OTL logfile created on: 06/15/13 6:49:41 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\johnt\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy 2.00 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 55.28% Memory free 3.35 Gb Paging File | 2.53 Gb Available in Paging File | 75.54% Paging File free Paging file location(s): C:\pagefile.sys 1534 1534 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.24 Gb Total Space | 18.32 Gb Free Space | 49.20% Space Free | Partition Type: NTFS Computer Name: JOHN | User Name: johnt | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013/06/15 18:24:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\johnt\Desktop\OTL.exe PRC - [2013/05/21 04:33:54 | 000,181,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2013/01/26 07:08:30 | 004,480,768 | ---- | M] (Akamai Technologies, Inc.) -- C:\Documents and Settings\johnt\Local Settings\Application Data\Akamai\netsession_win.exe PRC - [2012/08/30 04:03:36 | 000,497,320 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe PRC - [2012/08/30 04:03:12 | 000,738,984 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ForceField.exe PRC - [2012/08/29 16:17:06 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe PRC - [2012/08/29 15:45:24 | 000,073,392 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe PRC - [2011/04/19 16:39:30 | 000,935,744 | ---- | M] (SonicWALL, Inc.) -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mantispm.exe PRC - [2010/03/11 12:07:54 | 000,124,432 | ---- | M] ( Pro-Softnet) -- C:\Program Files\ZoneAlarmBackup\ZABackupWebM.exe PRC - [2010/03/11 12:01:32 | 000,149,008 | ---- | M] (Pro Softnet Corporation) -- C:\Program Files\ZoneAlarmBackup\ZABackup Service.exe PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) -- C:\Program Files\UPHClean\uphclean.exe PRC - [2001/08/17 16:36:42 | 000,024,064 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\devldr32.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/08/29 15:45:16 | 000,074,928 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\fde\fde_api.dll MOD - [2011/04/19 16:40:06 | 000,088,896 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\crsrpt.dll MOD - [2011/04/19 16:39:34 | 000,013,120 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\MlfHook.dll MOD - [2011/04/19 16:39:32 | 000,290,112 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mtdsdk.dll MOD - [2011/04/19 16:39:24 | 000,222,016 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\resources\mbzaenu.dll MOD - [2006/10/22 12:22:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll MOD - [2006/10/22 12:22:00 | 000,212,992 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2013/05/21 04:33:54 | 000,181,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2013/02/16 17:28:26 | 000,277,744 | ---- | M] (SpeedBit Ltd.) [Disabled | Stopped] -- C:\Program Files\SpeedBit Video Accelerator\VideoAcceleratorService.exe -- (VideoAcceleratorService) SRV - [2012/09/13 06:50:41 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Disabled | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE) SRV - [2012/08/30 04:03:36 | 000,497,320 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc) SRV - [2012/08/29 16:17:06 | 002,445,880 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon) SRV - [2011/05/25 15:14:34 | 000,053,248 | ---- | M] (NOS Microsystems Ltd.) [Disabled | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper) SRV - [2010/03/29 08:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.) [Disabled | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) SRV - [2010/03/11 12:07:54 | 000,124,432 | ---- | M] ( Pro-Softnet) [Auto | Running] -- C:\Program Files\ZoneAlarmBackup\ZABackupWebM.exe -- (ZABackupWebM) SRV - [2010/03/11 12:01:32 | 000,149,008 | ---- | M] (Pro Softnet Corporation) [Auto | Running] -- C:\Program Files\ZoneAlarmBackup\ZABackup Service.exe -- (ZoneAlarmBackup Service) SRV - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme) DRV - [2012/08/30 04:03:48 | 000,027,056 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL) DRV - [2012/08/30 04:03:08 | 000,036,784 | ---- | M] (Check Point Software Technologies) [Kernel | On_Demand | Running] -- C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys -- (icsak) DRV - [2012/08/29 15:45:24 | 000,526,640 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant) DRV - [2012/01/09 18:59:34 | 000,485,808 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF) DRV - [2012/01/09 18:59:30 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (KL1) DRV - [2012/01/09 18:59:30 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2) DRV - [2011/07/22 09:27:02 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | Disabled | Stopped] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV) DRV - [2011/07/12 14:55:22 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | Disabled | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL) DRV - [2010/02/17 11:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | Disabled | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM) DRV - [2009/07/22 12:13:20 | 000,028,592 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901) DRV - [2008/06/19 17:24:30 | 000,028,544 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot) DRV - [2008/04/13 11:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm) DRV - [2008/04/13 11:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum) DRV - [2004/09/17 09:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt) DRV - [2003/08/29 04:59:24 | 001,101,696 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMSM.sys -- (BCMModem) DRV - [2003/05/07 16:54:38 | 000,008,960 | ---- | M] (Prolific Technology Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\usbbc2.sys -- (PLUsbbc2) DRV - [2001/08/17 05:19:34 | 000,036,480 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sfmanm.sys -- (sfman) DRV - [2001/08/17 05:19:28 | 000,006,912 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctlfacem.sys -- (emu10k1) DRV - [2001/08/17 05:19:26 | 000,283,904 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emu10k1m.sys -- (emu10k) DRV - [2001/08/17 05:19:20 | 000,003,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctljystk.sys -- (ctljystk) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes,DefaultScope = {1AC1A6B1-4A97-1E66-7281-6ED8C4DF2D7E} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C4 1C C2 05 D2 5A CE 01 [binary data] IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6C73F24A-310C-41FE-8601-CEDBBF4C03B5} IE - HKCU\..\SearchScopes,DefaultScope = {1AC1A6B1-4A97-1E66-7281-6ED8C4DF2D7E} IE - HKCU\..\SearchScopes\{1AC1A6B1-4A97-1E66-7281-6ED8C4DF2D7E}: "URL" = http://www.google.com/search?hl=en&as_q={searchTerms}&as_epq=&as_oq=&as_eq=&num=10&lr=&as_filetype=&ft=i&as_sitesearch=&as_qdr=all&as_rights=&as_occt=any&cr=&as_nlo=&as_nhi=&safe=images IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: File not found FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10516.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+(R),version=1.6.2.100: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.) FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+(R),version=1.6.2.102: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.) FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+(R),version=1.6.2.103: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.) FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+(R),version=1.6.2.97: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/10/09 21:04:48 | 000,000,000 | ---D | M] [2012/08/14 15:35:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions O1 HOSTS File: ([2013/06/15 15:41:00 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Zonealarm Helper Object) - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\1.6.7.4\bh\zonealarm.dll (Montera Technologeis LTD) O2 - BHO: (Google Analytics Opt-out Browser Add-on) - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\1.6.7.4\zonealarmTlbr.dll (Montera Technologeis LTD) O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies) O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD) O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Documents and Settings\johnt\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKCU..\RunOnce: [Privacy Suite] C:\Program Files\CyberScrub Privacy Suite\CSPSeraser.exe (CyberScrub LLC) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\toolbars present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun- = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun- = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0 O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://qtinstall.apple.com/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1369263711078 (MUWebControl Class) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{81C850C1-0954-4D79-8392-C01EBD557CC6}: DhcpNameServer = 75.75.75.75 75.75.76.76 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com) O29 - HKLM SecurityProviders - (mirpywre.dll) - File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/07/10 11:40:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009/09/04 14:54:31 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013/06/15 18:24:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\johnt\Desktop\OTL.exe [2013/06/15 17:52:06 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\johnt\Recent [2013/06/15 16:18:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP [2013/06/15 16:04:10 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2013/06/15 14:53:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\ComboFix log jun15 [2013/06/15 11:25:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Problems Registry Change History [2013/06/15 11:18:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Problems Repair Fixes Links [2013/06/15 11:11:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Deleting Temp _Temporary Internet Files [2013/06/14 23:32:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Local Services Configurations Checking [2013/06/14 16:10:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Active x Controls and Plug-Ins Settings [2013/06/14 14:10:43 | 000,000,000 | ---D | C] -- C:\Program Files\autoruns filealyz [2013/06/14 13:04:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer New possible downloads programs etc [2013/06/14 13:00:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET [2013/06/14 12:19:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% Dell diagnoses downloads etc [2013/06/14 12:01:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\Local Settings\Application Data\Akamai [2013/06/10 12:22:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Combinations [2013/06/09 17:09:18 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2013/06/09 17:09:18 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2013/06/09 17:09:18 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2013/06/09 17:09:18 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2013/06/09 17:08:41 | 000,000,000 | ---D | C] -- C:\Qoobox [2013/06/09 14:20:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer AUTORUNS changes jun 2013 [2013/06/09 12:38:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Programs Free Jun 2013 [2013/06/09 12:00:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% Create System Restore Point [2013/06/09 10:33:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% uninstall programs from msconfig computer [2013/06/09 03:41:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% Computer Repairs Tweaks June 2013 [2013/06/08 20:09:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% My Awake Experiences [2013/06/08 14:33:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\TagsRevisited [2013/06/08 14:29:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Safer Networking [2013/06/08 14:29:44 | 000,000,000 | ---D | C] -- C:\Program Files\Safer Networking [2013/06/08 14:09:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\New Folder [2013/06/08 14:07:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Repair Programs for Event Viewer Application Files [2013/06/08 02:38:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Combofix Total Removal [2013/06/07 12:45:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Complete Specs [2013/06/06 22:42:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer chkdsk & sfc commands & use [2013/06/06 22:09:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\StarApp [2013/06/06 22:08:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\InstallMate [2013/06/06 20:28:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN [2013/06/06 17:56:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer superantispyware online scan [2013/06/06 02:02:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Google Prevent tracking by google [2013/06/06 01:37:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Changes Registry __Dates [2013/06/03 02:07:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer %Problems to correct [2013/06/03 01:21:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer useful RUN links [2013/06/03 00:08:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Internet Explorer IE8 [2013/06/03 00:06:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Programs Online Forums [2013/06/02 15:53:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Programs Problems [2013/06/02 15:51:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer test programs [2013/06/02 15:46:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Ads and Files to block [2013/06/02 13:02:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\$ Wise Information [2013/06/02 12:55:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Polar Manuals [2013/06/02 12:34:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer desktop icons [2013/06/02 12:32:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Dell [2013/06/02 12:30:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Copying music talks to disc [2013/06/02 12:28:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Juan Cole misc government improvements [2013/06/02 12:19:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Buddhism [2013/06/02 12:14:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Money Making Schemes [2013/06/02 12:10:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\johnt\My Documents\& MajorGeeK repair May june 2013 [2013/06/02 11:41:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Family Tree [2013/06/02 11:39:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Synonyms Antonyms [2013/06/02 11:39:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% Safety Check_Online_links sites [2013/06/02 11:32:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Warnings desktop icons [2013/06/02 10:34:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Mental Health [2013/06/02 10:33:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Class Reunion [2013/06/02 09:50:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Searching [2013/06/02 09:49:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Shopping [2013/06/02 09:45:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Files Unknown To Check [2013/06/02 09:33:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Passwords Names [2013/06/02 09:24:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Auto [2013/06/02 09:24:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Cats [2013/06/02 09:11:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Changes [2013/06/02 08:31:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Terms such as %windir% [2013/06/01 20:09:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Dates of Installments Updates Modification [2013/06/01 19:21:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer files folders in question [2013/06/01 17:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Programs [2013/06/01 17:24:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer ZoneAlarm Extreme Security [2013/06/01 17:20:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Health Improving [2013/06/01 17:13:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Contra Costa College [2013/06/01 17:07:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Meier Billy [2013/06/01 17:04:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Nursing Home References [2013/06/01 17:00:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Nardil [2013/06/01 16:55:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Movies To watch Actors Etc [2013/06/01 16:53:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Mental Telepathy [2013/06/01 16:48:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Repair Current [2013/06/01 16:45:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Songs [2013/06/01 16:43:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Health of John [2013/06/01 16:34:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer Files Deletion_Exempt [2013/06/01 16:33:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\eyes [2013/06/01 16:32:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\66 villa dr [2013/06/01 16:31:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Dizziness [2013/06/01 16:13:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Juan Cole Politics [2013/06/01 15:42:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Juan Cole Friends [2013/06/01 15:30:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Spiritual___AfterDeath AstralTravel [2013/06/01 15:17:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Computer [2013/06/01 15:06:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\% aa videos saved vlc etc [2013/06/01 15:05:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Juan Cole Posts [2013/06/01 15:04:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\Healthcare Plan by John B [2013/05/28 23:17:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs [2013/05/26 16:43:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT [2013/05/20 14:09:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\johnt\My Documents\My Pictures for Paint [2009/08/11 15:41:36 | 000,553,832 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Program Files\autorunsc.exe [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013/06/15 18:24:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\johnt\Desktop\OTL.exe [2013/06/15 17:54:06 | 000,000,315 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Advanced Web Search.url [2013/06/15 17:45:04 | 000,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2013/06/15 17:43:33 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013/06/15 17:42:20 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013/06/15 15:41:00 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2013/06/15 11:51:50 | 000,000,247 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Google AdvBrit.url [2013/06/15 10:04:39 | 000,000,282 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\15 Project Free TV.url [2013/06/15 01:14:05 | 000,000,799 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\11 Knowing.url [2013/06/14 18:12:18 | 000,001,779 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\10 imdb movies.url [2013/06/14 17:18:27 | 000,000,236 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\12 Rolling Stone.url [2013/06/14 16:15:14 | 000,000,439 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\9 Cnet.url [2013/06/14 13:19:31 | 000,503,590 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013/06/14 13:19:31 | 000,088,884 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2013/06/12 20:11:12 | 000,005,762 | ---- | M] () -- C:\Documents and Settings\johnt\My Documents\% % movie jun 12 RBkkAq.html [2013/06/10 23:34:31 | 000,000,319 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\Watch Odyssey 5 Online - LetMeWatchThis.url [2013/06/10 20:16:06 | 000,002,023 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\16Watch Btvguide.url [2013/06/09 22:45:33 | 000,000,281 | RHS- | M] () -- C:\boot.ini [2013/06/09 22:33:47 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2013/06/09 10:31:51 | 000,000,346 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\Unable to uninstall PC Tools Utilities Product.url [2013/06/08 16:56:42 | 000,007,896 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\wklnhst.dat [2013/06/08 15:26:38 | 000,000,082 | ---- | M] () -- C:\Documents and Settings\johnt\My Documents\CCleaner reg backup cc_20130608_152607.reg [2013/06/08 03:46:47 | 000,000,393 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Google AdvUSA.url [2013/06/06 21:42:14 | 000,010,617 | ---- | M] () -- C:\Documents and Settings\johnt\My Documents\a07kyxersblo.htm [2013/06/05 23:11:57 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\johnt\defogger_reenable [2013/06/05 22:40:27 | 000,002,556 | ---- | M] () -- C:\Documents and Settings\johnt\My Documents\MajorGeeks cleanup jun 5 steps.rtf [2013/06/04 02:58:59 | 000,000,357 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\My Documents.lnk [2013/06/03 15:59:40 | 000,000,410 | ---- | M] () -- C:\Documents and Settings\johnt\My Documents\% a may 20 bootkit zeroaccess repair ltr jun 3 wpad.rtf [2013/06/03 00:34:37 | 000,165,912 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013/06/02 18:02:24 | 000,000,373 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\8 Mercola Archive.url [2013/06/02 14:47:41 | 000,740,309 | ---- | M] () -- C:\Documents and Settings\johnt\My Documents\Gold Star button removal.mht [2013/05/31 11:15:37 | 000,000,899 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Auslogics Disk Defrag.lnk [2013/05/31 11:09:49 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\CCleaner.lnk [2013/05/27 20:04:27 | 000,001,094 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Options.lnk [2013/05/27 20:00:56 | 000,000,541 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\All Docs.lnk [2013/05/27 19:57:12 | 000,001,699 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2013/05/27 19:55:39 | 000,000,557 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Paint Docs.lnk [2013/05/27 19:48:52 | 000,001,533 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\4 Comcast.url [2013/05/26 14:51:49 | 000,000,754 | ---- | M] () -- C:\WINDOWS\WORDPAD.INI [2013/05/20 19:20:49 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\johnt\Desktop\19 Revo Uninstaller.lnk [2013/05/19 16:02:09 | 000,004,334 | ---- | M] () -- C:\Documents and Settings\johnt\ie-guid.reg [2013/05/18 16:27:31 | 000,000,678 | ---- | M] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Dictionary and Thesaurus - Merriam-Webster Online.url [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/06/13 03:55:21 | 000,098,008 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat [2013/06/12 20:11:46 | 000,005,762 | ---- | C] () -- C:\Documents and Settings\johnt\My Documents\% % movie jun 12 RBkkAq.html [2013/06/09 17:09:18 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2013/06/09 17:09:18 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2013/06/09 17:09:18 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2013/06/09 17:09:18 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2013/06/09 17:09:18 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2013/06/09 10:31:51 | 000,000,346 | ---- | C] () -- C:\Documents and Settings\johnt\Desktop\Unable to uninstall PC Tools Utilities Product.url [2013/06/08 15:26:38 | 000,000,082 | ---- | C] () -- C:\Documents and Settings\johnt\My Documents\CCleaner reg backup cc_20130608_152607.reg [2013/06/06 22:04:01 | 000,000,319 | ---- | C] () -- C:\Documents and Settings\johnt\Desktop\Watch Odyssey 5 Online - LetMeWatchThis.url [2013/06/06 21:42:25 | 000,010,617 | ---- | C] () -- C:\Documents and Settings\johnt\My Documents\a07kyxersblo.htm [2013/06/05 23:11:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\johnt\defogger_reenable [2013/06/05 22:40:27 | 000,002,556 | ---- | C] () -- C:\Documents and Settings\johnt\My Documents\MajorGeeks cleanup jun 5 steps.rtf [2013/06/04 02:58:59 | 000,000,357 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\My Documents.lnk [2013/06/03 15:59:40 | 000,000,410 | ---- | C] () -- C:\Documents and Settings\johnt\My Documents\% a may 20 bootkit zeroaccess repair ltr jun 3 wpad.rtf [2013/06/02 18:02:23 | 000,000,373 | ---- | C] () -- C:\Documents and Settings\johnt\Desktop\8 Mercola Archive.url [2013/06/02 14:47:38 | 000,740,309 | ---- | C] () -- C:\Documents and Settings\johnt\My Documents\Gold Star button removal.mht [2013/05/31 11:15:37 | 000,000,899 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Auslogics Disk Defrag.lnk [2013/05/30 11:29:45 | 000,000,315 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Advanced Web Search.url [2013/05/27 19:11:49 | 000,002,023 | ---- | C] () -- C:\Documents and Settings\johnt\Desktop\16Watch Btvguide.url [2013/05/25 10:48:12 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2013/05/20 19:20:49 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\johnt\Desktop\19 Revo Uninstaller.lnk [2013/05/19 15:45:37 | 000,001,699 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2013/05/19 13:59:16 | 000,004,334 | ---- | C] () -- C:\Documents and Settings\johnt\ie-guid.reg [2013/02/16 17:28:59 | 000,109,256 | ---- | C] () -- C:\WINDOWS\System32\EasyHook64.dll [2013/02/16 17:28:59 | 000,090,824 | ---- | C] () -- C:\WINDOWS\System32\EasyHook32.dll [2012/08/13 14:19:45 | 000,000,144 | ---- | C] () -- C:\WINDOWS\System32\lkfl.dat [2012/08/13 14:19:45 | 000,000,128 | ---- | C] () -- C:\WINDOWS\System32\pdfl.dat [2012/08/13 14:19:45 | 000,000,080 | ---- | C] () -- C:\WINDOWS\System32\ibfl.dat [2012/05/29 23:45:15 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2012/05/29 23:45:15 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2012/05/26 09:47:05 | 000,007,896 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\wklnhst.dat [2012/05/12 17:27:23 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2012/02/15 10:49:53 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011/09/07 04:16:34 | 000,026,128 | ---- | C] () -- C:\WINDOWS\System32\ZABackupXceedCryReg.exe [2011/09/07 04:16:33 | 000,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll [2011/09/07 04:16:32 | 000,441,705 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll [2011/01/03 12:22:15 | 000,000,112 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\xYQ6vl.dat [2010/12/08 16:31:57 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\johnt\Cache.db [2010/07/08 03:43:41 | 000,000,144 | ---- | C] () -- C:\Program Files\Filter On.reg [2010/07/08 03:39:36 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\johnt\Filter On.reg [2010/04/17 22:04:02 | 000,010,074 | --S- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\58G3tyIDc [2010/04/17 22:04:02 | 000,010,074 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\58G3tyIDc [2010/04/16 18:28:28 | 000,009,596 | --S- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\3367619789 [2010/04/16 18:20:32 | 000,011,334 | --S- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\jrNYi6G [2010/04/16 18:20:32 | 000,011,334 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\jrNYi6G [2010/04/14 13:23:03 | 000,009,654 | --S- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\3469191438 [2010/04/14 13:22:29 | 000,009,942 | --S- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\2509137411 [2010/04/14 13:21:45 | 000,009,466 | --S- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\50vGiJ1FW7x2 [2010/04/14 13:16:40 | 000,010,704 | --S- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\50vGiJ1FW7x2 [2010/04/14 13:16:40 | 000,009,466 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\50vGiJ1FW7x2 [2009/08/20 13:17:14 | 000,017,897 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\cyvykofu.ban [2009/08/20 13:17:14 | 000,017,687 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\gihusegiki.scr [2009/08/20 13:17:14 | 000,017,036 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\hazenez.sys [2009/08/20 13:17:14 | 000,017,010 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\qefyvylam.ban [2009/08/20 13:17:14 | 000,015,961 | ---- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\wymyfe.bin [2009/08/20 13:17:14 | 000,012,349 | ---- | C] () -- C:\Documents and Settings\johnt\Application Data\azefygo.sys [2009/07/12 15:05:01 | 000,056,832 | ---- | C] () -- C:\Documents and Settings\johnt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008/12/16 17:46:54 | 000,049,244 | ---- | C] () -- C:\Program Files\autoruns.chm [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/27 05:31:09 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 17:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 17:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2009/10/28 19:51:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications [2011/01/01 22:06:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\cFdMl01832 [2012/10/09 21:00:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CheckPoint [2011/04/09 13:56:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFi01845lLaAa01845 [2011/01/14 20:24:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hIdEa01827 [2013/05/19 19:23:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro [2011/01/10 17:21:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iCmEm07003 [2013/06/10 22:56:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate [2009/09/06 11:41:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky SDK [2013/03/02 14:30:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Licenses [2011/03/24 03:48:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\nOaEiMjOdGp01820 [2012/07/14 14:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Utility Kit [2012/10/11 07:31:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCDr [2011/04/06 21:21:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pJo01819pNfLn01819 [2013/02/16 17:29:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Speedbit [2013/06/06 22:09:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\StarApp [2013/06/15 17:36:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2012/11/13 03:26:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\#ISW.FS# [2012/03/31 14:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\0 final solutions to America's & world's crises [2012/07/14 16:27:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\Auslogics [2012/10/09 21:07:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\Check Point Software Technologies LTD [2012/08/13 14:20:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\CheckPoint [2011/02/16 22:19:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2009/07/12 15:29:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\CyberScrub [2012/05/22 14:56:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\ElevatedDiagnostics [2011/12/21 03:28:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\ieSpell [2011/01/06 17:29:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\MailFrontier [2012/07/14 14:33:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\PC Utility Kit [2011/11/19 22:40:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\Product_RM [2012/05/26 09:47:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\johnt\Application Data\Template [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 186 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B4AF47A7 < End of report >