Malwarebytes' Anti-Malware 1.44
Database version: 3642
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/8/2010 10:25:52 PM
mbam-log-2010-02-08 (22-25-49).txt
Scan type: Full Scan (C:\|)
Objects scanned: 175739
Time elapsed: 35 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP398\A0065408.sys (Malware.Trace) -> No action taken.
C:\System Volume Information\_restore{41AF0825-6FA2-4B5C-80A2-9C945A290842}\RP398\A0065500.sys (Malware.Trace) -> No action taken.
ESET
C:\Share\Nero-6.6.1.15a.exe Win32/Toolbar.AskSBar application deleted - quarantined
OTL
OTL logfile created on: 2/8/2010 11:26:27 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\SB\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 162.00 Mb Available Physical Memory | 32.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.01 Gb Total Space | 104.15 Gb Free Space | 69.90% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SB
Current User Name: SB
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/02/08 23:25:34 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\SB\Desktop\OTL.exe
PRC - [2010/02/07 11:10:48 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2010/02/07 11:10:48 | 000,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2010/01/24 17:15:36 | 001,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/01/24 17:15:34 | 002,033,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/01/24 17:15:32 | 000,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/01/24 17:15:32 | 000,600,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/01/24 17:15:32 | 000,503,576 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/01/24 17:15:30 | 000,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2008/04/13 20:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/21 20:09:02 | 000,842,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2004/10/08 19:16:24 | 000,088,363 | R--- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2003/11/13 18:23:52 | 000,062,464 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2003/11/12 04:48:20 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
PRC - [2003/08/28 06:32:38 | 000,155,648 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxtray.exe
PRC - [2003/08/28 06:19:34 | 000,118,784 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\hkcmd.exe
========== Modules (SafeList) ========== MOD - [2010/02/08 23:25:34 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\SB\Desktop\OTL.exe
========== Win32 Services (SafeList) ========== SRV - [2010/02/07 11:10:48 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2010/01/24 17:15:30 | 000,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2008/08/09 00:35:50 | 000,350,672 | ---- | M] (Assistance & Resources for Computing, Inc.) [Disabled | Stopped] -- C:\Program Files\PurgeIE\PurgPro_Service.exe -- (PurgProService)
SRV - [2005/04/04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003/11/12 04:48:20 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm...tf8&oe=utf8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/28 00:10:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/28 00:10:10 | 000,000,000 | ---D | M]
[2010/01/24 16:08:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Mozilla\Extensions
[2010/01/24 16:08:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/01/28 00:10:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Mozilla\Firefox\Profiles\vk274px8.default\extensions
[2010/01/28 00:10:10 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/12/05 22:59:22 | 000,000,727 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [EPSON Stylus CX4200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://download.bitdefender.com/resources/...can8/oscan8.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
https://mac.otpp.com/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O22 - SharedTaskScheduler: {D06075B5-6E89-4DE1-BFFF-57F4ACEAE1F2} - MepyrinaSfc - C:\WINDOWS\system32\mepyrina.dll ( )
O24 - Desktop WallPaper: C:\Documents and Settings\SB\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\SB\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/02/09 19:02:30 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/02/09 18:54:42 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - C:\WINDOWS\system32\irmon.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17173366603513856)
========== Files/Folders - Created Within 14 Days ========== [2010/02/08 23:25:32 | 000,549,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\SB\Desktop\OTL.exe
[2010/02/08 22:28:52 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/02/07 23:18:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SB\My Documents\My Videos - Delete
[2010/02/07 20:19:05 | 000,000,000 | -HSD | C] -- C:\Recycled
[2010/02/07 19:51:06 | 000,000,000 | ---D | C] -- C:\FOUND.000
[2010/02/07 19:47:40 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/02/07 19:47:02 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/02/07 19:47:02 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/02/07 19:47:02 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/02/07 19:47:02 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/02/07 19:46:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/02/07 19:46:41 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/02/07 11:30:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\SB\Recent
[2010/01/30 16:49:41 | 000,472,064 | ---- | C] ( ) -- C:\Documents and Settings\SB\Desktop\RootRepeal.exe
[2010/01/30 12:31:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google
