StellaLynn
Topic Starter
I got this backup '02 XP Professional computer up and running (though I'm sure there are still nasties on it I can't see). It was originally infected with "system progressive protection". Standard symptoms: no .exe files, no control panel, giving us ridiculous over-explanatory warnings like "Do you want to visit this unsecure site and allow keyloggers to send your personal info?".
First, off a self-help tutorial, I logged into safe mode w/ networking, ran rKill, and then ran mbam. Malwarebytes found 5 things to remove (fairly easy to find things any beginner could remove by just doing a windows search of the virus name), but the system was still infected with no visible change when I got back into normal mode.
Later (without turning off our firewall or disabling windows automatic virus protection, it's been awhile and I'm trying to re-learn everything I forgot a decade ago), I got into safemode w/ networking, made sure there was no proxy server listed under our IE LAN settings, ran exe-fix.bat, ran Kapersky, then rKill, then mbam. They found nothing. Somewhere along the line, windows' built in virus killer that I should have disabled said it cleaned something off the computer…and now it appears to be running fine now.
We also have a newer windows 7 computer infected with (in my novice opinion) a more malicious virus that did things like kill my alt+f4 option and make me hard boot my computer after it wouldn't even let me shut it down. I plan to post it in it's own thread like I'm supposed to after our "cleaner" computer gets fixed, I'm just trying to offer the option of starting with that computer instead if someone here thinks that would be a better idea for whatever reason. I also have the past logs from the scans above saved on this older computer if they'd be helpful.
I can't stay online past 9pm PST, but I will definitely be back each new day this takes and staying until the end of the fix. Thanks to all of you that take the time to help us all!
OTL logs from 2002 Windows XP Professional with Service Pack 3 on a 32-bit computer:
OTL.Txt:
OTL logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Services (SafeList) ==========
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys File not found
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EE 11 8B DA 82 F7 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4%7D:3.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/20 18:52:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/20 18:50:50 | 000,000,000 | —D | M]
[2013/01/08 16:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/01/10 21:02:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions
[2013/01/20 16:56:17 | 000,004,020 | —- | M] () (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
[2013/01/20 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/20 18:52:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/04 19:45:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/04 19:45:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2013/01/20 17:38:43 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] J:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = File not found
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230409023906 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05DCF09B-B7E7-470F-884D-25C0A0CAA390}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/27 12:02:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/01/20 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\CC Support Logs
[2013/01/20 18:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/20 18:31:08 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/20 17:44:07 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2013/01/20 17:33:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/01/20 17:32:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/20 17:32:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/20 17:32:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/20 17:32:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/20 17:25:39 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/20 17:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/01/20 17:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/01/12 20:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:17:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/01/12 20:17:52 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/01/12 20:17:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/12 20:15:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2013/01/11 10:50:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Scansoft
[2013/01/10 21:03:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/10 21:01:35 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2013/01/10 18:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2013/01/10 18:21:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2013/01/09 18:22:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Adobe
[2013/01/09 18:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2013/01/09 18:12:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2013/01/09 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2013/01/09 18:00:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/09 16:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\newebay
[2013/01/09 16:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\IrfanView
[2013/01/09 16:19:16 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2013/01/09 16:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Ahead
[2013/01/09 15:21:54 | 000,000,000 | R–D | C] – C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2013/01/09 14:45:03 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2013/01/09 14:45:02 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2013/01/09 12:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2013/01/09 12:40:13 | 000,779,704 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:40:12 | 000,859,072 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:40:12 | 000,260,528 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:40:06 | 000,174,000 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:40:06 | 000,173,992 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:40:06 | 000,093,640 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/01/09 12:32:01 | 020,293,080 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series User Registration
[2013/01/09 10:35:23 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/01/09 10:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2013/01/09 10:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\ScanSoft
[2013/01/09 10:34:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2013/01/09 10:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/01/09 10:34:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2013/01/09 10:34:17 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2013/01/09 10:33:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/01/09 10:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2013/01/09 10:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series Manual
[2013/01/09 10:30:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:30:45 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8U.DLL
[2013/01/09 10:30:42 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2013/01/09 10:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series
[2013/01/09 10:30:39 | 000,200,704 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470L.DLL
[2013/01/09 10:30:39 | 000,188,416 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC470O.DLL
[2013/01/09 10:30:39 | 000,098,304 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470I.DLL
[2013/01/09 10:30:38 | 001,400,832 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470C.DLL
[2013/01/09 10:30:29 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/09 10:30:02 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/08 18:04:24 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/08 18:04:24 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/08 17:35:18 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/01/08 16:59:52 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/01/08 16:59:29 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/01/08 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Mozilla
[2013/01/08 16:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Mozilla
