This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horses virus on computer [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I was running a free anti-virus software program on my computer called AVG, which found several Trojan Horse viruses. I purchased the the actual monitoring/removing product from them AFTER it found the viruses, but I think they're still on my computer. It's been running extremely slow and at times will not shut down. Please help! LG
So sorry. I forgot to post my HiJackthis scan results.

LG



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:37:50 PM, on 1/23/2013
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2013\avgfws.exe
C:\Program Files\AVG\AVG2013\avgidsagent.exe
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\AVG\AVG2013\avgnsx.exe
C:\Program Files\AVG\AVG2013\avgemcx.exe
C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Webcetera\EzPDFUpload_WinXP_x86\EzPDFUploadConsole.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\AVG\AVG2013\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Laura\Local Settings\Application Data\AMS Services, Inc\AMS 360\WorkstationCoordinator.exe
C:\Program Files\ScanSoft\PaperPort\PaprPort.exe
C:\Program Files\ScanSoft\PaperPort\pplinks.exe
C:\Program Files\ScanSoft\PaperPort\ppscanmg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Laura\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.3.0.17\AVG Secure Search_toolbar.dll
O2 - BHO: EzLynx.EZPlugin.EZIEPlugin - {a1a0bbcd-6b07-436e-9e0a-99250c464bcb} - mscoree.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.3.0.17\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.894
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [{4F70AF45-3499-AD40-C4B5-8187F503A295}] "C:\Documents and Settings\Laura\Application Data\Itwi\doahk.exe"
O4 - Startup: Shortcut to Primary output from EzPDFUploadConsole (Active).lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.ams-benefits.com
O15 - Trusted Zone: *.ams-services.com
O15 - Trusted Zone: *.ams-support.com
O15 - Trusted Zone: *.ams360.com
O15 - Trusted Zone: *.amsservices.com
O15 - Trusted Zone: *.prevailnetwork.com
O15 - Trusted Zone: http://*.travelers.com
O15 - Trusted Zone: http://*.travelerspc.com
O15 - Trusted Zone: *.vertafore.com
O15 - Trusted Zone: http://forums.whatthetech.com
O15 - Trusted Zone: forums.whatthetech.info
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://hoaic.live.ptsapp.com/systemInfo/ScriptX/smsx.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContac…nderControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1358803182078
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://akamaicdn.webex.com/client/WBXclien…ent/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.3.2\ViProtocol.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: GoToMyPC - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToMyPC\g2svc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Smart Client App Manager (SCAppMgr) - Ellie Mae, Inc. - C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: vToolbarUpdater13.3.2 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe

–
End of file - 11172 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Hi and sorry for any delay…

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Thanks for getting back to me, Jeff. Here are the logs.

dds log:

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 12:34:00 on 2013-01-28
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.363 [GMT -6:00]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2013 *Enabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Citrix\GoToMyPC\g2svc.exe
C:\Program Files\Citrix\GoToMyPC\g2comm.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Citrix\GoToMyPC\g2pre.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\Citrix\GoToMyPC\g2tray.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Webcetera\EzPDFUpload_WinXP_x86\EzPDFUploadConsole.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ScanSoft\PaperPort\PaprPort.exe
C:\Program Files\ScanSoft\PaperPort\pplinks.exe
C:\Program Files\ScanSoft\PaperPort\ppscanmg.exe
C:\Program Files\ScanSoft\PaperPort\ppprint.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\13.3.0.17\AVG Secure Search_toolbar.dll
BHO: EzLynx.EZPlugin.EZIEPlugin: {a1a0bbcd-6b07-436e-9e0a-99250c464bcb} -
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.8313.1002\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: : {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 -
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\13.3.0.17\AVG Secure Search_toolbar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [{4F70AF45-3499-AD40-C4B5-8187F503A295}] "c:\documents and settings\laura\application data\itwi\doahk.exe"
mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe
mRun: [DrvLsnr] c:\program files\analog devices\soundmax\DrvLsnr.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [SetDefPrt] c:\program files\brother\brmfl04g\BrStDvPt.exe
mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.894
StartupFolder: c:\docume~1\laura\startm~1\programs\startup\shortc~1.lnk - c:\documents and settings\laura\application data\microsoft\installer\{1b9f2fac-c00f-4045-b01e-5794fe4b42e7}\_7D7E3722E4A22B95024766.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: ams-benefits.com
Trusted Zone: ams-services.com
Trusted Zone: ams-support.com
Trusted Zone: ams360.com
Trusted Zone: amsservices.com
Trusted Zone: prevailnetwork.com
Trusted Zone: travelers.com
Trusted Zone: travelers.com
Trusted Zone: travelerspc.com
Trusted Zone: travelerspc.com
Trusted Zone: vertafore.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxps://hoaic.live.ptsapp.com/systemInfo/ScriptX/smsx.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxps://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1358803182078
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_38-windows-i586.cab
DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} - hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab
DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_38-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_38-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://akamaicdn.webex.com/client/WBXclient-T27L10NSP24-10113/event/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 192.168.2.1 192.168.1.254
TCP: Interfaces\{2AEBD565-32C5-476F-82CC-25EF8932D585} : DHCPNameServer = 192.168.2.1 192.168.1.254
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\13.3.2\ViProtocol.dll
Notify: GoToMyPC - c:\program files\citrix\gotomypc\G2WinLogon.dll
Notify: LMIinit - LMIinit.dll
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.56\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-11-15 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-9-21 164832]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-1-21 26984]
R2 avgfws;AVG Firewall;c:\program files\avg\avg2013\avgfws.exe [2012-12-10 1342024]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-11-15 5814904]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-22 196664]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-4-8 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-1-27 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-4-8 47640]
R2 SCAppMgr;Smart Client App Manager;c:\program files\ellie mae\scappmgr\SCAppMgr.exe [2011-1-17 59392]
R2 vToolbarUpdater13.3.2;vToolbarUpdater13.3.2;c:\program files\common files\avg secure search\vtoolbarupdater\13.3.2\ToolbarUpdater.exe [2013-1-21 894920]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2012-1-12 30944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2012-1-12 30944]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2013-01-22 14:58:49 473072 —-a-w- c:\windows\system32\deployJava1.dll
2012-11-02 14:08:59 83912 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-11-02 14:08:58 92072 —-a-w- c:\windows\system32\LMIinit.dll
2012-11-02 14:08:58 52648 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2012-11-02 14:08:58 31144 —-a-w- c:\windows\system32\LMIport.dll
.
============= FINISH: 12:40:32.68 ===============



attach log:


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 4/8/2011 3:36:25 PM
System Uptime: 1/23/2013 3:03:16 AM (129 hours ago)
.
Motherboard: Hewlett-Packard | | 085Ch
Processor: Intel® Pentium® 4 CPU 2.60GHz | XU1 PROCESSOR | 2593/800mhz
Processor: Intel® Pentium® 4 CPU 2.60GHz | XU1 PROCESSOR | 2593/800mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 129.627 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&369939D9&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&369939D9&0
Service: i8042prt
.
Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Device ID: ACPI\PNP0303\4&369939D9&0
Manufacturer: (Standard keyboards)
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&369939D9&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP587: 10/30/2012 9:14:14 PM - System Checkpoint
RP588: 10/31/2012 10:14:13 PM - System Checkpoint
RP589: 11/1/2012 11:14:14 PM - System Checkpoint
RP590: 11/2/2012 9:10:19 AM - Printer Driver LogMeIn Printer Driver Installed
RP591: 11/3/2012 9:14:14 AM - System Checkpoint
RP592: 11/4/2012 9:14:13 AM - System Checkpoint
RP593: 11/5/2012 12:44:32 PM - System Checkpoint
RP594: 11/6/2012 1:18:20 PM - System Checkpoint
RP595: 11/7/2012 2:16:40 PM - System Checkpoint
RP596: 11/8/2012 5:19:30 PM - System Checkpoint
RP597: 11/9/2012 5:43:30 PM - System Checkpoint
RP598: 11/10/2012 6:18:18 PM - System Checkpoint
RP599: 11/11/2012 7:18:18 PM - System Checkpoint
RP600: 11/12/2012 8:15:35 PM - System Checkpoint
RP601: 11/13/2012 8:18:19 PM - System Checkpoint
RP602: 11/14/2012 9:18:19 PM - System Checkpoint
RP603: 11/15/2012 10:18:19 PM - System Checkpoint
RP604: 11/16/2012 11:18:20 PM - System Checkpoint
RP605: 11/18/2012 12:18:18 AM - System Checkpoint
RP606: 11/19/2012 1:18:18 AM - System Checkpoint
RP607: 11/20/2012 1:26:43 AM - System Checkpoint
RP608: 11/21/2012 2:14:13 AM - System Checkpoint
RP609: 11/22/2012 3:14:13 AM - System Checkpoint
RP610: 11/22/2012 6:53:26 PM - Avg Update
RP611: 11/23/2012 7:14:12 PM - System Checkpoint
RP612: 11/24/2012 8:14:12 PM - System Checkpoint
RP613: 11/25/2012 9:14:12 PM - System Checkpoint
RP614: 11/26/2012 9:18:00 PM - System Checkpoint
RP615: 11/27/2012 9:18:05 PM - System Checkpoint
RP616: 11/28/2012 10:18:07 PM - System Checkpoint
RP617: 11/29/2012 11:18:06 PM - System Checkpoint
RP618: 12/1/2012 12:18:07 AM - System Checkpoint
RP619: 12/2/2012 1:18:06 AM - System Checkpoint
RP620: 12/3/2012 2:18:06 AM - System Checkpoint
RP621: 12/4/2012 3:14:37 AM - System Checkpoint
RP622: 12/5/2012 4:14:37 AM - System Checkpoint
RP623: 12/6/2012 5:14:38 AM - System Checkpoint
RP624: 12/7/2012 6:14:37 AM - System Checkpoint
RP625: 12/8/2012 7:14:37 AM - System Checkpoint
RP626: 12/9/2012 8:14:36 AM - System Checkpoint
RP627: 12/10/2012 11:46:24 AM - System Checkpoint
RP628: 12/11/2012 1:14:38 PM - System Checkpoint
RP629: 12/12/2012 5:03:48 PM - System Checkpoint
RP630: 12/13/2012 5:26:02 PM - System Checkpoint
RP631: 12/14/2012 6:17:38 PM - System Checkpoint
RP632: 12/15/2012 7:17:38 PM - System Checkpoint
RP633: 12/16/2012 8:17:38 PM - System Checkpoint
RP634: 12/17/2012 6:53:36 PM - Avg Update
RP635: 12/18/2012 7:15:03 PM - System Checkpoint
RP636: 12/19/2012 8:16:08 PM - System Checkpoint
RP637: 12/20/2012 9:15:04 PM - System Checkpoint
RP638: 12/21/2012 10:15:03 PM - System Checkpoint
RP639: 12/22/2012 11:15:02 PM - System Checkpoint
RP640: 12/24/2012 12:15:02 AM - System Checkpoint
RP641: 12/25/2012 12:17:09 AM - System Checkpoint
RP642: 12/26/2012 1:17:09 AM - System Checkpoint
RP643: 12/27/2012 2:17:09 AM - System Checkpoint
RP644: 12/28/2012 3:17:10 AM - System Checkpoint
RP645: 12/29/2012 4:17:10 AM - System Checkpoint
RP646: 12/30/2012 5:17:10 AM - System Checkpoint
RP647: 12/31/2012 6:17:10 AM - System Checkpoint
RP648: 1/1/2013 7:15:26 AM - System Checkpoint
RP649: 1/2/2013 8:15:26 AM - System Checkpoint
RP650: 1/3/2013 11:18:49 AM - System Checkpoint
RP651: 1/4/2013 1:11:01 PM - System Checkpoint
RP652: 1/5/2013 1:15:54 PM - System Checkpoint
RP653: 1/6/2013 2:15:26 PM - System Checkpoint
RP654: 1/7/2013 5:32:33 PM - System Checkpoint
RP655: 1/8/2013 6:15:03 PM - System Checkpoint
RP656: 1/9/2013 7:15:01 PM - System Checkpoint
RP657: 1/10/2013 7:15:08 PM - System Checkpoint
RP658: 1/11/2013 8:15:23 PM - System Checkpoint
RP659: 1/12/2013 9:15:00 PM - System Checkpoint
RP660: 1/13/2013 8:01:57 AM - Avg Update
RP661: 1/14/2013 8:19:31 AM - System Checkpoint
RP662: 1/15/2013 8:01:57 AM - Avg Update
RP663: 1/16/2013 8:17:29 AM - System Checkpoint
RP664: 1/17/2013 10:42:58 AM - System Checkpoint
RP665: 1/18/2013 12:13:33 PM - System Checkpoint
RP666: 1/18/2013 5:16:57 PM - Avg Update
RP667: 1/19/2013 5:23:52 PM - System Checkpoint
RP668: 1/20/2013 6:59:52 PM - System Checkpoint
RP669: 1/21/2013 3:01:41 PM - Removed AVG Free 9.0
RP670: 1/21/2013 3:02:55 PM - Installed AVG Free 9.0
RP671: 1/21/2013 3:19:27 PM - Installed AVG 2013
RP672: 1/21/2013 3:20:35 PM - Installed AVG 2013
RP673: 1/21/2013 4:16:02 PM - Software Distribution Service 3.0
RP674: 1/21/2013 4:24:02 PM - Installed Microsoft Download Manager
RP675: 1/21/2013 4:47:52 PM - Installed Windows XP Service Pack 2.
RP676: 1/21/2013 5:58:34 PM - Removed Adobe Reader 9.3.3.
RP677: 1/21/2013 6:20:46 PM - Installed Windows Internet Explorer 8.
RP678: 1/21/2013 6:22:15 PM - Software Distribution Service 3.0
RP679: 1/22/2013 3:00:27 AM - Software Distribution Service 3.0
RP680: 1/22/2013 8:58:09 AM - Removed Java™ 6 Update 22
RP681: 1/22/2013 8:58:43 AM - Installed Java™ 6 Update 38
RP682: 1/22/2013 1:10:56 PM - Installed Windows XP WgaNotify.
RP683: 1/22/2013 1:45:12 PM - Software Distribution Service 3.0
RP684: 1/23/2013 3:00:16 AM - Software Distribution Service 3.0
RP685: 1/24/2013 3:01:22 AM - System Checkpoint
RP686: 1/25/2013 4:01:16 AM - System Checkpoint
RP687: 1/26/2013 5:01:15 AM - System Checkpoint
RP688: 1/27/2013 6:01:13 AM - System Checkpoint
RP689: 1/28/2013 7:01:13 AM - System Checkpoint
.
==== Installed Programs ======================
.
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.5.3
AMS 360 Client Rev 3
AVG 2013
Broadcom NetXtreme Ethernet Controller
Brother MFL-Pro Suite
Encompass360 SmartClient
EzPDFUpload_WinXP_x86
EZPlugin
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
GoToMeeting 5.1.0.880
GoToMyPC
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
Java Auto Updater
Java™ 6 Update 38
LogMeIn
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Download Manager
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Nero 6 Ultra Edition
PaperPort
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
SmartClient Core
SmartClient Installation Manager
SOS Online Backup
SoundMAX
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB898461)
Update for Windows XP (KB925720)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebEx
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Search 4.0
Windows XP Service Pack 2
.
==== Event Viewer Messages From Past Week ========
.
1/22/2013 3:26:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB980218).
1/22/2013 3:26:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB952954).
1/22/2013 3:26:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB951376).
1/22/2013 3:26:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB960859).
1/22/2013 3:26:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB959426).
1/22/2013 3:26:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB956803).
1/22/2013 3:26:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB946648).
1/22/2013 3:20:19 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB979683).
1/22/2013 3:20:19 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB971468).
1/22/2013 3:20:18 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB976662).
1/22/2013 3:20:18 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB958869).
1/22/2013 3:20:17 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP 2 (KB954155).
1/22/2013 3:20:17 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Cumulative Security Update for ActiveX Killbits for Windows XP (KB980195).
1/22/2013 3:20:07 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB955759).
1/22/2013 3:20:07 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB980232).
1/22/2013 3:19:49 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB974318).
1/22/2013 3:19:49 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB969059).
1/22/2013 3:19:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB978037).
1/22/2013 3:19:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB950974).
1/22/2013 3:19:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB2229593).
1/22/2013 3:19:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB961118).
1/22/2013 3:19:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB978338).
1/22/2013 3:19:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB975713).
1/22/2013 3:19:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB972270).
1/22/2013 3:19:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB971657).
1/22/2013 3:19:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB960225).
1/22/2013 3:12:14 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB974112).
1/22/2013 3:12:14 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB956844).
1/22/2013 3:12:14 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB956572).
1/22/2013 3:12:13 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB961501).
1/22/2013 3:11:08 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB975561).
1/22/2013 3:10:52 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: February 2007 CardSpace Update for Windows XP (KB925720).
1/22/2013 3:10:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP Service Pack 2 (KB952069).
1/22/2013 3:10:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB973869).
1/22/2013 3:10:50 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP Service Pack 2 (KB973540).
1/22/2013 3:10:50 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB975025).
1/22/2013 3:10:49 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB974571).
1/22/2013 3:10:49 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB952004).
1/22/2013 3:10:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB975560).
1/22/2013 3:10:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB973507).
1/22/2013 3:10:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB973687).
1/22/2013 3:10:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB977816).
1/22/2013 3:10:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB963093).
1/22/2013 3:10:46 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB981793).
1/22/2013 3:10:46 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB978601).
1/22/2013 3:10:46 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB950762).
1/22/2013 3:10:45 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB952287).
1/22/2013 3:10:45 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB979559).
1/22/2013 3:10:44 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB967715).
1/22/2013 3:10:44 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB981332).
1/22/2013 3:10:44 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB974392).
1/22/2013 3:10:44 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB973904).
1/22/2013 3:10:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB978542).
1/22/2013 3:10:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB977914).
1/22/2013 3:10:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB970238).
1/22/2013 3:10:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB951748).
1/22/2013 3:10:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB979482).
1/22/2013 3:10:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB979309).
1/22/2013 3:10:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows Media Format Runtime 9, 9.5 & 11 for Windows XP SP2 (KB978695).
1/22/2013 3:10:41 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB978706).
1/22/2013 3:10:41 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB973815).
1/22/2013 3:10:41 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB960803).
1/22/2013 3:10:41 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB958470).
1/22/2013 3:10:40 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB975562).
1/22/2013 3:04:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB971032).
1/22/2013 3:04:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB958644).
1/22/2013 3:04:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Jscript 5.8 for Windows XP (KB971961).
1/22/2013 3:04:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB955069).
1/22/2013 3:04:42 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows Media Player 9 for Windows XP SP2 (KB979402).
1/22/2013 3:00:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB956802).
1/22/2013 3:00:28 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Update for Windows XP (KB968389).
1/22/2013 3:00:28 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f205: Security Update for Windows XP (KB923561).
1/21/2013 4:53:51 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
1/21/2013 4:53:43 PM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.
.
==== End Of File ===========================