[2010/01/30 09:31:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/01/30 09:26:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/01/28 19:02:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SB\Local Settings\Application Data\Apple Computer
[2010/01/28 19:02:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/01/28 00:10:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SB\Local Settings\Application Data\Mozilla
[2010/01/28 00:10:09 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/01/26 23:33:42 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\SB\IECompatCache
[2010/01/26 23:32:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\SB\PrivacIE
[2010/01/26 23:31:07 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\SB\IETldCache
[2010/01/26 23:28:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/01/26 23:27:08 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/01/26 18:22:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2007/03/31 10:00:20 | 000,319,488 | ---- | C] ( ) -- C:\WINDOWS\System32\mepyrina.dll
[2007/01/13 14:49:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Juniper Networks
[2006/09/19 23:26:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Juniper Networks
[2004/02/09 19:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2004/02/09 19:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2004/02/09 18:56:30 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2004/02/09 18:56:30 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 14 Days ========== [2010/02/08 23:25:34 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\SB\Desktop\OTL.exe
[2010/02/08 20:41:08 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0FD9F4EC-D188-407D-ABD4-C88E9F1B6015}.job
[2010/02/07 23:54:24 | 000,235,008 | ---- | M] () -- C:\Documents and Settings\SB\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/07 20:00:48 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/07 19:59:40 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/02/07 19:51:42 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\BackgroundTaskUserS-1-5-21-2636412022-791471798-114929213-1005.job
[2010/02/07 19:51:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/02/07 19:51:28 | 528,011,264 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/07 19:47:50 | 006,291,456 | -H-- | M] () -- C:\Documents and Settings\SB\NTUSER.DAT
[2010/02/07 19:47:44 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/02/07 19:45:04 | 003,850,968 | R--- | M] () -- C:\Documents and Settings\SB\Desktop\schrauber.exe
[2010/02/07 19:35:44 | 000,318,464 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\MBANX.XLS
[2010/02/07 11:58:48 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\SB\ntuser.ini
[2010/02/07 11:40:16 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\SB\Desktop\kxvj4h3g.exe
[2010/02/07 11:35:36 | 000,524,288 | ---- | M] () -- C:\Documents and Settings\SB\Desktop\dds.scr
[2010/02/07 09:56:18 | 000,082,944 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\SD.09t
[2010/02/07 09:38:58 | 000,001,754 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\StudioTax 2009.lnk
[2010/02/07 09:37:58 | 000,412,416 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/02/07 09:37:58 | 000,398,402 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/02/07 09:37:58 | 000,060,204 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/02/07 00:20:28 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2010/02/06 11:40:38 | 000,161,280 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\EXPENSE.XLS
[2010/02/06 10:43:28 | 000,270,848 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\MTG.XLS
[2010/02/06 10:37:26 | 000,054,272 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\RRSP.XLS
[2010/02/06 10:18:12 | 000,103,424 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\car.xls
[2010/02/06 09:58:22 | 000,015,776 | ---- | M] () -- C:\Documents and Settings\SB\My Documents\The_Soup_2010_01_29_PDTV_XviD_MOMENTUM.torrent
[2010/01/30 16:49:38 | 000,472,064 | ---- | M] ( ) -- C:\Documents and Settings\SB\Desktop\RootRepeal.exe
[2010/01/28 19:02:46 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/01/28 19:02:46 | 000,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2010/01/28 00:10:24 | 000,000,000 | ---- | M] () -- C:\WINDOWS\nsreg.dat
[2010/01/28 00:10:14 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/01/27 00:20:56 | 000,001,327 | ---- | M] () -- C:\Limewire Music.lnk
[2010/01/26 23:22:44 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/01/26 18:44:12 | 000,000,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/02/07 19:47:42 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/02/07 19:47:40 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/02/07 19:47:02 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/02/07 19:47:02 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/02/07 19:47:02 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/02/07 19:47:02 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/02/07 19:47:02 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/02/07 19:45:03 | 003,850,968 | R--- | C] () -- C:\Documents and Settings\SB\Desktop\schrauber.exe
[2010/02/07 11:40:15 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\SB\Desktop\kxvj4h3g.exe
[2010/02/07 09:55:50 | 000,082,944 | ---- | C] () -- C:\Documents and Settings\SB\My Documents\SD.09t
[2010/02/07 09:38:56 | 000,001,754 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\StudioTax 2009.lnk
[2010/02/06 09:58:28 | 000,015,776 | ---- | C] () -- C:\Documents and Settings\SB\My Documents\The_Soup_2010_01_29_PDTV_XviD_MOMENTUM.torrent
[2010/01/30 16:47:02 | 000,524,288 | ---- | C] () -- C:\Documents and Settings\SB\Desktop\dds.scr
