Hi OCD! Thank you so much for replying. Full disclosure…since I first posted on WTT, I did several things. I was able to download Malwarebytes Anti-Malware in safe mode and run it. I deleted all malware shown. I tried to do a System Restore and each time I would choose a date and go through the process, my computer would say that System Restore was "incomplete." However, at some point, I realized that Microsoft Security Essentials was back on my husband's computer! Strange since I had uninstalled it and had been unable to reinstall it. Apparently, I had been successful in reinstalling it but the virus was hiding its existence from me?? Anyway; I updated MSE and ran it. It found a Trojan:Win 32/Sirefef.AB. I quarantined it and then deleted it. So now I will follow your instructions carefully. Here is the checkup.txt log:
Results of screen317's Security Check version 0.99.73
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spykee
Malwarebytes Anti-Malware version 1.75.0.1300
Wise Disk Cleaner Professional v5.2
JavaFX 2.0.2
Java™ 7 Update 2
Java™ 6 Update 7
Java version out of Date!
Adobe Flash Player 11.8.800.168
Adobe Reader 10.1.8
Adobe Reader out of Date!
Mozilla Firefox (23.0.1)
Google Chrome 29.0.1547.66
Google Chrome 29.0.1547.76
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Microsoft Security Essentials MSMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 21%
Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
Here is aswMBR.txt:
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-09-27 23:41:19
—————————–
23:41:19.328 OS Version: Windows 5.1.2600 Service Pack 3
23:41:19.328 Number of processors: 2 586 0x1706
23:41:19.328 ComputerName: D3H5MKH1 UserName:
23:41:20.281 Initialize success
23:43:48.812 AVAST engine defs: 13092702
23:44:02.875 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
23:44:02.875 Disk 0 Vendor: Hitachi_HDP725050GLA360 GM4OA5BA Size: 476940MB BusType: 3
23:44:03.078 Disk 0 MBR read successfully
23:44:03.078 Disk 0 MBR scan
23:44:03.125 Disk 0 Windows XP default MBR code
23:44:03.140 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
23:44:03.171 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 476874 MB offset 112455
23:44:03.203 Disk 0 scanning sectors +976752000
23:44:03.296 Disk 0 scanning C:\WINDOWS\system32\drivers
23:44:22.265 Service scanning
23:44:36.375 Service MpKsl5d4d37ee c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{82E4A7D1-4639-4B8E-88A5-9377E32D0804}\MpKsl5d4d37ee.sys **LOCKED** 32
23:44:52.437 Service ?etadpug C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ **HIDDEN**
23:44:52.968 Modules scanning
23:44:59.015 Disk 0 trace - called modules:
23:44:59.046 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
23:44:59.062 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8abf2ab8]
23:44:59.078 3 CLASSPNP.SYS[ba0f8fd7] -> nt!IofCallDriver -> \Device\0000006d[0x8ac72248]
23:44:59.078 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8abf6940]
23:44:59.984 AVAST engine scan C:\WINDOWS
23:45:17.859 AVAST engine scan C:\WINDOWS\system32
23:49:23.703 AVAST engine scan C:\WINDOWS\system32\drivers
23:49:56.421 AVAST engine scan C:\Documents and Settings\Drew Krajeski
23:53:44.812 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES\MBR.dat"
23:53:44.859 The log file has been saved successfully to "C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES\aswMBR.txt"
Here is the OTL.txt:
OTL logfile created on: 9/28/2013 12:00:59 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Drew Krajeski\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 64.88% Memory free
4.83 Gb Paging File | 3.77 Gb Available in Paging File | 77.98% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.70 Gb Total Space | 399.11 Gb Free Space | 85.70% Space Free | Partition Type: NTFS
Drive E: | 133.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 931.30 Gb Total Space | 927.86 Gb Free Space | 99.63% Space Free | Partition Type: NTFS
Computer Name: D3H5MKH1 | User Name: Drew Krajeski | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\aswMBR(1).exe (AVAST Software)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AOL Desktop 9.7\waol.exe (AOL Inc.)
PRC - C:\Program Files\AOL Desktop 9.7\shellmon.exe (AOL Inc.)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
PRC - C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR)
PRC - C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GbR)
PRC - C:\Documents and Settings\Drew Krajeski\Local Settings\Temp\Foxit Updater.exe (Foxit Corporation)
PRC - C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
PRC - C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
PRC - C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
PRC - C:\Program Files\Upromise\UpromiseTray.exe (Upromise, Inc.)
PRC - C:\Program Files\Upromise\dca-ua.exe (Compete, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
PRC - C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\WizMouse\WizMouse.exe ()
PRC - C:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacReminder.exe (Storage Appliance Corp.)
