StellaLynn
Reset IE and Firefox, (don't have chrome) haven't seen any redirects.
I see the OTL.txt that popped up, but the extras didn't. When I checked in the folder it still has the log from the 21st in the same file folder as the new log from today.
ComboFix 13-01-28.02 - User 01/28/2013 14:19:43.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.668 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi"
.
.
((((((((((((((((((((((((( Files Created from 2012-12-28 to 2013-01-28 )))))))))))))))))))))))))))))))
.
.
2013-01-27 19:21 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E9EABE9A-32FF-4736-A752-27846C720B72}\mpengine.dll
2013-01-27 18:10 . 2013-01-27 18:10 ——– d—–w- c:\program files\ERUNT
2013-01-27 18:03 . 2013-01-27 18:03 ——– d—–w- C:\i386
2013-01-26 18:39 . 2013-01-26 18:39 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-26 18:39 . 2013-01-26 18:39 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-21 01:44 . 2013-01-21 01:44 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\PCHealth
2013-01-21 01:08 . 2013-01-21 01:08 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-13 04:17 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-01-13 04:15 . 2013-01-21 03:20 ——– d—–w- c:\documents and settings\Administrator
2013-01-11 18:50 . 2013-01-11 18:50 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Scansoft
2013-01-11 05:03 . 2013-01-21 01:18 ——– d—–w- c:\documents and settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
2013-01-11 05:01 . 2013-01-11 05:01 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Sun
2013-01-11 02:22 . 2013-01-11 02:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2013-01-10 02:22 . 2013-01-10 02:22 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2013-01-10 02:16 . 2013-01-10 02:16 ——– d—–w- c:\program files\Common Files\Adobe
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 00:19 . 2013-01-10 00:19 ——– d—–w- c:\program files\IrfanView
2013-01-10 00:02 . 2013-01-10 00:02 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ahead
2013-01-09 22:45 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2013-01-09 22:45 . 2008-04-14 13:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2013-01-09 20:40 . 2013-01-09 20:39 779704 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 859072 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 93640 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 20:39 . 2013-01-09 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2013-01-09 20:35 . 2013-01-22 02:27 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-01-09 18:37 . 2013-01-09 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2013-01-09 18:35 . 2008-04-14 08:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2013-01-09 18:35 . 2008-04-14 08:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\User\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\ScanSoft
2013-01-09 18:33 . 2013-01-09 18:33 ——– d—–w- c:\program files\Common Files\CANON
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2013-01-09 18:30 . 2007-04-02 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 215040 —-a-w- c:\windows\system32\CNMLM8U.DLL
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-09 18:30 . 2007-03-23 16:29 98304 —-a-w- c:\windows\system32\CNC470I.DLL
2013-01-09 18:30 . 2007-03-19 10:21 200704 —-a-w- c:\windows\system32\CNC470L.DLL
2013-01-09 18:30 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNC470O.DLL
2013-01-09 18:30 . 2007-03-23 16:30 1400832 —-a-w- c:\windows\system32\CNC470C.DLL
2013-01-09 18:30 . 2013-01-09 18:37 ——– d—–w- c:\program files\Canon
2013-01-09 01:35 . 2012-11-01 12:17 521728 -c—-w- c:\windows\system32\dllcache\jsdbgui.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-01-09 01:30 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-09 00:59 . 2008-04-14 08:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2013-01-09 00:04 . 2013-01-09 00:04 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 20:39 . 2008-12-27 20:36 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-12-16 12:23 . 2008-04-14 12:39 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2008-04-14 08:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01 . 2008-04-14 12:42 1371648 —-a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02 . 2008-04-14 12:41 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 12:42 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 12:42 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 12:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 07:07 385024 —-a-w- c:\windows\system32\html.iec
2013-01-21 02:52 . 2013-01-21 02:50 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-27 c:\windows\Tasks\defrag.job
- c:\windows\system32\cmd.exe [2008-04-14 12:42]
.
2013-01-28 c:\windows\Tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w4nexsx6.default-1359407675069\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-28 14:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4056)
c:\windows\system32\WININET.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2013-01-28 14:25:20
ComboFix-quarantined-files.txt 2013-01-28 22:25
ComboFix2.txt 2013-01-27 18:23
ComboFix3.txt 2013-01-25 03:51
ComboFix4.txt 2013-01-23 23:30
.