[2010/01/30 11:47:20 | 528,011,264 | -HS- | C] () -- C:\hiberfil.sys
[2010/01/28 19:02:44 | 000,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2010/01/28 19:02:44 | 000,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2010/01/28 00:10:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/01/28 00:10:12 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/01/26 23:33:41 | 000,000,428 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0FD9F4EC-D188-407D-ABD4-C88E9F1B6015}.job
[2010/01/18 19:18:43 | 000,000,754 | ---- | C] () -- C:\WINDOWS\wordpad.INI
[2009/08/22 16:54:33 | 000,373,342 | ---- | C] () -- C:\Documents and Settings\SB\Application Data\CleanUp!.log
[2009/01/20 18:19:56 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2008/08/09 20:05:09 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2008/04/09 23:41:17 | 000,000,419 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2008/04/09 23:41:17 | 000,000,027 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2008/02/23 11:25:37 | 000,000,067 | ---- | C] () -- C:\WINDOWS\AVIConverter.INI
[2008/02/23 01:02:57 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/02/23 01:02:56 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/01/01 16:40:46 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\SB\Local Settings\Application Data\fusioncache.dat
[2007/07/12 19:12:16 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\uccspecc.sys
[2007/03/31 10:00:16 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\getmemoc.dll
[2006/06/30 23:18:24 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/06/17 23:21:24 | 000,000,022 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2006/06/17 15:39:08 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2006/06/17 15:38:06 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPCX4200.ini
[2006/01/12 17:09:14 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\DXFLib.dll
[2005/12/11 01:01:04 | 000,000,836 | ---- | C] () -- C:\Documents and Settings\SB\Application Data\ViewerApp.dat
[2005/12/11 00:54:38 | 000,003,654 | ---- | C] () -- C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2005/09/28 10:12:40 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\YCRWin32.dll
[2005/09/12 17:49:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\autorun.INI
[2005/06/30 22:53:09 | 000,000,783 | ---- | C] () -- C:\WINDOWS\NTIWVEDT.INI
[2005/06/09 22:08:03 | 000,000,202 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2005/06/01 19:24:34 | 000,000,211 | ---- | C] () -- C:\WINDOWS\nanoPEG.ini
[2005/06/01 19:21:40 | 000,000,382 | ---- | C] () -- C:\WINDOWS\HCWBlast.ini
[2005/06/01 19:21:27 | 000,026,124 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2005/06/01 19:21:08 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
[2005/06/01 19:19:42 | 000,000,657 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2005/06/01 19:17:32 | 000,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2005/03/13 10:13:02 | 000,000,277 | ---- | C] () -- C:\WINDOWS\Jcmkr32.INI
[2005/03/13 09:42:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/03/12 21:28:55 | 000,235,008 | ---- | C] () -- C:\Documents and Settings\SB\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/03/12 19:28:09 | 000,000,173 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2004/02/09 19:28:34 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/02/09 19:25:54 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK32.dll
[2004/02/09 19:19:26 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/02/09 19:05:02 | 000,007,961 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/02/09 18:59:55 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2001/12/26 16:12:30 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/19 13:41:46 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\opcode.dll
[2001/09/03 23:46:38 | 000,110,592 | R--- | C] () -- C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 16:33:56 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 22:04:36 | 000,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
[1980/01/01 00:00:00 | 000,000,113 | ---- | C] () -- C:\WINDOWS\ALaunch.ini
========== LOP Check ========== [2005/06/01 19:23:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/09/19 18:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2009/05/14 23:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rogers Online Protection
[2009/07/01 17:56:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/01/24 13:24:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/01/24 17:15:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2004/02/09 19:05:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\InterTrust
[2008/02/23 00:35:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\uTorrent
[2008/08/09 00:35:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\PurgeIE
[2008/12/09 00:19:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\LimeWire
[2009/03/21 17:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Any Video Converter
[2005/06/02 18:00:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Ulead Systems
[2006/06/20 17:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\EPSON
[2006/09/19 18:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Juniper Networks
[2009/05/14 23:25:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SB\Application Data\Rogers Online Protection
[2010/02/07 19:51:42 | 000,000,266 | ---- | M] () -- C:\WINDOWS\Tasks\BackgroundTaskUserS-1-5-21-2636412022-791471798-114929213-1005.job
[2009/07/31 20:45:02 | 000,000,320 | ---- | M] () -- C:\WINDOWS\Tasks\shutdown.job
[2010/02/08 20:41:08 | 000,000,428 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{0FD9F4EC-D188-407D-ABD4-C88E9F1B6015}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2007/01/13 14:13:06 | 022,245,337 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2008/09/12 18:51:44 | 023,852,652 | ---- | M] () .cab file -- C:\I386\sp3.cab:AGP440.sys
[2007/01/13 14:13:06 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/09/12 18:51:44 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >[2003/03/31 12:00:00 | 010,158,890 | ---- | M] () .cab file -- C:\I386\sp1.cab:atapi.sys
[2007/01/13 14:13:06 | 022,245,337 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2008/09/12 18:51:44 | 023,852,652 | ---- | M] () .cab file -- C:\I386\sp3.cab:atapi.sys
[2007/01/13 14:13:06 | 022,245,337 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/09/12 18:51:44 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2003/03/31 12:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2003/03/31 12:00:00 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 20:11:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 20:12:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >[2004/08/04 02:56:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s > ========== Files - Unicode (All) ==========[2009/12/12 23:03:06 | 000,000,040 | ---- | M] ()(C:\WINDOWS\System32\?????????????????????????????????????????????????) -- C:\WINDOWS\System32\㩃停潲牧浡䘠汩獥剜杯牥湏楬敮倠潲整瑣潩屮潒敧獲传汮湩牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩潣普杩
[2009/12/12 23:03:05 | 000,000,040 | ---- | C] ()(C:\WINDOWS\System32\?????????????????????????????????????????????????) -- C:\WINDOWS\System32\㩃停潲牧浡䘠汩獥剜杯牥湏楬敮倠潲整瑣潩屮潒敧獲传汮湩牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩潣普杩
< End of report >
OTL Extras logfile created on: 2/8/2010 11:26:28 PM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\SB\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.00 Mb Total Physical Memory | 162.00 Mb Available Physical Memory | 32.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 2000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.01 Gb Total Space | 104.15 Gb Free Space | 69.90% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: SB
Current User Name: SB
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe" = C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy -- (Juniper Networks)
"C:\Documents and Settings\SB\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe" = C:\Documents and Settings\SB\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe:*:Enabled:Juniper Terminal Services Client -- (Juniper Networks)
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{068502DA-6979-4D9A-BBE1-C3AD0FF11F19}" = Ulead DVD MovieFactory 3 SE
"{0E4BC542-9CFD-4E97-B586-9F1E5516E7B9}" = Microsoft IntelliPoint 6.1
"{1E2F8AE3-3437-44E6-BB75-E95751D6B83F}" = Picture Package
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java 6 Update 10
"{316CDA1E-4760-4772-94B0-0FFC56D85700}" = RPS CRT
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{34E95EA8-EEED-469A-A5C6-4BCFE33CA1B7}" = StudioTax 2008
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4ecaf021-478c-40c1-b777-3368a15f9966}" = Macromedia Flash Player
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6F9301C3-F016-450D-97A1-B376DB98E967}" = RPS CRT
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8441D243-8B1D-4E39-AF5E-5307E2E0C4B1}" = StudioTax 2009
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{A987FEC8-5616-49BD-BCA6-ACFFFE7403FE}" = IKEA Home Planner
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker
"{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}" = ArcSoft PhotoImpression 5
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
"AVG9Uninstall" = AVG Free 9.0
"bitRipper" = bitRipper
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"ExtractNow_is1" = ExtractNow
"Free RAR Extract Frog 1.00" = Free RAR Extract Frog 1.00
"Hauppauge English Help Files and Resources" = Hauppauge English Help Files and Resources
"Hauppauge WinTV Infrared Remote" = Hauppauge WinTV Infrared Remote
"Hauppauge WinTV IR Blaster" = Hauppauge WinTV IR Blaster
"Hauppauge WinTV Scheduler" = Hauppauge WinTV Scheduler
"Hauppauge WinTV2000" = Hauppauge WinTV2000
"Hauppauge WinTV-PVR 150 Drivers" = Hauppauge WinTV-PVR 150 Drivers
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"InstallShield_{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker 6.5 Gold
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"LimeWire" = LimeWire 5.3.6
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OfotoEZUpload" = KODAK EASYSHARE Gallery Upload ActiveX Control
"PurgeIE Pro_is1" = PurgeIE Pro - 4.01
"RealPlayer 6.0" = RealPlayer
"Silent Package Run-Time Sample" = EPSON CX 4200 4800 Guide
"WinAVI Video Converter_is1" = WinAVI Video Converter
"Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.3c
"Windows XP Service Pack" = Windows XP Service Pack 3
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD_is1" = XviD 1.1 final uninstall
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Juniper_Setup_Client" = Juniper Networks Setup Client
"Juniper_Term_Services" = Juniper Terminal Services Client
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 1/24/2010 2:57:29 PM | Computer Name = SB | Source = UmxAgent | ID = 99
Description =
Error - 1/24/2010 4:38:18 PM | Computer Name = SB | Source = UmxAgent | ID = 99
Description =
Error - 1/24/2010 4:56:15 PM | Computer Name = SB | Source = UmxAgent | ID = 99
Description =
Error - 1/24/2010 6:06:27 PM | Computer Name = SB | Source = Microsoft Office 10 | ID = 1000
Description = Faulting application outlook.exe, version 10.0.4024.0, faulting module
unknown, version 0.0.0.0, fault address 0x005e001f.
Error - 1/27/2010 12:12:57 AM | Computer Name = SB | Source = MsiInstaller | ID = 11334
Description = Product: Microsoft .NET Framework 1.1 -- Error 1334.The file 'FL_mscorees_dll_ENU_X86.3643236F_FC70_11D3_A536_0090278A1BB8'
cannot be installed because the file cannot be found in cabinet file 'PCW_CAB_NDP'.
This could indicate a network error, an error reading from the CD-ROM, or a problem
with this package.
Error - 1/27/2010 12:12:58 AM | Computer Name = SB | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{EBC491BC-BB34-4269-B391-DD3D36B869FE}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\DOCUME~1\SB\LOCALS~1\Temp\MSIb426f.LOG.
Error - 1/27/2010 12:13:28 AM | Computer Name = SB | Source = MsiInstaller | ID = 11334
Description = Product: Microsoft .NET Framework 1.1 -- Error 1334.The file 'FL_mscorees_dll_ENU_X86.3643236F_FC70_11D3_A536_0090278A1BB8'
cannot be installed because the file cannot be found in cabinet file 'PCW_CAB_NDP'.
This could indicate a network error, an error reading from the CD-ROM, or a problem
with this package.
Error - 1/27/2010 12:13:29 AM | Computer Name = SB | Source = MsiInstaller | ID = 1023
Description = Product: Microsoft .NET Framework 1.1 - Update '{EBC491BC-BB34-4269-B391-DD3D36B869FE}'
could not be installed. Error code 1603. Additional information is available in
the log file C:\DOCUME~1\SB\LOCALS~1\Temp\MSIbd20c.LOG.
Error - 1/27/2010 8:30:45 PM | Computer Name = SB | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 1/28/2010 11:36:57 PM | Computer Name = SB | Source = Application Error | ID = 1000
Description = Faulting application avgwdsvc.exe, version 9.0.0.663, faulting module
unknown, version 0.0.0.0, fault address 0x00000804.
[ System Events ]
Error - 1/17/2010 12:04:16 PM | Computer Name = SB | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/26/2010 7:32:51 PM | Computer Name = SB | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
HY that believes that it is the master browser for the domain on transport NetBT_Tcpip_{003EA2C5-6355-4B40-89.
The
master browser is stopping or an election is being forced.
Error - 1/29/2010 4:47:07 PM | Computer Name = SB | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
HOME-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{003EA2C5-6355-4B40-8. The master browser is stopping or an election
is being forced.
Error - 1/29/2010 9:44:10 PM | Computer Name = SB | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
HOME-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{003EA2C5-6355-4B40-8. The master browser is stopping or an election
is being forced.
Error - 1/30/2010 11:41:04 AM | Computer Name = SB | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/30/2010 12:28:44 PM | Computer Name = SB | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/30/2010 12:41:50 PM | Computer Name = SB | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 1/30/2010 12:46:36 PM | Computer Name = SB | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 2/2/2010 12:23:34 AM | Computer Name = SB | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{003EA2C5-6355-4B40-8982-A78CAEC88DD8}. The
backup browser is stopping.
Error - 2/7/2010 8:52:15 PM | Computer Name = SB | Source = System Error | ID = 1003
Description = Error code 00000019, parameter1 00000020, parameter2 822c6288, parameter3
822c6a98, parameter4 1b02003a.
< End of report >