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/21 10:34:30 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 19:55:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/01/20 19:50:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/20 19:50:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/20 17:38:43 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/01/10 18:21:42 | 000,001,771 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/01/10 18:21:42 | 000,001,765 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/01/09 18:17:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 18:00:00 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2013/01/09 17:07:40 | 000,003,584 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/09 16:19:18 | 000,000,685 | —- | M] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:39:55 | 000,093,640 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:51 | 000,260,528 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:39:50 | 000,174,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:39:50 | 000,173,992 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:39:50 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/09 12:39:49 | 000,859,072 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:39:49 | 000,779,704 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:35:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:36:55 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/09 10:27:11 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2013/01/08 18:23:34 | 000,178,648 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/08 18:08:17 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/08 18:04:25 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/08 18:04:24 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 18:34:38 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/01/20 17:33:37 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/01/20 17:33:34 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/01/20 17:32:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/20 17:32:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/20 17:32:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/20 17:32:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/20 17:32:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/10 18:21:42 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/01/10 18:21:36 | 000,001,765 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/01/09 18:17:33 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/09 18:17:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | C] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:35:39 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/01/09 10:36:55 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/18 18:42:08 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/12/13 20:37:49 | 000,003,584 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/04 10:39:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\User\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/10/15 17:00:10 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 04:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/20 17:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/09 10:30:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/04 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org
[2013/01/09 10:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ScanSoft
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.SCF >
[2004/08/04 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 21:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\iexplore.exe
< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/03/09 10:41:40 | 000,012,532 | —- | M] () MD5=C911CCDCFD72B36DCA1B99005E32E8C3 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/01/20 17:25:32 | 000,017,902 | —- | M] () MD5=353F3AB8AA9281BE6FFA467C1EBE081A – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/21 10:16:55 | 000,092,130 | —- | M] () MD5=14FFE76CCE0BD0BF18FD5851F514D5F5 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 04:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 11:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.CNF >
[2003/02/13 19:43:03 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb\_vti_pvt\services.cnf
[2003/07/15 14:54:19 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb2\_vti_pvt\services.cnf
[2003/07/15 15:10:48 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb3\_vti_pvt\services.cnf
[2003/07/15 15:27:05 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb4\_vti_pvt\services.cnf
[2003/07/15 15:32:39 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb5\_vti_pvt\services.cnf
[2003/11/05 11:58:40 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb6\_vti_pvt\services.cnf
[2003/11/05 12:00:32 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb7\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb8\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,074 | —- | M] () MD5=C781AE0262BEB173EFFB27E59A6E6F17 – C:\Documents and Settings\User\My Documents\My Webs\_vti_pvt\services.cnf
< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2008/12/27 12:03:05 | 000,001,602 | —- | M] () MD5=74AD18AA5CB38E317767841416B45580 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.RDB >
[2008/09/30 17:46:24 | 005,406,720 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2008/09/30 17:55:38 | 000,262,144 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/27 11:56:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/01/20 17:39:58 | 000,013,832 | —- | M] () – C:\ComboFix.txt
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 21:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 23:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/20 19:49:58 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2013/01/20 17:23:44 | 000,072,056 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_17.23.20_log.txt
[2013/01/20 19:28:07 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
[2013/01/20 19:30:22 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.30.02_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/12/27 12:02:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/01 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8U.DLL
[2007/04/01 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8U.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/12/27 03:51:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/12/27 03:51:12 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/12/27 03:51:12 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:03:05 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/31 10:02:48 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/31 10:02:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2010/03/05 14:15:23 | 001,688,360 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\User\Desktop\SkypeSetup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-21 02:01:40
< End of report >
Extras.Txt:
OTL Extras logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"S3" = VIA/S3G Display Driver
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTOverlay" = S3 S3Overlay
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/9/2010 2:35:03 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:35:27 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:36:48 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:13 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:42 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/9/2010 2:39:51 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:39:57 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:40:45 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:10 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:40 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
[ System Events ]
Error - 1/20/2013 10:31:27 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 10:39:24 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:35 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:51 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:20:52 PM | Computer Name = JOANIESYS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter
Error - 1/20/2013 11:27:22 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:36 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:53 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:30:39 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:49:04 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
< End of report >
First, off a self-help tutorial, I logged into safe mode w/ networking, ran rKill, and then ran mbam. Malwarebytes found 5 things to remove (fairly easy to find things any beginner could remove by just doing a windows search of the virus name), but the system was still infected with no visible change when I got back into normal mode.