Pre-Run: 65,050,263,552 bytes free
Post-Run: 65,067,622,400 bytes free
.
- - End Of File - - CB2B0347B3E8F07ABCA67917912AFF49
OTL logfile created on: 1/28/2013 2:40:50 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 550.23 Mb Available Physical Memory | 57.35% Memory free
2.26 Gb Paging File | 1.97 Gb Available in Paging File | 86.98% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 60.62 Gb Free Space | 79.43% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mbr) – C:\ComboFix\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys File not found
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 7A B4 2F 9C FD CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/20 18:52:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/20 18:50:50 | 000,000,000 | —D | M]
[2013/01/08 16:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/01/20 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/20 18:52:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/04 19:45:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/04 19:45:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2013/01/27 10:22:32 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230409023906 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05DCF09B-B7E7-470F-884D-25C0A0CAA390}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/27 12:02:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/01/28 14:39:11 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/28 14:25:22 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/01/28 13:14:41 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Old Firefox Data
[2013/01/27 10:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/01/27 10:10:09 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/01/27 10:03:19 | 000,000,000 | —D | C] – C:\i386
[2013/01/26 10:39:33 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/26 10:39:33 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/24 15:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Krystal
[2013/01/23 14:47:18 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/20 19:12:12 | 005,028,084 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/20 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\CC Support Logs
[2013/01/20 18:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/20 17:44:07 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2013/01/20 17:33:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/01/20 17:32:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/20 17:32:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/20 17:32:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/20 17:32:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/20 17:25:39 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/20 17:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/01/20 17:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/01/12 20:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:17:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/01/12 20:17:52 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/01/12 20:17:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/12 20:15:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2013/01/11 10:50:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Scansoft
[2013/01/10 21:03:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/10 21:01:35 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2013/01/10 18:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2013/01/09 18:22:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2013/01/09 18:12:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2013/01/09 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2013/01/09 18:00:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/09 16:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\newebay
[2013/01/09 16:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\IrfanView
[2013/01/09 16:19:16 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2013/01/09 16:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Ahead
[2013/01/09 15:21:54 | 000,000,000 | R–D | C] – C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2013/01/09 14:45:03 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2013/01/09 14:45:02 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2013/01/09 12:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2013/01/09 12:40:13 | 000,779,704 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:40:12 | 000,859,072 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:40:12 | 000,260,528 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:40:06 | 000,174,000 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:40:06 | 000,173,992 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:40:06 | 000,093,640 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/01/09 12:32:01 | 020,293,080 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series User Registration
[2013/01/09 10:35:23 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/01/09 10:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2013/01/09 10:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\ScanSoft
[2013/01/09 10:34:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2013/01/09 10:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/01/09 10:34:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2013/01/09 10:34:17 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2013/01/09 10:33:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/01/09 10:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2013/01/09 10:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series Manual
[2013/01/09 10:30:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:30:45 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8U.DLL
[2013/01/09 10:30:42 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2013/01/09 10:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series
[2013/01/09 10:30:39 | 000,200,704 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470L.DLL
[2013/01/09 10:30:39 | 000,188,416 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC470O.DLL
[2013/01/09 10:30:39 | 000,098,304 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470I.DLL
[2013/01/09 10:30:38 | 001,400,832 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470C.DLL
[2013/01/09 10:30:29 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/09 10:30:02 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/08 17:35:18 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/01/08 16:59:52 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/01/08 16:59:29 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/01/08 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Mozilla
[2013/01/08 16:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Mozilla
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/28 14:17:50 | 005,028,084 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/28 13:17:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/28 13:17:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/28 13:12:39 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
[2013/01/27 11:06:01 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2013/01/27 10:22:32 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/27 10:12:50 | 000,000,128 | —- | M] () – C:\Documents and Settings\User\Desktop\fix.reg
[2013/01/27 10:10:14 | 000,000,611 | —- | M] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2013/01/27 10:10:14 | 000,000,592 | —- | M] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2013/01/27 10:03:17 | 000,005,120 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/26 18:00:00 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2013/01/26 10:39:33 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/26 10:39:33 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/23 14:48:28 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/01/09 18:17:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | M] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:39:55 | 000,093,640 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:51 | 000,260,528 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:39:50 | 000,174,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:39:50 | 000,173,992 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:39:50 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/09 12:39:49 | 000,859,072 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:39:49 | 000,779,704 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:35:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:36:55 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 18:23:34 | 000,178,648 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/08 18:08:24 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/07 08:02:00 | 000,365,568 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2013/01/05 21:34:35 | 006,009,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/27 10:12:50 | 000,000,128 | —- | C] () – C:\Documents and Settings\User\Desktop\fix.reg
