:43:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Mozilla
[2012/11/24 00:43:12 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/11/19 07:48:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/19 07:48:28 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINXP\System32\drivers\mbam.sys
[2012/11/19 07:48:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/19 07:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\SUPERAntiSpyware.com
[2012/11/19 07:28:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\SUPERAntiSpyware
[2012/11/19 07:28:03 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/11/15 01:29:09 | 000,000,000 | —D | C] – C:\Program Files\AOL Toolbar
[2012/11/15 01:28:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2012/11/15 00:46:20 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\PerformerSoft
[2012/11/15 00:39:52 | 000,017,464 | —- | C] (PerformerSoft LLC) – C:\WINXP\System32\roboot.exe
[2012/11/12 01:48:39 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeSuiteX
[2012/11/12 01:47:40 | 000,000,000 | –SD | C] – C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Office Suite X 3.3
[2012/11/12 01:45:55 | 000,000,000 | —D | C] – C:\Program Files\Office Suite X 3
[2012/11/12 01:35:58 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Sun
[2012/11/12 01:35:31 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Desktop\OfSX
[2012/11/11 01:46:17 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Toolbar4
[2012/11/10 20:08:39 | 000,000,000 | —D | C] – C:\WINXP\System32\cache
[2012/11/09 02:01:44 | 000,000,000 | -H-D | C] – C:\WINXP\ie8
[2012/11/08 03:40:07 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeNow
[2012/11/08 03:18:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\OfficeNow 3.5
[2012/11/08 03:15:52 | 000,000,000 | —D | C] – C:\Program Files\OfficeNow 3.5
[2012/11/08 03:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\My Documents\ShopToWin
[2012/11/08 03:13:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer
[2012/11/08 03:13:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Applications
[2012/11/08 03:12:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/11/08 03:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Babylon
[2012/11/08 03:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Babylon
[2012/11/08 03:11:33 | 000,000,000 | —D | C] – C:\Program Files\OfficeNow and Options
[1 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/11/30 23:06:30 | 000,000,890 | —- | M] () – C:\WINXP\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/30 22:32:08 | 000,000,886 | —- | M] () – C:\WINXP\tasks\SentryBayUpdateTaskMachineUA.job
[2012/11/30 22:28:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:22:30 | 000,000,886 | —- | M] () – C:\WINXP\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/30 22:22:28 | 000,000,418 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro startups.job
[2012/11/30 22:22:27 | 000,000,882 | —- | M] () – C:\WINXP\tasks\SentryBayUpdateTaskMachineCore.job
[2012/11/30 22:21:29 | 000,002,048 | –S- | M] () – C:\WINXP\bootstat.dat
[2012/11/30 22:21:28 | 000,304,416 | —- | M] () – C:\WINXP\System32\FNTCACHE.DAT
[2012/11/30 22:18:16 | 003,902,728 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
[2012/11/30 21:53:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/11/30 21:24:15 | 000,000,426 | -H– | M] () – C:\WINXP\tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
[2012/11/30 20:22:40 | 000,013,024 | —- | M] () – C:\WINXP\System32\drivers\SWDUMon.sys
[2012/11/30 01:29:43 | 000,141,429 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\OakBuilding001.pdf
[2012/11/29 18:11:49 | 000,000,372 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\spider.sav
[2012/11/28 07:52:00 | 000,001,600 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\QuickTime Player.lnk
[2012/11/28 07:20:04 | 000,000,284 | —- | M] () – C:\WINXP\tasks\AppleSoftwareUpdate.job
[2012/11/28 06:44:55 | 000,001,587 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Staples Easy Button.lnk
[2012/11/28 04:03:33 | 000,006,598 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Desktop\New OpenDocument Spreadsheet.ods
[2012/11/28 03:44:01 | 000,000,446 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro Updates.job
[2012/11/28 02:55:18 | 000,002,206 | —- | M] () – C:\WINXP\System32\wpa.dbl
[2012/11/25 14:47:54 | 000,000,960 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Norton PC Checkup 3.0.lnk
[2012/11/25 14:47:49 | 000,000,400 | —- | M] () – C:\WINXP\tasks\PC Checkup 3 Weekly Scan.job
[2012/11/25 04:53:22 | 000,002,022 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Driver Restore.lnk
[2012/11/24 00:43:15 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Mozilla Firefox.lnk
[2012/11/24 00:41:48 | 000,077,472 | -H– | M] () – C:\WINXP\System32\mlfcache.dat
[2012/11/24 00:40:43 | 000,002,183 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Safari.lnk
[2012/11/20 17:10:36 | 000,000,284 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro Scan.job
[2012/11/20 00:54:52 | 000,591,480 | —- | M] () – C:\WINXP\System32\perfh009.dat
[2012/11/20 00:54:51 | 000,106,952 | —- | M] () – C:\WINXP\System32\perfc009.dat
[2012/11/19 08:15:47 | 000,000,664 | —- | M] () – C:\WINXP\System32\d3d9caps.dat
[2012/11/19 07:48:33 | 000,000,802 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:48:33 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:28:07 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/11/16 02:14:48 | 000,001,831 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/14 13:38:43 | 000,018,240 | —- | M] (SentryBay) – C:\WINXP\System32\drivers\epfilter.sys
[2012/11/14 02:52:12 | 000,001,393 | —- | M] () – C:\WINXP\imsins.BAK
[2012/11/14 01:28:32 | 000,013,492 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\Untitled 1.ods
[2012/11/12 06:35:12 | 000,014,144 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\D KID SPREAD SHEET.ods
[2012/11/12 01:47:40 | 000,000,885 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Desktop\Office Suite X 3.3.lnk
[2012/11/09 20:19:36 | 000,000,815 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/11/09 01:11:15 | 000,000,754 | —- | M] () – C:\WINXP\WORDPAD.INI
[2012/11/08 04:22:53 | 000,007,495 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\MY NOTES BJC.ods
[2012/11/08 03:18:42 | 000,000,827 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\OfficeNow 3.5.lnk
[2012/11/01 03:02:10 | 000,007,477 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\.facebook_-2119691970.jpg
[1 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/11/30 21:53:25 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/11/28 07:51:59 | 000,001,600 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\QuickTime Player.lnk
[2012/11/28 06:44:55 | 000,001,587 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Staples Easy Button.lnk
[2012/11/28 04:03:33 | 000,006,598 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Desktop\New OpenDocument Spreadsheet.ods
[2012/11/28 04:02:18 | 000,001,764 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\VIPRE Internet Security.lnk
[2012/11/25 14:47:54 | 000,000,960 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Norton PC Checkup 3.0.lnk
[2012/11/25 14:47:49 | 000,000,400 | —- | C] () – C:\WINXP\tasks\PC Checkup 3 Weekly Scan.job
[2012/11/25 04:53:22 | 000,002,022 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Driver Restore.lnk
[2012/11/24 00:43:15 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/24 00:43:15 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Mozilla Firefox.lnk
[2012/11/20 17:10:34 | 000,000,284 | —- | C] () – C:\WINXP\tasks\PC Optimizer Pro Scan.job
[2012/11/19 14:43:01 | 000,141,429 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\OakBuilding001.pdf
[2012/11/19 07:48:33 | 000,000,802 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:48:33 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:28:07 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/11/15 00:06:17 | 000,000,426 | -H– | C] () – C:\WINXP\tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
[2012/11/14 01:28:32 | 000,013,492 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\Untitled 1.ods
[2012/11/12 06:35:12 | 000,014,144 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\D KID SPREAD SHEET.ods
[2012/11/12 01:47:40 | 000,000,885 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Desktop\Office Suite X 3.3.lnk
[2012/11/09 01:11:15 | 000,000,754 | —- | C] () – C:\WINXP\WORDPAD.INI
[2012/11/08 04:22:49 | 000,007,495 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\MY NOTES BJC.ods
[2012/11/08 03:18:42 | 000,000,827 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\OfficeNow 3.5.lnk
[2012/11/01 03:02:09 | 000,007,477 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\.facebook_-2119691970.jpg
[2012/10/08 13:11:12 | 000,013,024 | —- | C] () – C:\WINXP\System32\drivers\SWDUMon.sys
[2012/09/07 05:41:32 | 000,032,490 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\bgauuubu.exe
[2012/07/25 20:43:21 | 000,000,088 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\usb.inf
[2012/05/13 01:26:28 | 000,363,520 | —- | C] () – C:\WINXP\System32\PsisDecd.dll
[2012/05/01 01:17:15 | 000,000,391 | —- | C] () – C:\WINXP\label.ini
[2012/05/01 00:33:21 | 000,000,036 | —- | C] () – C:\WINXP\odbcddp.ini
[2012/05/01 00:33:20 | 000,001,327 | —- | C] () – C:\WINXP\ODBC.INI
[2012/05/01 00:20:37 | 000,001,286 | —- | C] () – C:\WINXP\resume32.ini
[2012/05/01 00:19:06 | 000,001,297 | —- | C] () – C:\WINXP\mymark32.ini
[2012/05/01 00:18:39 | 000,000,033 | —- | C] () – C:\WINXP\mybc32.ini
[2012/05/01 00:18:31 | 000,001,612 | —- | C] () – C:\WINXP\bussta32.ini
[2012/04/25 03:21:12 | 000,017,920 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/24 01:39:33 | 000,061,678 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\PFP100JPR.{PB
[2012/04/24 01:39:33 | 000,012,358 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\PFP100JCM.{PB
[2012/04/14 19:41:42 | 000,200,704 | —- | C] () – C:\WINXP\System32\igfxCoIn_v4704.dll
[2012/04/14 19:41:41 | 000,447,120 | —- | C] () – C:\WINXP\System32\igmedkrn.dll
[2012/04/13 23:40:03 | 000,000,664 | —- | C] () – C:\WINXP\System32\d3d9caps.dat
[2012/04/12 10:21:03 | 000,003,072 | —- | C] () – C:\WINXP\System32\iacenc.dll
[2012/04/11 20:21:58 | 000,077,824 | R— | C] () – C:\WINXP\System32\HPZIDS01.dll
[2012/04/11 04:48:32 | 000,077,472 | -H– | C] () – C:\WINXP\System32\mlfcache.dat
[2012/04/11 02:58:39 | 000,117,364 | —- | C] () – C:\WINXP\hpoins11.dat.temp
[2012/04/11 02:58:38 | 000,011,634 | —- | C] () – C:\WINXP\hpomdl11.dat.temp
[2012/04/10 19:33:21 | 000,000,000 | R— | C] () – C:\WINXP\System32\DVEMODEM.DAT
[2012/04/10 19:32:29 | 000,004,272 | R— | C] () – C:\WINXP\System32\drivers\bvrp_pci.sys
[2012/04/10 16:30:01 | 000,000,006 | —- | C] () – C:\WINXP\msoffice.ini
[2012/04/10 16:14:41 | 000,000,715 | —- | C] () – C:\WINXP\aolback.exe.lnk
[2012/04/09 10:24:28 | 000,000,132 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\fusioncache.dat
[2012/04/09 07:19:14 | 000,000,335 | —- | C] () – C:\WINXP\nsreg.dat
[2012/04/09 01:49:10 | 000,002,048 | –S- | C] () – C:\WINXP\bootstat.dat
[2012/04/09 01:43:36 | 000,021,640 | —- | C] () – C:\WINXP\System32\emptyregdb.dat
[2012/01/20 22:42:52 | 000,136,166 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2129685425-2355302513-2605349347-1007-0.dat
[2011/07/04 14:27:55 | 000,272,054 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2129685425-2355302513-2605349347-1006-0.dat
[2011/07/04 14:27:55 | 000,136,166 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
========== ZeroAccess Check ==========
[2012/04/11 20:34:48 | 000,000,227 | RHS- | M] () – C:\WINXP\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2012/02/28 13:50:30 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINXP\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINXP\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/09/06 00:11:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\036E18E8ECDC1B1C236255877B07D329
[2012/10/18 00:20:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/11/08 03:13:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Applications
[2012/11/08 03:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Babylon
[2012/04/10 14:40:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Citrix
[2012/10/08 13:11:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Common Files
[2012/09/08 19:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Downloaded Installations
[2012/11/25 04:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Driver Restore
[2012/08/31 11:15:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Garmin
[2012/08/05 00:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\muvee Technologies
[2012/07/25 07:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\PC Optimizer Pro
[2012/05/10 12:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle
[2012/05/10 12:44:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle Studio HD
[2012/05/10 12:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle Studio Plus
[2012/04/12 08:44:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Price Check by AOL
[2012/11/30 21:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\SpeedMaxPc
[2012/05/10 12:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Studio 15
[2012/11/30 22:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer
[2012/08/05 00:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\TEMP
[2012/11/25 04:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\UAB
[2012/11/30 21:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Viewpoint
[2012/06/07 10:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\White Sky, Inc
[2012/08/05 00:33:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\{299AD074-3B8B-4811-BF5C-E2EDBC6DEB23}
[2012/04/11 04:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/12 22:34:44 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\acccore
[2012/11/08 03:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Babylon
[2012/09/09 02:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Business Logic
[2012/05/13 00:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/10/04 12:39:41 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\DriverCure
[2012/04/25 03:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\FUJIFILM
[2012/08/31 11:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Garmin
[2012/07/25 21:11:57 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Image Zone Express
[2012/04/11 02:28:41 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\InterTrust
[2012/08/05 00:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\muvee Technologies
[2012/11/08 03:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeNow
[2012/11/12 01:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeSuiteX
[2012/07/14 02:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OpenOffice.org
[2012/11/25 04:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\PCCUStubInstaller
[2012/11/30 21:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\PerformerSoft
[2012/08/11 02:41:37 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SentryBay
[2012/10/10 04:18:08 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Smilebox
[2012/10/04 12:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SpeedMaxPc
[2012/11/30 20:44:30 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Staples Easy Button
[2012/05/08 21:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SupportSoft
[2012/11/30 21:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\TeamViewer
[2012/11/11 01:46:17 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Toolbar4
[2012/05/01 01:14:50 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Windows Desktop Search
[2012/10/18 22:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/04/08 15:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp
[2012/04/08 15:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp\1
[2012/04/27 11:01:03 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp\2
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/04 05:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\i386\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/12 08:57:20 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINXP\$NtServicePackUninstall$\explorer.exe
< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/04/08 17:52:48 | 000,090,326 | —- | M] () MD5=A1B929C5451DA91CBE6C337C73E65EB2 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
< MD5 for: EXPLORER.EXE-17D69B44.PF >
[2012/11/30 18:29:50 | 000,052,138 | —- | M] () MD5=7D75FA0502D072092F0BE1518785FAA0 – C:\WINXP\Prefetch\EXPLORER.EXE-17D69B44.pf
< MD5 for: EXPLORER.SC_ >
[2004/08/04 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/04 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
[2004/08/12 08:57:20 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINXP\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINXP\Help\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/08/12 08:58:01 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINXP\ie8\iexplore.chm
< MD5 for: IEXPLORE.CHW >
[2012/05/29 01:44:29 | 000,153,185 | —- | M] () MD5=3680C8BC82A0E88026ECFE100DB2C78A – C:\WINXP\Help\iexplore.chw
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 05:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINXP\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINXP\ServicePackFiles\i386\iexplore.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINXP\system32\dllcache\iexplore.exe
[2004/08/04 05:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie8\iexplore.exe
[2004/08/12 08:58:01 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINXP\$NtServicePackUninstall$\iexplore.exe
< MD5 for: IEXPLORE.EXE.HDMP >
[2011/07/06 03:56:59 | 005,578,495 | —- | M] () MD5=04E4011AC97D9BBD00916842DA673BC7 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERed39.dir00\iexplore.exe.hdmp
[2012/01/19 22:51:36 | 004,409,131 | —- | M] () MD5=43077588CC285663DA30458A8688D205 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER8f20.dir00\iexplore.exe.hdmp
[2011/12/17 16:27:00 | 007,398,843 | —- | M] () MD5=935306B67B7AFBB4260245E7EF21F79E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER0de0.dir00\iexplore.exe.hdmp
[2012/04/08 15:35:51 | 006,897,432 | —- | M] () MD5=9F1FA801F4FCCF7207524DF3A92AAA9C – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER722e.dir00\iexplore.exe.hdmp
[2012/11/20 16:50:12 | 019,163,917 | —- | M] () MD5=AA4D4D7F5C1337E315878FE35E45829F – C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\WER912c.dir00\iexplore.exe.hdmp
[2012/02/16 07:05:08 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER2bf7.dir00\iexplore.exe.hdmp
[2011/10/16 07:04:36 | 014,412,897 | —- | M] () MD5=E685A77790767C8AB83646325F8104B2 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER7c69.dir00\iexplore.exe.hdmp
[2011/12/19 16:26:21 | 006,963,994 | —- | M] () MD5=FA810B9078808FAAC2F20140F6BFE932 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERfa3c.dir00\iexplore.exe.hdmp
< MD5 for: IEXPLORE.EXE.MDMP >
[2011/07/06 03:56:56 | 000,068,413 | —- | M] () MD5=1E571B6C12DA737D6CBA8209699DCA1C – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERed39.dir00\iexplore.exe.mdmp
[2011/10/09 05:25:21 | 000,083,359 | —- | M] () MD5=5479E40655C9EE59C363B7F1B3A41CCC – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER206a.dir00\iexplore.exe.mdmp
[2012/04/08 15:35:42 | 000,073,927 | —- | M] () MD5=571ED32BF2B1449FF5C93FBCC4864E6E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER722e.dir00\iexplore.exe.mdmp
[2011/10/08 02:28:00 | 000,075,235 | —- | M] () MD5=66AD3D424DAF2ECB0B0072EA39C897AB – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERa8bb.dir00\iexplore.exe.mdmp
[2012/11/20 16:50:09 | 000,078,557 | —- | M] () MD5=68229361750175A92E913DCB5C10859F – C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\WER912c.dir00\iexplore.exe.mdmp
[2011/10/16 07:04:33 | 000,115,299 | —- | M] () MD5=A02490CA1BD807F4798892008E7545E4 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER7c69.dir00\iexplore.exe.mdmp
[2011/12/17 16:26:57 | 000,072,225 | —- | M] () MD5=AFBBCF6A0A0B26CC462608AA5BA74214 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER0de0.dir00\iexplore.exe.mdmp
[2012/02/16 07:05:07 | 000,092,662 | —- | M] () MD5=D37DF78C2E5EB8121AE6C3D11F260586 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER2bf7.dir00\iexplore.exe.mdmp
[2012/01/19 22:51:33 | 000,063,229 | —- | M] () MD5=F41EB20F4B795CB9657D564E4AAE1ED9 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER8f20.dir00\iexplore.exe.mdmp
[2011/12/19 16:26:17 | 000,071,668 | —- | M] () MD5=FA7542F81DFF6FAEA4105F3B8450814D – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERfa3c.dir00\iexplore.exe.mdmp
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/04/08 18:01:55 | 000,088,036 | —- | M] () MD5=146BAD1D7DEA1BAC9C50EE0D71427AD6 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
[2012/11/30 22:27:01 | 000,068,666 | —- | M] () MD5=F7D0A71D4B6B086555E8B5142D64DEF6 – C:\WINXP\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
[2004/08/12 08:58:01 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINXP\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[2004/08/12 09:05:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINXP\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/01/03 08:10:44 | 000,585,874 | —- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINXP\$NtUninstallKB956572$\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINXP\ServicePackFiles\i386\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\i386\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINXP\$NtServicePackUninstall$\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINXP\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\system32\services.exe
[2004/08/12 09:05:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINXP\$NtUninstallKB956572_0$\services.exe
< MD5 for: SERVICES.LNK >
[2012/07/14 02:57:12 | 000,001,590 | —- | M] () MD5=1DC649CD3A981792970A2A7929CFF0D2 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
[2012/07/14 02:57:47 | 000,001,590 | —- | M] () MD5=2522AAD5468A85CCEBD8C6386910BA71 – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Administrative Tools\Services.lnk
[2012/07/14 02:58:35 | 000,001,608 | —- | M] () MD5=FFAE08D234081A15D87D50816B427810 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\smtmp\1\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
[2004/08/12 09:05:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINXP\system32\services.msc
< MD5 for: SERVICES.RDB >
[2012/06/04 07:32:06 | 000,008,060 | —- | M] () MD5=365F626303EBC6DB5DCA7BBC4FAE0564 – C:\Program Files\OfficeNow 3.5\URE\misc\services.rdb
[2011/12/23 18:19:16 | 000,237,568 | —- | M] () MD5=507957679AE4579C15D57FA741EA6FFA – C:\Program Files\Office Suite X 3\URE\misc\services.rdb
[2011/12/23 18:18:40 | 005,314,560 | —- | M] () MD5=B31F4ECB1247A650528A040A2D791105 – C:\Program Files\Office Suite X 3\Basis\program\services.rdb
[2012/06/04 22:31:04 | 000,180,201 | —- | M] () MD5=FB73C2F46884319721B2BBA533490429 – C:\Program Files\OfficeNow 3.5\program\services\services.rdb
< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/12 09:09:30 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINXP\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2012/04/12 12:16:13 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2012/04/12 12:16:13 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2012/08/05 00:12:32 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2012/09/20 14:04:37 | 000,000,316 | -HS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/06/20 20:55:34 | 000,008,290 | R— | M] () – C:\dell.sdr
[2011/07/21 01:45:48 | 000,001,471 | —- | M] () – C:\GingerSetup.log
[2007/03/30 00:07:43 | 1063,161,856 | -HS- | M] () – C:\hiberfil.sys
[2011/06/21 21:17:07 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2012/05/08 22:17:24 | 000,030,546 | —- | M] () – C:\install.log
[2012/11/30 21:53:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/11/28 17:04:54 | 000,000,112 | —- | M] () – C:\INSTALLHELPER.LOG
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\IO.SYS
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2011/06/20 20:55:42 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/07/04 03:46:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/11/30 22:21:26 | 1594,662,912 | -HS- | M] () – C:\pagefile.sys
[2012/09/20 14:16:31 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/07/29 02:07:46 | 000,000,186 | —- | M] () – C:\picsetup.log
[2012/04/10 16:11:50 | 000,000,320 | -H– | M] () – C:\T4Metrics.log
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINXP\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINXP\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINXP\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINXP\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2006/02/19 02:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINXP\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2012/04/09 01:46:11 | 000,000,067 | -HS- | M] () – C:\WINXP\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 13:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2007/03/29 19:31:36 | 000,094,208 | —- | M] () – C:\WINXP\System32\config\default.sav
[2007/03/29 19:31:36 | 000,634,880 | —- | M] () – C:\WINXP\System32\config\software.sav
[2007/03/29 19:31:36 | 000,901,120 | —- | M] () – C:\WINXP\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012/04/12 09:31:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINXP\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/04/12 10:17:14 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/04/09 01:56:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/04/16 02:23:10 | 001,552,605 | —- | M] (Ion Audio LLC ) – C:\Documents and Settings\YOUNG ONE\Desktop\EZVinylTapeConverterSetup_v10.exe
[2012/04/11 02:00:45 | 004,258,424 | —- | M] (McAfee, Inc.) – C:\Documents and Settings\YOUNG ONE\Desktop\McAfeeSetup.exe
[2012/11/30 22:28:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:18:16 | 003,902,728 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-11-14 08:06:46
========== Alternate Data Streams ==========
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINXP\Application Data\TEMP:79DD4F33
< End of report >
——————
OTL Extras logfile created on: 11/30/2012 11:16:43 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\YOUNG ONE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.86 Mb Total Physical Memory | 481.32 Mb Available Physical Memory | 47.47% Memory free
2.38 Gb Paging File | 1.64 Gb Available in Paging File | 68.83% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 145.00 Gb Total Space | 81.00 Gb Free Space | 55.86% Space Free | Partition Type: NTFS
Computer Name: JAMES-91746AC0C | User Name: YOUNG ONE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL Inc.)
"C:\Program Files\Common Files\aol\ACS\AOLDial.exe" = C:\Program Files\Common Files\aol\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\aol\ACS\AOLacsd.exe" = C:\Program Files\Common Files\aol\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0b\waol.exe" = C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
"C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
"C:\Program Files\Common Files\aol\1334092339\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\aol\1334092339\EE\AOLServiceHost.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\aol\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\aol\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\aol\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\aol\1334093993\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1334093993\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
"C:\Program Files\Common Files\aol\1334093993\ee\AOLDesktop.exe" = C:\Program Files\Common Files\aol\1334093993\ee\AOLDesktop.exe:*:Enabled:AOL Desktop
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe – (Hewlett-Packard Development Company, L.P.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"E:\skype\Skype.exe" = E:\skype\Skype.exe:*:Enabled:Skype
"C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\waol.exe" = C:\Program Files\AOL Desktop 9.7\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{12365698-8042-4774-8CAF-35BE91DC657B}" = Creative Vado HD Codec
"{1362E602-9625-42D3-B57F-CDA9D26F9DA8}" = Pinnacle Studio 15
"{13F054F3-0B07-4D15-9E80-C55B496AB557}" = Garmin Communicator Plugin
"{14ECAABB-C8B9-4A09-92F7-CDF1A45B6DDE}" = Google Drive
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F56A6C9-81CA-4B5F-B471-8CCB13CF85DA}" = Office Suite X 3.3
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{251C65C0-15FF-4603-98BB-E4A61C7DA424}" = CarMD
"{273130E8-117C-4237-A0FA-83EBBF11E051}" = Driver Restore
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D3CD3E-7715-4341-8441-A3A6409FCDE4}" = BIAS SoundSoap 2.0
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{524AC636-ADC4-4E42-B149-D0B6B5F4D24A}" = Garmin BaseCamp
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{555B2506-E17C-4EEF-AA70-03985F664BAD}" = Creative Vado Central muvee Plugin
"{5802F606-7F09-4CCE-800C-7B53B0906662}" = Mail List
"{5A9AA2C0-972F-4239-AA41-E409434194D5}" = MobileMe Control Panel
"{5FDA577D-2C25-405F-B759-235CA8016D19}" = Newsletters
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Driver
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9A61BE73-18A3-4AC2-AFF1-E4B8D92158BD}" = OfficeNow 3.5
"{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3217415-0BD4-4252-BF9F-3AF4A267B04C}" = DataMask by AOL
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AA104808-94FA-4C82-ABFE-F630E44192E2}" = Resumes
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABA5E381-EC46-425C-86C5-5CD15BBFB4BF}" = Garmin USB Drivers
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BA38CDB0-B61C-4490-9A9C-92241C05FA33}" = SentryBay Update Helper
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BC85D7C6-028A-4012-8E3C-B4D11D74E34B}" = DriverUpdate
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DED01768-E634-11E1-AEB0-984BE15F174E}" = Evernote v. 4.5.8
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E488C022-045B-11D5-97A7-00C04F6BFB42}" = LabelMaker
"{E75AE16E-43CF-446D-AD44-999550BFD78E}" = Stationery
"{EC27311B-0012-11D5-8341-0001023FF70B}" = CD Organizer
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{FA4C2D53-205F-4245-9717-F3761154824D}" = Safari
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FC030CB5-46A6-4229-AD6E-0AC869F509C8}" = Pinnacle Studio Bonus Content
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AOL Deskbar" = AOL Deskbar
"AOL Toolbar" = AOL Toolbar
"AOL Toolbar for Firefox" = AOL Toolbar for Firefox
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"Audacity_is1" = Audacity 1.2.4
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Creative Vado HD Codec" = Creative Vado HD Codec
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter by MixMeister 1.0.5
"EZ Vinyl/Tape Converter by Ion Audio_is1" = EZ Vinyl/Tape Converter 10 by Ion Audio
"Google Chrome" = Google Chrome
"Google Chrome Frame" = Google Chrome Frame
"GoToAssist" = GoToAssist Corporate
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 17.0 (x86 en-US)" = Mozilla Firefox 17.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Norton PC Checkup_is1" = Norton PC Checkup
"OfficeNow_and_Options" = OfficeNow and Options
"Price Check by AOL" = Price Check by AOL
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer Basic
"SoftwareUpdUtility" = Download Updater (AOL Inc.)
"Staples Easy Button" = Staples Easy Button (remove only)
"stax-Pinnacle_is1" = SureThing Express Labeler
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AOL Toolbar" = AOL Toolbar
"Smilebox" = Smilebox
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 11/29/2012 12:52:33 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 11/29/2012 12:53:29 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 11/29/2012 12:55:23 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 11/29/2012 4:36:31 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19328, fault address 0x000da6ff.
Error - 11/29/2012 4:36:31 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19328, fault address 0x000da6ff.
Error - 11/30/2012 2:00:39 AM | Computer Name = JAMES-91746AC0C | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 2116 (0x844) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\SUPERAntiSpyware\sasdifsv.sys
by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 4(0)(0) 4(0)(0)
7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)
Error - 11/30/2012 1:35:46 PM | Computer Name = JAMES-91746AC0C | Source = Application Hang | ID = 1002
Description = Hanging application PCPerformer.exe, version 11.10.1.2217, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 11/30/2012 1:37:26 PM | Computer Name = JAMES-91746AC0C | Source = Application Hang | ID = 1001
Description = Fault bucket -1400214861.
Error - 11/30/2012 10:19:12 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module , version 13.2.0.5, fault address 0x000ea1b9.
Error - 11/30/2012 11:02:04 PM | Computer Name = JAMES-91746AC0C | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3068 (0xbfc) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\McAfee.com\Agent\mcagent.exe
by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 4(0)(0) 4(0)(0)
7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)
[ System Events ]
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:03 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:03 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:18 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:18 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:34:28 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
< End of report >
—————
OTL logfile created on: 11/30/2012 11:16:43 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\YOUNG ONE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.86 Mb Total Physical Memory | 481.32 Mb Available Physical Memory | 47.47% Memory free
2.38 Gb Paging File | 1.64 Gb Available in Paging File | 68.83% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 145.00 Gb Total Space | 81.00 Gb Free Space | 55.86% Space Free | Partition Type: NTFS
Computer Name: JAMES-91746AC0C | User Name: YOUNG ONE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AOL\DataMask by AOL\pl.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\ep.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\epservice.exe (AOL)
PRC - C:\Program Files\AOL\DataMask by AOL\dps.exe (AOL)
PRC - C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\TeamViewer.exe (TeamViewer GmbH)
PRC - c:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\TeamViewer_Desktop.exe (TeamViewer GmbH)
PRC - C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files\SentryBay\Update\SentryBayUpdate.exe (AOL)
PRC - C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\WINXP\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\WINXP\system32\mmc.exe (Microsoft Corporation)
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)
PRC - C:\WINXP\system32\dfrgntfs.exe (Microsoft Corp. and Executive Software International, Inc.)
PRC - C:\WINXP\system32\HPZipm12.exe (HP)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AOL\DataMask by AOL\libxmlsec.dll ()
MOD - C:\Program Files\AOL\DataMask by AOL\libxmlsec-mscrypto.dll ()
MOD - C:\Program Files\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\AOL\DataMask by AOL\libxml2.dll ()
MOD - C:\WINXP\system32\msdmo.dll ()
MOD - C:\WINXP\system32\devenum.dll ()
========== Services (SafeList) ==========
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (EntryProtect) – C:\Program Files\AOL\DataMask by AOL\epservice.exe (AOL)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\822\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (sbupdate) – C:\Program Files\SentryBay\Update\SentryBayUpdate.exe (AOL)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (mfevtp) – C:\WINXP\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
SRV - (Pml Driver HPZ12) – C:\WINXP\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mfeavfk01) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (SWDUMon) – C:\WINXP\system32\drivers\SWDUMon.sys ()
DRV - (epfilter) – C:\WINXP\system32\drivers\epfilter.sys (SentryBay)
DRV - (MBAMProtector) – C:\WINXP\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (ASCTRM) – C:\WINXP\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (mfehidk) – C:\WINXP\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINXP\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINXP\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINXP\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINXP\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINXP\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINXP\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINXP\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINXP\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINXP\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (motccgpfl) – C:\WINXP\system32\drivers\motccgpfl.sys (Motorola)
DRV - (motccgp) – C:\WINXP\system32\drivers\motccgp.sys (Motorola)
DRV - (MPE) – C:\WINXP\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (motport) – C:\WINXP\system32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\WINXP\system32\drivers\motmodem.sys (Motorola)
DRV - (emAudio) – C:\WINXP\system32\drivers\emAudio.sys (Pinnacle Systems GmbH)
DRV - (STHDA) – C:\WINXP\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DCamUSBEMPIA) – C:\WINXP\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINXP\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINXP\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (MarvinBus) – C:\WINXP\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (bvrp_pci) – C:\WINXP\system32\drivers\bvrp_pci.sys ()
DRV - (HSFHWBS2) – C:\WINXP\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINXP\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINXP\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (wanatw) – C:\WINXP\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – C:\WINXP\system32\drivers\omci.sys (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/
IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=15-11-2012
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aol.com/?ncid=customie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - HKCU\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…0000019d17406b1
IE - HKCU\..\SearchScopes\{40267B06-090D-4211-B671-4647C071C5C8}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=15-11-2012
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://search.coupons.com/search.asp?p=df&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@update.sentrybay.com/SentryBay Update;version=8: C:\Program Files\SentryBay\Update\1.0.0.7621\npSentryBayOneClick8.dll (AOL)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/11/30 22:33:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AOL\DataMask by AOL\ffext [2012/11/14 15:42:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/28 07:52:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/11/24 05:44:16 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Extensions
[2012/11/25 05:53:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions
[2012/11/25 05:53:12 | 000,000,000 | —D | M] (ProxTube - Unblock YouTube) – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla\Firefox\Profiles\r4me9otk.default\extensions\[removed]
[2012/11/24 00:43:09 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/11/20 01:17:52 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/20 01:17:14 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/20 01:17:14 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bjaehcnihbogidpfieaepehilfecnodk\4.2.0.7869_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kochbcmingebnmbcpbbpfpmipakoipge\4.2.0.8207_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.20.90_0\crossrider
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpfapcdfbbledbojijcbcclmlieaoogk\1.20.90_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\
CHR - Extension: No name found = C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\.bak
O1 HOSTS File: ([2012/04/12 08:33:06 | 000,000,947 | —- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DataMask by AOL) - {3955aa73-8c60-4a9b-acdb-0c2edb1b6748} - C:\Program Files\AOL\DataMask by AOL\epbho32.dll (AOL)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20120709150211.dll (McAfee, Inc.)
O2 - BHO: (Price Check by AOL) - {D25B97E9-62B2-40CE-BECF-E43A7B879072} - C:\Program Files\Price Check by AOL\aolpricecheck.dll (AOL Inc.)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome\Application\24.0.1312.27\npchrome_frame.dll (Google Inc.)
O2 - BHO: (TBSB07898 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O2 - BHO: (DataMask by AOL) - {ff507020-a257-4527-a222-b6f5732e55ee} - C:\Program Files\AOL\DataMask by AOL\plbho32.dll (AOL)
O3 - HKLM\..\Toolbar: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Coupons.com CouponBar) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Data Protection Suite] C:\Program Files\AOL\DataMask by AOL\dps.exe (AOL)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [PhishLock] C:\Program Files\AOL\DataMask by AOL\pl.exe (AOL)
O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found
O4 - Startup: C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.3.0…xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3523D06-520B-4086-8151-9C5A7784F32F}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome\Application\24.0.1312.27\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\822\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\822\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop Components:0 () - http://www.carmd.com/Content/Images/Home/b…at-is-CarMD.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/08/05 00:12:32 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29de-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29e0-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1d5c29e2-b1d0-11e1-ba92-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINXP\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.mjpg - pvmjpg30.dll File not found
Drivers32: wave1 - C:\WINXP\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/11/30 22:28:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:18:14 | 003,902,728 | —- | C] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
[2012/11/30 21:27:19 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\TeamViewer
[2012/11/28 07:51:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\QuickTime
[2012/11/28 06:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Staples Easy Button
[2012/11/28 06:44:56 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Staples Easy Button
[2012/11/28 06:44:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Staples Easy Button
[2012/11/28 06:44:54 | 000,000,000 | —D | C] – C:\Program Files\Staples Easy Button
[2012/11/25 14:58:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/11/25 14:47:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Norton PC Checkup 3.0
[2012/11/25 14:47:12 | 000,000,000 | —D | C] – C:\Program Files\Norton PC Checkup 3.0
[2012/11/25 14:47:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Norton
[2012/11/25 04:56:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\UAB
[2012/11/25 04:56:22 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\PC_Drivers_Headquarters
[2012/11/25 04:56:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Driver Restore
[2012/11/25 04:55:57 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\PCCUStubInstaller
[2012/11/25 04:53:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Driver Restore
[2012/11/25 04:53:14 | 000,000,000 | —D | C] – C:\Program Files\Driver Restore
[2012/11/24 05:43:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\Mozilla
[2012/11/24 05:43:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Mozilla
[2012/11/24 00:43:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Mozilla
[2012/11/24 00:43:12 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/11/19 07:48:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/19 07:48:28 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINXP\System32\drivers\mbam.sys
[2012/11/19 07:48:28 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/19 07:28:13 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\SUPERAntiSpyware.com
[2012/11/19 07:28:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\SUPERAntiSpyware
[2012/11/19 07:28:03 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2012/11/15 01:29:09 | 000,000,000 | —D | C] – C:\Program Files\AOL Toolbar
[2012/11/15 01:28:50 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2012/11/15 00:46:20 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\PerformerSoft
[2012/11/15 00:39:52 | 000,017,464 | —- | C] (PerformerSoft LLC) – C:\WINXP\System32\roboot.exe
[2012/11/12 01:48:39 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeSuiteX
[2012/11/12 01:47:40 | 000,000,000 | –SD | C] – C:\Documents and Settings\YOUNG ONE\Start Menu\Programs\Office Suite X 3.3
[2012/11/12 01:45:55 | 000,000,000 | —D | C] – C:\Program Files\Office Suite X 3
[2012/11/12 01:35:58 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Sun
[2012/11/12 01:35:31 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Desktop\OfSX
[2012/11/11 01:46:17 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Toolbar4
[2012/11/10 20:08:39 | 000,000,000 | —D | C] – C:\WINXP\System32\cache
[2012/11/09 02:01:44 | 000,000,000 | -H-D | C] – C:\WINXP\ie8
[2012/11/08 03:40:07 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeNow
[2012/11/08 03:18:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\OfficeNow 3.5
[2012/11/08 03:15:52 | 000,000,000 | —D | C] – C:\Program Files\OfficeNow 3.5
[2012/11/08 03:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\My Documents\ShopToWin
[2012/11/08 03:13:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer
[2012/11/08 03:13:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Applications
[2012/11/08 03:12:36 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2012/11/08 03:11:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINXP\Application Data\Babylon
[2012/11/08 03:11:47 | 000,000,000 | —D | C] – C:\Documents and Settings\YOUNG ONE\Application Data\Babylon
[2012/11/08 03:11:33 | 000,000,000 | —D | C] – C:\Program Files\OfficeNow and Options
[1 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/11/30 23:06:30 | 000,000,890 | —- | M] () – C:\WINXP\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/30 22:32:08 | 000,000,886 | —- | M] () – C:\WINXP\tasks\SentryBayUpdateTaskMachineUA.job
[2012/11/30 22:28:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:22:30 | 000,000,886 | —- | M] () – C:\WINXP\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/30 22:22:28 | 000,000,418 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro startups.job
[2012/11/30 22:22:27 | 000,000,882 | —- | M] () – C:\WINXP\tasks\SentryBayUpdateTaskMachineCore.job
[2012/11/30 22:21:29 | 000,002,048 | –S- | M] () – C:\WINXP\bootstat.dat
[2012/11/30 22:21:28 | 000,304,416 | —- | M] () – C:\WINXP\System32\FNTCACHE.DAT
[2012/11/30 22:18:16 | 003,902,728 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
[2012/11/30 21:53:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/11/30 21:24:15 | 000,000,426 | -H– | M] () – C:\WINXP\tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
[2012/11/30 20:22:40 | 000,013,024 | —- | M] () – C:\WINXP\System32\drivers\SWDUMon.sys
[2012/11/30 01:29:43 | 000,141,429 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\OakBuilding001.pdf
[2012/11/29 18:11:49 | 000,000,372 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\spider.sav
[2012/11/28 07:52:00 | 000,001,600 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\QuickTime Player.lnk
[2012/11/28 07:20:04 | 000,000,284 | —- | M] () – C:\WINXP\tasks\AppleSoftwareUpdate.job
[2012/11/28 06:44:55 | 000,001,587 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Staples Easy Button.lnk
[2012/11/28 04:03:33 | 000,006,598 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Desktop\New OpenDocument Spreadsheet.ods
[2012/11/28 03:44:01 | 000,000,446 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro Updates.job
[2012/11/28 02:55:18 | 000,002,206 | —- | M] () – C:\WINXP\System32\wpa.dbl
[2012/11/25 14:47:54 | 000,000,960 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Norton PC Checkup 3.0.lnk
[2012/11/25 14:47:49 | 000,000,400 | —- | M] () – C:\WINXP\tasks\PC Checkup 3 Weekly Scan.job
[2012/11/25 04:53:22 | 000,002,022 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Driver Restore.lnk
[2012/11/24 00:43:15 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Mozilla Firefox.lnk
[2012/11/24 00:41:48 | 000,077,472 | -H– | M] () – C:\WINXP\System32\mlfcache.dat
[2012/11/24 00:40:43 | 000,002,183 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Safari.lnk
[2012/11/20 17:10:36 | 000,000,284 | —- | M] () – C:\WINXP\tasks\PC Optimizer Pro Scan.job
[2012/11/20 00:54:52 | 000,591,480 | —- | M] () – C:\WINXP\System32\perfh009.dat
[2012/11/20 00:54:51 | 000,106,952 | —- | M] () – C:\WINXP\System32\perfc009.dat
[2012/11/19 08:15:47 | 000,000,664 | —- | M] () – C:\WINXP\System32\d3d9caps.dat
[2012/11/19 07:48:33 | 000,000,802 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:48:33 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:28:07 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/11/16 02:14:48 | 000,001,831 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/14 13:38:43 | 000,018,240 | —- | M] (SentryBay) – C:\WINXP\System32\drivers\epfilter.sys
[2012/11/14 02:52:12 | 000,001,393 | —- | M] () – C:\WINXP\imsins.BAK
[2012/11/14 01:28:32 | 000,013,492 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\Untitled 1.ods
[2012/11/12 06:35:12 | 000,014,144 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\D KID SPREAD SHEET.ods
[2012/11/12 01:47:40 | 000,000,885 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Desktop\Office Suite X 3.3.lnk
[2012/11/09 20:19:36 | 000,000,815 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/11/09 01:11:15 | 000,000,754 | —- | M] () – C:\WINXP\WORDPAD.INI
[2012/11/08 04:22:53 | 000,007,495 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\MY NOTES BJC.ods
[2012/11/08 03:18:42 | 000,000,827 | —- | M] () – C:\Documents and Settings\All Users.WINXP\Desktop\OfficeNow 3.5.lnk
[2012/11/01 03:02:10 | 000,007,477 | —- | M] () – C:\Documents and Settings\YOUNG ONE\My Documents\.facebook_-2119691970.jpg
[1 C:\WINXP\*.tmp files -> C:\WINXP\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/11/30 21:53:25 | 000,000,000 | —- | C] () – C:\install.rdf
[2012/11/28 07:51:59 | 000,001,600 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\QuickTime Player.lnk
[2012/11/28 06:44:55 | 000,001,587 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Staples Easy Button.lnk
[2012/11/28 04:03:33 | 000,006,598 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Desktop\New OpenDocument Spreadsheet.ods
[2012/11/28 04:02:18 | 000,001,764 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\VIPRE Internet Security.lnk
[2012/11/25 14:47:54 | 000,000,960 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Norton PC Checkup 3.0.lnk
[2012/11/25 14:47:49 | 000,000,400 | —- | C] () – C:\WINXP\tasks\PC Checkup 3 Weekly Scan.job
[2012/11/25 04:53:22 | 000,002,022 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Driver Restore.lnk
[2012/11/24 00:43:15 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/24 00:43:15 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Mozilla Firefox.lnk
[2012/11/20 17:10:34 | 000,000,284 | —- | C] () – C:\WINXP\tasks\PC Optimizer Pro Scan.job
[2012/11/19 14:43:01 | 000,141,429 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\OakBuilding001.pdf
[2012/11/19 07:48:33 | 000,000,802 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:48:33 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/19 07:28:07 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/11/15 00:06:17 | 000,000,426 | -H– | C] () – C:\WINXP\tasks\User_Feed_Synchronization-{BAE1211D-518D-41FA-952A-BC9133310994}.job
[2012/11/14 01:28:32 | 000,013,492 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\Untitled 1.ods
[2012/11/12 06:35:12 | 000,014,144 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\D KID SPREAD SHEET.ods
[2012/11/12 01:47:40 | 000,000,885 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Desktop\Office Suite X 3.3.lnk
[2012/11/09 01:11:15 | 000,000,754 | —- | C] () – C:\WINXP\WORDPAD.INI
[2012/11/08 04:22:49 | 000,007,495 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\MY NOTES BJC.ods
[2012/11/08 03:18:42 | 000,000,827 | —- | C] () – C:\Documents and Settings\All Users.WINXP\Desktop\OfficeNow 3.5.lnk
[2012/11/01 03:02:09 | 000,007,477 | —- | C] () – C:\Documents and Settings\YOUNG ONE\My Documents\.facebook_-2119691970.jpg
[2012/10/08 13:11:12 | 000,013,024 | —- | C] () – C:\WINXP\System32\drivers\SWDUMon.sys
[2012/09/07 05:41:32 | 000,032,490 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\bgauuubu.exe
[2012/07/25 20:43:21 | 000,000,088 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\usb.inf
[2012/05/13 01:26:28 | 000,363,520 | —- | C] () – C:\WINXP\System32\PsisDecd.dll
[2012/05/01 01:17:15 | 000,000,391 | —- | C] () – C:\WINXP\label.ini
[2012/05/01 00:33:21 | 000,000,036 | —- | C] () – C:\WINXP\odbcddp.ini
[2012/05/01 00:33:20 | 000,001,327 | —- | C] () – C:\WINXP\ODBC.INI
[2012/05/01 00:20:37 | 000,001,286 | —- | C] () – C:\WINXP\resume32.ini
[2012/05/01 00:19:06 | 000,001,297 | —- | C] () – C:\WINXP\mymark32.ini
[2012/05/01 00:18:39 | 000,000,033 | —- | C] () – C:\WINXP\mybc32.ini
[2012/05/01 00:18:31 | 000,001,612 | —- | C] () – C:\WINXP\bussta32.ini
[2012/04/25 03:21:12 | 000,017,920 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/24 01:39:33 | 000,061,678 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\PFP100JPR.{PB
[2012/04/24 01:39:33 | 000,012,358 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Application Data\PFP100JCM.{PB
[2012/04/14 19:41:42 | 000,200,704 | —- | C] () – C:\WINXP\System32\igfxCoIn_v4704.dll
[2012/04/14 19:41:41 | 000,447,120 | —- | C] () – C:\WINXP\System32\igmedkrn.dll
[2012/04/13 23:40:03 | 000,000,664 | —- | C] () – C:\WINXP\System32\d3d9caps.dat
[2012/04/12 10:21:03 | 000,003,072 | —- | C] () – C:\WINXP\System32\iacenc.dll
[2012/04/11 20:21:58 | 000,077,824 | R— | C] () – C:\WINXP\System32\HPZIDS01.dll
[2012/04/11 04:48:32 | 000,077,472 | -H– | C] () – C:\WINXP\System32\mlfcache.dat
[2012/04/11 02:58:39 | 000,117,364 | —- | C] () – C:\WINXP\hpoins11.dat.temp
[2012/04/11 02:58:38 | 000,011,634 | —- | C] () – C:\WINXP\hpomdl11.dat.temp
[2012/04/10 19:33:21 | 000,000,000 | R— | C] () – C:\WINXP\System32\DVEMODEM.DAT
[2012/04/10 19:32:29 | 000,004,272 | R— | C] () – C:\WINXP\System32\drivers\bvrp_pci.sys
[2012/04/10 16:30:01 | 000,000,006 | —- | C] () – C:\WINXP\msoffice.ini
[2012/04/10 16:14:41 | 000,000,715 | —- | C] () – C:\WINXP\aolback.exe.lnk
[2012/04/09 10:24:28 | 000,000,132 | —- | C] () – C:\Documents and Settings\YOUNG ONE\Local Settings\Application Data\fusioncache.dat
[2012/04/09 07:19:14 | 000,000,335 | —- | C] () – C:\WINXP\nsreg.dat
[2012/04/09 01:49:10 | 000,002,048 | –S- | C] () – C:\WINXP\bootstat.dat
[2012/04/09 01:43:36 | 000,021,640 | —- | C] () – C:\WINXP\System32\emptyregdb.dat
[2012/01/20 22:42:52 | 000,136,166 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2129685425-2355302513-2605349347-1007-0.dat
[2011/07/04 14:27:55 | 000,272,054 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-2129685425-2355302513-2605349347-1006-0.dat
[2011/07/04 14:27:55 | 000,136,166 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
========== ZeroAccess Check ==========
[2012/04/11 20:34:48 | 000,000,227 | RHS- | M] () – C:\WINXP\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2012/02/28 13:50:30 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINXP\system32\wbem\fastprox.dll – [2009/02/09 07:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINXP\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/09/06 00:11:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\036E18E8ECDC1B1C236255877B07D329
[2012/10/18 00:20:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/11/08 03:13:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Applications
[2012/11/08 03:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Babylon
[2012/04/10 14:40:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Citrix
[2012/10/08 13:11:03 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Common Files
[2012/09/08 19:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Downloaded Installations
[2012/11/25 04:56:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Driver Restore
[2012/08/31 11:15:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Garmin
[2012/08/05 00:11:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\muvee Technologies
[2012/07/25 07:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\PC Optimizer Pro
[2012/05/10 12:43:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle
[2012/05/10 12:44:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle Studio HD
[2012/05/10 12:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Pinnacle Studio Plus
[2012/04/12 08:44:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Price Check by AOL
[2012/11/30 21:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\SpeedMaxPc
[2012/05/10 12:34:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Studio 15
[2012/11/30 22:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Tarma Installer
[2012/08/05 00:46:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\TEMP
[2012/11/25 04:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\UAB
[2012/11/30 21:54:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\Viewpoint
[2012/06/07 10:58:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\White Sky, Inc
[2012/08/05 00:33:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\{299AD074-3B8B-4811-BF5C-E2EDBC6DEB23}
[2012/04/11 04:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINXP\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/04/12 22:34:44 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\acccore
[2012/11/08 03:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Babylon
[2012/09/09 02:15:28 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Business Logic
[2012/05/13 00:33:45 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/10/04 12:39:41 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\DriverCure
[2012/04/25 03:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\FUJIFILM
[2012/08/31 11:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Garmin
[2012/07/25 21:11:57 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Image Zone Express
[2012/04/11 02:28:41 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\InterTrust
[2012/08/05 00:18:23 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\muvee Technologies
[2012/11/08 03:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeNow
[2012/11/12 01:48:39 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OfficeSuiteX
[2012/07/14 02:59:59 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\OpenOffice.org
[2012/11/25 04:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\PCCUStubInstaller
[2012/11/30 21:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\PerformerSoft
[2012/08/11 02:41:37 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SentryBay
[2012/10/10 04:18:08 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Smilebox
[2012/10/04 12:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SpeedMaxPc
[2012/11/30 20:44:30 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Staples Easy Button
[2012/05/08 21:16:32 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\SupportSoft
[2012/11/30 21:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\TeamViewer
[2012/11/11 01:46:17 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Toolbar4
[2012/05/01 01:14:50 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Windows Desktop Search
[2012/10/18 22:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\Application Data\Windows Search
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/04/08 15:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp
[2012/04/08 15:01:46 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp\1
[2012/04/27 11:01:03 | 000,000,000 | —D | M] – C:\Documents and Settings\YOUNG ONE\..\JAMES YOUNG\Local Settings\Temp\smtmp\2
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/04 05:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\i386\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/12 08:57:20 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINXP\$NtServicePackUninstall$\explorer.exe
< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2012/04/08 17:52:48 | 000,090,326 | —- | M] () MD5=A1B929C5451DA91CBE6C337C73E65EB2 – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
< MD5 for: EXPLORER.EXE-17D69B44.PF >
[2012/11/30 18:29:50 | 000,052,138 | —- | M] () MD5=7D75FA0502D072092F0BE1518785FAA0 – C:\WINXP\Prefetch\EXPLORER.EXE-17D69B44.pf
< MD5 for: EXPLORER.SC_ >
[2004/08/04 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/04 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
[2004/08/12 08:57:20 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINXP\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINXP\Help\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
[2004/08/12 08:58:01 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINXP\ie8\iexplore.chm
< MD5 for: IEXPLORE.CHW >
[2012/05/29 01:44:29 | 000,153,185 | —- | M] () MD5=3680C8BC82A0E88026ECFE100DB2C78A – C:\WINXP\Help\iexplore.chw
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 05:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2008/04/13 19:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINXP\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINXP\ServicePackFiles\i386\iexplore.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINXP\system32\dllcache\iexplore.exe
[2004/08/04 05:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie8\iexplore.exe
[2004/08/12 08:58:01 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINXP\$NtServicePackUninstall$\iexplore.exe
< MD5 for: IEXPLORE.EXE.HDMP >
[2011/07/06 03:56:59 | 005,578,495 | —- | M] () MD5=04E4011AC97D9BBD00916842DA673BC7 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERed39.dir00\iexplore.exe.hdmp
[2012/01/19 22:51:36 | 004,409,131 | —- | M] () MD5=43077588CC285663DA30458A8688D205 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER8f20.dir00\iexplore.exe.hdmp
[2011/12/17 16:27:00 | 007,398,843 | —- | M] () MD5=935306B67B7AFBB4260245E7EF21F79E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER0de0.dir00\iexplore.exe.hdmp
[2012/04/08 15:35:51 | 006,897,432 | —- | M] () MD5=9F1FA801F4FCCF7207524DF3A92AAA9C – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER722e.dir00\iexplore.exe.hdmp
[2012/11/20 16:50:12 | 019,163,917 | —- | M] () MD5=AA4D4D7F5C1337E315878FE35E45829F – C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\WER912c.dir00\iexplore.exe.hdmp
[2012/02/16 07:05:08 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER2bf7.dir00\iexplore.exe.hdmp
[2011/10/16 07:04:36 | 014,412,897 | —- | M] () MD5=E685A77790767C8AB83646325F8104B2 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER7c69.dir00\iexplore.exe.hdmp
[2011/12/19 16:26:21 | 006,963,994 | —- | M] () MD5=FA810B9078808FAAC2F20140F6BFE932 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERfa3c.dir00\iexplore.exe.hdmp
< MD5 for: IEXPLORE.EXE.MDMP >
[2011/07/06 03:56:56 | 000,068,413 | —- | M] () MD5=1E571B6C12DA737D6CBA8209699DCA1C – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERed39.dir00\iexplore.exe.mdmp
[2011/10/09 05:25:21 | 000,083,359 | —- | M] () MD5=5479E40655C9EE59C363B7F1B3A41CCC – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER206a.dir00\iexplore.exe.mdmp
[2012/04/08 15:35:42 | 000,073,927 | —- | M] () MD5=571ED32BF2B1449FF5C93FBCC4864E6E – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER722e.dir00\iexplore.exe.mdmp
[2011/10/08 02:28:00 | 000,075,235 | —- | M] () MD5=66AD3D424DAF2ECB0B0072EA39C897AB – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERa8bb.dir00\iexplore.exe.mdmp
[2012/11/20 16:50:09 | 000,078,557 | —- | M] () MD5=68229361750175A92E913DCB5C10859F – C:\Documents and Settings\YOUNG ONE\Local Settings\Temp\WER912c.dir00\iexplore.exe.mdmp
[2011/10/16 07:04:33 | 000,115,299 | —- | M] () MD5=A02490CA1BD807F4798892008E7545E4 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER7c69.dir00\iexplore.exe.mdmp
[2011/12/17 16:26:57 | 000,072,225 | —- | M] () MD5=AFBBCF6A0A0B26CC462608AA5BA74214 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER0de0.dir00\iexplore.exe.mdmp
[2012/02/16 07:05:07 | 000,092,662 | —- | M] () MD5=D37DF78C2E5EB8121AE6C3D11F260586 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER2bf7.dir00\iexplore.exe.mdmp
[2012/01/19 22:51:33 | 000,063,229 | —- | M] () MD5=F41EB20F4B795CB9657D564E4AAE1ED9 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WER8f20.dir00\iexplore.exe.mdmp
[2011/12/19 16:26:17 | 000,071,668 | —- | M] () MD5=FA7542F81DFF6FAEA4105F3B8450814D – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\WERfa3c.dir00\iexplore.exe.mdmp
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2012/04/08 18:01:55 | 000,088,036 | —- | M] () MD5=146BAD1D7DEA1BAC9C50EE0D71427AD6 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
[2012/11/30 22:27:01 | 000,068,666 | —- | M] () MD5=F7D0A71D4B6B086555E8B5142D64DEF6 – C:\WINXP\Prefetch\IEXPLORE.EXE-2D97EBE6.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
[2004/08/12 08:58:01 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINXP\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[2004/08/12 09:05:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINXP\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/01/03 08:10:44 | 000,585,874 | —- | M] () MD5=0E19E0BEA7B159153258688CF8ED7716 – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2009/02/06 06:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/13 19:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINXP\$NtUninstallKB956572$\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINXP\ServicePackFiles\i386\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\i386\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 12:14:03 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=37561F8D4160D62DA86D24AE41FAE8DE – C:\WINXP\$NtServicePackUninstall$\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 05:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINXP\$hf_mig$\KB956572\SP2QFE\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINXP\system32\services.exe
[2004/08/12 09:05:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINXP\$NtUninstallKB956572_0$\services.exe
< MD5 for: SERVICES.LNK >
[2012/07/14 02:57:12 | 000,001,590 | —- | M] () MD5=1DC649CD3A981792970A2A7929CFF0D2 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
[2012/07/14 02:57:47 | 000,001,590 | —- | M] () MD5=2522AAD5468A85CCEBD8C6386910BA71 – C:\Documents and Settings\All Users.WINXP\Start Menu\Programs\Administrative Tools\Services.lnk
[2012/07/14 02:58:35 | 000,001,608 | —- | M] () MD5=FFAE08D234081A15D87D50816B427810 – C:\Documents and Settings\JAMES YOUNG\Local Settings\Temp\smtmp\1\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
[2004/08/12 09:05:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINXP\system32\services.msc
< MD5 for: SERVICES.RDB >
[2012/06/04 07:32:06 | 000,008,060 | —- | M] () MD5=365F626303EBC6DB5DCA7BBC4FAE0564 – C:\Program Files\OfficeNow 3.5\URE\misc\services.rdb
[2011/12/23 18:19:16 | 000,237,568 | —- | M] () MD5=507957679AE4579C15D57FA741EA6FFA – C:\Program Files\Office Suite X 3\URE\misc\services.rdb
[2011/12/23 18:18:40 | 005,314,560 | —- | M] () MD5=B31F4ECB1247A650528A040A2D791105 – C:\Program Files\Office Suite X 3\Basis\program\services.rdb
[2012/06/04 22:31:04 | 000,180,201 | —- | M] () MD5=FB73C2F46884319721B2BBA533490429 – C:\Program Files\OfficeNow 3.5\program\services\services.rdb
< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/12 09:09:30 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINXP\$NtServicePackUninstall$\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\ServicePackFiles\i386\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2012/04/12 12:16:13 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2012/04/12 12:16:13 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2012/08/05 00:12:32 | 000,000,050 | —- | M] () – C:\AUTOEXEC.BAT
[2012/09/20 14:04:37 | 000,000,316 | -HS- | M] () – C:\boot.ini
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/06/20 20:55:34 | 000,008,290 | R— | M] () – C:\dell.sdr
[2011/07/21 01:45:48 | 000,001,471 | —- | M] () – C:\GingerSetup.log
[2007/03/30 00:07:43 | 1063,161,856 | -HS- | M] () – C:\hiberfil.sys
[2011/06/21 21:17:07 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2012/05/08 22:17:24 | 000,030,546 | —- | M] () – C:\install.log
[2012/11/30 21:53:25 | 000,000,000 | —- | M] () – C:\install.rdf
[2012/11/28 17:04:54 | 000,000,112 | —- | M] () – C:\INSTALLHELPER.LOG
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\IO.SYS
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2011/06/20 20:55:42 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/07/04 03:46:04 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/11/30 22:21:26 | 1594,662,912 | -HS- | M] () – C:\pagefile.sys
[2012/09/20 14:16:31 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2011/07/29 02:07:46 | 000,000,186 | —- | M] () – C:\picsetup.log
[2012/04/10 16:11:50 | 000,000,320 | -H– | M] () – C:\T4Metrics.log
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINXP\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINXP\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINXP\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINXP\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2006/02/19 02:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINXP\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2012/04/09 01:46:11 | 000,000,067 | -HS- | M] () – C:\WINXP\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 13:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2007/03/29 19:31:36 | 000,094,208 | —- | M] () – C:\WINXP\System32\config\default.sav
[2007/03/29 19:31:36 | 000,634,880 | —- | M] () – C:\WINXP\System32\config\software.sav
[2007/03/29 19:31:36 | 000,901,120 | —- | M] () – C:\WINXP\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012/04/12 09:31:03 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users.WINXP\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/04/12 10:17:14 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2012/04/09 01:56:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\YOUNG ONE\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2012/04/16 02:23:10 | 001,552,605 | —- | M] (Ion Audio LLC ) – C:\Documents and Settings\YOUNG ONE\Desktop\EZVinylTapeConverterSetup_v10.exe
[2012/04/11 02:00:45 | 004,258,424 | —- | M] (McAfee, Inc.) – C:\Documents and Settings\YOUNG ONE\Desktop\McAfeeSetup.exe
[2012/11/30 22:28:12 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\YOUNG ONE\Desktop\OTL.exe
[2012/11/30 22:18:16 | 003,902,728 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\YOUNG ONE\Desktop\TeamViewer_Setup_en.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-11-14 08:06:46
========== Alternate Data Streams ==========
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINXP\Application Data\TEMP:79DD4F33
< End of report >
——————
OTL Extras logfile created on: 11/30/2012 11:16:43 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\YOUNG ONE\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1013.86 Mb Total Physical Memory | 481.32 Mb Available Physical Memory | 47.47% Memory free
2.38 Gb Paging File | 1.64 Gb Available in Paging File | 68.83% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 145.00 Gb Total Space | 81.00 Gb Free Space | 55.86% Space Free | Partition Type: NTFS
Computer Name: JAMES-91746AC0C | User Name: YOUNG ONE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL Inc.)
"C:\Program Files\Common Files\aol\ACS\AOLDial.exe" = C:\Program Files\Common Files\aol\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\aol\ACS\AOLacsd.exe" = C:\Program Files\Common Files\aol\ACS\AOLacsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\America Online 9.0b\waol.exe" = C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon
"C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\aol\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed
"C:\Program Files\Common Files\aol\1334092339\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\aol\1334092339\EE\AOLServiceHost.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\aol\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\aol\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\aol\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\aol\1334093993\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1334093993\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
"C:\Program Files\Common Files\aol\1334093993\ee\AOLDesktop.exe" = C:\Program Files\Common Files\aol\1334093993\ee\AOLDesktop.exe:*:Enabled:AOL Desktop
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service – (Apple Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe – (Hewlett-Packard Development Company, L.P.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"E:\skype\Skype.exe" = E:\skype\Skype.exe:*:Enabled:Skype
"C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1336533290\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\waol.exe" = C:\Program Files\AOL Desktop 9.7\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi – (Pinnacle Systems)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{12365698-8042-4774-8CAF-35BE91DC657B}" = Creative Vado HD Codec
"{1362E602-9625-42D3-B57F-CDA9D26F9DA8}" = Pinnacle Studio 15
"{13F054F3-0B07-4D15-9E80-C55B496AB557}" = Garmin Communicator Plugin
"{14ECAABB-C8B9-4A09-92F7-CDF1A45B6DDE}" = Google Drive
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F56A6C9-81CA-4B5F-B471-8CCB13CF85DA}" = Office Suite X 3.3
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{251C65C0-15FF-4603-98BB-E4A61C7DA424}" = CarMD
"{273130E8-117C-4237-A0FA-83EBBF11E051}" = Driver Restore
"{29D88826-2AB9-11D5-8854-00902761A46D}" = WordPerfect Office 2002
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D3CD3E-7715-4341-8441-A3A6409FCDE4}" = BIAS SoundSoap 2.0
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{524AC636-ADC4-4E42-B149-D0B6B5F4D24A}" = Garmin BaseCamp
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{555B2506-E17C-4EEF-AA70-03985F664BAD}" = Creative Vado Central muvee Plugin
"{5802F606-7F09-4CCE-800C-7B53B0906662}" = Mail List
"{5A9AA2C0-972F-4239-AA41-E409434194D5}" = MobileMe Control Panel
"{5FDA577D-2C25-405F-B759-235CA8016D19}" = Newsletters
"{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}" = Acrobat.com
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Driver
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9A61BE73-18A3-4AC2-AFF1-E4B8D92158BD}" = OfficeNow 3.5
"{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3217415-0BD4-4252-BF9F-3AF4A267B04C}" = DataMask by AOL
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AA104808-94FA-4C82-ABFE-F630E44192E2}" = Resumes
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABA5E381-EC46-425C-86C5-5CD15BBFB4BF}" = Garmin USB Drivers
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BA38CDB0-B61C-4490-9A9C-92241C05FA33}" = SentryBay Update Helper
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BC85D7C6-028A-4012-8E3C-B4D11D74E34B}" = DriverUpdate
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DED01768-E634-11E1-AEB0-984BE15F174E}" = Evernote v. 4.5.8
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E488C022-045B-11D5-97A7-00C04F6BFB42}" = LabelMaker
"{E75AE16E-43CF-446D-AD44-999550BFD78E}" = Stationery
"{EC27311B-0012-11D5-8341-0001023FF70B}" = CD Organizer
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{FA4C2D53-205F-4245-9717-F3761154824D}" = Safari
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FC030CB5-46A6-4229-AD6E-0AC869F509C8}" = Pinnacle Studio Bonus Content
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AOL Deskbar" = AOL Deskbar
"AOL Toolbar" = AOL Toolbar
"AOL Toolbar for Firefox" = AOL Toolbar for Firefox
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"Audacity_is1" = Audacity 1.2.4
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Creative Vado HD Codec" = Creative Vado HD Codec
"EZ Vinyl Converter by MixMeister_is1" = EZ Vinyl Converter by MixMeister 1.0.5
"EZ Vinyl/Tape Converter by Ion Audio_is1" = EZ Vinyl/Tape Converter 10 by Ion Audio
"Google Chrome" = Google Chrome
"Google Chrome Frame" = Google Chrome Frame
"GoToAssist" = GoToAssist Corporate
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 17.0 (x86 en-US)" = Mozilla Firefox 17.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Norton PC Checkup_is1" = Norton PC Checkup
"OfficeNow_and_Options" = OfficeNow and Options
"Price Check by AOL" = Price Check by AOL
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer Basic
"SoftwareUpdUtility" = Download Updater (AOL Inc.)
"Staples Easy Button" = Staples Easy Button (remove only)
"stax-Pinnacle_is1" = SureThing Express Labeler
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AOL Toolbar" = AOL Toolbar
"Smilebox" = Smilebox
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 11/29/2012 12:52:33 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 11/29/2012 12:53:29 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 11/29/2012 12:55:23 AM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb.
Error - 11/29/2012 4:36:31 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19328, fault address 0x000da6ff.
Error - 11/29/2012 4:36:31 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.19328, fault address 0x000da6ff.
Error - 11/30/2012 2:00:39 AM | Computer Name = JAMES-91746AC0C | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 2116 (0x844) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\SUPERAntiSpyware\sasdifsv.sys
by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 4(0)(0) 4(0)(0)
7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)
Error - 11/30/2012 1:35:46 PM | Computer Name = JAMES-91746AC0C | Source = Application Hang | ID = 1002
Description = Hanging application PCPerformer.exe, version 11.10.1.2217, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 11/30/2012 1:37:26 PM | Computer Name = JAMES-91746AC0C | Source = Application Hang | ID = 1001
Description = Fault bucket -1400214861.
Error - 11/30/2012 10:19:12 PM | Computer Name = JAMES-91746AC0C | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module , version 13.2.0.5, fault address 0x000ea1b9.
Error - 11/30/2012 11:02:04 PM | Computer Name = JAMES-91746AC0C | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3068 (0xbfc) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\McAfee.com\Agent\mcagent.exe
by C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 4(0)(0) 4(0)(0)
7200(0)(0) 7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)
[ System Events ]
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:24:40 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:03 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:03 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:18 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:25:18 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
Error - 12/1/2012 12:34:28 AM | Computer Name = JAMES-91746AC0C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service mcmscsvc with
arguments "" in order to run the server: {DDC6C82A-BCD6-480F-BAE7-9F406F687A53}
< End of report >