PRC - c:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe (Storage Appliance Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\Clickfree\cfagent.exe (Clickfree)
PRC - C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe (AOL Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\zlib.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libcef.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libGLESv2.dll ()
MOD - C:\Program Files\AOL Desktop 9.7\libEGL.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f93600ac836b9140e1df13bb0f6bfccf\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\10df39542df7d48462451fc39bce8418\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll ()
MOD - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
MOD - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelperPS.dll ()
MOD - C:\Program Files\WizMouse\WizMouse.exe ()
MOD - C:\WINDOWS\system32\IS_ContextMenu.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\1530Class.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SPTIASPI.DLL ()
MOD - C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe ()
========== Services (SafeList) ==========
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe File not found
SRV - (etadpug) – C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ \ﯹ๛\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe < [WARNING: C:\Program Files\Google\Desktop\Install\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\ \ \???\{8ebeb61c-28f9-4e19-9e26-e0c11898f8b2}\GoogleUpdate.exe <] File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (PDF Architect Helper Service) – C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR)
SRV - (PDF Architect Service) – C:\Program Files\PDF Architect\ConversionService.exe (pdfforge GbR)
SRV - (Intel® – C:\WINDOWS\system32\IPROSetMonitor.exe (Intel Corporation)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (SacNetAgentService_C57C4F854F53) – c:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe (Storage Appliance Corporation)
SRV - (DragonSvc) – C:\Program Files\Common Files\Nuance\dgnsvc.exe (Nuance Communications, Inc.)
SRV - (rpcapd) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (SSPORT) – C:\WINDOWS\system32\Drivers\SSPORT.sys File not found
DRV - (rt2870) – system32\DRIVERS\rt2870.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (PCASp50) – System32\Drivers\PCASp50.sys File not found
DRV - (MRESP50a64) – C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS File not found
DRV - (MRESP50) – C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS File not found
DRV - (MRENDIS5) – C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS File not found
DRV - (MREMPR5) – C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS File not found
DRV - (MREMP50a64) – C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS File not found
DRV - (MREMP50) – C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (chakfphd) – C:\WINDOWS\system32\drivers\chakfphd.sys File not found
DRV - (catchme) – C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswMBR) – C:\DOCUME~1\DREWKR~1\LOCALS~1\Temp\aswMBR.sys File not found
DRV - (MpKsl5d4d37ee) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{82E4A7D1-4639-4B8E-88A5-9377E32D0804}\MpKsl5d4d37ee.sys (Microsoft Corporation)
DRV - (DigiartyVirtualCDBus) – C:\WINDOWS\system32\drivers\DigiartyVirtualCDBus.sys (LotSoft, Inc.)
DRV - (SWDUMon) – C:\WINDOWS\system32\drivers\SWDUMon.sys ()
DRV - (cpudrv) – C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (Linksys_adapter_H) – C:\WINDOWS\system32\drivers\AE1200xp.sys (Broadcom Corporation)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (wanatw) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6081010
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes,DefaultScope = {443789B7-F39C-4b5c-9287-DA72D38F4FE6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" =
http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
IE - HKLM\..\SearchScopes\{79809194-BE76-9834-A9A7-3EAFA9125A67}: "URL" =
http://slirsredirect.search.aol.com/redire…mrud=17-07-2011
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.foxnews.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {2d914c15-11e5-93b4-ad21-35ba2aec33c8} - C:\Program Files\Ebates Cash Back Toolbar\Helper.dll ()
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes,DefaultScope = {DD234610-0BA5-43EE-B017-E6C01556EB35}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://websearch.ask.com/redirect?client=i…56-EBC4D0131CA7
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" =
http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{79809194-BE76-9834-A9A7-3EAFA9125A67}: "URL" =
http://blekkosearch.mystart.com/blekkotb_s…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{D5F539B8-1FC6-48C7-85E9-4D74D6906162}: "URL" =
http://slirsredirect.search.aol.com/redire…mrud=17-07-2011
IE - HKCU\..\SearchScopes\{DD234610-0BA5-43EE-B017-E6C01556EB35}: "URL" =