[2013/01/27 10:10:14 | 000,000,611 | —- | C] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2013/01/27 10:10:14 | 000,000,592 | —- | C] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2013/01/24 18:27:06 | 000,365,568 | —- | C] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 17:33:37 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/01/20 17:33:34 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/01/20 17:32:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/20 17:32:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/20 17:32:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/20 17:32:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/20 17:32:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/09 18:17:33 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/09 18:17:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | C] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:35:39 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/01/09 10:36:55 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/18 18:42:08 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/12/13 20:37:49 | 000,005,120 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/04 10:39:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\User\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/10/15 17:00:10 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 04:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/20 17:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/09 10:30:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/04 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org
[2013/01/09 10:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ScanSoft
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2013/01/27 10:24:01 | 000,080,380 | —- | M] () MD5=991AC060CF34A96D8A01DA84AFA825B0 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SCF >
[2004/08/04 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 21:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\iexplore.exe
[2013/01/20 17:23:08 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) MD5=EBC984F0CE40E0DAF0454D806EC2A7EC – C:\Documents and Settings\User\My Documents\Krystal\Tools\iexplore.exe
< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/03/09 10:41:40 | 000,012,532 | —- | M] () MD5=C911CCDCFD72B36DCA1B99005E32E8C3 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/01/28 14:18:09 | 000,018,278 | —- | M] () MD5=5C8F427E11D21C2D6B394B361F056C23 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf
< MD5 for: IEXPLORE.EXE-12915967.PF >
[2013/01/28 14:18:08 | 000,020,818 | —- | M] () MD5=DD4967A5F334C850A217DDFD387DBFBA – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf
< MD5 for: IEXPLORE.EXE-12BBAE74.PF >
[2013/01/28 14:18:13 | 000,010,934 | —- | M] () MD5=0E1B1FF6DE6C718FC105984E9D5C7915 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/28 14:10:24 | 000,106,246 | —- | M] () MD5=124AC62710C150D484B4EEBB592DE905 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 04:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 11:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.CNF >
[2003/02/13 19:43:03 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb\_vti_pvt\services.cnf
[2003/07/15 14:54:19 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb2\_vti_pvt\services.cnf
[2003/07/15 15:10:48 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb3\_vti_pvt\services.cnf
[2003/07/15 15:27:05 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb4\_vti_pvt\services.cnf
[2003/07/15 15:32:39 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb5\_vti_pvt\services.cnf
[2003/11/05 11:58:40 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb6\_vti_pvt\services.cnf
[2003/11/05 12:00:32 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb7\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb8\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,074 | —- | M] () MD5=C781AE0262BEB173EFFB27E59A6E6F17 – C:\Documents and Settings\User\My Documents\My Webs\_vti_pvt\services.cnf
< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2008/12/27 12:03:05 | 000,001,602 | —- | M] () MD5=74AD18AA5CB38E317767841416B45580 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.RDB >
[2008/09/30 17:46:24 | 005,406,720 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2008/09/30 17:55:38 | 000,262,144 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/27 11:56:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/01/28 14:25:20 | 000,010,851 | —- | M] () – C:\ComboFix.txt
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 21:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 23:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/28 13:16:57 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2013/01/20 17:23:44 | 000,072,056 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_17.23.20_log.txt
[2013/01/20 19:28:07 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
[2013/01/20 19:30:22 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.30.02_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/12/27 12:02:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/01 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8U.DLL
[2007/04/01 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8U.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/12/27 03:51:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/12/27 03:51:12 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/12/27 03:51:12 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:03:05 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/31 10:02:48 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/31 10:02:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2013/01/23 14:48:28 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/28 14:17:50 | 005,028,084 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/07 08:02:00 | 000,365,568 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2010/03/05 14:15:23 | 001,688,360 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\User\Desktop\SkypeSetup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-22 02:01:10
< End of report >
OTL Extras logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"S3" = VIA/S3G Display Driver
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTOverlay" = S3 S3Overlay
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/9/2010 2:35:03 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:35:27 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:36:48 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:13 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:42 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/9/2010 2:39:51 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:39:57 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:40:45 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:10 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:40 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
[ System Events ]
Error - 1/20/2013 10:31:27 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 10:39:24 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:35 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:51 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:20:52 PM | Computer Name = JOANIESYS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter
Error - 1/20/2013 11:27:22 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:36 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:53 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:30:39 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:49:04 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
< End of report >
I see the OTL.txt that popped up, but the extras didn't. When I checked in the folder it still has the log from the 21st in the same file folder as the new log from today.