aswMBR log:

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-28 12:44:35
—————————–
12:44:35.345 OS Version: Windows 5.1.2600 Service Pack 2
12:44:35.345 Number of processors: 2 586 0x209
12:44:35.345 ComputerName: PIP-110972 UserName: Laura
12:44:36.189 Initialize success
12:47:14.365 AVAST engine defs: 13012800
12:49:16.111 The log file has been saved successfully to "C:\Documents and Settings\Laura\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-28 12:44:35
—————————–
12:44:35.345 OS Version: Windows 5.1.2600 Service Pack 2
12:44:35.345 Number of processors: 2 586 0x209
12:44:35.345 ComputerName: PIP-110972 UserName: Laura
12:44:36.189 Initialize success
12:47:14.365 AVAST engine defs: 13012800
12:49:16.111 The log file has been saved successfully to "C:\Documents and Settings\Laura\Desktop\aswMBR.txt"
12:53:54.510 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
12:53:54.510 Disk 0 Vendor: MAXTOR_STM3160812A 3.AAK Size: 152627MB BusType: 3
12:53:54.572 Disk 0 MBR read successfully
12:53:54.572 Disk 0 MBR scan
12:53:54.635 Disk 0 Windows XP default MBR code
12:53:54.650 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 152617 MB offset 63
12:53:54.682 Disk 0 scanning sectors +312560640
12:53:54.760 Disk 0 scanning C:\WINDOWS\system32\drivers
12:54:16.491 Service scanning
12:54:37.754 Modules scanning
12:54:48.221 Disk 0 trace - called modules:
12:54:48.237 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
12:54:48.237 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f80ab8]
12:54:48.252 3 CLASSPNP.SYS[f74ef05b] -> nt!IofCallDriver -> \Device\0000005e[0x86f64510]
12:54:48.252 5 ACPI.sys[f7465620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86f93940]
12:54:48.877 AVAST engine scan C:\WINDOWS
12:55:04.656 AVAST engine scan C:\WINDOWS\system32
13:01:02.715 AVAST engine scan C:\WINDOWS\system32\drivers
13:01:25.243 AVAST engine scan C:\Documents and Settings\Laura
13:14:13.540 AVAST engine scan C:\Documents and Settings\All Users
13:15:49.560 Scan finished successfully
13:56:15.455 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Laura\Desktop\MBR.dat"
13:56:15.455 The log file has been saved successfully to "C:\Documents and Settings\Laura\Desktop\aswMBR.txt"
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
ckfiles: CKScanner 2.1 - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.UQCPRA —– EOF —–
Hi, Would you mind posting all the logs that were created? Did you have to run the program more than once? I just need to see what we are dealing with.
I ran it twice because it didn't look like anything showed up on the first log. So, I ran it again but it looked the same. Should I run it again? I didn't save the log after the second time I ran the scan.

Should I run it again?

No…no problem
——–

[external image: Posted Image]
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-
extras.txt

OTL Extras logfile created on: 1/29/2013 3:47:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Laura\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 351.96 Mb Available Physical Memory | 34.39% Memory free
2.41 Gb Paging File | 1.48 Gb Available in Paging File | 61.36% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 129.45 Gb Free Space | 86.86% Space Free | Partition Type: NTFS

Computer Name: PIP-110972 | User Name: Laura | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"21668:UDP" = 21668:UDP:*:Enabled:UDP 21668
"26076:TCP" = 26076:TCP:*:Enabled:TCP 26076
"13396:UDP" = 13396:UDP:*:Enabled:UDP 13396
"13763:TCP" = 13763:TCP:*:Enabled:TCP 13763

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Documents and Settings\Laura\Local Settings\Application Data\AMS Services, Inc\AMS 360\WorkstationCoordinator.exe" = C:\Documents and Settings\Laura\Local Settings\Application Data\AMS Services, Inc\AMS 360\WorkstationCoordinator.exe:*:Enabled:AMS360 Assembly – (Vertafore, Inc.)
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer – (Microsoft Corporation)
"C:\Program Files\AVG\AVG2013\avgnsx.exe" = C:\Program Files\AVG\AVG2013\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgdiagex.exe" = C:\Program Files\AVG\AVG2013\avgdiagex.exe:*:Enabled:AVG Diagnostics 2013 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgmfapx.exe" = C:\Program Files\AVG\AVG2013\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2013\avgemcx.exe" = C:\Program Files\AVG\AVG2013\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1B9F2FAC-C00F-4045-B01E-5794FE4B42E7}" = EzPDFUpload_WinXP_x86
"{20F6DD05-F69A-45B4-B337-A2DCC5688060}" = AMS 360 Client Rev 3
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216038FF}" = Java™ 6 Update 38
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CCC5C78-20FF-478E-8B65-46B58CC5781B}" = AVG 2013
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E9C4FBE-4E6C-4389-A4B3-4AE027D0BF2E}" = Encompass360 SmartClient
"{4475560E-9418-4908-A158-472D873AE139}" = LogMeIn
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{568AEE95-B0FB-4FD9-B7E7-4C8B6A3180C9}" = SmartClient Core
"{58F4D4FD-1814-4068-B316-C28FC776C6DD}" = GoToMyPC
"{5DE8AE5E-240B-4DA7-8BCF-DA269FFC9D8B}" = SmartClient Installation Manager
"{654977DB-0001-0002-0001-EABD228DDE8B}" = Microsoft Download Manager
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{731E713B-C13E-4527-B624-8A6DF2D33DAF}" = AVG 2013
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{96D146BB-54C8-4810-9BD1-5ED238FA204A}" = SOS Online Backup
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.3
"{B3284109-47EC-49E7-BDAD-045247A374F8}" = EZPlugin
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D83BD5E2-5AF4-49F6-B5C1-484A9760E73D}" = Brother MFL-Pro Suite
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F870B987-18BC-45FC-9BE8-35C02DCDA10F}" = Broadcom NetXtreme Ethernet Controller
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG" = AVG 2013
"Google Chrome" = Google Chrome
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROPLUS" = Microsoft Office Professional Plus 2007
"RealPlayer 12.0" = RealPlayer
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 5.1.0.880

========== Last 20 Event Log Errors ==========

[ AMS 360 Events ]
Error - 1/25/2013 11:29:17 AM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1027
Description = Source: ServerObjects.Loader Agency: 2037131-2, Login Id: UserName:Laura
PID:2144
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ Failed to load manifest. Message: Could not find
file 'C:\Documents and Settings\Laura\Desktop\manifest.xml'.

Error - 1/25/2013 11:30:17 AM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1027
Description = Source: ServerObjects.Loader Agency: 2037131-2, Login Id: UserName:Laura
PID:2144
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ Failed to load manifest. Message: Could not find
file 'C:\Documents and Settings\Laura\Desktop\manifest.xml'.

Error - 1/25/2013 11:31:17 AM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1027
Description = Source: ServerObjects.Loader Agency: 2037131-2, Login Id: UserName:Laura
PID:2144
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ Failed to load manifest. Message: Could not find
file 'C:\Documents and Settings\Laura\Desktop\manifest.xml'.

Error - 1/25/2013 11:32:17 AM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1027
Description = Source: ServerObjects.Loader Agency: 2037131-2, Login Id: UserName:Laura
PID:2144
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ Failed to load manifest. Message: Could not find
file 'C:\Documents and Settings\Laura\Desktop\manifest.xml'.

Error - 1/25/2013 7:42:21 PM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1023
Description =

Error - 1/28/2013 11:21:25 AM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 100
Description = Source: frmProgress1 Agency: 2037131-2, Login Id: Laura UserName:Laura
PID:4584
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ frmProgress1 was launched with WorkId 88970e9f-6e2c-4d8a-8559-d683e7620484
which was not registered with the Work Manager. This may indicate that the work
completed while frmProgress1 was opening

Error - 1/28/2013 11:29:13 AM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1018
Description = Source: ServerObjects Agency: 2037131-2, Login Id: Laura UserName:Laura
PID:4584
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ Fire Cannot access a disposed object. Object name:
'frmCustomer'. at System.Windows.Forms.Control.MarshaledInvoke(Control caller,
Delegate method, Object[] args, Boolean synchronous) at System.Windows.Forms.Control.Invoke(Delegate
method, Object[] args) at AMSBothell.Components.Controls.FormBase.OnNotificationReceivedInternal(String
strEventType, ListDictionary oLD, Object oData) at AMSBothell.Components.WorkstationCoordinator.ClientObject.DataChanged(String
strEventType, ListDictionary e, Object oData) at AMSBothell.Components.WorkstationCoordinator.Notification.Server.Fire(String
strEventType, ListDictionary e, Object oData)

Error - 1/28/2013 4:57:20 PM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1018
Description = Source: ServerObjects Agency: 2037131-2, Login Id: Laura UserName:Laura
PID:4880
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ Fire Cannot access a disposed object. Object name:
'frmCustomer'. at System.Windows.Forms.Control.MarshaledInvoke(Control caller,
Delegate method, Object[] args, Boolean synchronous) at System.Windows.Forms.Control.Invoke(Delegate
method, Object[] args) at AMSBothell.Components.Controls.FormBase.OnNotificationReceivedInternal(String
strEventType, ListDictionary oLD, Object oData) at AMSBothell.Components.WorkstationCoordinator.ClientObject.DataChanged(String
strEventType, ListDictionary e, Object oData) at AMSBothell.Components.WorkstationCoordinator.Notification.Server.Fire(String
strEventType, ListDictionary e, Object oData)

Error - 1/28/2013 7:17:55 PM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 100
Description = Source: frmProgress1 Agency: 2037131-2, Login Id: Laura UserName:Laura
PID:6816
Application:
Client Application Directory: C:\Documents and Settings\Laura\Local Settings\Application
Data\AMS Services, Inc\AMS 360\ frmProgress1 was launched with WorkId 20c37ce5-bde0-41ab-8a35-f99b3c30ed4c
which was not registered with the Work Manager. This may indicate that the work
completed while frmProgress1 was opening

Error - 1/28/2013 7:57:24 PM | Computer Name = PIP-110972 | Source = AMS 360 | ID = 1023
Description =

[ Application Events ]
Error - 1/21/2013 4:34:24 PM | Computer Name = PIP-110972 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/21/2013 4:44:17 PM | Computer Name = PIP-110972 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/21/2013 4:44:38 PM | Computer Name = PIP-110972 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/21/2013 4:47:26 PM | Computer Name = PIP-110972 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/21/2013 5:19:25 PM | Computer Name = PIP-110972 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/21/2013 7:05:56 PM | Computer Name = PIP-110972 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/22/2013 5:10:30 AM | Computer Name = PIP-110972 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- Failed to compile: PresentationBuildTasks, Version=3.0.0.0, Culture=neutral,
PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070005

Error - 1/22/2013 5:10:32 AM | Computer Name = PIP-110972 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- Failed to compile: PresentationCFFRasterizer, Version=3.0.0.0, Culture=neutral,
PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070005

Error - 1/22/2013 5:14:22 AM | Computer Name = PIP-110972 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32)
- Failed to compile: PresentationFramework.Aero, Version=3.0.0.0, Culture=neutral,
PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070020

Error - 1/22/2013 5:44:07 AM | Computer Name = PIP-110972 | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

[ System Events ]
Error - 1/22/2013 5:26:43 AM | Computer Name = PIP-110972 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007f205: Security Update for Windows XP (KB980218).

Error - 1/22/2013 5:44:01 AM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/22/2013 5:44:01 AM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/22/2013 5:44:07 AM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt

Error - 1/22/2013 4:04:16 PM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/22/2013 4:04:16 PM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/22/2013 4:04:19 PM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt

Error - 1/23/2013 5:04:18 AM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/23/2013 5:04:18 AM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 1/23/2013 5:04:22 AM | Computer Name = PIP-110972 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt


< End of report >
OTL.txt

OTL logfile created on: 1/29/2013 3:47:28 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Laura\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 351.96 Mb Available Physical Memory | 34.39% Memory free
2.41 Gb Paging File | 1.48 Gb Available in Paging File | 61.36% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 129.45 Gb Free Space | 86.86% Space Free | Partition Type: NTFS

Computer Name: PIP-110972 | User Name: Laura | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Laura\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Laura\Local Settings\Application Data\AMS Services, Inc\AMS 360\WorkstationCoordinator.exe (Vertafore, Inc.)
PRC - C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe (Ellie Mae, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2tray.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2pre.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2comm.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Webcetera\EzPDFUpload_WinXP_x86\EzPDFUploadConsole.exe (Webcetera)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\50130ef751b98a4a11bd4ab73af7cab5\System.Data.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Program Files\AVG Secure Search\13.3.0.17\AVG Secure Search_toolbar.dll ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\DNTInstaller\13.3.2\avgdttbx.dll ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.3.2\SiteSafety.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()


========== Services (SafeList) ==========

SRV - (vToolbarUpdater13.3.2) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.3.2\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files\AVG\AVG2013\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (SCAppMgr) – C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe (Ellie Mae, Inc.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (GoToMyPC) – C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (SoundMAX Agent Service (default) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (aswMBR) – C:\DOCUME~1\Laura\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (mbr) – C:\Documents and Settings\Laura\Local Settings\Temp\mbr.sys ()
DRV - (avgtp) – C:\WINDOWS\system32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (G400) – C:\WINDOWS\system32\drivers\G400m.sys (Matrox Graphics Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.planocomputer.com/antivirususe.html [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enUS427
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={A479EE8…mp;d=2013-01-21 15:23:41&v=13.3.0.17&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.3.2\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_38: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1: C:\WINDOWS\ [2013/01/23 09:35:21 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/04 10:27:51 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.224\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.224\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.224\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Laura\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.4_0\

O1 HOSTS File: ([2001/08/23 00:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.3.0.17\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.3.0.17\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [{4F70AF45-3499-AD40-C4B5-8187F503A295}] "C:\Documents and Settings\Laura\Application Data\Itwi\doahk.exe" File not found
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Laura\Start Menu\Programs\Startup\Shortcut to Primary output from EzPDFUploadConsole (Active).lnk = C:\Documents and Settings\Laura\Application Data\Microsoft\Installer\{1B9F2FAC-C00F-4045-B01E-5794FE4B42E7}\_7D7E3722E4A22B95024766.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: agentinside.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ams360.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ams-benefits.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: amsservices.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ams-services.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ams-support.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: prevailnetwork.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: travelers.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: travelers.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: travelerspc.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: travelerspc.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: vertafore.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] http in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: whatthetech.info ([forums] * in Trusted sites)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} https://hoaic.live.ptsapp.com/systemInfo/ScriptX/smsx.cab (MeadCo ScriptX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} https://www.linkedin.com/cab/LinkedInContac…nderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1358803182078 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.microsoft.com/download/C/9…loadManager.cab (Microsoft Download Manager ActiveX control)
O16 - DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclien…ent/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2AEBD565-32C5-476F-82CC-25EF8932D585}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.3.2\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToMyPC: DllName - (C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll) - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Laura\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Laura\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/08 14:34:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/29 15:45:49 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Laura\Desktop\OTL.exe
[2013/01/28 12:44:24 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Laura\Desktop\aswMBR.exe
[2013/01/28 12:32:22 | 000,688,992 | R— | C] (Swearware) – C:\Documents and Settings\Laura\Desktop\dds.com
[2013/01/23 16:36:47 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Laura\Desktop\HiJackThis.exe
[2013/01/22 13:12:26 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Laura\PrivacIE
[2013/01/22 13:09:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/01/22 08:59:08 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/22 08:59:07 | 000,477,168 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2013/01/22 08:59:07 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2013/01/22 08:59:07 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2013/01/22 08:59:07 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2013/01/22 08:58:46 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/01/22 08:56:14 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Laura\IETldCache
[2013/01/22 03:00:34 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/21 18:22:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2013/01/21 18:18:03 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2013/01/21 17:58:34 | 000,000,000 | —D | C] – C:\0c690b23e37de43c882a0a1e95
[2013/01/21 17:55:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/21 17:13:51 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2013/01/21 17:12:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\Laura\Start Menu\Programs\Administrative Tools
[2013/01/21 17:06:44 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2013/01/21 17:06:23 | 000,352,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2013/01/21 17:05:39 | 000,454,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2013/01/21 17:05:32 | 000,743,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2013/01/21 17:05:12 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2013/01/21 17:04:02 | 003,555,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2013/01/21 17:03:41 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2013/01/21 17:01:53 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2013/01/21 17:01:48 | 002,137,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2013/01/21 17:01:47 | 002,181,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2013/01/21 17:01:46 | 002,016,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2013/01/21 17:01:44 | 002,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2013/01/21 16:59:44 | 000,655,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstscax.dll
[2013/01/21 16:58:38 | 000,332,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2013/01/21 16:58:33 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2013/01/21 16:52:56 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2013/01/21 16:49:07 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2013/01/21 16:49:06 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2013/01/21 16:24:03 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Download Manager
[2013/01/21 16:24:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Download Manager
[2013/01/21 16:15:22 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/01/21 16:15:22 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/01/21 16:15:18 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/01/21 16:15:16 | 001,985,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/01/21 16:15:12 | 011,076,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/01/21 15:29:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2013/01/21 15:25:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Application Data\AVG2013
[2013/01/21 15:23:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/01/21 15:23:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Application Data\TuneUp Software
[2013/01/21 15:23:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Local Settings\Application Data\AVG Secure Search
[2013/01/21 15:23:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Application Data\AVG Secure Search
[2013/01/21 15:23:37 | 000,026,984 | —- | C] (AVG Technologies) – C:\WINDOWS\System32\drivers\avgtpx86.sys
[2013/01/21 15:23:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/01/21 15:23:32 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/01/21 15:22:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2013/01/21 15:22:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2013/01/21 15:21:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2013/01/21 15:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Local Settings\Application Data\MFAData
[2013/01/21 15:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2013/01/21 15:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Local Settings\Application Data\Avg2013
[2012/03/23 13:05:35 | 011,881,936 | —- | C] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Documents and Settings\Laura\gosetup.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/29 15:45:49 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Laura\Desktop\OTL.exe
[2013/01/29 15:15:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/29 15:15:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/29 14:41:23 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\Biport
[2013/01/29 14:12:42 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1177238915-602162358-725345543-1003.job
[2013/01/29 14:12:42 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1177238915-602162358-725345543-1003.job
[2013/01/29 09:23:10 | 000,002,571 | —- | M] () – C:\Documents and Settings\Laura\Start Menu\Programs\Startup\Shortcut to Primary output from EzPDFUploadConsole (Active).lnk
[2013/01/29 09:23:00 | 000,002,521 | —- | M] () – C:\Documents and Settings\Laura\Desktop\Microsoft Office Outlook 2007.lnk
[2013/01/29 09:22:42 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/28 14:46:15 | 000,681,984 | —- | M] () – C:\Documents and Settings\Laura\Desktop\CKScanner.exe
[2013/01/28 12:44:33 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Laura\Desktop\aswMBR.exe
[2013/01/28 12:32:23 | 000,688,992 | R— | M] (Swearware) – C:\Documents and Settings\Laura\Desktop\dds.com
[2013/01/25 02:21:01 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/01/23 16:36:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Laura\Desktop\HiJackThis.exe
[2013/01/23 03:05:23 | 000,516,772 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/01/23 03:05:23 | 000,091,228 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/01/23 03:03:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/23 03:03:43 | 1073,270,784 | -HS- | M] () – C:\hiberfil.sys
[2013/01/23 03:00:39 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/22 14:03:10 | 000,267,800 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/22 08:58:49 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2013/01/22 08:58:49 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/22 08:58:49 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2013/01/22 08:58:49 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2013/01/22 08:58:49 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2013/01/22 08:58:49 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/22 08:56:18 | 000,000,815 | —- | M] () – C:\Documents and Settings\Laura\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/21 18:14:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2013/01/21 16:53:56 | 000,000,804 | —- | M] () – C:\Documents and Settings\Laura\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2013/01/21 16:53:52 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2013/01/21 16:50:09 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2013/01/21 16:24:03 | 000,001,892 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Download Manager.lnk
[2013/01/21 15:23:57 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/01/21 15:23:20 | 000,026,984 | —- | M] (AVG Technologies) – C:\WINDOWS\System32\drivers\avgtpx86.sys
[2013/01/14 09:04:38 | 000,001,831 | —- | M] () – C:\Documents and Settings\Laura\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/11 14:34:41 | 000,002,608 | —- | M] () – C:\Documents and Settings\Laura\Local Settings\Application Data\d3d9caps.dat
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/28 14:46:15 | 000,681,984 | —- | C] () – C:\Documents and Settings\Laura\Desktop\CKScanner.exe
[2013/01/21 18:01:21 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2013/01/21 18:01:18 | 000,002,347 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2013/01/21 16:24:03 | 000,001,892 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Download Manager.lnk
[2013/01/21 15:23:57 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2012/06/21 09:45:36 | 000,103,720 | —- | C] () – C:\Documents and Settings\Laura\GoToAssistDownloadHelper.exe
[2012/01/27 13:24:30 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2012/01/09 09:03:41 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2011/11/03 10:14:23 | 000,060,304 | —- | C] () – C:\Documents and Settings\Laura\g2mdlhlpx.exe
[2011/07/01 13:10:44 | 000,002,608 | —- | C] () – C:\Documents and Settings\Laura\Local Settings\Application Data\d3d9caps.dat
[2011/05/24 09:36:24 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/04/11 08:02:03 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2011/04/08 16:11:17 | 000,000,752 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2011/04/08 16:11:17 | 000,000,426 | —- | C] () – C:\WINDOWS\brwmark.ini
[2011/04/08 16:11:17 | 000,000,092 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2011/04/08 16:11:17 | 000,000,065 | —- | C] () – C:\WINDOWS\System32\BD7220.dat
[2011/04/08 16:11:17 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2011/04/08 16:10:54 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2011/04/08 16:10:47 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2011/04/08 16:09:13 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2011/04/08 14:40:55 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2011/04/08 14:36:29 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/08 14:32:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/08 10:13:50 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/08 10:13:03 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2011/04/11 08:58:28 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2006/09/23 12:12:50 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 04:20:33 | 000,473,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2004/08/03 23:56:48 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/21 15:29:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2013/01/21 15:25:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2013/01/21 15:02:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2012/03/23 13:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CitrixLogs
[2011/04/08 16:09:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2013/01/29 12:11:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2013/01/29 15:37:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/08 16:08:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/05/24 15:00:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SOS Online Backup
[2013/01/21 15:23:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\AVG Secure Search
[2013/01/21 15:25:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\AVG2013
[2011/04/11 09:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\ePASS
[2012/06/20 12:44:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\EzPDFUpload
[2012/02/03 14:36:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\EZPlugin
[2013/01/21 15:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\Itwi
[2011/04/11 08:02:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\ScanSoft
[2013/01/21 15:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\TuneUp Software
[2011/04/19 08:19:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\webex
[2011/04/08 22:24:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\Windows Desktop Search
[2011/05/08 20:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\Windows Search
[2013/01/18 14:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\Ziwya

========== Purity Check ==========



< End of report >
Hi,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Right-click and Run as Administrator SystemLook.exe to run it.
  • Copy the content within the following codebox into the main textfield:
    :dir
    C:\Documents and Settings\Laura\Application Data\Itwi /s
    C:\Documents and Settings\Laura\Application Data\Ziwya /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Here you go. Thanks! SystemLook 30.07.11 by jpshortstuff Log created at 09:45 on 30/01/2013 by Laura Administrator - Elevation successful ========== dir ========== C:\Documents and Settings\Laura\Application Data\Itwi - Parameters: "/s" —Files— None found. No folders found. C:\Documents and Settings\Laura\Application Data\Ziwya - Parameters: "/s" —Files— None found. No folders found. -= EOF =-
Hi,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services

    :OTL
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
    O4 - HKCU..\Run: [{4F70AF45-3499-AD40-C4B5-8187F503A295}] "C:\Documents and Settings\Laura\Application Data\Itwi\doahk.exe" File not found
    O15 - HKCU\..Trusted Domains: agentinside.com ([www] https in Trusted sites)
    O15 - HKCU\..Trusted Domains: ams360.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: ams-benefits.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: amsservices.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: ams-services.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: ams-support.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: prevailnetwork.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: travelers.com ([]http in Trusted sites)
    O15 - HKCU\..Trusted Domains: travelers.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: travelerspc.com ([]http in Trusted sites)
    O15 - HKCU\..Trusted Domains: travelerspc.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: vertafore.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: whatthetech.com ([forums] http in Trusted sites)
    O15 - HKCU\..Trusted Domains: whatthetech.com ([www] https in Trusted sites)
    O15 - HKCU\..Trusted Domains: whatthetech.info ([forums] * in Trusted sites)
    O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
    O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [2013/01/21 15:46:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\Itwi
    [2013/01/18 14:59:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Laura\Application Data\Ziwya

    :Files
    ipconfig /flushdns /c

    :Commands
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
————

Post the new OTL log and let me know how your system is running now. :)
Seems to running more smoothly now. Let me know if you need me to run any more scans! Thanks!


OTL logfile created on: 1/30/2013 3:11:43 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Laura\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 224.20 Mb Available Physical Memory | 21.91% Memory free
2.41 Gb Paging File | 1.40 Gb Available in Paging File | 58.03% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 130.35 Gb Free Space | 87.46% Space Free | Partition Type: NTFS

Computer Name: PIP-110972 | User Name: Laura | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
PRC - C:\Documents and Settings\Laura\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Laura\Local Settings\Application Data\AMS Services, Inc\AMS 360\WorkstationCoordinator.exe (Vertafore, Inc.)
PRC - C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe (Ellie Mae, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2tray.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2pre.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2comm.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Webcetera\EzPDFUpload_WinXP_x86\EzPDFUploadConsole.exe (Webcetera)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ScanSoft\PaperPort\PaprPort.exe (ScanSoft, Inc.)
PRC - C:\Program Files\ScanSoft\PaperPort\ppscanmg.exe (ScanSoft, Inc.)
PRC - C:\Program Files\ScanSoft\PaperPort\pplinks.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\SiteSafety.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\8ef8d556899a4a10b7f288a80925489f\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\f352c5cb50bee105e4c873ca050f9f46\System.Design.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\50130ef751b98a4a11bd4ab73af7cab5\System.Data.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll ()
MOD - c:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files\ScanSoft\PaperPort\ocr\ssocrf.o32 ()


========== Services (SafeList) ==========

SRV - (vToolbarUpdater14.0.1) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files\AVG\AVG2013\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (SCAppMgr) – C:\Program Files\Ellie Mae\SCAppMgr\SCAppMgr.exe (Ellie Mae, Inc.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (LMIMaint) – C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (GoToMyPC) – C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (LogMeIn) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (SoundMAX Agent Service (default) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (avgtp) – C:\WINDOWS\system32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (LMIRfsClientNP) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\WINDOWS\system32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) – C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (G400) – C:\WINDOWS\system32\drivers\G400m.sys (Matrox Graphics Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.planocomputer.com/antivirususe.html [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ADFA_enUS427
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={A479EE8…mp;d=2013-01-21 15:23:41&v=13.3.0.17&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_38: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1: C:\WINDOWS\ [2013/01/30 11:24:08 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/05/04 10:27:51 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.224\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.224\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\8.0.552.224\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.53\npGoogleUpdate3.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Laura\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.4_0\

O1 HOSTS File: ([2013/01/30 11:24:11 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Laura\Start Menu\Programs\Startup\Shortcut to Primary output from EzPDFUploadConsole (Active).lnk = C:\Documents and Settings\Laura\Application Data\Microsoft\Installer\{1B9F2FAC-C00F-4045-B01E-5794FE4B42E7}\_7D7E3722E4A22B95024766.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: ams360.com ([www] https in Trusted sites)
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} https://hoaic.live.ptsapp.com/systemInfo/ScriptX/smsx.cab (MeadCo ScriptX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} https://www.linkedin.com/cab/LinkedInContac…nderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1358803182078 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.microsoft.com/download/C/9…loadManager.cab (Microsoft Download Manager ActiveX control)
O16 - DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://akamaicdn.webex.com/client/WBXclien…ent/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2AEBD565-32C5-476F-82CC-25EF8932D585}: DhcpNameServer = 192.168.2.1 192.168.1.254
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToMyPC: DllName - (C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll) - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Laura\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Laura\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/08 14:34:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2013\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/30 12:46:46 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Business Objects
[2013/01/30 12:46:40 | 002,134,016 | R— | C] (Amyuni Technologies
http://www.amyuni.com) – C:\WINDOWS\System32\cdintf300.dll
[2013/01/30 12:46:34 | 000,000,000 | —D | C] – C:\Program Files\AMS Services, Inc
[2013/01/30 11:23:57 | 000,000,000 | —D | C] – C:\_OTL
[2013/01/30 11:21:43 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2013/01/30 11:20:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2013/01/30 11:20:57 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2013/01/30 11:20:14 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Laura\Desktop\erunt-setup.exe
[2013/01/30 09:16:00 | 000,000,000 | —D | C] – C:\WINDOWS\System32\cache
[2013/01/29 15:45:49 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Laura\Desktop\OTL.exe
[2013/01/28 12:44:24 | 004,732,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Laura\Desktop\aswMBR.exe
[2013/01/28 12:32:22 | 000,688,992 | R— | C] (Swearware) – C:\Documents and Settings\Laura\Desktop\dds.com
[2013/01/23 16:36:47 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Laura\Desktop\HiJackThis.exe
[2013/01/22 13:12:26 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Laura\PrivacIE
[2013/01/22 13:09:59 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/01/22 08:59:08 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/22 08:59:07 | 000,477,168 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2013/01/22 08:59:07 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2013/01/22 08:59:07 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2013/01/22 08:59:07 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2013/01/22 08:58:46 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/01/22 08:56:14 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Laura\IETldCache
[2013/01/22 03:00:34 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2013/01/21 18:22:25 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2013/01/21 18:18:03 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2013/01/21 17:58:34 | 000,000,000 | —D | C] – C:\0c690b23e37de43c882a0a1e95
[2013/01/21 17:55:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee
[2013/01/21 17:13:51 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2013/01/21 17:12:34 | 000,000,000 | R–D | C] – C:\Documents and Settings\Laura\Start Menu\Programs\Administrative Tools
[2013/01/21 17:06:44 | 000,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2013/01/21 17:06:23 | 000,352,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\srv.sys
[2013/01/21 17:05:39 | 000,454,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2013/01/21 17:05:32 | 000,743,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2013/01/21 17:05:12 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2013/01/21 17:04:02 | 003,555,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2013/01/21 17:03:41 | 000,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2013/01/21 17:01:53 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2013/01/21 17:01:48 | 002,137,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2013/01/21 17:01:47 | 002,181,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2013/01/21 17:01:46 | 002,016,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2013/01/21 17:01:44 | 002,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2013/01/21 16:59:44 | 000,655,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstscax.dll
[2013/01/21 16:58:38 | 000,332,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\netapi32.dll
[2013/01/21 16:58:33 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msxml3.dll
[2013/01/21 16:52:56 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2013/01/21 16:49:07 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\rwnh.dll
[2013/01/21 16:49:06 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\smtpapi.dll
[2013/01/21 16:24:03 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Download Manager
[2013/01/21 16:24:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Download Manager
[2013/01/21 16:15:22 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2013/01/21 16:15:22 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2013/01/21 16:15:18 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2013/01/21 16:15:16 | 001,985,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2013/01/21 16:15:12 | 011,076,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2013/01/21 15:29:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2013/01/21 15:25:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Application Data\AVG2013
[2013/01/21 15:23:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2013/01/21 15:23:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Application Data\TuneUp Software
[2013/01/21 15:23:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Local Settings\Application Data\AVG Secure Search
[2013/01/21 15:23:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Application Data\AVG Secure Search
[2013/01/21 15:23:37 | 000,031,576 | —- | C] (AVG Technologies) – C:\WINDOWS\System32\drivers\avgtpx86.sys
[2013/01/21 15:23:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AVG Secure Search
[2013/01/21 15:23:32 | 000,000,000 | —D | C] – C:\Program Files\AVG Secure Search
[2013/01/21 15:22:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2013/01/21 15:22:28 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2013/01/21 15:21:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2013
[2013/01/21 15:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Local Settings\Application Data\MFAData
[2013/01/21 15:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2013/01/21 15:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Laura\Local Settings\Application Data\Avg2013
[2012/03/23 13:05:35 | 011,881,936 | —- | C] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Documents and Settings\Laura\gosetup.exe

========== Files - Modified Within 30 Days ==========

[2013/01/30 15:15:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/30 15:15:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/30 14:51:56 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1177238915-602162358-725345543-1003.job
[2013/01/30 14:51:56 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1177238915-602162358-725345543-1003.job
[2013/01/30 14:51:43 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\Biport
[2013/01/30 13:09:06 | 000,002,521 | —- | M] () – C:\Documents and Settings\Laura\Desktop\Microsoft Office Outlook 2007.lnk
[2013/01/30 12:52:49 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/01/30 12:52:35 | 000,002,571 | —- | M] () – C:\Documents and Settings\Laura\Start Menu\Programs\Startup\Shortcut to Primary output from EzPDFUploadConsole (Active).lnk
[2013/01/30 12:52:13 | 000,000,342 | —- | M] () – C:\WINDOWS\tasks\ROC_JAN2013_TB_rmv.job
[2013/01/30 12:51:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/01/30 12:51:47 | 1073,270,784 | -HS- | M] () – C:\hiberfil.sys
[2013/01/30 12:46:39 | 000,516,772 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/01/30 12:46:39 | 000,091,228 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/01/30 11:24:11 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2013/01/30 11:20:14 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Laura\Desktop\erunt-setup.exe
[2013/01/30 09:43:06 | 000,139,264 | —- | M] () – C:\Documents and Settings\Laura\Desktop\SystemLook.exe
[2013/01/30 09:15:47 | 000,031,576 | —- | M] (AVG Technologies) – C:\WINDOWS\System32\drivers\avgtpx86.sys
[2013/01/29 16:47:28 | 000,002,608 | —- | M] () – C:\Documents and Settings\Laura\Local Settings\Application Data\d3d9caps.dat
[2013/01/29 15:45:49 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Laura\Desktop\OTL.exe
[2013/01/28 14:46:15 | 000,681,984 | —- | M] () – C:\Documents and Settings\Laura\Desktop\CKScanner.exe
[2013/01/28 12:44:33 | 004,732,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Laura\Desktop\aswMBR.exe
[2013/01/28 12:32:23 | 000,688,992 | R— | M] (Swearware) – C:\Documents and Settings\Laura\Desktop\dds.com
[2013/01/25 02:21:01 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/01/23 16:36:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Laura\Desktop\HiJackThis.exe
[2013/01/23 03:00:39 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/01/22 14:03:10 | 000,267,800 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/01/22 08:58:49 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2013/01/22 08:58:49 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2013/01/22 08:58:49 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2013/01/22 08:58:49 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2013/01/22 08:58:49 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2013/01/22 08:58:49 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2013/01/22 08:56:18 | 000,000,815 | —- | M] () – C:\Documents and Settings\Laura\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/01/21 18:14:51 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2013/01/21 16:53:56 | 000,000,804 | —- | M] () – C:\Documents and Settings\Laura\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2013/01/21 16:53:52 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2013/01/21 16:50:09 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2013/01/21 16:24:03 | 000,001,892 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Download Manager.lnk
[2013/01/21 15:23:57 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2013/01/14 09:04:38 | 000,001,831 | —- | M] () – C:\Documents and Settings\Laura\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

========== Files Created - No Company Name ==========

[2013/01/30 09:43:06 | 000,139,264 | —- | C] () – C:\Documents and Settings\Laura\Desktop\SystemLook.exe
[2013/01/30 09:16:04 | 000,000,342 | —- | C] () – C:\WINDOWS\tasks\ROC_JAN2013_TB_rmv.job
[2013/01/28 14:46:15 | 000,681,984 | —- | C] () – C:\Documents and Settings\Laura\Desktop\CKScanner.exe
[2013/01/21 18:01:21 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2013/01/21 18:01:18 | 000,002,347 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2013/01/21 16:24:03 | 000,001,892 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Download Manager.lnk
[2013/01/21 15:23:57 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2013.lnk
[2012/06/21 09:45:36 | 000,103,720 | —- | C] () – C:\Documents and Settings\Laura\GoToAssistDownloadHelper.exe
[2012/01/27 13:24:30 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2012/01/09 09:03:41 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2011/11/03 10:14:23 | 000,060,304 | —- | C] () – C:\Documents and Settings\Laura\g2mdlhlpx.exe
[2011/07/01 13:10:44 | 000,002,608 | —- | C] () – C:\Documents and Settings\Laura\Local Settings\Application Data\d3d9caps.dat
[2011/05/24 09:36:24 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/04/11 08:02:03 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2011/04/08 16:11:17 | 000,000,752 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2011/04/08 16:11:17 | 000,000,426 | —- | C] () – C:\WINDOWS\brwmark.ini
[2011/04/08 16:11:17 | 000,000,092 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2011/04/08 16:11:17 | 000,000,065 | —- | C] () – C:\WINDOWS\System32\BD7220.dat
[2011/04/08 16:11:17 | 000,000,052 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2011/04/08 16:10:54 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\BROSNMP.DLL
[2011/04/08 16:10:47 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2011/04/08 16:09:13 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2011/04/08 14:40:55 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\msssc.dll
[2011/04/08 14:36:29 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/08 14:32:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/08 10:13:50 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/08 10:13:03 | 000,267,800 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2011/04/11 08:58:28 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll – [2006/09/23 12:12:50 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll – [2009/02/09 04:20:33 | 000,473,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll – [2004/08/03 23:56:48 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI