This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus redirecting me TO Google [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'd really appreciate any help you all can give me on this.

Not sure how long I've had this virus, the only symptoms I can see is that whenever I try to update Malwarebytes (which I've had for years - I also have F-Secure running at all times), or access any page on microsoft.com (and a few other random sites dealing with virus detection/cure) it sends me to the URL with the domain portion switched to google.com, resulting in a 404 error page. This happens on Firefox, MSIE AND Chrome. I ran both the FULL F-Secure and Malwarebytes scans and each found a couple viruses and fixed them, but neither seemed to have fixed this. Also have had trouble with my WD Passport Backup drive (Drive J:) getting errors and having to stop, for a couple of months now, but don't think it is related to this. In fact it was while trying to download new software to fix that, that I first noticed I could not get to microsoft.

I read another similar thread on this forum where the advisor requested running Gooredfix, so here is the result from that first (followed by the OTL results):

GooredFix by jpshortstuff (03.07.10.1)
Log created at 12:29 on 24/12/2012 (Owner)
Firefox version 16.0.2 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{3112ca9c-de6d-4884-a869-9855de68056c} [14:40 05/12/2012]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [14:40 05/12/2012]

C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [00:11 03/12/2012]
{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [03:06 15/12/2011]
{99079a25-328f-4bd4-be04-00955acaa0a7}(2) [11:20 16/12/2011]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"[removed]"="C:\Program Files\CenturyLink Online Security\NRS\[removed]" [22:51 16/04/2011]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [22:57 15/11/2010]
"{0153E448-190B-4987-BDE1-F256CADA672F}"="C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext" [22:57 15/11/2010]

-=E.O.F=-






============================================================

I also ran OLT as requested by the new submission page (it took over 2 hours!) Here are the results from that:

==============================================================



OTL Extras logfile created on: 12/24/2012 12:49:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 43.70% Memory free
3.72 Gb Paging File | 2.98 Gb Available in Paging File | 80.14% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 0.81 Gb Free Space | 0.91% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.26 Gb Free Space | 99.72% Space Free | Partition Type: NTFS

Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00626135-E60A-4550-9503-4F50C6C9B8BB}" = Google AdWords Editor
"{03EDED24-8375-407D-A721-4643D9768BE1}" = kgchlwn
"{0673654C-5296-453B-9798-B61CD7E03FEB}" = SES Driver
"{069730C2-755A-485B-A205-27A1AAFA836A}" = InstantShareAlert
"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC
"{07D4701F-50D6-4C69-A785-DC556E60663F}" = Eudora
"{08F7CCA6-8590-4401-8B44-CEB09A909AAB}" = del.icio.us Buttons for Internet Explorer
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{11F3F858-4131-4FFA-A560-3FE282933B6E}" = kgchday
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2522EE78-994E-45C8-9CE5-CE6CB2E0297F}" = Map of North and Central America
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{2FD94FBC-07AE-475C-B522-BFE899B9048E}" = Garmin WebUpdater
"{3004FB81-7B9E-4808-BD13-BC5A530BA60B}" = cp_PrintOnCDConfig
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{31492759-0E89-46B5-9770-F6E5808E3017}" = xImage
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{40631ADD-7633-F1F1-32D2-D1FB6374BAFB}" = Market Samurai
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{4FC9DA9D-F608-454E-8191-D7EFFDCC5726}" = SpyHunter
"{523BD5B6-E904-493C-B902-1BC9B7D44DF4}" = Lexmark Photo Center
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53AF3638-DDB4-4755-B3DC-259981689DB7}" = MioNet
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68131B0A-D78D-4aed-B74E-33A6C7324E50}" = WD Anywhere Backup
"{693C08A7-9E76-43FF-B11E-9A58175474C4}" = kgckids
"{6EEE2F18-AF5C-4E49-9C5B-F6ACC39B2F0E}" = FTP Explorer
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{79ED0EE7-098C-465F-A853-B17F6FC6CDD8}" = GPS TrackMaker
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{80A2A967-C1B7-412D-B2B2-C4A33209C205}" = Garmin POI Loader
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{84F1DE76-C48C-4281-87A0-CC9548D1E7F9}" = Rhapsody Player Engine
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8A8664E1-84C8-4936-891C-BC1F07797549}" = kgcvday
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98D451C4-4ACA-4273-BB47-57CFE46B048E}" = WD SmartWare
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BD54685-1496-46A5-AB62-357CD140ED8B}" = kgcinvt
"{A1588373-1D86-4D44-86C9-78ABD190F9CC}" = kgcmove
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B27901FA-F157-4049-B1EC-BC43890A1DCC}" = Active@ File Recovery
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BB7C0C8E-CF0B-44C5-B838-9ED93D15DBDF}" = Map of South America
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C012BF9F-79EA-4601-9778-BFE9B3CE83A1}" = hpg3010QFolder
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB71FF8-DE82-469C-8641-44378F4443EB}" = Garmin WebUpdater
"{CCD04643-5246-48AC-9D8C-F43A37BB8F36}" = WD Drive Manager (x86)
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{E18B549C-5D15-45DA-8D8F-8FD2BD946344}" = kgcbaby
"{E2C5C0D1-B4F7-4C1C-9AEF-C80E17677052}" = hpg3010
"{E2E7A0E8-77C4-495F-8FA3-63DAEDAA2DB3}" = F-Secure PSC Prerequisites
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}" = kgcbase
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F64D55C1-734C-4249-886E-4C41A9889A36}" = HP Scanjet G3010 7.0
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Acoustica MP3 Audio Mixer" = Acoustica MP3 Audio Mixer
"Actual Search & Replace_is1" = Actual Search & Replace Version 2.8.2
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Alexa Toolbar" = Alexa Toolbar
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"ASTRA32_is1" = ASTRA32 - Advanced System Information Tool 1.52
"Capitalism Plus" = Capitalism Plus
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"CoffeeCup HTML Editor 2008" = CoffeeCup HTML Editor 2008
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"EasyGPS_is1" = EasyGPS
"ExpressBurn" = Express Burn
"ExpressRip" = Express Rip
"ExtraPuTTY 0.24" = ExtraPuTTY 0.24
"Free RAR Extract Frog 1.00" = Free RAR Extract Frog 1.00
"F-Secure Product 444" = CenturyLink™ Online Security
"FTP Explorer" = FTP Explorer
"getPlus®_ocx" = getPlus®_ocx
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"HTML Search and Replace_is1" = HTML Search and Replace 1.0
"IconForge version 6.28_is1" = IconForge version 6.28
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{523BD5B6-E904-493C-B902-1BC9B7D44DF4}" = Lexmark Photo Center
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"Lexmark S300-S400 Series" = Lexmark S300-S400 Series
"Lexmark Z700-P700 Series" = Lexmark Z700-P700 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1" = Market Samurai
"MasterClipsDeinstKey" = MasterClips Browser v2.03
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"Motherboard Monitor 5_is1" = Motherboard Monitor 5
"Mozilla Firefox 16.0.2 (x86 en-US)" = Mozilla Firefox 16.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa2" = Picasa 2
"PlayBox" = PlayBox Toolbar
"Port Magic" = Pure Networks Port Magic
"RealPlayer 15.0" = RealPlayer
"Samsung CLP-320 Series" = Maintenance Samsung CLP-320 Series
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"Ulead PhotoImpact 5.0" = Ulead PhotoImpact 5
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xenu's Link Sleuth" = Xenu's Link Sleuth

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 12/23/2012 2:33:57 AM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2012-12-22 22:33:57-07:00 MIKE MIKE\Owner F-Secure Anti-Virus

No scanner engines loaded and enabled. Virus protection is disabled.

Error - 12/23/2012 6:13:34 AM | Computer Name = MIKE | Source = Application Error | ID = 1000
Description = Faulting application wddmstatus.exe, version 3.1.0.11, faulting module
upnp.dll, version 5.1.2600.2180, fault address 0x0000e896.

Error - 12/23/2012 7:47:58 AM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 1 2012-12-23 03:47:54-07:00 MIKE MIKE\Owner F-Secure Anti-Virus

Malicious code found in file C:\WINDOWS\Temp\USS1052.tmp. Infection: Gen:Variant.Barys.536


Error - 12/23/2012 12:03:21 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2012-12-23 08:03:21-07:00 MIKE MIKE\Owner F-Secure Anti-Virus

No scanner engines loaded and enabled. Virus protection is disabled.

Error - 12/23/2012 12:18:55 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 3 2012-12-23 08:18:55-07:00 MIKE MIKE\Owner F-Secure Anti-Virus

Malicious code found in file C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1102\A0309754.sys.
Infection: Gen:Variant.Barys.536 Action: The file was quarantined.

Error - 12/23/2012 6:26:32 PM | Computer Name = MIKE | Source = F-Secure Anti-Virus | ID = 103
Description = 4 2012-12-23 14:26:32-07:00 MIKE MIKE\Owner F-Secure Anti-Virus

Manual scanning was finished - workstation was found infected!

Error - 12/23/2012 8:33:18 PM | Computer Name = MIKE | Source = .NET Runtime 2.0 Error Reporting | ID = 1000
Description = Faulting application wdsmartware.exe, version 1.4.1.1, stamp 4c87cbb7,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug? 0,
fault address 0x00012a5b.

Error - 12/23/2012 10:35:44 PM | Computer Name = MIKE | Source = MsiInstaller | ID = 10005
Description = Product: WD Software Upgrader – This application requires Microsoft
.NET Framework 4.0 client profile. Install the .NET Framework then run this installer
again.

Error - 12/24/2012 12:55:26 AM | Computer Name = MIKE | Source = Application Error | ID = 1000
Description = Faulting application mbam.exe, version 1.62.0.140, faulting module
version.dll, version 5.1.2600.2180, fault address 0x00001deb.

Error - 12/24/2012 3:59:14 PM | Computer Name = MIKE | Source = .NET Runtime 2.0 Error Reporting | ID = 5000
Description = EventType clr20r3, P1 memeobackup.exe, P2 2.0.0.0, P3 491494cf, P4
mscorlib, P5 2.0.0.0, P6 471ebc5b, P7 3404, P8 15a, P9 system.unauthorizedaccess,
P10 NIL.

[ System Events ]
Error - 12/24/2012 5:52:51 AM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =

Error - 12/24/2012 5:54:33 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.

Error - 12/24/2012 5:54:33 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7000
Description = The HTTP SSL service failed to start due to the following error: %%1053

Error - 12/24/2012 5:54:34 AM | Computer Name = MIKE | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460

Error - 12/24/2012 6:22:16 AM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =

Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Image Acquisition
(WIA) service to connect.

Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7000
Description = The Windows Image Acquisition (WIA) service failed to start due to
the following error: %%1053

Error - 12/24/2012 4:07:42 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
gagp30kx
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp

Error - 12/24/2012 4:10:55 PM | Computer Name = MIKE | Source = F-Secure Gatekeeper | ID = 327681
Description =

Error - 12/24/2012 4:12:23 PM | Computer Name = MIKE | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460


< End of report >

================================================================================
=


OTL logfile created on: 12/24/2012 12:49:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 43.70% Memory free
3.72 Gb Paging File | 2.98 Gb Available in Paging File | 80.14% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 0.81 Gb Free Space | 0.91% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.26 Gb Free Space | 99.72% Space Free | Partition Type: NTFS

Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeaserv.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\lxeacoms.exe ( )
PRC - C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackup.exe (Memeo Inc.)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\VTTrayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\sst3cl3.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\hashlib_x86.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fm4av.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\System.Data.SQLite.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epoemdll.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epstring.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizres.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizard.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\customui.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epfunct.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\eputil.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\imagutil.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeascw.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeamicro.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Spam Control\fsas.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSPC\fspcfsm.eng ()
MOD - \\?\c:\program files\centurylink online security\hips\fsumi.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\strres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\gres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\flyerres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\fsavures.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\about.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\aboutres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsavhres.eng ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeadatr.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeaptp.dll ()
MOD - C:\WINDOWS\system32\lxeasmr.dll ()
MOD - C:\WINDOWS\system32\lxeasm.dll ()
MOD - C:\Program Files\WD\WD Anywhere Backup\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\923bd55258380eae77353d36a5a1b08f\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\67cfb70213562afe2ca9b9066764af3a\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\29c7192327cf3999961560bf3a3995c6\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3d8c79c45aa674e43f075e2e66b8caf5\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e83aac37b2623f1a24c70979f31dd56\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL ()
MOD - C:\WINDOWS\system32\CISPMON.DLL ()


========== Services (SafeList) ==========

SRV - (napagent) – %SystemRoot%\System32\qagentrt.dll File not found
SRV - (hkmsvc) – %SystemRoot%\System32\kmsvc.dll File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (EapHost) – %SystemRoot%\System32\eapsvc.dll File not found
SRV - (Dot3svc) – %SystemRoot%\System32\dot3svc.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (FSORSPClient) – C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (lxeaCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (lxea_device) – C:\WINDOWS\system32\lxeacoms.exe ( )
SRV - (FSMA) – C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) – C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (MemeoBackgroundService) – C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
SRV - (MioNet) – C:\Program Files\MioNet\MioNetManager.exe ()
SRV - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (F-Secure Gatekeeper) – C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\fsgk.sys ()
DRV - (fsbts) – C:\WINDOWS\system32\drivers\fsbts.sys ()
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (F-Secure HIPS) – C:\Program Files\CenturyLink Online Security\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (FSFW) – C:\WINDOWS\system32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (F-Secure Filter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsfilter.sys ()
DRV - (F-Secure Recognizer) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsrec.sys ()
DRV - (NDISRD) – C:\WINDOWS\System32\drivers\ndisrd.sys (NT Kernel Resources)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ASTRA32) – C:\Program Files\ASTRA32\astra32.sys (Licensed for Sysinfo Lab)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mbmiodrvr) – C:\WINDOWS\system32\mbmiodrvr.sys ([removed])
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {39170861-6644-4F57-95E4-17683AFA09F4}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{39170861-6644-4F57-95E4-17683AFA09F4}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGIT_en
IE - HKCU\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Twitter"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4
FF - prefs.js..extensions.enabledAddons: %7B8f8fe09b-0bd3-4470-bc1b-8cad42b8203a%7D:0.17
FF - prefs.js..extensions.enabledAddons: %7B0153E448-190B-4987-BDE1-F256CADA672F%7D:15.0.6
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=119&systemid;=406&sr;=0&q;="
FF - prefs.js..network.proxy.type: 4


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\3.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=1.0: C:\Program Files\Virtual Earth 3D\ [2007/05/17 16:50:24 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CenturyLink Online Security\NRS\[removed] [2011/05/30 16:21:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/05 06:41:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/05 06:40:57 | 000,000,000 | —D | M]

[2011/12/16 03:20:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/10/03 22:39:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/12/19 03:12:42 | 000,000,000 | —D | M] (Live HTTP Headers) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2011/12/19 03:12:02 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}(2)
[2012/11/20 12:25:46 | 000,243,496 | —- | M] () (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\searchplugins\Search_Results.xml
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012/10/11 14:15:02 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/12/05 06:41:44 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 13:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 13:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/10/11 14:13:20 | 000,129,176 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/09/21 00:45:46 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012/10/13 05:23:37 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a;…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.searchqu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Alexa Traffic Rank = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel\1.1.0_0\
CHR - Extension: KOCAttack - Extra Features! = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbbngjfcccafhimngmokmoejfdcjepgc\0.9.1_1\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\

O1 HOSTS File: ([2012/03/13 19:42:32 | 000,244,641 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8540 more lines…
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O2 - BHO: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O2 - BHO: (del.icio.us Toolbar Helper) - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKLM\..\Toolbar: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKLM\..\Toolbar: (Alexa Toolbar) - {EA582743-9076-4178-9AA6-7393FDF4D5CE} - C:\Program Files\Alexa Toolbar\AlexaToolbar.10.0.dll (Alexa.com)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKCU\..\Toolbar\WebBrowser: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\CenturyLink Online Security\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [WD Anywhere Backup] C:\Program Files\WD\WD Anywhere Backup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKCU..\Run: [Siufsyut] C:\Documents and Settings\Owner\Application Data\Yzly\cygia.exe (Корпорация Майкрософт)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: samsungsetup.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase9563.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1165369289625 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75A8BD71-DED9-4086-856F-C1CA51592ECB}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\toolbarchrome {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AutorunsDisabled: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 10:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0139f1c3-0909-11da-ad6b-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{45a99c35-0aaa-11da-92d3-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{977d7f84-a735-11df-89b4-00038a000015}\Shell\AutoRun\command - "" = K:\setup.exe
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ca330a43-33a6-11da-b73f-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\{d8a3e2f8-2abb-11e2-8a4e-00038a000015}\Shell\AutoRun\command - "" = K:\WDSetup.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: napagent - %SystemRoot%\System32\qagentrt.dll File not found
NetSvcs: hkmsvc - %SystemRoot%\System32\kmsvc.dll File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/24 12:42:16 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GooredFix Backups
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Yzly
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Akvea
[2012/12/05 06:40:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2008/04/09 17:23:24 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/12/24 13:28:03 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:09:15 | 000,000,412 | —- | M] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/24 12:05:03 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/24 12:04:41 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/24 12:04:21 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/12/24 12:04:14 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/24 11:47:01 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2012/12/24 03:29:10 | 000,004,442 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2012/12/24 01:50:54 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/12/24 01:19:09 | 000,000,402 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/24 00:02:28 | 000,000,508 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2012/12/23 22:17:02 | 000,000,406 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/23 16:46:27 | 000,000,600 | —- | M] () – C:\Documents and Settings\Owner\PUTTY.RND
[2012/12/23 16:12:33 | 000,002,243 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FTP Explorer.lnk
[2012/12/23 15:26:43 | 000,023,972 | —- | M] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2012/12/22 03:09:29 | 000,000,030 | —- | M] () – C:\WINDOWS\Iedit.INI
[2012/12/21 15:28:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/12/20 15:19:03 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/20 01:32:18 | 000,002,752 | —- | M] () – C:\WINDOWS\MAML.INI
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2012/12/13 12:43:48 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/12/13 03:08:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/11 15:30:07 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/12/11 15:30:06 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/12/10 03:39:00 | 000,000,330 | —- | M] () – C:\WINDOWS\tasks\jucheck.job
[2012/12/03 19:10:31 | 000,003,325 | —- | M] () – C:\Documents and Settings\All Users\Documents\shows-copyscape.htm
[2012/12/03 16:26:38 | 000,003,075 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:41:58 | 000,072,797 | —- | M] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/12/01 16:30:56 | 000,001,579 | —- | M] () – C:\Documents and Settings\Owner\My Documents\coupon-form.rtf
[2012/11/28 18:26:55 | 000,000,879 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/18 01:10:01 | 000,000,412 | —- | C] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/18 01:09:54 | 000,000,406 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/18 01:09:51 | 000,000,402 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/09 00:00:53 | 000,452,508 | —- | C] () – C:\error.fstmp
[2012/12/09 00:00:53 | 000,000,000 | —- | C] () – C:\infect.fstmp
[2012/12/03 16:26:38 | 000,003,075 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:44:44 | 000,072,797 | —- | C] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/11/28 18:26:55 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[2012/11/28 18:26:46 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Copy of WordPad.lnk
[2012/07/25 15:12:16 | 000,109,312 | —- | C] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.BAT
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.~BA
[2012/04/09 22:49:40 | 000,060,228 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2012/03/29 00:58:50 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/01/14 15:38:12 | 000,008,703 | —- | C] () – C:\Documents and Settings\All Users\Application Data\7aa1ff29
[2012/01/14 15:38:12 | 000,008,693 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\9c228de1
[2012/01/14 15:38:12 | 000,008,629 | —- | C] () – C:\Documents and Settings\Owner\Application Data\f739919
[2011/09/29 11:45:08 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\sst3cl3.dll
[2011/08/20 13:42:15 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\lxeasm.dll
[2011/08/20 13:42:15 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\lxeasmr.dll
[2011/08/20 13:42:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxeavs.dll
[2011/08/20 13:42:11 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoin.dll
[2011/08/20 13:42:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\lxeagcfg.dll
[2011/08/20 13:42:00 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxeacui.dll
[2011/08/20 13:42:00 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\lxeacuir.dll
[2011/08/20 13:38:30 | 000,847,872 | —- | C] ( ) – C:\WINDOWS\System32\lxeausb1.dll
[2011/08/20 13:38:30 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxeainpa.dll
[2011/08/20 13:38:30 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\LXEAhcp.dll
[2011/08/20 13:38:30 | 000,344,064 | —- | C] ( ) – C:\WINDOWS\System32\lxeaiesc.dll
[2011/08/20 13:38:30 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\LXEAinst.dll
[2011/08/20 13:38:29 | 001,048,576 | —- | C] ( ) – C:\WINDOWS\System32\lxeaserv.dll
[2011/08/20 13:38:29 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxeapmui.dll
[2011/08/20 13:38:28 | 000,577,536 | —- | C] ( ) – C:\WINDOWS\System32\lxealmpm.dll
[2011/08/20 13:38:28 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\lxeains.dll
[2011/08/20 13:38:28 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lxeainsb.dll
[2011/08/20 13:38:28 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lxeainsr.dll
[2011/08/20 13:38:28 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\lxeajswr.dll
[2011/08/20 13:38:27 | 000,688,128 | —- | C] ( ) – C:\WINDOWS\System32\lxeahbn3.dll
[2011/08/20 13:38:27 | 000,324,264 | —- | C] ( ) – C:\WINDOWS\System32\lxeaih.exe
[2011/08/20 13:38:27 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxeagrd.dll
[2011/08/20 13:38:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\lxeacu.dll
[2011/08/20 13:38:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\lxeacub.dll
[2011/08/20 13:38:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\lxeacur.dll
[2011/08/20 13:38:25 | 000,598,696 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoms.exe
[2011/08/20 13:38:24 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomm.dll
[2011/08/20 13:38:23 | 000,802,816 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomc.dll
[2011/08/20 13:38:23 | 000,373,416 | —- | C] ( ) – C:\WINDOWS\System32\lxeacfg.exe
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Compressor
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Command Line Utility
[2011/07/21 02:49:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2011/07/21 02:49:31 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Core Data Application
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 14:54:02 | 000,042,664 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 01:15:55 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/14 22:47:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Fqureh.dat
[2011/04/14 22:47:28 | 000,000,000 | —- | C] () – C:\WINDOWS\Tbovewipezupew.bin
[2009/10/19 14:15:11 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\PUTTY.RND
[2009/09/21 15:57:13 | 000,000,064 | —- | C] () – C:\Documents and Settings\Owner\setpath.bat
[2008/12/21 03:46:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Common
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Colors
[2008/12/16 17:52:18 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2008/12/16 17:52:18 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Configure Folder Actions
[2008/02/15 17:19:07 | 000,010,240 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/17 16:52:33 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/05/14 01:39:17 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/14 13:52:06 | 000,000,008 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.dat.bin
[2006/12/04 16:39:00 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\PUTTY.RND
[2006/12/04 16:38:00 | 000,356,352 | —- | C] () – C:\Program Files\putty.exe
[2006/12/03 17:04:02 | 000,023,972 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat

========== ZeroAccess Check ==========

[2004/01/01 15:49:53 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = shell32.dll – [2007/10/25 19:34:01 | 008,460,288 | —- | M] (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2006/09/03 22:12:56 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2004/08/04 11:00:00 | 000,472,064 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2004/08/04 11:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011/12/16 02:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/04/16 14:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2011/04/15 00:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fAk02400lLmCj02400
[2011/05/22 19:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2011/09/19 04:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lexmark S300-S400 Series
[2009/09/27 23:55:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2009/06/29 01:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2004/01/01 16:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/02/16 04:14:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/07/21 02:51:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/09/29 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2012/12/23 16:13:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/25 15:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/11/11 15:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2010/08/08 11:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/19 03:12:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B49A644A-1076-4A3D-B124-DAA7862F2318}
[2011/11/29 13:30:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Actual Search & Replace
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Akvea
[2008/06/26 09:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/10/23 14:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/28 01:29:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CursorArts
[2011/04/15 13:13:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Desktopicon
[2010/02/26 00:08:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/04/16 23:00:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F-Secure
[2012/12/24 02:04:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2010/01/31 23:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2009/12/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2012/04/09 18:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/08/23 02:11:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MioNet
[2009/06/29 01:05:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\muvee Technologies
[2010/02/16 05:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
[2011/07/21 02:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2010/01/24 16:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayBox
[2004/01/01 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2011/12/19 03:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchqutoolbar(2)
[2011/09/29 02:24:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Stellarium
[2006/12/03 17:04:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/05/25 15:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/09/30 16:17:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WD
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Yzly