ComboFix 13-01-28.02 - User 01/28/2013 14:19:43.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.668 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w3jvr33j.default\extensions\{3d0ca2b9-a54e-4f4b-81ad-6edbdfcd2ee4}.xpi"
.
.
((((((((((((((((((((((((( Files Created from 2012-12-28 to 2013-01-28 )))))))))))))))))))))))))))))))
.
.
2013-01-27 19:21 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E9EABE9A-32FF-4736-A752-27846C720B72}\mpengine.dll
2013-01-27 18:10 . 2013-01-27 18:10 ——– d—–w- c:\program files\ERUNT
2013-01-27 18:03 . 2013-01-27 18:03 ——– d—–w- C:\i386
2013-01-26 18:39 . 2013-01-26 18:39 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-26 18:39 . 2013-01-26 18:39 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-21 01:44 . 2013-01-21 01:44 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\PCHealth
2013-01-21 01:08 . 2013-01-21 01:08 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-01-13 04:17 . 2013-01-13 04:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-01-13 04:17 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-01-13 04:15 . 2013-01-21 03:20 ——– d—–w- c:\documents and settings\Administrator
2013-01-11 18:50 . 2013-01-11 18:50 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Scansoft
2013-01-11 05:03 . 2013-01-21 01:18 ——– d—–w- c:\documents and settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
2013-01-11 05:01 . 2013-01-11 05:01 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Sun
2013-01-11 02:22 . 2013-01-11 02:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2013-01-10 02:22 . 2013-01-10 02:22 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2013-01-10 02:16 . 2013-01-10 02:16 ——– d—–w- c:\program files\Common Files\Adobe
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2013-01-10 02:00 . 2013-01-10 02:00 ——– d—–w- c:\program files\MSXML 4.0
2013-01-10 00:19 . 2013-01-10 00:19 ——– d—–w- c:\program files\IrfanView
2013-01-10 00:02 . 2013-01-10 00:02 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ahead
2013-01-09 22:45 . 2001-08-18 06:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2013-01-09 22:45 . 2008-04-14 13:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2013-01-09 20:40 . 2013-01-09 20:39 779704 —-a-w- c:\windows\system32\deployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 859072 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-09 20:40 . 2013-01-09 20:39 93640 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-09 20:39 . 2013-01-09 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2013-01-09 20:35 . 2013-01-22 02:27 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-01-09 18:37 . 2013-01-09 18:37 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2013-01-09 18:35 . 2008-04-14 08:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2013-01-09 18:35 . 2008-04-14 08:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\User\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2013-01-09 18:34 . 2013-01-09 18:34 ——– d—–w- c:\program files\ScanSoft
2013-01-09 18:33 . 2013-01-09 18:33 ——– d—–w- c:\program files\Common Files\CANON
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2013-01-09 18:30 . 2007-04-02 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2013-01-09 18:30 . 2007-04-02 05:00 215040 —-a-w- c:\windows\system32\CNMLM8U.DLL
2013-01-09 18:30 . 2013-01-09 18:30 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-09 18:30 . 2007-03-23 16:29 98304 —-a-w- c:\windows\system32\CNC470I.DLL
2013-01-09 18:30 . 2007-03-19 10:21 200704 —-a-w- c:\windows\system32\CNC470L.DLL
2013-01-09 18:30 . 2007-03-15 14:12 188416 —-a-w- c:\windows\system32\CNC470O.DLL
2013-01-09 18:30 . 2007-03-23 16:30 1400832 —-a-w- c:\windows\system32\CNC470C.DLL
2013-01-09 18:30 . 2013-01-09 18:37 ——– d—–w- c:\program files\Canon
2013-01-09 01:35 . 2012-11-01 12:17 521728 -c—-w- c:\windows\system32\dllcache\jsdbgui.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll
2013-01-09 01:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-01-09 01:30 . 2013-01-08 04:57 6991832 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-09 00:59 . 2008-04-14 08:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2013-01-09 00:59 . 2008-04-14 08:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2013-01-09 00:04 . 2013-01-09 00:04 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Mozilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 20:39 . 2008-12-27 20:36 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-12-16 12:23 . 2008-04-14 12:39 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-13 01:25 . 2008-04-14 08:00 1866368 —-a-w- c:\windows\system32\win32k.sys
2012-11-06 02:01 . 2008-04-14 12:42 1371648 —-a-w- c:\windows\system32\msxml6.dll
2012-11-02 02:02 . 2008-04-14 12:41 375296 —-a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 12:42 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-01 12:17 . 2008-04-14 12:42 916992 —-a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 12:41 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-11-01 00:35 . 2008-04-14 07:07 385024 —-a-w- c:\windows\system32\html.iec
2013-01-21 02:52 . 2013-01-21 02:50 262552 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-18 946352]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-27 c:\windows\Tasks\defrag.job
- c:\windows\system32\cmd.exe [2008-04-14 12:42]
.
2013-01-28 c:\windows\Tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w4nexsx6.default-1359407675069\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-28 14:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4056)
c:\windows\system32\WININET.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2013-01-28 14:25:20
ComboFix-quarantined-files.txt 2013-01-28 22:25
ComboFix2.txt 2013-01-27 18:23
ComboFix3.txt 2013-01-25 03:51
ComboFix4.txt 2013-01-23 23:30
.
Pre-Run: 65,050,263,552 bytes free
Post-Run: 65,067,622,400 bytes free
.
- - End Of File - - CB2B0347B3E8F07ABCA67917912AFF49
OTL logfile created on: 1/28/2013 2:40:50 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 550.23 Mb Available Physical Memory | 57.35% Memory free
2.26 Gb Paging File | 1.97 Gb Available in Paging File | 86.98% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 60.62 Gb Free Space | 79.43% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\User\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (Agere Systems)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mbr) – C:\ComboFix\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\DOCUME~1\User\LOCALS~1\Temp\catchme.sys File not found
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ALCXWDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D8 7A B4 2F 9C FD CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/20 18:52:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/20 18:50:50 | 000,000,000 | —D | M]
[2013/01/08 16:04:52 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/01/20 18:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/20 18:52:01 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/04 19:45:12 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/04 19:45:12 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2013/01/27 10:22:32 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1230409023906 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{05DCF09B-B7E7-470F-884D-25C0A0CAA390}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/27 12:02:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/01/28 14:39:11 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2013/01/28 14:25:22 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/01/28 13:14:41 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\Old Firefox Data
[2013/01/27 10:10:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/01/27 10:10:09 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/01/27 10:03:19 | 000,000,000 | —D | C] – C:\i386
[2013/01/26 10:39:33 | 000,697,864 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/26 10:39:33 | 000,074,248 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/24 15:04:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Krystal
[2013/01/23 14:47:18 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/20 19:12:12 | 005,028,084 | R— | C] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/20 19:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop\CC Support Logs
[2013/01/20 18:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/20 17:44:07 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\PCHealth
[2013/01/20 17:33:34 | 000,000,000 | RHSD | C] – C:\cmdcons
[2013/01/20 17:32:27 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/01/20 17:32:27 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/01/20 17:32:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/01/20 17:32:27 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/01/20 17:25:39 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/20 17:25:25 | 000,000,000 | —D | C] – C:\WINDOWS\erdnt
[2013/01/20 17:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/01/12 20:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/12 20:17:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/01/12 20:17:52 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/01/12 20:17:52 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/12 20:15:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2013/01/11 10:50:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Scansoft
[2013/01/10 21:03:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/10 21:01:35 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Sun
[2013/01/10 18:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\McAfee
[2013/01/09 18:22:31 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2013/01/09 18:16:12 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2013/01/09 18:12:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2013/01/09 18:00:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2013/01/09 18:00:27 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/09 16:46:19 | 000,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\newebay
[2013/01/09 16:19:18 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Start Menu\Programs\IrfanView
[2013/01/09 16:19:16 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2013/01/09 16:02:29 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Ahead
[2013/01/09 15:21:54 | 000,000,000 | R–D | C] – C:\Documents and Settings\User\Start Menu\Programs\Administrative Tools
[2013/01/09 14:45:03 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2013/01/09 14:45:02 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2013/01/09 12:40:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2013/01/09 12:40:13 | 000,779,704 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:40:12 | 000,859,072 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:40:12 | 000,260,528 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:40:06 | 000,174,000 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:40:06 | 000,173,992 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:40:06 | 000,093,640 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/01/09 12:35:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/01/09 12:32:01 | 020,293,080 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:36:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series User Registration
[2013/01/09 10:35:23 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2013/01/09 10:34:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2013/01/09 10:34:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\ScanSoft
[2013/01/09 10:34:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2013/01/09 10:34:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/01/09 10:34:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2013/01/09 10:34:17 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2013/01/09 10:33:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/01/09 10:31:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2013/01/09 10:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series Manual
[2013/01/09 10:30:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:30:45 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8U.DLL
[2013/01/09 10:30:42 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2013/01/09 10:30:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP470 series
[2013/01/09 10:30:39 | 000,200,704 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470L.DLL
[2013/01/09 10:30:39 | 000,188,416 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC470O.DLL
[2013/01/09 10:30:39 | 000,098,304 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470I.DLL
[2013/01/09 10:30:38 | 001,400,832 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC470C.DLL
[2013/01/09 10:30:29 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/01/09 10:30:02 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/01/08 17:35:18 | 000,521,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsdbgui.dll
[2013/01/08 16:59:52 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2013/01/08 16:59:29 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2013/01/08 16:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Mozilla
[2013/01/08 16:04:48 | 000,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Mozilla
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/28 14:17:50 | 005,028,084 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/28 13:17:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/28 13:17:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/28 13:12:39 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0AD6E957-5295-4ABC-999F-6DDB91F18EE8}.job
[2013/01/27 11:06:01 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2013/01/27 10:22:32 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2013/01/27 10:12:50 | 000,000,128 | —- | M] () – C:\Documents and Settings\User\Desktop\fix.reg
[2013/01/27 10:10:14 | 000,000,611 | —- | M] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2013/01/27 10:10:14 | 000,000,592 | —- | M] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2013/01/27 10:03:17 | 000,005,120 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/26 18:00:00 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\defrag.job
[2013/01/26 10:39:33 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/01/26 10:39:33 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/01/23 14:48:28 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2013/01/09 18:17:34 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | M] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:39:55 | 000,093,640 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/01/09 12:39:51 | 000,260,528 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/01/09 12:39:50 | 000,174,000 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/01/09 12:39:50 | 000,173,992 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/01/09 12:39:50 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/09 12:39:49 | 000,859,072 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/01/09 12:39:49 | 000,779,704 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/09 12:35:39 | 000,000,742 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/09 10:36:55 | 000,001,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | M] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | M] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 18:23:34 | 000,178,648 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/08 18:08:24 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/07 08:02:00 | 000,365,568 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2013/01/05 21:34:35 | 006,009,856 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/27 10:12:50 | 000,000,128 | —- | C] () – C:\Documents and Settings\User\Desktop\fix.reg
[2013/01/27 10:10:14 | 000,000,611 | —- | C] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2013/01/27 10:10:14 | 000,000,592 | —- | C] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2013/01/24 18:27:06 | 000,365,568 | —- | C] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2013/01/20 20:35:49 | 000,000,442 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/20 17:33:37 | 000,000,211 | —- | C] () – C:\Boot.bak
[2013/01/20 17:33:34 | 000,260,272 | RHS- | C] () – C:\cmldr
[2013/01/20 17:32:27 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/01/20 17:32:27 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/01/20 17:32:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/01/20 17:32:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/01/20 17:32:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/01/09 18:17:33 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/01/09 18:17:33 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2013/01/09 16:19:18 | 000,000,685 | —- | C] () – C:\Documents and Settings\User\Desktop\IrfanView.lnk
[2013/01/09 12:35:39 | 000,000,742 | —- | C] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/01/09 12:35:39 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2013/01/09 10:36:55 | 000,001,685 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP470 series User Registration.LNK
[2013/01/09 10:34:52 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2013/01/09 10:32:37 | 000,001,644 | —- | C] () – C:\Documents and Settings\All Users\Desktop\My Printer.lnk
[2013/01/09 10:32:25 | 000,001,680 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon Solution Menu.lnk
[2013/01/09 10:32:15 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Easy-PhotoPrint EX.lnk
[2013/01/09 10:31:29 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP Navigator EX 1.0.lnk
[2013/01/09 10:30:59 | 000,001,914 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MP470 series On-screen Manual.lnk
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2013/01/08 17:34:57 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/12/18 18:42:08 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/12/13 20:37:49 | 000,005,120 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/04 10:39:37 | 000,000,000 | —- | C] () – C:\Documents and Settings\User\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/10/15 17:00:10 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 04:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/14 04:42:10 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/01/20 17:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\7CC910FC505D677500007CC894386C25
[2013/01/09 10:30:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2013/01/09 10:37:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2013/01/09 10:34:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/12/04 11:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org
[2013/01/09 10:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ScanSoft
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2013/01/27 10:24:01 | 000,080,380 | —- | M] () MD5=991AC060CF34A96D8A01DA84AFA825B0 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.SCF >
[2004/08/04 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2007/04/02 21:09:24 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/28 23:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 21:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2008/10/14 22:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2QFE\iexplore.exe
[2009/04/24 21:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 21:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2008/08/22 21:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/06/29 00:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 04:42:24 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/10/14 23:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\SoftwareDistribution\Download\c74979a750f473b6d9d8ef0bba9b356c\SP2GDR\iexplore.exe
[2009/02/27 20:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\erdnt\cache\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/27 20:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 21:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2008/08/22 21:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\iexplore.exe
[2013/01/20 17:23:08 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) MD5=EBC984F0CE40E0DAF0454D806EC2A7EC – C:\Documents and Settings\User\My Documents\Krystal\Tools\iexplore.exe
< MD5 for: IEXPLORE.EXE.EXP.LOG >
[2010/03/09 10:41:40 | 000,012,532 | —- | M] () MD5=C911CCDCFD72B36DCA1B99005E32E8C3 – C:\Program Files\Internet Explorer\iexplore.exe.exp.log
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-0A31FE70.PF >
[2013/01/28 14:18:09 | 000,018,278 | —- | M] () MD5=5C8F427E11D21C2D6B394B361F056C23 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf
< MD5 for: IEXPLORE.EXE-12915967.PF >
[2013/01/28 14:18:08 | 000,020,818 | —- | M] () MD5=DD4967A5F334C850A217DDFD387DBFBA – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf
< MD5 for: IEXPLORE.EXE-12BBAE74.PF >
[2013/01/28 14:18:13 | 000,010,934 | —- | M] () MD5=0E1B1FF6DE6C718FC105984E9D5C7915 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2013/01/28 14:10:24 | 000,106,246 | —- | M] () MD5=124AC62710C150D484B4EEBB592DE905 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.HLP >
[2004/08/04 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 04:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 11:08:30 | 000,559,043 | —- | M] () MD5=BA25E8F1460C7453B7488FE4B42F6919 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.CNF >
[2003/02/13 19:43:03 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb\_vti_pvt\services.cnf
[2003/07/15 14:54:19 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb2\_vti_pvt\services.cnf
[2003/07/15 15:10:48 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb3\_vti_pvt\services.cnf
[2003/07/15 15:27:05 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb4\_vti_pvt\services.cnf
[2003/07/15 15:32:39 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb5\_vti_pvt\services.cnf
[2003/11/05 11:58:40 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb6\_vti_pvt\services.cnf
[2003/11/05 12:00:32 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb7\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,003 | —- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 – C:\Documents and Settings\User\My Documents\My Webs\myweb8\_vti_pvt\services.cnf