Later (without turning off our firewall or disabling windows automatic virus protection, it's been awhile and I'm trying to re-learn everything I forgot a decade ago), I got into safemode w/ networking, made sure there was no proxy server listed under our IE LAN settings, ran exe-fix.bat, ran Kapersky, then rKill, then mbam. They found nothing. Somewhere along the line, windows' built in virus killer that I should have disabled said it cleaned something off the computer…and now it appears to be running fine now.
We also have a newer windows 7 computer infected with (in my novice opinion) a more malicious virus that did things like kill my alt+f4 option and make me hard boot my computer after it wouldn't even let me shut it down. I plan to post it in it's own thread like I'm supposed to after our "cleaner" computer gets fixed, I'm just trying to offer the option of starting with that computer instead if someone here thinks that would be a better idea for whatever reason. I also have the past logs from the scans above saved on this older computer if they'd be helpful.
I can't stay online past 9pm PST, but I will definitely be back each new day this takes and staying until the end of the fix. Thanks to all of you that take the time to help us all!
OTL logs from 2002 Windows XP Professional with Service Pack 3 on a 32-bit computer:
OTL.Txt:
OTL logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Services (SafeList) ==========
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys File not found
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EE 11 8B DA 82 F7 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4%7D:3.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/20 18:52:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/20 18:50:50 | 000,000,000 | —D | M]
[2013/01/08 16:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/01/10 21:02:47 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions
[2013/01/20 16:56:17 | 000,004,020 | —- | M] () (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi
[2013/01/20 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/20 18:52:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/04 19:45:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/04 19:45:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2013/01/20 17:38:43 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] J:\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = File not found
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230409023906 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05DCF09B-B7E7-470F-884D-25C0A0CAA390}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/27 12:02:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/01/20 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\CC Support Logs
[2013/01/20 18:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/20 18:31:08 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/20 17:44:07 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2013/01/20 17:33:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/01/20 17:32:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/20 17:32:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/20 17:32:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/20 17:32:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/20 17:25:39 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/20 17:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/01/20 17:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/01/12 20:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:17:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/01/12 20:17:52 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/01/12 20:17:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/12 20:15:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2013/01/11 10:50:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Scansoft
[2013/01/10 21:03:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/10 21:01:35 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2013/01/10 18:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2013/01/10 18:21:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2013/01/09 18:22:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Adobe
[2013/01/09 18:18:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2013/01/09 18:12:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2013/01/09 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2013/01/09 18:00:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/09 16:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\newebay
[2013/01/09 16:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\IrfanView
[2013/01/09 16:19:16 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2013/01/09 16:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Ahead
[2013/01/09 15:21:54 | 000,000,000 | R–D | C] – C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2013/01/09 14:45:03 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2013/01/09 14:45:02 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2013/01/09 12:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2013/01/09 12:40:13 | 000,779,704 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:40:12 | 000,859,072 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:40:12 | 000,260,528 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:40:06 | 000,174,000 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:40:06 | 000,173,992 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:40:06 | 000,093,640 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/01/09 12:32:01 | 020,293,080 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series User Registration
[2013/01/09 10:35:23 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/01/09 10:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2013/01/09 10:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\ScanSoft
[2013/01/09 10:34:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2013/01/09 10:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/01/09 10:34:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2013/01/09 10:34:17 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2013/01/09 10:33:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/01/09 10:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2013/01/09 10:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series Manual
[2013/01/09 10:30:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:30:45 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8U.DLL
[2013/01/09 10:30:42 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2013/01/09 10:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series
[2013/01/09 10:30:39 | 000,200,704 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470L.DLL
[2013/01/09 10:30:39 | 000,188,416 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC470O.DLL
[2013/01/09 10:30:39 | 000,098,304 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470I.DLL
[2013/01/09 10:30:38 | 001,400,832 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470C.DLL
[2013/01/09 10:30:29 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/09 10:30:02 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/08 18:04:24 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/08 18:04:24 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/08 17:35:18 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/01/08 16:59:52 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/01/08 16:59:29 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/01/08 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Mozilla
[2013/01/08 16:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Mozilla
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/21 10:34:30 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 19:55:15 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/01/20 19:50:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/20 19:50:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/20 17:38:43 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/01/10 18:21:42 | 000,001,771 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/01/10 18:21:42 | 000,001,765 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/01/09 18:17:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 18:00:00 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2013/01/09 17:07:40 | 000,003,584 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/09 16:19:18 | 000,000,685 | —- | M] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:39:55 | 000,093,640 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:51 | 000,260,528 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:39:50 | 000,174,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:39:50 | 000,173,992 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:39:50 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/09 12:39:49 | 000,859,072 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:39:49 | 000,779,704 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:35:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:36:55 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/09 10:27:11 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2013/01/08 18:23:34 | 000,178,648 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/08 18:08:17 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/08 18:04:25 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/08 18:04:24 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 18:34:38 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/01/20 17:33:37 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/01/20 17:33:34 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/01/20 17:32:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/20 17:32:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/20 17:32:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/20 17:32:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/20 17:32:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/10 18:21:42 | 000,001,771 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/01/10 18:21:36 | 000,001,765 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/01/09 18:17:33 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/09 18:17:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | C] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:35:39 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/01/09 10:36:55 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/18 18:42:08 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/12/13 20:37:49 | 000,003,584 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/04 10:39:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\User\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/10/15 17:00:10 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 04:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/20 17:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/09 10:30:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/04 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org
[2013/01/09 10:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ScanSoft
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.SCF >
[2004/08/04 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 21:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\iexplore.exe
< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/03/09 10:41:40 | 000,012,532 | —- | M] () MD5=C911CCDCFD72B36DCA1B99005E32E8C3 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/01/20 17:25:32 | 000,017,902 | —- | M] () MD5=353F3AB8AA9281BE6FFA467C1EBE081A – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/21 10:16:55 | 000,092,130 | —- | M] () MD5=14FFE76CCE0BD0BF18FD5851F514D5F5 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 04:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 11:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.CNF >
[2003/02/13 19:43:03 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb\_vti_pvt\services.cnf
[2003/07/15 14:54:19 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb2\_vti_pvt\services.cnf
[2003/07/15 15:10:48 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb3\_vti_pvt\services.cnf
[2003/07/15 15:27:05 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb4\_vti_pvt\services.cnf
[2003/07/15 15:32:39 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb5\_vti_pvt\services.cnf
[2003/11/05 11:58:40 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb6\_vti_pvt\services.cnf
[2003/11/05 12:00:32 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb7\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb8\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,074 | —- | M] () MD5=C781AE0262BEB173EFFB27E59A6E6F17 – C:\Documents and Settings\User\My Documents\My Webs\_vti_pvt\services.cnf
< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2008/12/27 12:03:05 | 000,001,602 | —- | M] () MD5=74AD18AA5CB38E317767841416B45580 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.RDB >
[2008/09/30 17:46:24 | 005,406,720 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2008/09/30 17:55:38 | 000,262,144 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/27 11:56:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/01/20 17:39:58 | 000,013,832 | —- | M] () – C:\ComboFix.txt
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 21:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 23:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/20 19:49:58 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2013/01/20 17:23:44 | 000,072,056 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_17.23.20_log.txt
[2013/01/20 19:28:07 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
[2013/01/20 19:30:22 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.30.02_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/12/27 12:02:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/01 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8U.DLL
[2007/04/01 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8U.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/12/27 03:51:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/12/27 03:51:12 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/12/27 03:51:12 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:03:05 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/31 10:02:48 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/31 10:02:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2010/03/05 14:15:23 | 001,688,360 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\User\Desktop\SkypeSetup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-21 02:01:40
< End of report >
Extras.Txt:
OTL Extras logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"S3" = VIA/S3G Display Driver
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTOverlay" = S3 S3Overlay
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/9/2010 2:35:03 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:35:27 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:36:48 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:13 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:42 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/9/2010 2:39:51 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:39:57 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:40:45 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:10 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:40 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
[ System Events ]
Error - 1/20/2013 10:31:27 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 10:39:24 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:35 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:51 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:20:52 PM | Computer Name = JOANIESYS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter
Error - 1/20/2013 11:27:22 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:36 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:53 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:30:39 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:49:04 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
< End of report >