http://srp.freecause.com/?ourmark=4&si…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search the Web"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.foxnews.com|www.google.com"
FF - prefs.js..extensions.enabledAddons: FFToolbar%40upromise:7.1.0.5277
FF - prefs.js..extensions.enabledAddons: %7Bb9871413-95b7-01c4-69cf-961a01420158%7D:1.301.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Verizon\VSP\nprpspa.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\PDF Architect\FFPDFArchitectExt [2013/01/11 15:58:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/09/07 15:21:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/27 14:57:28 | 000,000,000 | —D | M]
[2009/08/09 15:05:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Extensions
[2013/09/27 11:52:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions
[2013/05/09 17:45:09 | 000,000,000 | —D | M] (Support.com Toolbar) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\[removed]
[2013/01/12 15:56:20 | 000,455,818 | —- | M] () (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\[removed]
[2013/09/07 14:33:29 | 000,431,310 | —- | M] () (No name found) – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\extensions\{b9871413-95b7-01c4-69cf-961a01420158}.xpi
[2013/05/09 17:45:09 | 000,002,336 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Application Data\Mozilla\Firefox\Profiles\detycbl9.default-1358020424890\searchplugins\askcom.xml
[2013/09/07 15:21:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/09/07 15:22:05 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/12/09 19:16:12 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2008/06/03 01:35:57 | 000,002,275 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\aolsearch.xml
[2012/01/06 07:31:07 | 000,002,049 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
[2012/06/07 20:39:30 | 000,002,158 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\search.xml
========== Chrome ==========
CHR - default_search_provider: Web Search (Enabled)
CHR - default_search_provider: search_url =
http://start.funmoods.com/results.php?f=4&…p;cr=1837363338
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://start.funmoods.com/?f=1&a=fmtob…p;cr=1837363338
CHR - plugin: First user (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Error reading preferences file
CHR - Extension: SaveByclick = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bgfaeeogolelccmmfcfoikennpedhhno\1_0\
CHR - Extension: FunDial = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Make this page red = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dnfaglepmjgohnkcoieaijlheabmcdeo\1.2_0\
CHR - Extension: Funmoods = C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
O1 HOSTS File: ([2012/02/01 16:50:17 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
O2 - BHO: (Qwiklinx) - {3E7C8B5A-96AB-438F-BF9B-782400655440} - C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx\Qwiklinx.dll (Qwiklinx, Inc.)
O2 - BHO: (ShopAtHome.com Cash Back Helper) - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O2 - BHO: (Ebates Cash Back Toolbar BHO) - {796E3F7C-B3A1-6094-41A6-21866FF2BAD6} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll (Compete, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll File not found
O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O2 - BHO: (Shop to Win) - {F9E44926-2497-46F3-8A25-928136AC079E} - C:\Program Files\Shop to Win 20\Shop to Win 20.dll (Shop To Win, LLC)
O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Support.com Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Ebates Cash Back Toolbar) - {FC5405B9-EE85-8754-9D4F-9CC300948A6F} - C:\Program Files\Ebates Cash Back Toolbar\Toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey File not found
O4 - HKLM..\Run: [Nuance.ctfmngr] C:\Program Files\Nuance\NaturallySpeaking11\Program\ctfmngr.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe ()
O4 - HKLM..\Run: [ShopAtHomeWatcher] C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
O4 - HKCU..\Run: [AnVir Task Manager] C:\Program Files\AnVir Task Manager\anvir.exe (AnVir Software)
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\AOL Desktop 9.7\AOL.EXE (AOL Inc.)
O4 - HKCU..\Run: [ClickfreeMonitor] C:\Documents and Settings\All Users\Application Data\Clickfree\cfagent.exe (Clickfree)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [fsm] File not found
O4 - HKCU..\Run: [Google Update] Reg Error: Value error. File not found
O4 - HKCU..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [PC Speed Maximizer] "C:\Program Files\PC Speed Maximizer\SPMStarter.exe" File not found
O4 - HKCU..\Run: [SacReminderHDDV2N] c:\Documents and Settings\All Users\Application Data\Clickfree\C2NPlus\Reminder\SacReminder.exe (Storage Appliance Corp.)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [SPMTray] "C:\Program Files\PC Speed Maximizer\SPMTray.exe" File not found
O4 - HKCU..\Run: [Upromise Tray] C:\Program Files\Upromise\UpromiseTray.exe (Upromise, Inc.)
O4 - HKCU..\Run: [Upromise Update] C:\Program Files\Upromise\dca-ua.exe (Compete, Inc.)
O4 - HKCU..\Run: [WizMouse] C:\Program Files\WizMouse\WizMouse.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
https://activatemyfios.verizon.net/sdcCommo…20Installer.cab (Support.com Configuration Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778}
https://www.hpwindows7upgrade.arvato.com/no…PProdDetect.cab (HP Product Detection Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_02)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{876863F4-F078-43F9-8055-5AB0D8D5915E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E4D8A072-3585-4EEB-ACE6-BE1418B200FE}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 17:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/07/06 13:55:49 | 000,000,097 | R— | M] () - E:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2012/01/21 13:16:52 | 000,000,044 | —- | M] () - J:\Autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: edlipers - (C:\WINDOWS\system32\MRTsi64.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Remoteaccess - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.pspgru - C:\WINDOWS\System32\PSPGRU.acm (Philips Austria GmbH - Speech Processing)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/09/27 15:42:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\Desktop\AOL Saved PFC
[2013/09/27 15:26:15 | 000,000,000 | —D | C] – C:\Program Files\AOL Desktop 9.7
[2013/09/27 15:03:40 | 000,000,000 | —D | C] – C:\43145a898785a1f02137b8f8
[2013/09/27 10:50:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\VIRUS FIXES
[2013/09/26 16:33:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\Application Data\Systweak
[2013/09/26 15:27:25 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Apple Computer
[2013/09/19 17:12:38 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2013/09/19 17:12:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2013/09/12 20:42:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header
[2013/09/07 15:21:33 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/09/07 13:20:51 | 000,027,648 | —- | C] (Johnson-Grace Company) – C:\WINDOWS\System32\jgpl400.dll
[2013/09/07 13:20:50 | 000,163,840 | —- | C] (America Online) – C:\WINDOWS\System32\jgdw400.dll
[2013/01/12 15:47:27 | 000,940,544 | —- | C] (Apache Software Foundation) – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\log4cxx.dll
========== Files - Modified Within 30 Days ==========
[2013/09/28 00:05:00 | 000,000,250 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2013/09/27 23:57:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/27 23:26:00 | 000,000,900 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/27 20:30:10 | 000,483,994 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/09/27 20:30:10 | 000,080,954 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/09/27 20:26:05 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/09/27 20:25:56 | 000,000,896 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/27 20:25:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/09/27 20:25:47 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2013/09/27 15:42:45 | 000,000,654 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk
[2013/09/27 15:42:45 | 000,000,636 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AOL Desktop 9.7.lnk
[2013/09/27 15:42:35 | 000,000,006 | —- | M] () – C:\WINDOWS\msoffice.ini
[2013/09/27 15:17:57 | 000,001,698 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\Microsoft Security Essentials.lnk
[2013/09/27 14:56:20 | 000,001,919 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2013/09/27 12:10:07 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/27 11:57:10 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/19 14:29:04 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/09/19 13:57:42 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/19 13:57:41 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/14 07:25:42 | 000,196,926 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\Esserman.zip
[2013/09/12 20:42:36 | 000,089,758 | —- | M] () – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header.zip
[2013/09/12 16:35:01 | 000,171,488 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/12 06:44:30 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/09/07 13:40:30 | 000,058,696 | —- | M] (AOL Inc.) – C:\WINDOWS\System32\AOLParconLink.exe
[2013/09/07 13:20:51 | 000,027,648 | —- | M] (Johnson-Grace Company) – C:\WINDOWS\System32\jgpl400.dll
[2013/09/07 13:20:50 | 000,163,840 | —- | M] (America Online) – C:\WINDOWS\System32\jgdw400.dll
========== Files Created - No Company Name ==========
[2013/09/27 15:30:31 | 000,000,654 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk
[2013/09/27 15:30:31 | 000,000,636 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AOL Desktop 9.7.lnk
[2013/09/27 15:17:57 | 000,001,698 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Desktop\Microsoft Security Essentials.lnk
[2013/09/27 14:58:26 | 3209,871,360 | -HS- | C] () – C:\hiberfil.sys
[2013/09/27 11:26:34 | 000,000,664 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\d3d9caps.dat
[2013/09/19 17:12:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/09/14 07:25:41 | 000,196,926 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\Esserman.zip
[2013/09/12 20:42:36 | 000,089,758 | —- | C] () – C:\Documents and Settings\Drew Krajeski\My Documents\eagle-logo-header.zip
[2013/01/12 15:47:27 | 000,094,208 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\common_functions.dll
[2012/09/03 19:44:27 | 000,000,844 | —- | C] () – C:\Documents and Settings\Drew Krajeski\.recently-used.xbel
[2012/07/10 07:13:35 | 000,000,000 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\SharedSettings.ccs
[2012/07/10 07:12:18 | 000,058,368 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\gdsukavj
[2012/06/07 20:58:12 | 000,302,425 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\funmoods-speeddial.crx
[2012/02/15 08:02:42 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012/01/25 13:10:40 | 000,015,312 | —- | C] () – C:\WINDOWS\System32\RaCoInst.dat
[2011/09/02 07:08:50 | 000,102,400 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\ie_runner_app.exe
[2011/08/25 17:19:48 | 000,001,715 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\SAS7_000.DAT
[2010/04/28 18:30:41 | 000,001,020 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Application Data\wklnhst.dat
[2009/04/11 16:23:46 | 000,038,912 | —- | C] () – C:\Documents and Settings\Drew Krajeski\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2004/08/11 17:21:56 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2009/04/29 00:46:52 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/09/27 20:26:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Anti-phishing Domain Advisor
[2013/05/09 17:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ask
[2012/06/23 08:44:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2011/04/07 17:31:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CFTEMP
[2011/03/19 14:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Clickfree
[2012/07/10 08:14:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F4D55F1722F092F00009A52DD151FC4E
[2012/07/10 10:46:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HitmanPro
[2013/07/04 15:19:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011/07/23 08:52:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/08/08 11:00:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/07/24 08:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pc health check
[2011/12/31 16:32:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/07/24 08:08:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spotmau
[2008/10/10 09:34:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2013/09/23 03:00:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/07/24 08:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp360
[2011/08/08 11:00:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UAB
[2008/10/10 09:35:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2009/04/11 16:26:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/02/02 07:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/12/18 08:09:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2009/04/11 16:28:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\acccore
[2011/12/26 17:31:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\alotappbar
[2013/01/11 15:59:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\APP_NAME_NON_STRING
[2012/02/13 21:12:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\BDlot
[2012/06/22 05:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\blekkotb_019
[2011/12/09 19:16:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Catalina Marketing Corp
[2009/10/10 19:10:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/04/25 21:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Digiarty
[2012/06/07 20:58:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\FCSB000063941
[2013/07/08 20:45:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\FCTB000100433
[2013/01/11 16:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Foxit Software
[2013/07/04 15:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Juniper Networks
[2011/07/23 09:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Nuance
[2012/02/02 12:44:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Oracle
[2012/06/07 20:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\PC Speed Maximizer
[2012/09/20 23:13:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\PCCUStubInstaller
[2013/01/11 16:10:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\PDF Architect
[2013/01/11 15:58:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\pdfforge
[2013/08/12 06:34:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Qwiklinx
[2013/03/29 12:20:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\ShopAtHome
[2013/09/27 15:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Software Informer
[2011/07/24 08:08:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\spotmau
[2012/01/25 17:11:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\SystemRequirementsLab
[2013/09/26 17:03:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Systweak
[2011/08/04 15:00:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Template
[2011/08/09 07:15:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Tific
[2013/01/12 15:47:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\upromise
[2011/11/21 06:29:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\URSoft
[2009/09/13 06:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew Krajeski\Application Data\Viewpoint
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2004/08/04 05:00:00 | 000,359,533 | —- | M] () MD5=4F061B12F3D5457315A0314954E7EF46 – C:\i386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\i386\explorer.exe
< MD5 for: EXPLORER.EXE-02121B1A.PF >
[2013/09/28 00:02:44 | 000,075,336 | —- | M] () MD5=4E43FD1EDEEEF65AD59A416CD63B60EF – C:\WINDOWS\Prefetch\EXPLORER.EXE-02121B1A.pf
< MD5 for: EXPLORER.HTM >
[2004/11/09 17:36:40 | 000,002,225 | —- | M] () MD5=27E8E84DB81847B335D3C78356EAEB78 – C:\Program Files\ZyXEL Communications Corporation\ZyXEL PLA-4xx Series Configuration Utility\Online_Help\wwhelp\wwhimpl\java\html\explorer.htm
< MD5 for: EXPLORER.SC_ >
[2004/08/04 05:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2004/08/04 05:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\i386\iexplore.chm
[2004/08/04 05:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie8\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2004/08/04 05:00:00 | 000,037,895 | —- | M] () MD5=F83009589844F0C30801CC2221F06AB9 – C:\i386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2012/07/10 09:16:19 | 001,012,656 | —- | M] () MD5=C7D040F4C3C0214B460AABDE52BE9189 – C:\Documents and Settings\Drew Krajeski\My Documents\Downloads\iExplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
< MD5 for: IEXPLORE.HLP >
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\i386\iexplore.hlp
[2004/08/04 05:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\i386\services
[2004/08/04 05:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >
[2013/09/03 09:53:56 | 000,558,864 | —- | M] () MD5=4097D9DB7F5DB4533DDA8271136C9B7B – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/02/06 07:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 20:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\ERDNT\cache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
[2004/08/04 05:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\i386\services.exe
< MD5 for: SERVICES.LNK >
[2004/08/11 17:15:06 | 000,001,506 | —- | M] () MD5=C04255E822F6017251E30CE1481EB38E – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MSC >
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\i386\services.msc
[2004/08/04 05:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: WINLOGON.EXE >
[2004/08/04 05:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\i386\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/04/11 06:50:03 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/01/29 11:43:14 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/02/01 16:51:20 | 000,016,085 | —- | M] () – C:\ComboFix.txt
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/10/10 09:07:32 | 000,007,477 | R— | M] () – C:\dell.sdr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/09/27 20:25:47 | 3209,871,360 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2013/09/27 15:30:37 | 000,061,624 | —- | M] () – C:\install.log
[2012/01/29 01:21:04 | 000,000,000 | —- | M] () – C:\install.rdf
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\IO.SYS
[2012/02/02 12:34:23 | 000,026,311 | —- | M] () – C:\JavaRa.log
[2004/08/11 17:15:00 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/18 06:24:39 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/09/27 20:25:45 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/07/10 09:41:50 | 000,000,436 | —- | M] () – C:\rkill.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/11 17:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is CCE1-E82B
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
08/14/2013 06:02 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
08/14/2013 06:01 AM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices
08/14/2013 06:06 AM v4.0_4.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
3 Dir(s) 428,492,554,240 bytes free
< %systemroot%\System32\config\*.sav >
[2004/08/11 17:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/11 17:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/11 17:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/03/28 17:46:56 | 000,309,560 | —- | M] () – C:\Documents and Settings\Drew Krajeski\Desktop\EbatesCashBackToolbar.exe
[2011/09/04 09:07:52 | 000,600,648 | —- | M] (Antibody Software ) – C:\Documents and Settings\Drew Krajeski\Desktop\wizmouse_1_6_0_1_setup.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-09-13 11:48:24
========== Base Services ==========
SRV - [2008/04/13 20:12:12 | 000,044,544 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\alg.exe – (ALG)
SRV - [2008/04/13 20:12:11 | 000,006,656 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wuauserv.dll – (wuauserv)
SRV - [2008/04/13 20:12:03 | 000,409,088 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\qmgr.dll – (BITS)
SRV - [2012/07/06 09:58:51 | 000,078,336 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\browser.dll – (Browser)
SRV - [2008/04/13 20:11:51 | 000,062,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\cryptsvc.dll – (CryptSvc)
SRV - [2008/04/13 20:11:51 | 000,126,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dhcpcsvc.dll – (Dhcp)
SRV - [2009/04/20 13:17:26 | 000,045,568 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\dnsrslvr.dll – (Dnscache)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (Eventlog)
SRV - [2008/04/13 20:11:52 | 000,033,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\eapsvc.dll – (EapHost)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\shsvcs.dll – (FastUserSwitchingCompatibility)
SRV - [2008/04/13 20:12:08 | 000,015,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\w3ssl.dll – (HTTPFilter)
SRV - [2008/04/13 20:11:54 | 000,021,504 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\hidserv.dll – (HidServ)
SRV - [2008/04/13 20:12:22 | 000,150,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\imapi.exe – (ImapiService)
No service found with a name of PolicyAgent
SRV - [2008/04/13 20:11:52 | 000,023,552 | —- | M] (Microsoft Corp.) [Auto | Running] – C:\WINDOWS\system32\dmserver.dll – (dmserver)
SRV - [2008/04/13 20:12:17 | 000,224,768 | —- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] – C:\WINDOWS\System32\dmadmin.exe – (dmadmin)
SRV - [2008/04/13 20:12:17 | 000,005,120 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\dllhost.exe – (SwPrv)
SRV - [2008/04/13 20:12:24 | 000,013,312 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\lsass.exe – (Netlogon)
SRV - [2008/04/13 20:12:01 | 000,198,144 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\netman.dll – (Netman)
SRV - [2008/06/20 12:02:47 | 000,245,248 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\mswsock.dll – (Nla)
SRV - [2009/02/06 07:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\services.exe – (PlugPlay)
SRV - [2010/08/17 09:17:06 | 000,058,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\spoolsv.exe – (Spooler)
SRV - [2008/04/13 20:12:24 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (ProtectedStorage)
SRV - [2008/04/13 20:12:03 | 000,088,576 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\rasauto.dll – (RasAuto)
SRV - [2008/04/13 20:12:03 | 000,186,368 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\rasmans.dll – (RasMan)
SRV - [2009/02/09 08:10:48 | 000,401,408 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\rpcss.dll – (RpcSs)
SRV - [2008/04/13 20:12:02 | 000,435,200 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\ntmssvc.dll – (NtmsSvc)
SRV - [2008/04/13 20:12:05 | 000,018,944 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\seclogon.dll – (seclogon)
SRV - [2008/04/13 20:12:24 | 000,013,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lsass.exe – (SamSs)
SRV - [2008/04/13 20:12:10 | 000,080,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wscsvc.dll – (wscsvc)
SRV - [2010/08/27 01:57:43 | 000,099,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srvsvc.dll – (lanmanserver)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/04/13 20:12:07 | 000,171,008 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\srsvc.dll – (srservice)
SRV - [2008/04/13 20:12:05 | 000,192,512 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\schedsvc.dll – (Schedule)
SRV - [2008/04/13 20:11:56 | 000,013,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\lmhsvc.dll – (LmHosts)
SRV - [2008/04/13 20:12:07 | 000,249,856 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\tapisrv.dll – (TapiSrv)
SRV - [2008/04/13 20:12:07 | 000,295,424 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\WINDOWS\system32\termsrv.dll – (TermService)
SRV - [2009/07/27 19:17:41 | 000,135,168 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\shsvcs.dll – (Themes)
SRV - [2008/04/13 20:12:38 | 000,289,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\vssvc.exe – (VSS)
SRV - [2008/04/13 20:11:50 | 000,042,496 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\audiosrv.dll – (AudioSrv)
SRV - [2008/04/13 20:11:55 | 000,331,264 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\ipnathlp.dll – (SharedAccess)
SRV - [2008/04/13 20:12:08 | 000,333,824 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wiaservc.dll – (stisvc)
SRV - [2008/04/13 20:12:28 | 000,078,848 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\System32\msiexec.exe – (MSIServer)
SRV - [2008/04/13 20:12:09 | 000,144,896 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wbem\wmisvc.dll – (winmgmt)
SRV - [2009/02/09 08:10:48 | 000,617,472 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\advapi32.dll – (Wmi)
SRV - [2008/04/13 20:11:52 | 000,132,096 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\system32\dot3svc.dll – (Dot3svc)
SRV - [2008/04/13 20:12:11 | 000,483,840 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wzcsvc.dll – (WZCSVC)
SRV - [2009/06/10 02:14:49 | 000,132,096 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\wkssvc.dll – (lanmanworkstation)
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: Hitachi HDP725050GLA360
Partitions: 2
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 - Removable media other than\tfloppy
Interface type: USB
Media Type: Removable media other than\tfloppy
Model: Clikfree Backup Drive USB Device
Partitions: 1
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: TEAC USB HS-CF Card USB Device
Partitions: 0
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: TEAC USB HS-xD/SM USB Device
Partitions: 0
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: TEAC USB HS-MS Card USB Device
Partitions: 0
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: TEAC USB HS-SD Card USB Device
Partitions: 0
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 55.00MB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 57576960
Hidden sectors: 0
DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 32256
Hidden sectors: 0
========== Alternate Data Streams ==========
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0FF263E8
< End of report >
The Extras.txt did not appear at the end of this scan but one did earlier when I ran OTL based on the instructions to run three scans posted in the Virus, Spyware & Malware Removal forum. Here is that txt:
OTL Extras logfile created on: 9/27/2013 8:33:27 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Drew Krajeski\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 2.25 Gb Available Physical Memory | 75.24% Memory free
4.83 Gb Paging File | 4.12 Gb Available in Paging File | 85.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.70 Gb Total Space | 399.26 Gb Free Space | 85.73% Space Free | Partition Type: NTFS
Drive E: | 133.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 931.30 Gb Total Space | 927.86 Gb Free Space | 99.63% Space Free | Partition Type: NTFS
Computer Name: D3H5MKH1 | User Name: Drew Krajeski | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"53271:UDP" = 53271:UDP:*:Enabled:SacNetAgentCommunicationPort1
"53272:TCP" = 53272:TCP:*:Enabled:SacNetAgentCommunicationPort2
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\aol\acs\AOLDial.exe" = C:\Program Files\Common Files\aol\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer – (America Online)
"C:\Program Files\Common Files\aol\acs\AOLacsd.exe" = C:\Program Files\Common Files\aol\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service – (AOL LLC)
"C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1270162804\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\waol.exe" = C:\Program Files\AOL Desktop 9.7\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL Inc.)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL System Information – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.7\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe" = c:\documents and settings\all users\application data\Clickfree\C2NPlus\Reminder\SacNetAgent.exe:*:Enabled:SacNetAgentService – (Storage Appliance Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09531CAE-B186-49A9-B44F-C607CC54FA2A}" = PDF Architect
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{1111706F-666A-4037-7777-202328764D10}" = JavaFX 2.0.2
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{26A24AE4-039D-4CA4-87B4-2F83217002FF}" = Java™ 7 Update 2
"{27F00C63-449B-2FAB-CBE8-24AB80E17449}" = Acrobat.com
"{2E497885-E60B-420A-832D-0148B392E058}_is1" = Qwiklinx
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D00BF1-C0BE-4237-ADD4-B166CAF3E284}" = ZyXEL PLA-4xx Series Configuration Utility
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DADB23F-94E6-4E4D-AFE8-15DE4395E8F3}" = Microsoft Security Client
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4640FDE1-B83A-4376-84ED-86F86BEE2D41}" = Driver Detective
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A5A427F-BA39-4BF0-9999-9A47FBE60C9F}" = Visual C++ 9.0 Runtime for Dragon NaturallySpeaking
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Logitech Harmony Remote Software
"{6438A99C-A37E-4758-A0AE-95F8A63AAFF5}" = Intel® Network Connections [removed]
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2713384-7398-43E9-9D43-565B3A7FEFEE}" = Security Advisor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.8)
"{AE502938-5BF1-4CEA-961D-0081B992C878}_is1" = Shop To Win
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0DA129B-1E45-494D-A362-5CD0109C306B}" = WOT for Internet Explorer
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E5D4B0C7-985F-4EF0-9932-8F1E4B60B89E}" = Coupons at Checkout
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EFE3D683-903C-4B58-AB8F-C68C69F33758}" = System Requirements Lab for Intel
"{EFFA53BC-8C04-2E21-3D90-A13B1697B0CA}" = Dragon NaturallySpeaking 11
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F169F5B9-776C-401B-AF01-155433C6BE9B}" = Vz In Home Agent
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Anti-phishing Domain Advisor" = Anti-phishing Domain Advisor
"AnVir Task Manager" = AnVir Task Manager
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Ebates Cash Back Toolbar" = Ebates Cash Back Toolbar
"ESET Online Scanner" = ESET Online Scanner v3
"Foxit Reader_is1" = Foxit Reader
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"GRTSoft Data Recovery_is1" = GRTSoft Data Recovery 2.5
"HDMI" = Intel® Graphics Media Accelerator Driver
"HitmanPro36" = HitmanPro 3.6
"ie8" = Windows Internet Explorer 8
"Juniper_Setup_Client Activex Control" = Juniper Networks, Inc. Setup Client Activex Control
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NortonPCCheckup" = Norton PC Checkup
"PC Speed Maximizer_is1" = PC Speed Maximizer v3.0
"Photo Stamp Remover_is1" = Photo Stamp Remover 3.1
"Realtek Drivers Update Utility 3.0_is1" = Realtek Drivers Update Utility 3.0
"Samsung CLP-300 Series" = Samsung CLP-300 Series
"SearchAssist" = SearchAssist
"ShopAtHome.com Helper" = ShopAtHome.com Helper
"ShopAtHome.com Toolbar" = ShopAtHome.com Toolbar
"Software Informer_is1" = Software Informer 1.1
"Spykee" = Spykee
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 4.1.1
"Wise Disk Cleaner_is1" = Wise Disk Cleaner Professional v5.2
"WizMouse_is1" = WizMouse v1.6.0.1
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YU2010_is1" = Your Uninstaller! 7
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Support.com Toolbar Updater
"Juniper_Setup_Client" = Juniper Networks, Inc. Setup Client
"Neoteris_Host_Checker" = Juniper Networks Host Checker
"Upromise TurboSaver" = Upromise TurboSaver (remove only)
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/26/2013 5:54:04 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80070643 Description:. 0x80070643. Fatal error during installation.
Error - 9/27/2013 10:27:22 AM | Computer Name = D3H5MKH1 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Security Client – The installer has encountered
an unexpected error installing this package. This may indicate a problem with this
package. The error code is 2324. The arguments are: 1920, c:\Program Files\Microsoft
Security Client\SymSrv.yes,
Error - 9/27/2013 10:27:41 AM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80070643 Description:. 0x80070643. Fatal error during installation.
Error - 9/27/2013 12:59:21 PM | Computer Name = D3H5MKH1 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Security Client – The installer has encountered
an unexpected error installing this package. This may indicate a problem with this
package. The error code is 2324. The arguments are: 1920, c:\Program Files\Microsoft
Security Client\SymSrv.yes,
Error - 9/27/2013 12:59:25 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x80070643 Description:. 0x80070643. Fatal error during installation.
Error - 9/27/2013 2:54:31 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF11 Description:. 0x8004FF11.
Error - 9/27/2013 2:56:20 PM | Computer Name = D3H5MKH1 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF11 Description:. 0x8004FF11.
Error - 9/27/2013 3:13:13 PM | Computer Name = D3H5MKH1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070490, P2 remediation, P3 remediationfailuretelemetry,
P4 1.1.9901.0, P5 mpengine, P6 0, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 9/27/2013 3:45:14 PM | Computer Name = D3H5MKH1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070490, P2 remediation, P3 remediationfailuretelemetry,
P4 1.1.9901.0, P5 mpengine, P6 0, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
Error - 9/27/2013 8:25:59 PM | Computer Name = D3H5MKH1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80070490, P2 remediation, P3 remediationfailuretelemetry,
P4 1.1.9901.0, P5 mpengine, P6 0, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.
[ System Events ]
Error - 9/27/2013 3:13:00 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2
Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20
Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2
Error - 9/27/2013 3:45:08 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The PCASp50 NDIS Protocol Driver service failed to start due to the
following error: %%2
Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%20
Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The Java Quick Starter service failed to start due to the following
error: %%2
Error - 9/27/2013 8:26:01 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2
Error - 9/27/2013 8:26:03 PM | Computer Name = D3H5MKH1 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
iaStor
< End of report >
Thank you!!