* System file checker just stalls when I try to run it.
* Downloaded MS Security Essentials as per Step 2 of your "Start here" instructions, but it crashes and restarts itself.
* Last set of Windows Updates I got wouldn't load completely, and the error report that was generated could not be sent.
* Tried a system restore to a point some weeks ago, but it didn't work and now I can't use Firefox (nor can I remove it, even though it's listed in the Add and Remove Programs list)
* A holograph of Princess Leia appeared above my machine, and she said "Help me, Geeks to Go." (OK, that didn't really happen.)
My first thought was a problem with a browser add-on, but I have removed and reinstalled Flash, Java, etc. with no improvement.
Am I right in suspecting malware? I've followed the Start Here steps (Malware Bytes found and fixed what could have been a couple of trojans, but that was about it) and am posting the logs below. These scans were done over a period of a few days -- does that interval pose a problem?
Again, thanks for your help!
(p.s. Er, judging by some of the names in the Hosts Files log, I think redirects have also been a problem. I don't remember seeing any of those sites!)
OTL logfile created on: 9/16/2010 6:40:20 PM - Run 1
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Documents and Settings\rob\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 502.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 39.31 Gb Free Space | 51.51% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 911.49 Gb Free Space | 97.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: COMP-1
Current User Name: rob
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/09/16 18:39:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\rob\Desktop\OTL.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2010/03/25 21:40:42 | 000,203,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/08/09 03:27:52 | 000,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2007/05/17 14:45:34 | 000,271,720 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft LifeCam\MSCamS32.exe
========== Modules (SafeList) ==========
MOD - [2010/09/16 18:39:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\rob\Desktop\OTL.exe
MOD - [2008/04/13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - [2010/03/25 21:40:44 | 000,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)
SRV - [2007/08/09 03:27:52 | 000,073,728 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2007/05/17 14:45:34 | 000,271,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XTrapD12.sys -- (XTrapD12)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\XDva132.sys -- (XDva132)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2010/03/25 21:30:22 | 000,151,216 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\MpFilter.sys -- (MpFilter)
DRV - [2008/07/01 01:09:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm)
DRV - [2008/04/13 14:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/01/23 17:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tapvpn.sys -- (tapvpn)
DRV - [2007/09/05 22:26:45 | 000,026,056 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2007/04/10 14:46:54 | 001,966,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX1000.sys -- (VX1000)
DRV - [2006/10/28 21:47:49 | 000,223,128 | ---- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\dtscsi.sys -- (dtscsi)
DRV - [2006/10/07 16:38:30 | 000,643,072 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/05/03 12:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/08/03 18:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2001/08/17 09:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/12 20:38:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/12 20:38:19 | 000,000,000 | ---D | M]
[2010/09/12 20:37:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Mozilla\Extensions
[2010/09/12 20:37:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Mozilla\Firefox\Profiles\q2t1xh37.default\extensions
[2010/09/12 20:38:33 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/12 20:39:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2010/09/12 20:39:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2006/05/06 12:42:04 | 007,260,160 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\libvlc.dll
[2010/07/03 12:02:17 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2006/05/06 12:42:04 | 000,478,720 | ---- | M] (VideoLAN Team) -- C:\Program Files\Mozilla Firefox\plugins\npvlc.dll
O1 HOSTS File: ([2010/09/08 16:48:10 | 000,418,427 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 14465 more lines...
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (no name) - {BE24A5A5-669F-4089-9E75-5AD1531B0600} - C:\WINDOWS\System32\ativvax.dll File not found
O2 - BHO: () - {C1626E66-C26B-C628-E1DF-CDACCFA26EE1} - C:\Program Files\Common Files\goskdl.dll File not found
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\rob\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O15 - HKCU\..Trusted Domains: canwest.com ([webmail] https in Trusted sites)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zon...er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.micr...01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zon...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} https://secure.gopet...v/GoPetsWeb.cab (GoPetsWeb Control)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\rob\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\rob\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {DC7596CB-D6CC-DCA3-DE52-DEEA63F6C61D} - C:\Program Files\Internet Explorer\rksldk.dll File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/10 04:03:52 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{770fd1b8-987c-11dd-9ae4-00138fba79c9}\Shell\Auto\command - "" = K:\Ghost.pif -- File not found
O33 - MountPoints2\{770fd1b8-987c-11dd-9ae4-00138fba79c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9a18a7ab-ea4d-11db-9a60-00138fba79c9}\Shell\Auto\command - "" = L:\Ghost.pif -- File not found
O33 - MountPoints2\{9a18a7ab-ea4d-11db-9a60-00138fba79c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f406f6c4-213f-11dd-9ab3-00138fba79c9}\Shell\Auto\command - "" = K:\Ghost.pif -- File not found
O33 - MountPoints2\{f406f6c4-213f-11dd-9ab3-00138fba79c9}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)
========== Files/Folders - Created Within 90 Days ==========
[2010/09/16 18:38:58 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\rob\Desktop\OTL.exe
[2010/09/14 18:45:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials
[2010/09/13 23:23:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Application Data\Malwarebytes
[2010/09/13 23:23:23 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/13 23:23:22 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/13 23:23:22 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/13 23:23:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/13 23:21:34 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/09/13 23:20:27 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/09/13 23:06:21 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\rob\Desktop\TFC.exe
[2010/09/12 23:25:56 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live Safety Center
[2010/09/12 20:38:42 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/09/12 20:38:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/09/12 20:36:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS
[2010/09/12 20:34:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\.housecall6.6
[2010/09/12 20:34:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Trillian
[2010/09/07 20:39:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\My Documents\gegl-0.0
[2010/09/07 19:33:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2010/09/07 19:31:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Application Data\QuickScan
[2010/09/07 00:23:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Local Settings\Application Data\Google
[2010/08/08 22:10:15 | 000,000,000 | ---D | C] -- C:\spoolerlogs
[2010/07/27 20:50:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Application Data\gtk-2.0
[2010/07/27 20:50:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\.thumbnails
[2010/07/27 20:45:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\.gimp-2.6
[2010/07/27 20:44:35 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2010/07/27 20:43:29 | 020,039,632 | ---- | C] (The GIMP Team ) -- C:\gimp-2.6.10-i686-setup-1.exe
[2010/07/24 00:46:22 | 000,000,000 | ---D | C] -- C:\Photos-pre08
[2010/07/24 00:26:25 | 000,000,000 | ---D | C] -- C:\photos-08etc
[2010/07/18 20:50:07 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2010/07/05 20:19:34 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2010/07/05 17:39:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Desktop\Articles 2010
[2010/07/04 13:06:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2010/07/04 12:47:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\Application Data\OpenOffice.org
[2010/07/04 12:44:48 | 000,000,000 | ---D | C] -- C:\Program Files\JRE
[2010/07/04 12:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2010/07/04 00:38:18 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2010/07/03 23:52:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rob\My Documents\Downloads
[2010/07/03 13:32:27 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\rob\IECompatCache
[2010/07/03 13:31:30 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\rob\PrivacIE
[2010/07/03 13:28:58 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2010/07/03 12:03:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/07/03 11:51:45 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\rob\IETldCache
[2010/07/03 01:21:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2010/07/03 01:20:57 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2010/07/03 01:20:44 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2010/07/03 00:55:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2010/07/03 00:50:16 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/07/02 23:31:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\microsoft
[2010/07/02 23:16:01 | 000,000,000 | ---D | C] -- C:\e03138076ac9c096a9
========== Files - Modified Within 90 Days ==========
[2010/09/16 18:39:19 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\rob\Desktop\OTL.exe
[2010/09/16 18:29:00 | 000,000,970 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1220945662-839522115-1003UA.job
[2010/09/16 17:53:38 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/16 17:35:59 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/16 17:35:30 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/16 17:35:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/16 17:35:24 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/15 23:50:09 | 006,512,640 | ---- | M] () -- C:\Documents and Settings\rob\ntuser.dat
[2010/09/15 23:50:09 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\rob\ntuser.ini
[2010/09/15 19:15:16 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/09/14 18:45:25 | 000,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/13 23:23:26 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/13 23:20:27 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\NTREGOPT.lnk
[2010/09/13 23:20:27 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\ERUNT.lnk
[2010/09/13 23:06:30 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\rob\Desktop\TFC.exe
[2010/09/12 23:41:29 | 008,054,566 | -H-- | M] () -- C:\Documents and Settings\rob\Local Settings\Application Data\IconCache.db
[2010/09/12 21:11:52 | 000,213,672 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/12 20:56:14 | 000,549,012 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/12 20:56:14 | 000,474,644 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/09/12 20:56:14 | 000,084,626 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/09/12 00:29:00 | 000,000,918 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1220945662-839522115-1003Core.job
[2010/09/11 11:49:12 | 000,000,765 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/11 11:49:12 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/09/09 20:22:31 | 000,008,890 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\mysteryspot.jpg
[2010/09/08 16:58:03 | 000,042,716 | ---- | M] () -- C:\Documents and Settings\rob\.recently-used.xbel
[2010/09/08 16:48:10 | 000,418,427 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/09/07 19:26:05 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\rob\Local Settings\Application Data\housecall.guid.cache
[2010/09/05 23:50:53 | 000,209,678 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\Sep52010bookmarks.html
[2010/09/05 20:46:08 | 000,027,863 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\Lard.jpg
[2010/07/27 20:45:08 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\GIMP 2.lnk
[2010/07/27 20:43:31 | 020,039,632 | ---- | M] (The GIMP Team ) -- C:\gimp-2.6.10-i686-setup-1.exe
[2010/07/24 01:00:45 | 000,000,389 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\Shortcut to Photos-pre08.lnk
[2010/07/24 00:50:48 | 000,000,389 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\Shortcut to photos-08etc.lnk
[2010/07/23 23:59:59 | 000,000,276 | ---- | M] () -- C:\WINDOWS\System\cmicnfg.ini
[2010/07/23 23:52:06 | 000,046,784 | ---- | M] () -- C:\Documents and Settings\rob\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/18 20:50:08 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\rob\Desktop\EVEREST Home Edition.lnk
[2010/07/06 19:59:42 | 000,000,800 | ---- | M] () -- C:\Documents and Settings\rob\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/07/06 19:57:43 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/07/06 19:57:43 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/07/05 20:17:34 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2010/07/04 12:56:04 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/07/04 12:46:29 | 000,000,885 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/07/03 12:26:03 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/07/03 11:51:52 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\rob\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/03 00:43:30 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\rob\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/03 00:43:29 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
========== Files Created - No Company Name ==========
[2010/09/14 18:55:21 | 000,000,408 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/09/14 18:45:25 | 000,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/09/13 23:23:26 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/13 23:20:27 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\NTREGOPT.lnk
[2010/09/13 23:20:27 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\ERUNT.lnk
[2010/09/08 16:58:03 | 000,042,716 | ---- | C] () -- C:\Documents and Settings\rob\.recently-used.xbel