[2003/11/05 12:01:38 | 000,000,074 | —- | M] () MD5=C781AE0262BEB173EFFB27E59A6E6F17 – C:\Documents and Settings\User\My Documents\My Webs\_vti_pvt\services.cnf
< MD5 for: SERVICES.EXE >
[2009/02/06 03:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 04:42:36 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\erdnt\cache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2008/12/27 12:03:05 | 000,001,602 | —- | M] () MD5=74AD18AA5CB38E317767841416B45580 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 04:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.RDB >
[2008/09/30 17:46:24 | 005,406,720 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb
[2008/09/30 17:55:38 | 000,262,144 | —- | M] () MD5=26ADA4D35A087DA76A00253AA882F694 – C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 04:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/27 11:56:48 | 000,000,211 | —- | M] () – C:\Boot.bak
[2013/01/20 17:33:37 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2013/01/28 14:25:20 | 000,010,851 | —- | M] () – C:\ComboFix.txt
[2008/12/27 12:02:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/12/27 12:02:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/13 21:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/13 23:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/01/28 13:16:57 | 1509,138,432 | -HS- | M] () – C:\pagefile.sys
[2013/01/20 17:23:44 | 000,072,056 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_17.23.20_log.txt
[2013/01/20 19:28:07 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.27.41_log.txt
[2013/01/20 19:30:22 | 000,072,852 | —- | M] () – C:\TDSSKiller.2.8.15.0_20.01.2013_19.30.02_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/12/27 12:02:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/01 21:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD8U.DLL
[2007/04/01 21:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP8U.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/12/27 03:51:12 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/12/27 03:51:12 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/12/27 03:51:12 | 000,913,408 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/12/27 12:03:05 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/08/31 10:02:48 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/08/31 10:02:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2013/01/23 14:48:28 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\User\Desktop\aswMBR.exe
[2013/01/28 14:17:50 | 005,028,084 | R— | M] (Swearware) – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2013/01/09 12:33:24 | 020,293,080 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 18.0.exe
[2013/01/07 08:02:00 | 000,365,568 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.exe
[2010/03/05 14:15:23 | 001,688,360 | —- | M] (Skype Technologies S.A.) – C:\Documents and Settings\User\Desktop\SkypeSetup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-22 02:01:10
< End of report >
OTL Extras logfile created on: 1/21/2013 1:47:53 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.48 Mb Total Physical Memory | 629.78 Mb Available Physical Memory | 65.64% Memory free
2.26 Gb Paging File | 2.04 Gb Available in Paging File | 90.09% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 63.42 Gb Free Space | 83.10% Space Free | Partition Type: NTFS
Computer Name: JOANIESYS | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP470_series" = Canon MP470 series
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{26A24AE4-039D-4CA4-87B4-2F83217010FF}" = Java 7 Update 10
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.01)
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Canon MP470 series User Registration" = Canon MP470 series User Registration
"CANONIJPLM100" = PIXMA Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"S3" = VIA/S3G Display Driver
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTOverlay" = S3 S3Overlay
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/9/2010 2:35:03 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:35:27 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:36:48 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:13 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:38:42 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/9/2010 2:39:51 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:39:57 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:40:45 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:10 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
Error - 3/9/2010 2:41:40 PM | Computer Name = ADMIN-EF8676DFC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x000101b3.
[ System Events ]
Error - 1/20/2013 10:31:27 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 10:39:24 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:35 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/20/2013 11:19:51 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:20:52 PM | Computer Name = JOANIESYS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter
Error - 1/20/2013 11:27:22 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:36 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:29:53 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:30:39 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/20/2013 11:49:04 PM | Computer Name = JOANIESYS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
< End of report >