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EX_ >
[2004/08/04 11:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\WINDOWS\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 16:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2007/06/13 03:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[1998/05/11 19:01:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=7ADA6F7250F04A62D84A09373F1BBAE9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\WINDOWS\EXPLORER.EXE
[1998/05/11 19:01:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=7ADA6F7250F04A62D84A09373F1BBAE9 – C:\tribble2-backup-c\WINDOWS\EXPLORER.EXE
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\explorer.exe
[2007/06/13 02:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\system32\dllcache\explorer.exe
[2004/08/04 11:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[1999/04/23 21:22:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=B22B28F61B1BB06723019307F0FAACFC – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\EXPLORER.EXE
[1999/04/23 22:22:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=B22B28F61B1BB06723019307F0FAACFC – C:\tribble2-backup-d\Office3\WINDOWS\EXPLORER.EXE

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/12/24 02:23:49 | 000,029,776 | —- | M] () MD5=F997F0D85F58421DA7CB8700FD005360 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SC_ >
[2004/08/04 11:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[1998/05/11 19:01:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\WINDOWS\EXPLORER.SCF
[1999/04/23 21:22:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\EXPLORER.SCF
[1998/05/11 19:01:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\tribble2-backup-c\WINDOWS\EXPLORER.SCF
[1999/04/23 22:22:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\tribble2-backup-d\Office3\WINDOWS\EXPLORER.SCF
[2004/08/04 11:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.001 >
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\mikes-backup\ofcc\WINDOWS\IEXPLORE.001
[1998/04/12 14:43:58 | 000,000,330 | —- | M] () MD5=F7D7C03A305089DBC032AC57068E7F6B – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\IEXPLORE.001

< MD5 for: IEXPLORE.ASF >
[1996/04/26 16:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLEC\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 16:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 17:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\tribble2-backup-d\TRIBBLEC\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF
[1996/04/26 17:12:18 | 000,094,247 | —- | M] () MD5=310E7D0C75DF0A85F2D6E787E4BB6B96 – C:\tribble2-backup-d\TRIBBLED\HMPRO3\STYLES\IEXPLORE.ASF

< MD5 for: IEXPLORE.CH_ >
[2004/08/04 11:00:00 | 000,199,077 | —- | M] () MD5=5F64795662F162CCD8B30969B6682029 – C:\WINDOWS\I386\IEXPLORE.CH_

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/04 11:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2010/11/04 14:30:34 | 000,153,185 | —- | M] () MD5=F879E396E373F6BD74411EEA8FBF9E75 – C:\WINDOWS\Help\iexplore.chw

< MD5 for: IEXPLORE.EX_ >
[2004/08/04 11:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\WINDOWS\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2007/04/24 06:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/04/22 00:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/04/21 23:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie8\iexplore.exe
[2007/12/06 03:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/27 00:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/29 00:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2007/08/17 02:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2006/10/17 12:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2007/08/17 02:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 16:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\iexplore.exe
[2007/10/10 00:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[1997/09/02 23:00:00 | 000,521,232 | —- | M] (Microsoft Corporation) MD5=683D4C04865A6906B308639EDE7E3859 – C:\tribble2-backup-c\mikes-backup\ofcd\IEXPLORE\IEXPLORE.EXE
[2007/02/21 00:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2008/02/22 01:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2007/12/06 00:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2007/04/24 06:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2007/06/27 01:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2007/02/27 22:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2004/08/04 11:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2007/10/10 02:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2002/08/28 23:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=EB9EAF627F705525D01DE5FA07EA1818 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Internet Explorer\IEXPLORE.EXE
[2002/08/28 23:00:00 | 000,091,136 | —- | M] (Microsoft Corporation) MD5=EB9EAF627F705525D01DE5FA07EA1818 – C:\tribble2-backup-c\Program Files\Internet Explorer\IEXPLORE.EXE
[1999/04/23 21:22:00 | 000,078,272 | —- | M] (Microsoft Corporation) MD5=F51690B7980BD05DB110FDCD1714688E – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\Program Files\Internet Explorer\IEXPLORE.EXE
[1999/04/23 22:22:00 | 000,078,272 | —- | M] (Microsoft Corporation) MD5=F51690B7980BD05DB110FDCD1714688E – C:\tribble2-backup-d\Office3\Program Files\Internet Explorer\IEXPLORE.EXE

< MD5 for: IEXPLORE.EXE.26E3AD32.INI.INUSE >
[2007/05/17 16:52:33 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory\iexplore.exe.26e3ad32.ini.inuse

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 17:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/12/23 18:59:41 | 000,106,880 | —- | M] () MD5=6C857BF7D0C08DB29AD1BAE13A276D56 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HL_ >
[2004/08/04 11:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_

< MD5 for: IEXPLORE.HLP >
[2004/08/04 11:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: IEXPLORE.INI >
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI
[2000/12/15 21:07:26 | 000,004,851 | —- | M] () MD5=B1BF8DF24255A67518EF3BD197B8DC9A – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\IEXPLORE.INI

< MD5 for: SERVICES >
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK\SERVICES
[1993/10/09 16:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\WINSOCK\SERVICES
[1993/10/09 17:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK\SERVICES
[1993/10/09 17:12:20 | 000,002,840 | —- | M] () MD5=0E5A25D5A160ECAE8E0E4C975D83ED3A – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[1996/09/12 09:26:42 | 000,004,299 | —- | M] () MD5=10C8703D8BF7D290E150E8B2C3FADC22 – C:\tribble2-backup-c\mikes-backup\ofcc\WINDOWS\INTUIT\SHARED\QWINSOCK\SERVICES
[2004/08/04 11:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 11:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 12:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-d\TRIBBLC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/06/12 12:18:04 | 000,001,791 | —- | M] () MD5=A038BF682A78E3007C6E322979DEA89E – C:\tribble2-backup-d\TRIBBLEC\INTERNET\NETSCAP2\DIALER\SERVICES
[1995/02/27 23:06:00 | 000,001,238 | —- | M] () MD5=AC1EC38D56985CC93876FF9F05274012 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Netcomplete\SERVICES
[1995/02/27 23:06:00 | 000,001,238 | —- | M] () MD5=AC1EC38D56985CC93876FF9F05274012 – C:\tribble2-backup-c\Program Files\Netcomplete\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 09:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK2\SERVICES
[1996/06/27 10:37:58 | 000,002,665 | —- | M] () MD5=B276FB9BFBC10778A10B1E1224A59115 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\SERVICES
[2000/02/04 10:28:42 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\RECYCLED\DC9.0\net\win98\services
[2000/02/24 09:35:36 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\RECYCLED\DC9.0\net\win98se\services
[1999/04/23 21:22:00 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\SERVICES
[2000/02/04 10:28:42 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-c\RECYCLED\DC9.0\net\win98\services
[2000/02/24 09:35:36 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-c\RECYCLED\DC9.0\net\win98se\services
[1999/04/23 22:22:00 | 000,006,007 | —- | M] () MD5=D5E21E6DD81F7E6BEF32A67898362A85 – C:\tribble2-backup-d\Office3\WINDOWS\SERVICES

< MD5 for: SERVICES._ >
[2004/08/04 11:00:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\WINDOWS\I386\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcc\MATT\TMP5\SERVICES._
[1996/06/27 09:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcd\TMP5\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcf\SERVICES._
[1996/12/11 09:07:14 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-c\mikes-backup\ofcf\TWK\SERVICES._
[1996/06/27 10:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\SERVICES._
[1996/06/27 10:37:58 | 000,000,902 | —- | M] () MD5=ED4B12C108904CDD6A12DCD3EE77B543 – C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\SERVICES._

< MD5 for: SERVICES.CHM >
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit6\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit3\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit4\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit5\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit6\Services.chm
[2002/11/18 03:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\intuit7\Services.chm
[2002/11/18 04:08:46 | 000,183,201 | —- | M] () MD5=CF5FE74030E199B13D7EE6E835D97754 – C:\tribble2-backup-d\QuickBooks Basic\Services.chm
[2003/10/29 17:30:46 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\services.chm
[2003/10/29 17:30:44 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Services.chm
[2003/10/29 17:30:46 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\services.chm
[2003/10/29 17:30:44 | 000,187,091 | —- | M] () MD5=F7A78B939E4B49FACB171B15F93E2AD5 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Services.chm

< MD5 for: SERVICES.CSS >
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Quickbooks-save\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 15:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2002/05/29 16:31:16 | 000,000,059 | —- | M] () MD5=1CBE6A85C95B5B19A497D71650D79E36 – C:\tribble2-backup-d\Quickbooks-save\QuickBooks\Components\Download\Guide\.update\.Digest\services.css
[2003/05/30 00:03:06 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Components\Services\services.css
[2003/05/30 00:03:06 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Components\Services\services.css
[2004/05/14 19:49:46 | 000,011,541 | —- | M] () MD5=4D54B29557DAA0935B8222A3DC5A1982 – C:\tribble2-backup-d\intuit7\Components\Services\services.css
[2002/05/29 15:31:02 | 000,007,703 | —- | M] () MD5=75A6BA0742A7EB410A0AFB38A9A59D29 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Quickbooks-save\QuickBooks\Components\Services\services.css
[2002/05/29 16:31:02 | 000,007,703 | —- | M] () MD5=75A6BA0742A7EB410A0AFB38A9A59D29 – C:\tribble2-backup-d\Quickbooks-save\QuickBooks\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit3\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit4\Components\Services\services.css
[2002/10/15 13:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\intuit5\Components\Services\services.css
[2002/10/15 14:10:20 | 000,011,453 | —- | M] () MD5=76B3A76E97CD029938EE1765522DFB4A – C:\tribble2-backup-d\QuickBooks Basic\Components\Services\services.css
[2004/11/09 23:43:02 | 000,011,525 | —- | M] () MD5=FF757041D7C3EBA68F0127402D174D27 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\Components\Services\services.css
[2004/11/09 23:43:02 | 000,011,525 | —- | M] () MD5=FF757041D7C3EBA68F0127402D174D27 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\Components\Services\services.css

< MD5 for: SERVICES.CV_ >
[1996/05/07 10:00:18 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\tribble2-backup-d\TRIBBLEC\TRIBBLED\WINFAX1\SERVICES.CV_

< MD5 for: SERVICES.DOC >
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC
[2000/07/06 09:22:28 | 000,025,088 | —- | M] () MD5=7DAB0A531E485FDB30A1D162A752494C – C:\tribble2-backup-c\mikes-backup\ofcc\EUDORA\ATTACH\SERVICES.DOC

< MD5 for: SERVICES.EX_ >
[2004/08/04 11:00:00 | 000,049,955 | —- | M] () MD5=85A738BA493104ED103B26CADEB8B543 – C:\WINDOWS\I386\SERVICES.EX_

< MD5 for: SERVICES.EXE >
[2008/04/13 16:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\system32\dllcache\services.exe
[2004/08/04 11:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\system32\services.exe

< MD5 for: SERVICES.GIF >
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2000/08/04 13:49:42 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.GIF
[2012/02/04 19:44:22 | 000,001,837 | —- | M] () MD5=4B9EBFD353BA746B6B7DEA4D8F4964A9 – C:\websites\bestdotcom-premove-backup\lvmarket\services.gif
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\mikes-backup\ofce\NVPAL-X\SERVICES.GIF
[1998/03/26 12:36:22 | 000,002,134 | —- | M] () MD5=FD1BFFFAF1769CCBA94FF61046D203A1 – C:\tribble2-backup-c\mikes-backup\ofce\NVPAL-X\SERVICES.GIF

< MD5 for: SERVICES.HTM >
[2012/02/04 19:44:24 | 000,003,652 | —- | M] () MD5=18DB327C3EFBEB7421648AB07F21DE23 – C:\websites\bestdotcom-premove-backup\lvmarket\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\galleria\web\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\mikes-backup\websites\galleria\web\services.htm
[2001/11/29 00:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2\websites\galleria\backup-051402\services.htm
[2001/11/29 00:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2\websites\galleria\web\services.htm
[2001/11/29 14:58:16 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\ofce\GAL\SERVICES.HTM
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\websites\galleria\backup-051402\services.htm
[2001/11/28 23:00:00 | 000,005,738 | —- | M] () MD5=2DE41DE6A6BB5F44E943108F270DF8DB – C:\tribble2-backup-c\mikes-backup\websites\galleria\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\preslimo\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\mikes-backup\websites\preslimo\web\services.htm
[2002/09/23 13:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\tribble2\websites\preslimo\web\services.htm
[2002/09/23 12:53:56 | 000,002,522 | —- | M] () MD5=64FC30091D04FA7459F558DE921CD8D7 – C:\tribble2-backup-c\mikes-backup\websites\preslimo\web\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\websites\preslimo\web\whatson\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\mikes-backup\websites\preslimo\web\whatson\services.htm
[2002/09/23 13:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2\websites\preslimo\web\whatson\services.htm
[2000/11/09 15:50:28 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2-backup-c\mikes-backup\ofce\PRESLIMO\SERVICES.HTM
[2002/09/23 12:56:50 | 000,002,386 | —- | M] () MD5=6D41B62B3C30BF7460978F2E6DBC11C9 – C:\tribble2-backup-c\mikes-backup\websites\preslimo\web\whatson\services.htm
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1999/01/20 17:44:34 | 000,005,492 | —- | M] () MD5=84530AA15391E42A1755C4495F5D1468 – C:\tribble2-backup-c\mikes-backup\ofce\VICTORIA\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/06 09:18:12 | 000,002,121 | —- | M] () MD5=A5B2817916852A47D0D57CE635F8B391 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\IDI\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\mikes-backup\ofce\IDI\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP3\SERVICES.HTM
[1997/03/09 19:22:22 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofcd\INTERNET\EUDORA\TEMP4\SERVICES.HTM
[1998/02/14 11:56:06 | 000,003,566 | —- | M] () MD5=C6FAAA5FBA33ABAB25F8673FE1E474B5 – C:\tribble2-backup-c\mikes-backup\ofce\IDI\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2000/08/28 10:26:42 | 000,003,884 | —- | M] () MD5=D1756FF9AF453969E10A80F6D3594D75 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM
[2001/03/09 13:39:42 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\tribble2-backup-c\mikes-backup\ofce\VICTORIA\FINAL\SERVICES.HTM

< MD5 for: SERVICES.HTML >
[2001/10/22 13:07:10 | 000,004,043 | —- | M] () MD5=BB431A68F828197874960F469A96304E – C:\Program Files\CoffeeCup Software\templates\Resturant\services.html

< MD5 for: SERVICES.JPG >
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.JPG
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\mikes-backup\ofce\LVMARKET\SERVICES.JPG
[2000/08/03 15:52:54 | 000,001,852 | —- | M] () MD5=D1175811A62B4662892F8E7B8096A115 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.JPG

< MD5 for: SERVICES.LIM >
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit3\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit4\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit5\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\intuit6\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\QuickBooks Basic\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit3\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit4\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit5\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit6\Services.lim
[2002/11/15 16:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\intuit7\Services.lim
[2002/11/15 17:05:00 | 000,085,871 | —- | M] () MD5=381327B5416FF67D60F82FDAC1822BE8 – C:\tribble2-backup-d\QuickBooks Basic\Services.lim
[2003/10/29 17:30:58 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks Basic\services.lim
[2003/10/29 17:30:56 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Intuit\QuickBooks\Services.lim
[2003/10/29 17:30:58 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks Basic\services.lim
[2003/10/29 17:30:56 | 000,086,308 | —- | M] () MD5=A576C4BD9B27221A77E27B6328147089 – C:\tribble2-backup-c\Program Files\Intuit\QuickBooks\Services.lim

< MD5 for: SERVICES.LNK >
[2004/08/26 10:04:45 | 000,001,602 | —- | M] () MD5=6EA8801235B7C68E8DFAA9C1B99BEDB2 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MS_ >
[2004/08/04 11:00:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\WINDOWS\I386\SERVICES.MS_

< MD5 for: SERVICES.MSC >
[2004/08/04 11:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.OLD >
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\GAL\SERVICES.OLD
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\mikes-backup\ofce\GAL\SERVICES.OLD
[1998/10/22 13:46:38 | 000,002,938 | —- | M] () MD5=2AC9D3819BA1986D8592F28AA29CD65D – C:\tribble2-backup-c\mikes-backup\ofce\GAL\SERVICES.OLD

< MD5 for: SERVICES.PNG >
[2008/03/27 04:42:50 | 000,003,143 | —- | M] () MD5=087ECCA024AB9A71D659CB6E4F910D2E – C:\Program Files\CoffeeCup Software\Graphics\plano\yellow\services.png
[2008/03/27 04:52:46 | 000,003,090 | —- | M] () MD5=1E9256F745C06682AFDCD57A5B038134 – C:\Program Files\CoffeeCup Software\Graphics\plano\orange\services.png
[2008/03/27 04:57:28 | 000,003,334 | —- | M] () MD5=5FF3A00670DE8D80ADA4BD034B55D154 – C:\Program Files\CoffeeCup Software\Graphics\plano\red\services.png
[2008/03/27 05:06:18 | 000,003,208 | —- | M] () MD5=BF7751362552A6E38BD3E6A610ED9889 – C:\Program Files\CoffeeCup Software\Graphics\plano\violet\services.png
[2008/03/27 04:38:18 | 000,003,827 | —- | M] () MD5=BFC0958B73C61EE6C5EEA8D8C6073D26 – C:\Program Files\CoffeeCup Software\Graphics\plano\blue\services.png
[2008/03/27 05:01:46 | 000,003,305 | —- | M] () MD5=CB54DD779139E4475AA92417CEB09846 – C:\Program Files\CoffeeCup Software\Graphics\plano\green\services.png
[2008/03/27 04:47:26 | 000,003,497 | —- | M] () MD5=F0AF7DB71281CC55799AB75203BFB664 – C:\Program Files\CoffeeCup Software\Graphics\plano\indigo\services.png

< MD5 for: SERVICES.SBS >
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
[2008/05/26 07:10:02 | 000,063,502 | —- | M] () MD5=00BEE3BF76561CFE12E4B9A12C776705 – C:\tribble2-backup-c\Program Files\Spybot - Search & Destroy\Includes\Services.sbs

< MD5 for: SERVICES.TIF >
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.TIF
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\mikes-backup\ofce\LVMARKET\SERVICES.TIF
[2000/08/03 15:13:26 | 000,016,472 | —- | M] () MD5=42255BF40EA203862AA3A01241EE8C3E – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.TIF

< MD5 for: SERVICES.TXT >
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\Documents and Settings\All Users\Documents\tribble2-backup\c-drive\mikes-backup\ofce\SERVICES.TXT
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\mikes-backup\ofce\SERVICES.TXT
[2000/07/06 12:34:46 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\tribble2-backup-c\mikes-backup\ofce\LVMARKET\SERVICES.TXT
[2000/07/06 12:33:30 | 000,001,787 | —- | M] () MD5=989C5C96CEFC0456415E8B11670017E7 – C:\tribble2-backup-c\mikes-backup\ofce\SERVICES.TXT
[1999/04/23 21:22:00 | 000,005,130 | —- | M] () MD5=9FD21574C1827280937828D2D8C67F5D – C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\Office3\WINDOWS\SERVICES.TXT
[1999/04/23 22:22:00 | 000,005,130 | —- | M] () MD5=9FD21574C1827280937828D2D8C67F5D – C:\tribble2-backup-d\Office3\WINDOWS\SERVICES.TXT

< MD5 for: WINLOGON.EX_ >
[2004/08/04 11:00:00 | 000,261,115 | —- | M] () MD5=F41C4F5745589D0BB8268C02B71594CA – C:\WINDOWS\I386\WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/04 11:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\winlogon.exe
[2012/09/29 18:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 16:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2006/11/06 15:33:15 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2006/11/06 15:33:15 | 000,001,039 | —- | M] () – C:\aolconnfix.txt
[2004/01/01 16:14:14 | 000,000,032 | —- | M] () – C:\ati.log
[2004/08/26 10:04:39 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/02 13:11:00 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2004/08/26 10:04:39 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2011/04/17 14:29:35 | 000,001,134 | —- | M] () – C:\FixNCR.reg
[2012/12/24 12:04:14 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2011/03/15 17:13:12 | 000,030,191 | —- | M] () – C:\install.log
[2004/08/26 10:04:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/11/24 15:31:03 | 000,018,947 | —- | M] () – C:\logfile
[2004/08/26 10:04:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/01/01 16:14:54 | 000,000,160 | —- | M] () – C:\napster.log
[2004/08/04 11:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 11:00:00 | 000,250,032 | —- | M] () – C:\ntldr
[2012/12/24 12:04:02 | 2078,785,536 | -HS- | M] () – C:\pagefile.sys
[2008/06/03 02:36:01 | 000,002,111 | —- | M] () – C:\rapport.txt
[2011/04/18 14:23:00 | 000,005,958 | —- | M] () – C:\recycbin-2.reg
[2011/04/18 11:53:06 | 000,000,569 | —- | M] () – C:\rkill.log
[2005/06/12 07:34:01 | 000,000,256 | —- | M] () – C:\SmartInstaller.log
[2011/04/19 17:23:21 | 000,050,682 | —- | M] () – C:\TDSSKiller.2.4.21.0_19.04.2011_18.17.46_log.txt
[2012/12/24 02:26:59 | 000,097,620 | —- | M] () – C:\TDSSKiller.2.8.15.0_24.12.2012_02.23.58_log.txt
[2012/07/19 13:09:11 | 000,069,966 | —- | M] () – C:\VETlog.dmp
[2012/07/19 13:09:12 | 002,351,370 | —- | M] () – C:\VETlog.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >
[2006/02/19 02:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2004/08/26 10:03:59 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2002/09/04 21:00:00 | 000,013,824 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD3q.DLL
[2002/09/04 21:00:00 | 000,046,080 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP3q.DLL
[2003/07/29 01:36:00 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL
[2009/11/04 07:14:19 | 000,157,696 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll
[2007/04/09 12:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2011/06/20 18:23:26 | 000,024,576 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\sst3cpc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/10/01 15:29:48 | 000,109,312 | —- | M] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:13:07 | 000,001,401 | —- | M] () – C:\Program Files\PRNTBILL.BAT
[2003/10/01 13:32:26 | 000,001,401 | —- | M] () – C:\Program Files\PRNTBILL.~BA
[2004/05/03 12:45:00 | 000,356,352 | —- | M] () – C:\Program Files\putty.exe
[2008/04/09 17:18:10 | 000,774,144 | —- | M] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/26 02:53:19 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/26 02:53:18 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/26 02:53:18 | 000,864,256 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/07/20 00:57:19 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/11/03 16:48:37 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/02/21 17:34:16 | 008,582,536 | —- | M] (Mozilla) – C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.6.13.exe
[1997/12/23 01:14:15 | 000,091,648 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gzip.exe
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-15 08:23:03

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB21672$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C10F9B26

< End of report >
Hi Mikepcap, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Well, I followed the instructions to the letter. combofix started running in a DOS box. Turns out it had to download and load the microsoft console, which took about 10 mins. Then it went into it's "this may take 10 minutes…. or more than double that mode" after about 10 min it came back and said: Rootkit.ZeroAcess was found in the tcp/ip stack Then it popped up windows saying "Rootkit is detected please be patient" a few more times Then it said rootkit activity detected, must reboot. and immediately rebooted. It came up just to the point of displaying my background screen, (no desktop program links) and then started over with running combofix in the DOS window again. It got to: Completed Stage_1…. _2…. and Completed Stage_3, but then apparently froze for over 30 minutes (so far - this is on a different computer of course) and it only hits the drive for a quick hit about every 10-15 seconds. Is this normal? Should I wait? Reboot?
Wait it out. If there is even the slightest bit of harddrive activity combofix is still running. The 10 minutes is just a general timeframe, heavily infected computers can take quite a bit longer.
Found a pop-up window buried behind the combofix window (after it rebooted) saying: MalwareBytes Anti-Malwate [Shell-Notify-Icon] Failed to perform desired action. Error Code:2 Clicked OK Disk got a little more active for a while, then died back down. Going on 6+ hours running combofix with no further progress reports. Going to bed.
Ok, did a hard reboot. Stopped security, and re-ran combofix from the desktop.
"Zipped" right through this time to stage-50 plus (in about 30 min) with no significant hang-ups.
Appears to have deleted on of my favorite DOS text editors (Analog = c:\a\a.exe) But I can get another copy.
Best of all, the virus appears gone as I can now access all of the sites I could not before.

Report is below:
Happy Holidays, by the way, and thank you so much. If this fix holds I WILL be making a donation to this site.

ComboFix 12-12-23.01 - Owner 12/25/2012 3:36.2.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: CenturyLink™ Online Security 9.01 *Disabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: CenturyLink™ Online Security 9.01 *Enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\a
c:\a\A.EXE
c:\a\A.X
c:\a\CFG\CFGCOLOR.X
c:\a\CFG\CFGCONF.AML
c:\a\CFG\CFGCONF.X
c:\a\CFG\CFGDESK.AML
c:\a\CFG\CFGDESK.X
c:\a\CFG\CFGEDIT1.AML
c:\a\CFG\CFGEDIT1.X
c:\a\CFG\CFGEDIT2.AML
c:\a\CFG\CFGEDIT2.X
c:\a\CFG\CFGFIND.AML
c:\a\CFG\CFGFIND.X
c:\a\CFG\CFGFMGR.AML
c:\a\CFG\CFGFMGR.X
c:\a\CFG\CFGFORM.AML
c:\a\CFG\CFGFORM.X
c:\a\CFG\CFGLDLM.AML
c:\a\CFG\CFGLDLM.X
c:\a\CFG\CFGMAIN.AML
c:\a\CFG\CFGMAIN.X
c:\a\CFG\CFGMARG.AML
c:\a\CFG\CFGMARG.X
c:\a\CFG\CFGMISC.AML
c:\a\CFG\CFGMISC.X
c:\a\CFG\CFGMOUSE.AML
c:\a\CFG\CFGMOUSE.X
c:\a\CFG\CFGOPEN.AML
c:\a\CFG\CFGOPEN.X
c:\a\CFG\CFGPRINT.AML
c:\a\CFG\CFGPRINT.X
c:\a\CFG\CFGPROM.AML
c:\a\CFG\CFGPROM.X
c:\a\CFG\CFGSAVE.AML
c:\a\CFG\CFGSAVE.X
c:\a\CFG\CFGSORT.AML
c:\a\CFG\CFGSORT.X
c:\a\CFG\CFGSTYL2.X
c:\a\CFG\CFGSTYLE.X
c:\a\CFG\CFGUPD.AML
c:\a\CFG\CFGUPD.X
c:\a\CFG\CFGVIDEO.AML
c:\a\CFG\CFGVIDEO.X
c:\a\COLOR.AML
c:\a\COLOR.OLD
c:\a\CONFIG.AML
c:\a\DEFINE.AML
c:\a\DOC\FUNCTION.DOX
c:\a\DOC\LANGUAGE.DOX
c:\a\DOC\QUICKFUN.DOX
c:\a\DOC\REGEXP.DOX
c:\a\DOC\TIPS.DOX
c:\a\DOC\USER.DOX
c:\a\EXT.AML
c:\a\FILE_ID.DIZ
c:\a\HISTORY.DAT
c:\a\INSTALL.AML
c:\a\INSTALL.X
c:\a\KBD.AML
c:\a\LIB.X
c:\a\LICENSE.DOC
c:\a\MACRO\ASCII2.AML
c:\a\MACRO\ASCII2.X
c:\a\MACRO\BOOKLIST.AML
c:\a\MACRO\BOOKLIST.X
c:\a\MACRO\CALCPAD.AML
c:\a\MACRO\CALCPAD.X
c:\a\MACRO\CALEN4.AML
c:\a\MACRO\CALEN4.X
c:\a\MACRO\CALENDAR.AML
c:\a\MACRO\CALENDAR.X
c:\a\MACRO\CLRCHART.AML
c:\a\MACRO\CLRCHART.X
c:\a\MACRO\COMPARE.AML
c:\a\MACRO\COMPARE.X
c:\a\MACRO\COMPRESS.AML
c:\a\MACRO\COMPRESS.X
c:\a\MACRO\COUNTCHR.AML
c:\a\MACRO\COUNTCHR.X
c:\a\MACRO\COUNTLIN.AML
c:\a\MACRO\COUNTLIN.X
c:\a\MACRO\COUNTWRD.AML
c:\a\MACRO\COUNTWRD.X
c:\a\MACRO\DELBLANK.AML
c:\a\MACRO\DELBLANK.X
c:\a\MACRO\DELDUP.AML
c:\a\MACRO\DELDUP.X
c:\a\MACRO\DLGDEMO.AML
c:\a\MACRO\DLGDEMO.X
c:\a\MACRO\DRAWBOX.AML
c:\a\MACRO\DRAWBOX.X
c:\a\MACRO\EXAMPLE.AML
c:\a\MACRO\FULLDATE.AML
c:\a\MACRO\FULLDATE.X
c:\a\MACRO\HELPLANG.AML
c:\a\MACRO\HELPLANG.X
c:\a\MACRO\HELPUSER.AML
c:\a\MACRO\HELPUSER.X
c:\a\MACRO\KEYCODES.AML
c:\a\MACRO\KEYCODES.X
c:\a\MACRO\KEYDEF.AML
c:\a\MACRO\KEYDEF.X
c:\a\MACRO\LONGLINE.AML
c:\a\MACRO\LONGLINE.X
c:\a\MACRO\MACLIST.AML
c:\a\MACRO\MACLIST.X
c:\a\MACRO\PALETTE.AML
c:\a\MACRO\PALETTE.X
c:\a\MACRO\SCAN2.AML
c:\a\MACRO\SCAN2.X
c:\a\MACRO\SCRSAVER.AML
c:\a\MACRO\SCRSAVER.X
c:\a\MACRO\STYLE.AML
c:\a\MACRO\STYLE.X
c:\a\MACRO\SUMBLOCK.AML
c:\a\MACRO\SUMBLOCK.X
c:\a\MACRO\TABS.AML
c:\a\MACRO\TABS.X
c:\a\MACRO\TEMPLATE.AML
c:\a\MACRO\TEMPLATE.DAT
c:\a\MACRO\TEMPLATE.X
c:\a\MACRO\WHERE.AML
c:\a\MACRO\WHERE.X
c:\a\MAIN.AML
c:\a\MENU.AML
c:\a\MOUSE.AML
c:\a\ORDERFRM.DOC
c:\a\PALETTE\BLUGREEN.AML
c:\a\PALETTE\FLUORESC.AML
c:\a\PALETTE\GREENCH.AML
c:\a\PALETTE\REDBLUE.AML
c:\a\PALETTE\WIMBLEDN.AML
c:\a\READ.ME
c:\a\STYLE\AUKBD.AML
c:\a\STYLE\AUMENU.AML
c:\a\STYLE\BRKBD.AML
c:\a\STYLE\BRMENU.AML
c:\a\STYLE\CUKBD.AML
c:\a\STYLE\CUMENU.AML
c:\a\STYLE\MEKBD.AML
c:\a\STYLE\MEMENU.AML
c:\a\STYLE\QEKBD.AML
c:\a\STYLE\QEMENU.AML
c:\a\STYLE\WPKBD.AML
c:\a\STYLE\WPMENU.AML
c:\a\STYLE\WSKBD.AML
c:\a\STYLE\WSMENU.AML
c:\a\SYNTAX.AML
c:\a\SYNTAX2.AML
c:\a\SYSTEM.AML
c:\a\TRAN.AML
c:\a\VENDOR.DOC
c:\a\WHATSNEW.DOC
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\7aa1ff29
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\SPL2392.tmp
c:\documents and settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Owner\Application Data\Adobe\plugs
c:\documents and settings\Owner\Application Data\Adobe\plugs\mmc77
c:\documents and settings\Owner\Application Data\Adobe\shed
c:\documents and settings\Owner\Application Data\Desktopicon
c:\documents and settings\Owner\Application Data\Desktopicon\config.ini
c:\documents and settings\Owner\Application Data\f739919
c:\documents and settings\Owner\Application Data\Yzly
c:\documents and settings\Owner\Application Data\Yzly\cygia.exe
c:\documents and settings\Owner\WINDOWS
c:\program files\alexa toolbar
c:\program files\alexa toolbar\AlexaToolbar.10.0.dll
c:\program files\alexa toolbar\AlexaToolbar.10.0.Uninstall.exe
c:\program files\alexa toolbar\AlexaToolbarSSB.10.0.dll
c:\program files\alexa toolbar\AlxSSBPS.dll
c:\program files\Program Files
c:\program files\Program Files\Common Files\Adobe\Color\ACE1Cache.lst
c:\program files\Program Files\Common Files\Adobe\TypeSpt\AdobeFnt.lst
c:\program files\Program Files\Common Files\Adobe\Workflow\Options.txt
c:\windows\dasetup.log
c:\windows\system32\BSTIEPrintCtl1.dll
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\ndisapi.dll
c:\windows\system32\SET71.tmp
c:\windows\system32\SET7D.tmp
c:\windows\system32\SET8A.tmp
c:\windows\system32\tmp.reg
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-11-25 to 2012-12-25 )))))))))))))))))))))))))))))))
.
.
2012-12-23 12:14 . 2012-12-23 12:14 138368 —-a-w- c:\windows\system32\drivers\afd.sys
2012-12-22 10:32 . 2012-12-25 06:36 ——– d—–w- c:\documents and settings\Owner\Application Data\Fiwecu
2012-12-22 10:32 . 2012-12-22 10:32 ——– d—–w- c:\documents and settings\Owner\Application Data\Akvea
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-11 23:30 . 2012-04-08 04:16 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-11 23:30 . 2011-06-05 11:02 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-30 02:54 . 2011-04-18 19:28 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-25 23:13 . 2012-07-25 23:12 1401 —-a-w- c:\program files\PRNTBILL.BAT
2008-04-10 01:18 . 2008-04-10 01:23 774144 -c–a-w- c:\program files\RngInterstitial.dll
2004-05-03 20:45 . 2006-12-05 00:38 356352 —-a-w- c:\program files\putty.exe
2012-12-05 14:41 . 2012-12-05 14:40 262112 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-16 06:40 . 2012-12-05 14:40 135680 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\qmgr.dll
[-] 2007-03-29 . CC431E6DEAAD867A583EE5E804EE4CF2 . 409600 . . [6.7.2600.3109] . . c:\windows\$NtServicePackUninstall$\qmgr.dll
[-] 2007-03-29 . CC431E6DEAAD867A583EE5E804EE4CF2 . 409600 . . [6.7.2600.3109] . . c:\windows\system32\qmgr.dll
[-] 2007-03-29 . CC431E6DEAAD867A583EE5E804EE4CF2 . 409600 . . [6.7.2600.3109] . . c:\windows\system32\bits\qmgr.dll
[-] 2007-03-29 . CC431E6DEAAD867A583EE5E804EE4CF2 . 409600 . . [6.7.2600.3109] . . c:\windows\system32\dllcache\qmgr.dll
[-] 2007-03-29 . 65E23953D337574E549B1EF34FE0B1DA . 409600 . . [6.7.2600.3109] . . c:\windows\$hf_mig$\KB923845\SP2QFE\qmgr.dll
[7] 2004-08-04 . 2C69EC7E5A311334D10DD95F338FCCEA . 382464 . . [6.6.2600.2180] . . c:\windows\$NtUninstallKB923845$\qmgr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B291E6C-9A74-4034-971B-A4B007A0B315}]
2010-01-11 23:43 452320 —-a-w- c:\program files\PlayBox\toolbar.ni.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5B291E6C-9A74-4034-971B-A4B007A0B315}"= "c:\program files\PlayBox\toolbar.ni.dll" [2010-01-11 452320]
.
[HKEY_CLASSES_ROOT\clsid\{5b291e6c-9a74-4034-971b-a4b007a0b315}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{810FCC0F-2CA3-414a-B8C8-550910C8B664}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{5B291E6C-9A74-4034-971B-A4B007A0B315}"= "c:\program files\PlayBox\toolbar.ni.dll" [2010-01-11 452320]
.
[HKEY_CLASSES_ROOT\clsid\{5b291e6c-9a74-4034-971b-a4b007a0b315}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{810FCC0F-2CA3-414a-B8C8-550910C8B664}]
[HKEY_CLASSES_ROOT\Pugi.PugiObj]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTrayp"="VTtrayp.exe" [2005-03-12 147456]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-16 1838592]
"lxeamon.exe"="c:\program files\Lexmark S300-S400 Series\lxeamon.exe" [2011-01-24 770728]
"EzPrint"="c:\program files\Lexmark S300-S400 Series\ezprint.exe" [2011-01-24 148280]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"WD Anywhere Backup"="c:\program files\WD\WD Anywhere Backup\MemeoLauncher2.exe" [2008-11-07 197856]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"F-Secure Manager"="c:\program files\CenturyLink Online Security\Common\FSM32.EXE" [2009-08-05 199264]
"F-Secure TNB"="c:\program files\CenturyLink Online Security\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2012-10-11 296096]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-04-19 421888]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2008-7-3 479232]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-9-8 5185536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\eudora\EuShlExt.dll" [2005-08-09 86016]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [4/16/2011 2:54 PM 42664]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [4/16/2011 2:52 PM 80000]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\CenturyLink Online Security\HIPS\drivers\fshs.sys [4/16/2011 2:51 PM 68064]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [2/22/2007 10:28 AM 30864]
R2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe -service –> c:\windows\system32\lxeacoms.exe -service [?]
R2 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxeaserv.exe [11/15/2010 1:03 AM 193192]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [9/19/2012 2:02 PM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/18/2011 11:29 AM 676936]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [5/18/2010 4:06 PM 327064]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [7/24/2008 2:22 PM 102400]
R2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [9/8/2010 10:41 AM 237056]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\CenturyLink Online Security\Anti-Virus\minifilter\fsgk.sys [4/16/2011 2:50 PM 148648]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\CenturyLink Online Security\ORSP Client\fsorsp.exe [4/16/2011 2:51 PM 61088]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/18/2011 11:28 AM 22856]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\WD\WD Anywhere Backup\MemeoBackgroundService.exe [11/7/2008 11:20 AM 25824]
S2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [9/8/2010 10:45 AM 1034752]
S2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [9/8/2010 10:44 AM 484352]
S3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [1/27/2010 5:10 PM 5248]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\CenturyLink Online Security\Anti-Virus\win2k\fsfilter.sys [4/16/2011 2:50 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\CenturyLink Online Security\Anti-Virus\win2k\fsrec.sys [4/16/2011 2:50 PM 25184]
S4 MioNet;MioNet;c:\program files\MioNet\MioNetManager.exe [9/17/2008 1:52 PM 139264]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - NDISRD
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 23:30]
.
2012-12-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2012-06-24 c:\windows\Tasks\expressburnSevenDaysInit.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-16 11:10]
.
2012-06-24 c:\windows\Tasks\expressburnShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-16 11:10]
.
2012-06-24 c:\windows\Tasks\expressripShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressRip\expressrip.exe [2010-02-16 11:10]
.
2012-12-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 04:44]
.
2012-12-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-03 08:49]
.
2012-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-03 08:49]
.
2005-11-04 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-07-20 19:00]
.
2005-11-04 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-07-20 19:00]
.
2005-11-04 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-07-20 19:00]
.
2012-12-10 c:\windows\Tasks\jucheck.job
- c:\program files\Java\jre1.5.0_02\bin\jucheck.exe [2004-01-02 11:36]
.
2012-12-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 21:27]
.
2012-12-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 21:27]
.
2012-12-24 c:\windows\Tasks\ReclaimerUpdateFiles_Owner.job
- c:\documents and settings\Owner\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.30\agent\rnupgagent.exe [2012-12-18 06:07]
.
2012-12-25 c:\windows\Tasks\ReclaimerUpdateXML_Owner.job
- c:\documents and settings\Owner\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.30\agent\rnupgagent.exe [2012-12-18 06:07]
.
2012-12-25 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_Owner.job
- c:\documents and settings\Owner\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.30\agent\rnupgagent.exe [2012-12-18 06:07]
.
2012-12-25 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\CENTUR~1\ANTI-V~1\fsav.exe [2011-04-16 15:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://bestsearchforever.biz/
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\CenturyLink Online Security\FSPS\program\FSLSP.DLL
Trusted Zone: samsungsetup.com\www
Trusted Zone: turbotax.com
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{75A8BD71-DED9-4086-856F-C1CA51592ECB}: DhcpNameServer = 192.168.1.1
Handler: toolbarchrome - {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - c:\program files\PlayBox\toolbar.ni.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\
FF - prefs.js: browser.search.selectedEngine - Twitter
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=119&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.type - 4
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{EA582743-9076-4178-9AA6-7393FDF4D5CE} - c:\program files\Alexa Toolbar\AlexaToolbar.10.0.dll
Toolbar-Locked - (no file)
HKCU-Run-Siufsyut - c:\documents and settings\Owner\Application Data\Yzly\cygia.exe
Notify-AutorunsDisabled - c:\windows\System32\dimsntfy.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-12-25 04:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(596)
c:\program files\CenturyLink Online Security\FSPS\program\FSLSP.DLL
.
- - - - - - - > 'explorer.exe'(2980)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\ftpxext.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe
c:\program files\CenturyLink Online Security\Anti-Virus\FSGK32.EXE
c:\program files\CenturyLink Online Security\Common\FSMA32.EXE
c:\program files\CenturyLink Online Security\Common\FSHDLL32.EXE
c:\windows\system32\lxeacoms.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\VTtrayp.exe
c:\windows\system32\VTTimer.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\SOUNDMAN.EXE
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\wscntfy.exe
c:\program files\CenturyLink Online Security\FWES\Program\fsdfwd.exe
c:\program files\CenturyLink Online Security\Anti-Virus\fssm32.exe
c:\program files\CenturyLink Online Security\Anti-Virus\fsav32.exe
c:\program files\WD\WD Anywhere Backup\MemeoBackup.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2012-12-25 04:29:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-12-25 12:29
.
Pre-Run: 894,857,216 bytes free
Post-Run: 7,196,729,344 bytes free
.
- - End Of File - - DD753DAB5590D66B3C98186C07820637
Hi Mikepcap,