[2010/09/07 19:26:05 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\rob\Local Settings\Application Data\housecall.guid.cache
[2010/09/07 00:24:51 | 000,000,970 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1220945662-839522115-1003UA.job
[2010/09/07 00:24:49 | 000,000,918 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1220945662-839522115-1003Core.job
[2010/09/05 23:50:53 | 000,209,678 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\Sep52010bookmarks.html
[2010/09/05 20:46:07 | 000,027,863 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\Lard.jpg
[2010/08/04 19:48:53 | 006,512,640 | ---- | C] () -- C:\Documents and Settings\rob\ntuser.dat
[2010/07/27 20:45:08 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\GIMP 2.lnk
[2010/07/24 01:00:45 | 000,000,389 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\Shortcut to Photos-pre08.lnk
[2010/07/24 00:50:48 | 000,000,389 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\Shortcut to photos-08etc.lnk
[2010/07/18 20:50:08 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\rob\Desktop\EVEREST Home Edition.lnk
[2010/07/05 21:01:59 | 000,000,800 | ---- | C] () -- C:\Documents and Settings\rob\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/07/05 21:00:57 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2010/07/05 21:00:57 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2010/07/04 12:46:29 | 000,000,885 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/07/03 00:43:29 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2008/07/04 18:15:39 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2008/07/04 18:15:39 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2008/07/04 18:15:39 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2008/06/28 13:59:42 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/06/15 20:12:28 | 000,015,498 | ---- | C] () -- C:\WINDOWS\VX1000.ini
[2008/02/26 00:42:58 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/01/09 16:01:48 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007/12/28 22:53:10 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2007/09/17 02:01:23 | 000,000,079 | ---- | C] () -- C:\WINDOWS\custvoic.ini
[2007/09/12 17:13:05 | 000,000,040 | ---- | C] () -- C:\WINDOWS\rdrive.ini
[2007/08/01 02:24:39 | 000,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/07/20 16:24:53 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2007/07/20 16:16:45 | 000,004,087 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/06/30 01:08:14 | 000,000,298 | ---- | C] () -- C:\WINDOWS\kaillera.ini
[2007/03/04 00:12:55 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini
[2007/02/18 03:17:04 | 000,000,126 | ---- | C] () -- C:\Documents and Settings\rob\Local Settings\Application Data\fusioncache.dat
[2006/12/02 00:30:26 | 000,003,308 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/07 16:38:30 | 000,643,072 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2006/10/07 16:38:30 | 000,096,384 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd1997.sys
[2006/09/15 17:45:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\rob\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/10 04:21:47 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/10 04:12:44 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2006/09/10 04:12:36 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2006/09/10 04:12:36 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2006/09/10 04:12:33 | 000,000,153 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2006/09/10 04:11:56 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2006/09/10 04:11:02 | 000,003,581 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2006/09/10 04:11:00 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2004/08/04 08:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 08:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 08:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 08:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 08:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll
========== LOP Check ==========
[2008/12/06 00:54:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
[2007/09/17 19:20:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/03 14:06:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/08/05 21:19:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Aim
[2006/10/28 21:57:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Atari
[2007/08/01 00:51:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Azureus
[2008/01/15 17:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Blue Box Network
[2006/12/09 12:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\foobar2000
[2010/09/12 20:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\gtk-2.0
[2008/01/03 12:02:40 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\rob\Application Data\ijjigame
[2006/11/17 19:00:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\IMVU
[2006/10/28 21:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Leadertech
[2010/07/04 12:47:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\OpenOffice.org
[2010/09/07 19:31:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\QuickScan
[2007/10/22 21:40:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\REAPER
[2008/01/09 23:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Sandbox
[2007/02/17 12:36:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\SecondLife
[2008/12/06 00:54:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Uniblue
[2010/09/12 20:36:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\uTorrent
[2007/03/16 16:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\rob\Application Data\Viewpoint
[2010/09/16 17:53:38 | 000,000,408 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/10 04:03:52 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/07/04 12:56:04 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2006/09/10 04:03:52 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2007/03/25 12:34:49 | 006,006,832 | ---- | M] (Mozilla) -- C:\Firefox Setup 2.0.0.3.exe
[2010/07/27 20:43:31 | 020,039,632 | ---- | M] (The GIMP Team ) -- C:\gimp-2.6.10-i686-setup-1.exe
[2010/09/16 17:35:24 | 1072,549,888 | -HS- | M] () -- C:\hiberfil.sys
[2006/09/10 04:03:52 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/03/04 00:20:24 | 000,002,068 | -H-- | M] () -- C:\IPH.PH
[2006/09/10 04:03:52 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/09/27 14:26:15 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/16 17:35:23 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2007/01/29 00:20:49 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
[2007/01/29 01:10:27 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2007/01/31 00:33:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2007/02/07 08:30:31 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2006/12/23 13:21:43 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2006/12/23 13:21:43 | 000,000,208 | -H-- | M] () -- C:\sqmdata05.sqm
[2006/12/28 17:30:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2006/12/28 19:43:00 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2007/01/06 00:18:29 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2007/01/11 08:17:26 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2007/01/11 23:09:57 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2007/01/14 21:40:46 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2007/01/15 08:42:33 | 000,000,280 | -H-- | M] () -- C:\sqmdata12.sqm
[2007/01/17 19:57:14 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2007/01/17 21:20:37 | 000,000,280 | -H-- | M] () -- C:\sqmdata14.sqm
[2007/01/17 21:45:02 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2007/01/25 03:11:50 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2007/01/29 00:03:32 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2007/01/29 00:18:04 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2007/01/29 00:18:05 | 000,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2007/01/29 00:20:49 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2007/01/29 01:10:27 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2007/01/31 00:33:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2007/02/07 08:30:31 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2006/12/23 13:21:43 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2006/12/23 13:21:43 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2006/12/28 17:30:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2006/12/28 19:43:00 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2007/01/06 00:18:29 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2007/01/11 08:17:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2007/01/11 23:09:57 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2007/01/14 21:40:46 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2007/01/15 08:42:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2007/01/17 19:57:14 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2007/01/17 21:20:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2007/01/17 21:45:02 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2007/01/25 03:11:50 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2007/01/29 00:03:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2007/01/29 00:18:04 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2007/01/29 00:18:05 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/09/09 20:45:34 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/09/09 20:45:34 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2006/09/09 20:45:34 | 000,888,832 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-15 23:15:29
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05D195EC
< End of report >
OTL Extras logfile created on: 9/16/2010 6:40:20 PM - Run 1
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Documents and Settings\rob\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 502.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.32 Gb Total Space | 39.31 Gb Free Space | 51.51% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 911.49 Gb Free Space | 97.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: COMP-1
Current User Name: rob
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- C:\MattVideoLAN\VLC\vlc.exe --one-instance-when-started-from-file --playlist-enqueue "%1" File not found
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- C:\MattVideoLAN\VLC\vlc.exe --one-instance-when-started-from-file --no-playlist-enqueue "%1" File not found
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Matt\AIM\aim.exe" = C:\Matt\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- File not found
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) -- File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Last.fm\LastFM.exe" = C:\Program Files\Last.fm\LastFM.exe:*:Enabled:LastFM -- File not found
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- File not found
"C:\Matt\Trillian\trillian.exe" = C:\Matt\Trillian\trillian.exe:*:Enabled:Trillian -- File not found
"C:\Matt\mIRC\mirc.exe" = C:\Matt\mIRC\mirc.exe:*:Enabled:mIRC -- File not found
"C:\Matt\Azureus\Azureus.exe" = C:\Matt\Azureus\Azureus.exe:*:Enabled:Azureus -- File not found
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\QuickTime\QuickTimePlayer.exe" = C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player -- File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- File not found
"C:\Matt\games\AOE2AOK+CONQUERORS\empires2.exe" = C:\Matt\games\AOE2AOK+CONQUERORS\empires2.exe:*:Enabled:Age of Empires II -- File not found
"C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing -- (Microsoft Corporation)
"C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® -- (Microsoft Corporation)
"C:\Matt\games\Starcraft\StarCraft.exe" = C:\Matt\games\Starcraft\StarCraft.exe:*:Enabled:Starcraft -- File not found
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:uTorrent -- ()
"C:\Matt\games\Warcraft III\Warcraft III.exe" = C:\Matt\games\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- File not found
"C:\Matt\New Folder\Edist_CD_01\openCanvas\OC11B72.EXE" = C:\Matt\New Folder\Edist_CD_01\openCanvas\OC11B72.EXE:*:Enabled:OC11B72 -- File not found
"C:\Matt\ENGLISH\Gunbound Revolution\GunBound.gme" = C:\Matt\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound -- File not found
"C:\Matt\games\LittleFighter2\LF2_v1.9c\lf2.exe" = C:\Matt\games\LittleFighter2\LF2_v1.9c\lf2.exe:*:Enabled:lf2 -- File not found
"C:\ijji\ENGLISH\u_gbound.exe" = C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:<ijji Downloader> -- File not found
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath -- File not found
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation)
"C:\Matt\AIM\aim.exe" = C:\Matt\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- File not found
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) -- File not found
"C:\Matt\VideoLAN\VLC\vlc.exe" = C:\Matt\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{20749F76-4228-43AD-8AB5-E7B20D8040C4}" = hph_readme
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 20
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{36DC3E2F-CD8C-4953-9E8F-9A1916D10AA1}" = hph_software
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ACCCEE83-B49B-4964-8A4F-378B8FBC9F75}" = hph_ProductContext
"{B19F9155-9337-4807-B5EF-ED471DDB2CCE}" = hph_software_req
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2A3C9D5-0B56-4656-8277-7EDC65D62B6E}" = HP Photosmart and Deskjet 7.0 Software
"{D8185007-3F98-413E-B22D-BA513517383A}" = D5100_Help
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}" = ATI Catalyst Control Center
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{FD100EAE-33D2-420D-BCEB-361AC512B0BB}" = D5100
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced WMA Workshop_is1" = Advanced WMA Workshop version 2.2
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"C-Media Audio Driver" = C-Media WDM Audio Driver
"ERUNT_is1" = ERUNT 1.1j
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"RPG Maker 2000 Project2" = RPG Maker 2000 - The Adventures of Lila & Floey
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
"Words That Follow" = Words That Follow
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/15/2010 7:05:02 PM | Computer Name = COMP-1 | Source = JavaQuickStarterService | ID = 1
Description =
Error - 9/15/2010 7:20:23 PM | Computer Name = COMP-1 | Source = JavaQuickStarterService | ID = 1
Description =
Error - 9/15/2010 7:20:30 PM | Computer Name = COMP-1 | Source = Application Error | ID = 1004
Description = Faulting application MsMpEng.exe, version 2.1.6805.0, faulting module
mpengine.dll, version 1.1.6103.0, fault address 0x0020e4cf.
Error - 9/15/2010 7:22:09 PM | Computer Name = COMP-1 | Source = Application Error | ID = 1001
Description = Fault bucket 2030123040.
Error - 9/16/2010 5:35:48 PM | Computer Name = COMP-1 | Source = JavaQuickStarterService | ID = 1
Description =
Error - 9/16/2010 5:35:50 PM | Computer Name = COMP-1 | Source = Application Error | ID = 1000
Description = Faulting application MsMpEng.exe, version 2.1.6805.0, faulting module
mpengine.dll, version 1.1.6103.0, fault address 0x001b24ce.
Error - 9/16/2010 5:48:16 PM | Computer Name = COMP-1 | Source = Application Error | ID = 1000
Description = Faulting application MsMpEng.exe, version 2.1.6805.0, faulting module
mpengine.dll, version 1.1.6103.0, fault address 0x00029887.
Error - 9/16/2010 5:51:22 PM | Computer Name = COMP-1 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x8050a005, P2 mpupdateengine, P3 am fe,
P4 2.1.1112.0, P5 mpsigstub.exe, P6 2.1.6805.0, P7 microsoft security essentials,
P8 NIL, P9 NIL, P10 NIL.
Error - 9/16/2010 5:51:25 PM | Computer Name = COMP-1 | Source = MSSecurityEssentials | ID = 5000
Description =
Error - 9/16/2010 6:37:29 PM | Computer Name = COMP-1 | Source = Application Error | ID = 1001
Description = Fault bucket 2005217565.
[ System Events ]
Error - 9/16/2010 5:48:11 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 5008
Description = %%861 engine has been terminated due to an unexpected error. Failure
Type: %%830 Exception code: 0xc0000005 Resource: file:C:\WINDOWS\System32\drivers\redbook.sys
Error - 9/16/2010 5:48:16 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 3002
Description = %%861 Real-Time Protection feature has encountered an error and failed.
Feature:
%%834 Error Code: 0x80070006 Error description: The handle is invalid. Reason: %%837
Error - 9/16/2010 5:48:16 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 3002
Description = %%861 Real-Time Protection feature has encountered an error and failed.
Feature:
%%835 Error Code: 0x80070006 Error description: The handle is invalid. Reason: %%837
Error - 9/16/2010 5:48:17 PM | Computer Name = COMP-1 | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 2 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.
Error - 9/16/2010 5:48:38 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 2004
Description = %%861 has encountered an error trying to load signatures and will
attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824
Error
Code: 0x8050800c Error description: An unexpected problem occurred. Install any
available updates, and then try to start the program again. For information on installing
updates, see Help and Support. Signature version: 1.89.1733.0;1.89.1733.0 Engine
version: 1.1.6103.0
Error - 9/16/2010 5:51:20 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 2003
Description = %%861 has encountered an error trying to update the engine. New Engine
Version: 1.1.6201.0 Previous Engine Version: User: NT AUTHORITY\SYSTEM Error Code:
0x8050a005 Error description: The program can't find definition files that help
detect unwanted software. Check for updates to the definition files, and then try
again. For information on installing updates, see Help and Support.
Error - 9/16/2010 5:51:20 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: 1.91.0.0 Previous Signature Version: Update Source: %%815 Update Stage:
%%854 Source Path: Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM
Current
Engine Version: 1.1.6201.0 Previous Engine Version: Error code: 0x8050a005 Error
description: The program can't find definition files that help detect unwanted software.
Check for updates to the definition files, and then try again. For information
on installing updates, see Help and Support.
Error - 9/16/2010 5:51:20 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: 1.91.0.0 Previous Signature Version: Update Source: %%815 Update Stage:
%%854 Source Path: Signature Type: %%801 Update Type: %%803 User: NT AUTHORITY\SYSTEM
Current
Engine Version: 1.1.6201.0 Previous Engine Version: Error code: 0x8050a005 Error
description: The program can't find definition files that help detect unwanted software.
Check for updates to the definition files, and then try again. For information
on installing updates, see Help and Support.
Error - 9/16/2010 5:51:24 PM | Computer Name = COMP-1 | Source = Microsoft Antimalware | ID = 2001
Description = %%861 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%854
Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM
Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070643 Error description:
Fatal error during installation.
Error - 9/16/2010 5:51:36 PM | Computer Name = COMP-1 | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Definition Update for Microsoft Security Essentials - KB972696
(Definition 1.91.0.0).
< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-15 23:21:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\rob\LOCALS~1\Temp\kwtdqpow.sys
---- System - GMER 1.0.15 ----
SSDT sptd.sys ZwCreateKey [0xF73F5C04]
SSDT sptd.sys ZwEnumerateKey [0xF73F5D48]
SSDT sptd.sys ZwEnumerateValueKey [0xF73F60C0]
SSDT sptd.sys ZwOpenKey [0xF73F5AE2]
SSDT sptd.sys ZwQueryKey [0xF73F618A]
SSDT sptd.sys ZwQueryValueKey [0xF73F6022]
SSDT sptd.sys ZwSetValueKey [0xF73F6212]
---- Kernel code sections - GMER 1.0.15 ----
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? C:\WINDOWS\System32\Drivers\SPTD1997.SYS The process cannot access the file because it is being used by another process.
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[772] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD135 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254666 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[848] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4EF0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215501 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD135 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254666 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4B6F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4AA1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4B0C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4972 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E49D4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4BD2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4A36 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1884] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4EF0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 86F9BBF8
Device \FileSystem\Fastfat \FatCdrom 86E57EB0
Device \Driver\NetBT \Device\NetBT_Tcpip_{E1193F17-A9C9-4911-8895-E404FF113E32} 86BD60E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86F9C2B8
Device \Driver\dmio \Device\DmControl\DmConfig 86F9C2B8
Device \Driver\dmio \Device\DmControl\DmPnP 86F9C2B8
Device \Driver\dmio \Device\DmControl\DmInfo 86F9C2B8
Device \Driver\Ftdisk \Device\HarddiskVolume1 86F9C4F0
Device \Driver\Ftdisk \Device\HarddiskVolume2 86F9C4F0
Device \Driver\USBSTOR \Device\00000065 86BDF0E8
Device \FileSystem\Rdbss \Device\FsWrap 86BDC0E8
Device \Driver\USBSTOR \Device\00000066 86BDF0E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7345B40] atapi.sys[unknown section] {MOV EAX, 0x86f9b008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7406684; RET }
Device \Driver\atapi \Device\Ide\IdePort0 [F7345B40] atapi.sys[unknown section] {MOV EAX, 0x86f9b008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7406684; RET }
Device \Driver\atapi \Device\Ide\IdePort1 [F7345B40] atapi.sys[unknown section] {MOV EAX, 0x86f9b008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf7406684; RET }
Device \Driver\NetBT \Device\NetBt_Wins_Export 86BD60E8
Device \Driver\NetBT \Device\NetbiosSmb 86BD60E8
Device \Driver\Disk \Device\Harddisk0\DR0 86F9BEB0
Device \Driver\Disk \Device\Harddisk1\DR2 86F9BEB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86B850E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{1951DA6F-74A3-492A-B0A3-AEF8F9AB283F} 86BD60E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86B850E8
Device \FileSystem\Npfs \Device\NamedPipe 86E560E8
Device \Driver\Ftdisk \Device\FtControl 86F9C4F0
Device \FileSystem\Msfs \Device\Mailslot 86BB40E8
Device \FileSystem\Fastfat \Fat 86E57EB0
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 1751639922
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -763658380
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 255451027
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x47 0x47 0x5C 0x7F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Matt\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xC2 0x54 0xF1 0x8B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4D 0xC4 0xB5 0x13 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBD 0x03 0x67 0x72 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x48 0x5A 0xB4 0xDB ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xA7 0x71 0xFF 0x78 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0xA7 0x71 0xFF 0x78 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x47 0x47 0x5C 0x7F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EAAC7FE8-8E06-6A2D-8639-86D5D50919A3}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EAAC7FE8-8E06-6A2D-8639-86D5D50919A3}@iankgbbiefhidpojoi 0x6A 0x61 0x6B 0x66 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EAAC7FE8-8E06-6A2D-8639-86D5D50919A3}@hahjippnhepoahjn 0x6A 0x61 0x61 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EAAC7FE8-8E06-6A2D-8639-86D5D50919A3}@habkopjhpeoaboma 0x61 0x61 0x00 0x7E
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EAAC7FE8-8E06-6A2D-8639-86D5D50919A3}@habkopjhggjgkhee 0x61 0x61 0x00 0x7E
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\rob\Local Settings\Temporary Internet Files\Content.IE5\8FTE7MYE\3[1].txt 0 bytes
File C:\Documents and Settings\rob\Local Settings\Temporary Internet Files\Content.IE5\8FTE7MYE\gw[1].php 0 bytes
---- EOF - GMER 1.0.15 ----
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4611
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/13/2010 11:31:46 PM
mbam-log-2010-09-13 (23-31-46).txt
Scan type: Quick scan
Objects scanned: 130532
Time elapsed: 5 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--
(end)