Happy Holiday to you too.

Open OTL
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check to box beside "scan all users"
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    /md5start
    putty.exe
    /md5stop
    c:\documents and settings\Owner\Application Data\Fiwecu\*.* /s
    c:\documents and settings\Owner\Application Data\Akvea\*.* /s
    %systemroot%\*. /mp /s
    %systemroot%\*. /rp /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window,OTL.Txt, no Extras.Txt this time.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTL logfile created on: 12/26/2012 11:55:35 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 0.57 Gb Available Physical Memory | 29.54% Memory free
3.72 Gb Paging File | 2.37 Gb Available in Paging File | 63.58% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.17 Gb Total Space | 6.48 Gb Free Space | 7.27% Space Free | Partition Type: NTFS
Drive D: | 3.98 Gb Total Space | 2.67 Gb Free Space | 67.09% Space Free | Partition Type: FAT32
Drive J: | 298.09 Gb Total Space | 297.25 Gb Free Space | 99.72% Space Free | Partition Type: NTFS

Computer Name: MIKE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeaserv.exe (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\lxeacoms.exe ( )
PRC - C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\Microsoft Office\Office12\Wordconv.exe ()
PRC - C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\Eudora\Eudora.exe (QUALCOMM Incorporated)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\VTTrayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\calc.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Works\WkDStore.exe (Microsoft® Corporation)
PRC - C:\Program Files\Microsoft Works\WksWP.exe (Microsoft® Corporation)
PRC - C:\Program Files\Microsoft Works\wkgdcach.exe (Microsoft® Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\system32\sst3cl3.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\sst3cdu.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\hashlib_x86.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fm4av.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\System.Data.SQLite.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epoemdll.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epstring.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizres.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epwizard.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\customui.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\epfunct.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\eputil.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\imagutil.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeadrs.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeascw.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeamicro.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeaprpr.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeadrui.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeadr.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeadrpp.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeahpec.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Spam Control\fsas.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSPC\fspcfsm.eng ()
MOD - \\?\c:\program files\centurylink online security\hips\fshook32.dll ()
MOD - \\?\c:\program files\centurylink online security\hips\fsumi.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\strres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\gres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\flyerres.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\fsavures.eng ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\about.dll ()
MOD - C:\Program Files\CenturyLink Online Security\FSGUI\aboutres.dll ()
MOD - C:\Program Files\CenturyLink Online Security\Anti-Virus\fsavhres.eng ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeadatr.dll ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxeaptpc.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\iptk.dll ()
MOD - C:\Program Files\Lexmark\S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeacaps.dll ()
MOD - C:\Program Files\Lexmark S300-S400 Series\lxeaptp.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\Wordconv.exe ()
MOD - C:\Program Files\Microsoft Office\Office12\Wordcnvr.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\Wordcnvpxy.cnv ()
MOD - C:\WINDOWS\system32\lxeasmr.dll ()
MOD - C:\WINDOWS\system32\lxeasm.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\hpqedit\3.0.0.0__a53cf5803f4c3827\hpqedit.dll ()
MOD - c:\windows\assembly\gac\hpqbakup\3.0.0.0__a53cf5803f4c3827\hpqbakup.dll ()
MOD - c:\windows\assembly\gac\hpqvideo\3.0.0.0__a53cf5803f4c3827\hpqvideo.dll ()
MOD - c:\windows\assembly\gac\hpqmdmr\4.0.0.0__a53cf5803f4c3827\hpqmdmr.dll ()
MOD - c:\windows\assembly\gac\hpqprrsc\4.0.0.0__a53cf5803f4c3827\hpqprrsc.dll ()
MOD - c:\windows\assembly\gac\hpqovskn\3.0.0.0__a53cf5803f4c3827\hpqovskn.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.113__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.113__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.113__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.113__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.113__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll ()
MOD - c:\windows\assembly\gac\lead.drawing.imaging.codecs\13.0.0.113__9cf889f53ea9b907\lead.drawing.imaging.codecs.dll ()
MOD - c:\windows\assembly\gac\interop.hpqvideo\4.0.0.0__a53cf5803f4c3827\interop.hpqvideo.dll ()
MOD - c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\4.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\hpqntrop\4.0.0.0__a53cf5803f4c3827\hpqntrop.dll ()
MOD - c:\windows\assembly\gac\hpqimvlt\3.0.0.0__a53cf5803f4c3827\hpqimvlt.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\4.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqtray\4.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqglutl\4.0.0.0__a53cf5803f4c3827\hpqglutl.dll ()
MOD - c:\windows\assembly\gac\hpqutils\4.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\4.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqasset\4.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\hpqiface\4.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqcc2\3.0.0.0__a53cf5803f4c3827\hpqcc2.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\193ac978af569ad9ee45110b359961b9\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\12e0aa1030badf4524f897e3f57b037a\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\29c7192327cf3999961560bf3a3995c6\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\eee9b48577689e92db5a7b5c5de98d9b\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\c98cb65a79cfccb44ea727ebe4593ede\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5f669e819da7010c1dca347a25597c42\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba0e3a22211ba7343e0116b051f2965a\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\32e6f703c114f3a971cbe706586e3655\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_107a6f33\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_e8fcec72\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_136bae39\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_a9d1d9ff\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_97116f71\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - C:\Eudora\EuLang.dll ()
MOD - C:\Eudora\plstclnt.dll ()
MOD - c:\Eudora\plugins\Unwrap32.dll ()
MOD - C:\Eudora\libexpat.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\Works Shared\aw.dll ()
MOD - C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBLPP5C.DLL ()
MOD - C:\WINDOWS\system32\CISPMON.DLL ()


========== Services (SafeList) ==========

SRV - (napagent) – %SystemRoot%\System32\qagentrt.dll File not found
SRV - (hkmsvc) – %SystemRoot%\System32\kmsvc.dll File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (EapHost) – %SystemRoot%\System32\eapsvc.dll File not found
SRV - (Dot3svc) – %SystemRoot%\System32\dot3svc.dll File not found
SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (FSORSPClient) – C:\Program Files\CenturyLink Online Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV - (lxeaCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe ()
SRV - (lxea_device) – C:\WINDOWS\system32\lxeacoms.exe ( )
SRV - (FSMA) – C:\Program Files\CenturyLink Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) – C:\Program Files\CenturyLink Online Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (MemeoBackgroundService) – C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe (Memeo)
SRV - (MioNet) – C:\Program Files\MioNet\MioNetManager.exe ()
SRV - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Driver Services (SafeList) ==========

DRV - (PCIDump) – File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (F-Secure Gatekeeper) – C:\Program Files\CenturyLink Online Security\Anti-Virus\minifilter\fsgk.sys ()
DRV - (fsbts) – C:\WINDOWS\system32\drivers\fsbts.sys ()
DRV - (BVRPMPR5) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (esgiguard) – C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ()
DRV - (F-Secure HIPS) – C:\Program Files\CenturyLink Online Security\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (FSFW) – C:\WINDOWS\system32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (F-Secure Filter) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsfilter.sys ()
DRV - (F-Secure Recognizer) – C:\Program Files\CenturyLink Online Security\Anti-Virus\win2k\fsrec.sys ()
DRV - (NDISRD) – C:\WINDOWS\System32\drivers\ndisrd.sys (NT Kernel Resources)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ASTRA32) – C:\Program Files\ASTRA32\astra32.sys (Licensed for Sysinfo Lab)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (SunkFilt) – C:\WINDOWS\system32\drivers\Sunkfilt.sys (Alcor Micro Corp.)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mbmiodrvr) – C:\WINDOWS\system32\mbmiodrvr.sys ([removed])
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\SearchScopes,DefaultScope = {39170861-6644-4F57-95E4-17683AFA09F4}
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\SearchScopes\{39170861-6644-4F57-95E4-17683AFA09F4}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGIT_en
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…hromesbox-en-us
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Twitter"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7B195A3098-0BD5-4e90-AE22-BA1C540AFD1E%7D:4.0.4
FF - prefs.js..extensions.enabledAddons: %7B8f8fe09b-0bd3-4470-bc1b-8cad42b8203a%7D:0.17
FF - prefs.js..extensions.enabledAddons: %7B0153E448-190B-4987-BDE1-F256CADA672F%7D:15.0.6
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=119&systemid=406&sr=0&q="
FF - prefs.js..network.proxy.type: 4


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=1.0: C:\Program Files\Virtual Earth 3D\ [2007/05/17 16:50:24 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CenturyLink Online Security\NRS\[removed] [2011/05/30 16:21:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/10/11 14:15:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/05 06:41:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/05 06:40:57 | 000,000,000 | —D | M]

[2011/12/16 03:20:57 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/10/03 22:39:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions
[2012/12/02 16:11:02 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/12/19 03:12:42 | 000,000,000 | —D | M] (Live HTTP Headers) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2011/12/19 03:12:02 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}(2)
[2012/11/20 12:25:46 | 000,243,496 | —- | M] () (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\searchplugins\Search_Results.xml
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/12/05 06:40:40 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2012/10/11 14:15:02 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/12/05 06:41:44 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/11/19 13:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 13:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/10/11 14:13:20 | 000,129,176 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/09/21 00:45:46 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/16 03:20:07 | 000,002,519 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
[2012/10/13 05:23:37 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.searchqu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Alexa Traffic Rank = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel\1.1.0_0\
CHR - Extension: KOCAttack - Extra Features! = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jbbngjfcccafhimngmokmoejfdcjepgc\0.9.1_1\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\

O1 HOSTS File: ([2012/12/25 04:05:04 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O2 - BHO: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O2 - BHO: (del.icio.us Toolbar Helper) - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\CenturyLink Online Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKLM\..\Toolbar: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No CLSID value found.
O3 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\Toolbar\WebBrowser: (PlayBox Toolbar) - {5B291E6C-9A74-4034-971B-A4B007A0B315} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O3 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\Toolbar\WebBrowser: (del.icio.us) - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll (del.icio.us, a Yahoo! Company)
O3 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe ()
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\CenturyLink Online Security\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\CenturyLink Online Security\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe ()
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconEM.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [WD Anywhere Backup] C:\Program Files\WD\WD Anywhere Backup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\CenturyLink Online Security\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O15 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..Trusted Domains: samsungsetup.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-376849671-2428409633-4025966157-1003\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/0/f…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase9563.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1165369289625 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9} http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75A8BD71-DED9-4086-856F-C1CA51592ECB}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\toolbarchrome {718733BC-AD64-4e5f-AC18-A85FBD75D54D} - C:\Program Files\PlayBox\toolbar.ni.dll (IMEDIX WEB TECHNOLOGIES LTD.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKU\.DEFAULT Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-18 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-19 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKU\S-1-5-20 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/26 10:04:39 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2003/08/08 17:24:26 | 000,000,045 | -HS- | M] () - D:\autorun.inf.aug.8 – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/12/25 16:15:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2012/12/25 04:30:03 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2012/12/25 01:15:39 | 002,213,976 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\Kaspersky.exe
[2012/12/24 16:34:18 | 000,000,000 | RHSD | C] – C:\cmdcons
[2012/12/24 16:31:15 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/12/24 16:31:15 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/12/24 16:31:15 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/12/24 16:31:15 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/12/24 16:29:43 | 000,000,000 | —D | C] – C:\Qoobox
[2012/12/24 16:29:06 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2012/12/24 16:15:53 | 005,012,686 | R— | C] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/12/24 12:42:16 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/24 12:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\GooredFix Backups
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2012/12/22 02:32:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Akvea
[2012/12/05 06:40:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2008/04/09 17:23:24 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/12/26 12:28:46 | 000,002,243 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FTP Explorer.lnk
[2012/12/26 12:28:01 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/26 11:47:00 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2012/12/26 11:05:45 | 000,000,600 | —- | M] () – C:\Documents and Settings\Owner\PUTTY.RND
[2012/12/26 10:41:55 | 000,024,010 | —- | M] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat
[2012/12/26 02:13:13 | 000,000,030 | —- | M] () – C:\WINDOWS\Iedit.INI
[2012/12/26 02:13:10 | 000,004,442 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2012/12/26 01:21:05 | 000,000,402 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/26 00:02:09 | 000,000,508 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2012/12/25 21:18:05 | 000,000,406 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/25 04:40:06 | 000,000,412 | —- | M] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/25 04:35:19 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/25 04:34:48 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/25 04:34:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/12/25 04:34:17 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/12/25 04:12:31 | 000,416,360 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/12/25 04:12:31 | 000,067,616 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/12/25 04:05:04 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/12/25 01:15:49 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\Kaspersky.exe
[2012/12/24 16:59:34 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/12/24 16:34:32 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2012/12/24 16:17:20 | 005,012,686 | R— | M] (Swearware) – C:\Documents and Settings\Owner\Desktop\ComboFix.exe
[2012/12/24 12:42:28 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2012/12/21 15:28:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/12/20 15:19:03 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/12/20 01:32:18 | 000,002,752 | —- | M] () – C:\WINDOWS\MAML.INI
[2012/12/16 02:24:27 | 000,452,508 | —- | M] () – C:\error.fstmp
[2012/12/16 00:00:28 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2012/12/13 12:43:48 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/12/13 03:08:29 | 000,010,240 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/11 15:30:07 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/12/11 15:30:06 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/12/10 03:39:00 | 000,000,330 | —- | M] () – C:\WINDOWS\tasks\jucheck.job
[2012/12/03 19:10:31 | 000,003,325 | —- | M] () – C:\Documents and Settings\All Users\Documents\shows-copyscape.htm
[2012/12/03 16:26:38 | 000,003,075 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:41:58 | 000,072,797 | —- | M] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/12/01 16:30:56 | 000,001,579 | —- | M] () – C:\Documents and Settings\Owner\My Documents\coupon-form.rtf
[2012/11/28 18:26:55 | 000,000,879 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/24 22:01:37 | 000,000,508 | —- | C] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2012/12/24 16:34:32 | 000,000,211 | —- | C] () – C:\Boot.bak
[2012/12/24 16:34:22 | 000,260,272 | RHS- | C] () – C:\cmldr
[2012/12/24 16:31:15 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/12/24 16:31:15 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/12/24 16:31:15 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/12/24 16:31:15 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/12/24 16:31:15 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/12/18 01:10:01 | 000,000,412 | —- | C] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/18 01:09:54 | 000,000,406 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/18 01:09:51 | 000,000,402 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Owner.job
[2012/12/09 00:00:53 | 000,452,508 | —- | C] () – C:\error.fstmp
[2012/12/09 00:00:53 | 000,000,000 | —- | C] () – C:\infect.fstmp
[2012/12/03 16:26:38 | 000,003,075 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Google-letter-about-vegas-com-paying-for-links.rtf
[2012/12/02 17:18:32 | 000,000,884 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoImpact 5.lnk
[2012/12/02 14:44:44 | 000,072,797 | —- | C] () – C:\Documents and Settings\All Users\Documents\bodies-1.jpg
[2012/11/28 18:26:55 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Copy of WordPad.lnk
[2012/11/28 18:26:46 | 000,000,879 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Copy of WordPad.lnk
[2012/07/25 15:12:16 | 000,109,312 | —- | C] () – C:\Program Files\lvlgbill.prn
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.BAT
[2012/07/25 15:12:16 | 000,001,401 | —- | C] () – C:\Program Files\PRNTBILL.~BA
[2012/04/09 22:49:40 | 000,060,228 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2012/03/29 00:58:50 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/01/14 15:38:12 | 000,008,693 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\9c228de1
[2011/09/29 11:45:08 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\sst3cl3.dll
[2011/08/20 13:42:15 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\lxeasm.dll
[2011/08/20 13:42:15 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\lxeasmr.dll
[2011/08/20 13:42:13 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxeavs.dll
[2011/08/20 13:42:11 | 000,442,368 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoin.dll
[2011/08/20 13:42:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\lxeagcfg.dll
[2011/08/20 13:42:00 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxeacui.dll
[2011/08/20 13:42:00 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\lxeacuir.dll
[2011/08/20 13:38:30 | 000,847,872 | —- | C] ( ) – C:\WINDOWS\System32\lxeausb1.dll
[2011/08/20 13:38:30 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxeainpa.dll
[2011/08/20 13:38:30 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\LXEAhcp.dll
[2011/08/20 13:38:30 | 000,344,064 | —- | C] ( ) – C:\WINDOWS\System32\lxeaiesc.dll
[2011/08/20 13:38:30 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\LXEAinst.dll
[2011/08/20 13:38:29 | 001,048,576 | —- | C] ( ) – C:\WINDOWS\System32\lxeaserv.dll
[2011/08/20 13:38:29 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxeapmui.dll
[2011/08/20 13:38:28 | 000,577,536 | —- | C] ( ) – C:\WINDOWS\System32\lxealmpm.dll
[2011/08/20 13:38:28 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\lxeains.dll
[2011/08/20 13:38:28 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lxeainsb.dll
[2011/08/20 13:38:28 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lxeainsr.dll
[2011/08/20 13:38:28 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\lxeajswr.dll
[2011/08/20 13:38:27 | 000,688,128 | —- | C] ( ) – C:\WINDOWS\System32\lxeahbn3.dll
[2011/08/20 13:38:27 | 000,324,264 | —- | C] ( ) – C:\WINDOWS\System32\lxeaih.exe
[2011/08/20 13:38:27 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxeagrd.dll
[2011/08/20 13:38:26 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\lxeacu.dll
[2011/08/20 13:38:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\lxeacub.dll
[2011/08/20 13:38:26 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\lxeacur.dll
[2011/08/20 13:38:25 | 000,598,696 | —- | C] ( ) – C:\WINDOWS\System32\lxeacoms.exe
[2011/08/20 13:38:24 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomm.dll
[2011/08/20 13:38:23 | 000,802,816 | —- | C] ( ) – C:\WINDOWS\System32\lxeacomc.dll
[2011/08/20 13:38:23 | 000,373,416 | —- | C] ( ) – C:\WINDOWS\System32\lxeacfg.exe
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Compressor
[2011/07/21 02:49:31 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Command Line Utility
[2011/07/21 02:49:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2011/07/21 02:49:31 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Core Data Application
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 14:54:02 | 000,042,664 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 01:15:55 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/14 22:47:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Fqureh.dat
[2011/04/14 22:47:28 | 000,000,000 | —- | C] () – C:\WINDOWS\Tbovewipezupew.bin
[2009/10/19 14:15:11 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\PUTTY.RND
[2009/09/21 15:57:13 | 000,000,064 | —- | C] () – C:\Documents and Settings\Owner\setpath.bat
[2008/12/21 03:46:31 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Common
[2008/12/16 17:52:18 | 000,000,268 | RH– | C] () – C:\Documents and Settings\Owner\Application Data\Colors
[2008/12/16 17:52:18 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT
[2008/12/16 17:52:18 | 000,000,012 | RH– | C] () – C:\Documents and Settings\All Users\Application Data\Configure Folder Actions
[2008/02/15 17:19:07 | 000,010,240 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/05/17 16:52:33 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2007/05/14 01:39:17 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/14 13:52:06 | 000,000,008 | —- | C] () – C:\Documents and Settings\Owner\Application Data\usb.dat.bin
[2006/12/04 16:39:00 | 000,000,600 | —- | C] () – C:\Documents and Settings\Owner\PUTTY.RND
[2006/12/04 16:38:00 | 000,356,352 | —- | C] () – C:\Program Files\putty.exe
[2006/12/03 17:04:02 | 000,024,010 | —- | C] () – C:\Documents and Settings\Owner\Application Data\wklnhst.dat

========== ZeroAccess Check ==========

[2012/12/24 16:48:32 | 000,000,000 | —D | M] – C:\WINDOWS\$NtUninstallKB21672$\302663330\L
[2012/12/22 02:41:11 | 000,000,000 | —D | M] – C:\WINDOWS\$NtUninstallKB21672$\302663330\U
[2004/01/01 15:49:53 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2006/09/03 22:12:56 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2004/08/04 11:00:00 | 000,472,064 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2004/08/04 11:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2004/01/01 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\SampleView
[2011/12/16 02:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2011/04/16 14:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2011/04/15 00:05:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fAk02400lLmCj02400
[2011/05/22 19:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2011/09/19 04:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lexmark S300-S400 Series
[2009/09/27 23:55:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2009/06/29 01:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2004/01/01 16:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2010/02/16 04:14:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2011/07/21 02:51:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2011/09/29 11:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2012/12/26 12:41:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/21 02:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/25 15:25:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/11/11 15:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2010/08/08 11:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/19 03:12:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B49A644A-1076-4A3D-B124-DAA7862F2318}
[2004/01/01 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\SampleView
[2011/11/29 13:30:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Actual Search & Replace
[2012/12/22 02:32:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Akvea
[2008/06/26 09:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2011/10/23 14:50:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/28 01:29:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CursorArts
[2010/02/26 00:08:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ElevatedDiagnostics
[2011/04/16 23:00:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\F-Secure
[2012/12/24 22:36:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Fiwecu
[2010/01/31 23:01:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2009/12/30 18:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2012/04/09 18:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/08/23 02:11:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MioNet
[2009/06/29 01:05:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\muvee Technologies
[2010/02/16 05:02:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
[2011/07/21 02:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nikon
[2010/01/24 16:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayBox
[2004/01/01 16:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2011/12/19 03:12:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\searchqutoolbar(2)
[2011/09/29 02:24:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Stellarium
[2006/12/03 17:04:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/05/25 15:25:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2011/09/30 16:17:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WD

========== Purity Check ==========



========== Custom Scans ==========

< >
[2004/08/26 08:12:03 | 000,000,065 | RH– | C] () – C:\WINDOWS\Tasks\desktop.ini
[2004/08/26 10:08:56 | 000,000,006 | -H– | C] () – C:\WINDOWS\Tasks\SA.DAT
[2005/11/03 16:47:30 | 000,000,258 | —- | C] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2005/11/03 16:47:30 | 000,000,258 | —- | C] () – C:\WINDOWS\Tasks\ISP signup reminder 2.job
[2005/11/03 16:47:31 | 000,000,258 | —- | C] () – C:\WINDOWS\Tasks\ISP signup reminder 3.job
[2009/03/24 05:54:55 | 000,000,868 | —- | C] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2010/01/03 00:54:09 | 000,000,882 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
[2010/01/03 00:54:09 | 000,000,886 | —- | C] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[2010/02/16 04:19:11 | 000,000,304 | —- | C] () – C:\WINDOWS\Tasks\expressburnSevenDaysInit.job
[2010/02/16 05:04:33 | 000,000,294 | —- | C] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2010/11/15 14:58:53 | 000,000,286 | —- | C] () – C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2010/12/09 17:40:02 | 000,000,330 | —- | C] () – C:\WINDOWS\Tasks\jucheck.job
[2011/04/19 14:44:10 | 000,000,298 | —- | C] () – C:\WINDOWS\Tasks\expressburnShakeIcon.job
[2011/07/08 14:59:10 | 000,000,284 | —- | C] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2012/02/04 00:56:05 | 000,000,278 | —- | C] () – C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-376849671-2428409633-4025966157-1003.job
[2012/04/07 20:16:20 | 000,000,830 | —- | C] () – C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
[2012/12/18 01:09:51 | 000,000,402 | —- | C] () – C:\WINDOWS\Tasks\ReclaimerUpdateXML_Owner.job
[2012/12/18 01:09:54 | 000,000,406 | —- | C] () – C:\WINDOWS\Tasks\ReclaimerUpdateFiles_Owner.job
[2012/12/18 01:10:01 | 000,000,412 | —- | C] () – C:\WINDOWS\Tasks\RNUpgradeHelperLogonPrompt_Owner.job
[2012/12/24 22:01:37 | 000,000,508 | —- | C] () – C:\WINDOWS\Tasks\Scheduled scanning task.job

< MD5 for: PUTTY.EXE >
[2009/06/01 11:40:34 | 000,794,624 | —- | M] (Simon Tatham) MD5=57853B6C77682CFFF5DCF11E2F25B625 – C:\Program Files\ExtraPuTTY\Bin\putty.exe
[2004/05/03 12:45:00 | 000,356,352 | —- | M] () MD5=7CE34C0AE6F41328864B5A975EB53355 – C:\Program Files\putty.exe

< c:\documents and settings\Owner\Application Data\Fiwecu\*.* /s >
[2012/12/24 22:36:04 | 000,000,058 | —- | M] () – c:\documents and settings\Owner\Application Data\Fiwecu\qiby.dat

< c:\documents and settings\Owner\Application Data\Akvea\*.* /s >
[2012/12/22 02:32:43 | 000,221,293 | —- | M] () – c:\documents and settings\Owner\Application Data\Akvea\ebafs.asq

< %systemroot%\*. /mp /s >

< %systemroot%\*. /rp /s >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 193 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C10F9B26

< End of report >
Hi Mikepcap,

Next, double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/14 22:47:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Fqureh.dat
[2011/04/14 22:47:28 | 000,000,000 | —- | C] () – C:\WINDOWS\Tbovewipezupew.bin
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d

:Files
c:\documents and settings\Owner\Application Data\Fiwecu\qiby.dat
c:\documents and settings\Owner\Application Data\Fiwecu
c:\documents and settings\Owner\Application Data\Akvea\ebafs.asq
c:\documents and settings\Owner\Application Data\Akvea
C:\WINDOWS\$NtUninstallKB21672$\302663330\L
C:\WINDOWS\$NtUninstallKB21672$\302663330\U
C:\WINDOWS\$NtUninstallKB21672$\302663330
rmdir C:\WINDOWS\$NtUninstallKB21672$ /c
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log
Well, attempted this procedure three times now and each time it clears all the icons from the desktop and displays at the bottom of the OTL window "Killing Processes… Please wait". Then it hangs. The last time I made sure I manually closed every process I practically could, and, of course the F-Secure virus SW and let it go for over an hour with no progress or change. I have had problems with the machine hanging while rebooting in the past (usually a scanner or printer driver getting an error shutting down), but it always pops up a window for manual intervention/approval in those cases. Any suggestions? . :pullhair:
Hi Mikepcap,

Try it with fix instead.

:Services

:OTL
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx
[2011/04/17 12:29:20 | 000,013,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/16 19:09:48 | 000,013,404 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867
[2011/04/14 22:47:28 | 000,000,120 | —- | C] () – C:\WINDOWS\Fqureh.dat
[2011/04/14 22:47:28 | 000,000,000 | —- | C] () – C:\WINDOWS\Tbovewipezupew.bin
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d
[2011/04/15 17:22:25 | 000,012,442 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d

:Files
c:\documents and settings\Owner\Application Data\Fiwecu\qiby.dat
c:\documents and settings\Owner\Application Data\Fiwecu
c:\documents and settings\Owner\Application Data\Akvea\ebafs.asq
c:\documents and settings\Owner\Application Data\Akvea
C:\WINDOWS\$NtUninstallKB21672$\302663330\L
C:\WINDOWS\$NtUninstallKB21672$\302663330\U
C:\WINDOWS\$NtUninstallKB21672$\302663330
rmdir C:\WINDOWS\$NtUninstallKB21672$ /c
ipconfig /flushdns /c

:Commands
[purity]
[createrestorepoint]
Sorry, was really busy yesterday.
That last set of instructions seemed to run a lot better, no hang-ups.
Here is the output. Anything exciting?


========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\Documents and Settings\Owner\Local Settings\Application Data\4y1j3m8n5fx moved successfully.
C:\Documents and Settings\All Users\Application Data\4y1j3m8n5fx moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\l068fp6ptd5np2lt166sas867 moved successfully.
C:\Documents and Settings\All Users\Application Data\l068fp6ptd5np2lt166sas867 moved successfully.
C:\WINDOWS\Fqureh.dat moved successfully.
C:\WINDOWS\Tbovewipezupew.bin moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d moved successfully.
C:\Documents and Settings\All Users\Application Data\g5qx2tpcjud266lm840m1c7310fod030x1d moved successfully.
========== FILES ==========
c:\documents and settings\Owner\Application Data\Fiwecu\qiby.dat moved successfully.
c:\documents and settings\Owner\Application Data\Fiwecu folder moved successfully.
c:\documents and settings\Owner\Application Data\Akvea\ebafs.asq moved successfully.
c:\documents and settings\Owner\Application Data\Akvea folder moved successfully.
C:\WINDOWS\$NtUninstallKB21672$\302663330\L folder moved successfully.
C:\WINDOWS\$NtUninstallKB21672$\302663330\U folder moved successfully.
C:\WINDOWS\$NtUninstallKB21672$\302663330 folder moved successfully.
< rmdir C:\WINDOWS\$NtUninstallKB21672$ /c >
C:\Documents and Settings\Owner\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Owner\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Owner\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Owner\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 12282012_185938
Hi Mikepcap,

Looks good so far. any problems?

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Next


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
Please post back with the MBAM log and ESET log if there was one.
Looks like Eset found a bunch, mostly in the incoming mail directory. Nothing in any program or doc file that I recognize. We ran it with Remove Threats unchecked, so I assume they are all still there. Malwarebytes: Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2012.12.29.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Owner :: MIKE [administrator] 12/29/2012 02:09:32 mbam-log-2012-12-29 (02-09-32).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 230559 Time elapsed: 14 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) C:\Documents and Settings\All Users\Documents\tribble2-backup\d-drive\TRIBBLC\INTERNET\WINSOCK3\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\zr0etru9.default\user.js JS/SecurityDisabler.A.Gen application C:\Eudora\attach\hsbcform.html HTML/Phishing.Gen trojan C:\Eudora\attach\PayPal - Security Measures.html HTML/Phishing.Gen trojan C:\Eudora\attach\PayPal - Security Measures1.html HTML/Fraud.AO trojan C:\Eudora\attach\PayPal_Limited_Form.html HTML/Phishing.Gen trojan C:\Eudora\attach\Personal Profile Form - PayPal-.htm HTML/Phishing.Gen trojan C:\Eudora\attach\Personal Profile Form - PayPal.htm HTML/Phishing.Gen trojan C:\Eudora\attach\Personal Profile Form - PayPal1.htm HTML/Phishing.Gen trojan C:\Eudora\attach\ReactivationForm.html HTML/Phishing.Gen trojan C:\Eudora\attach\Restore your PayPal account.html HTML/Phishing.Gen trojan C:\Eudora\attach\Restore Your PayPal Account1.html HTML/Phishing.Gen trojan C:\Eudora\attach\restore_form.html HTML/Phishing.Gen trojan C:\Eudora\attach\[removed] HTML/Phishing.Gen trojan C:\Eudora\attach\update_form.pdf PDF/WorldBusinessGuide application C:\Eudora\attach\update_form1.pdf PDF/WorldBusinessGuide application C:\Eudora\attach\Verify11.html HTML/Phishing.Gen trojan C:\Eudora\attach\Verify9.html HTML/Phishing.Gen trojan C:\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\Yzly\cygia.exe.vir a variant of Win32/Kryptik.ARGM trojan C:\Qoobox\Quarantine\C\RECYCLER\S-1-5-18\$29b3be207a05370e2d8a6576aa08d27a\n.vir a variant of Win32/Kryptik.AREI trojan C:\Qoobox\Quarantine\C\RECYCLER\S-1-5-21-376849671-2428409633-4025966157-1003\$29b3be207a05370e2d8a6576aa08d27a\n.vir a variant of Win32/Kryptik.AREI trojan C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1108\A0310009.exe Win32/Spy.Zbot.AAO trojan C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1108\A0310069.exe a variant of Win32/Kryptik.ARGM trojan C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1109\A0311677.exe a variant of Win32/Kryptik.ARGM trojan C:\tribble2-backup-c\mikes-backup\ofcc\MATT\INTERNET\WINSOCK2\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK2\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan C:\tribble2-backup-d\TRIBBLC\INTERNET\WINSOCK3\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK2\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan C:\tribble2-backup-d\TRIBBLEC\INTERNET\WINSOCK3\WINAPPS\TRUMPING.EXE Win16/Flooder.ICMP.ICMPBomb.A trojan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI