I changed my password.
I tried a few RootKit Scanners.
Noticed a lot of unexplained WiFi Traffic.
Un-Installed Daemon Tools Lite.
Changed name of SPTD.SYS
Not sure if I've solved the situation.
Please, can You help Me wrap this up?
Any help Greatly appreciated, I've so enjoyed reading your articles.
Here is latest OTL.LOG, {plus some ComboFix results from several days prior...}
Thank you, from Capstun7
============================
OTL logfile created on: 11/21/2011 12:08:06 PM - Run 5
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.82% Memory free
3.84 Gb Paging File | 3.33 Gb Available in Paging File | 86.71% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.99 Gb Total Space | 13.09 Gb Free Space | 18.71% Space Free | Partition Type: NTFS
Drive E: | 1.87 Gb Total Space | 0.61 Gb Free Space | 32.30% Space Free | Partition Type: FAT
Computer Name: KJS-TOUGHBOOK | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\PC Magazine Utilities\Flash Cookie Cop\FlashCookieCop.exe (Ziff Davis Inc.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Protector Suite QL\psqltray.exe (UPEK Inc.)
PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe (CMS Products™, Inc.)
PRC - C:\Program Files\HP Optical 4 Button USB Mouse\Kmaestro.exe (Kmaestro)
PRC - C:\Program Files\Panasonic\WSwitch\WSwitch.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe (Seagate LLC)
PRC - C:\Program Files\Seagate\Sync\SeaSyncServices.exe (Seagate Technology LLC)
PRC - C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Panasonic\Hotkey Appendix\hkeyapp.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMAsst.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\PhxPsSvr.exe (Phoenix Technologies Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\WINDOWS\system32\ac3filter.acm ()
MOD - c:\Program Files\McAfee\SiteAdvisor\apengine.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\WINDOWS\system32\tsd32.dll ()
MOD - C:\WINDOWS\system32\DVACM.acm ()
========== Win32 Services (SafeList) ==========
SRV - (!SASCORE) -- File not found
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (BBUpdate) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (AdvancedSystemCareService) -- C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe (IObit)
SRV - (nosGetPlusHelper) getPlus® -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (EvtEng) Intel® -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (WLANKEEPER) Intel® -- C:\Program Files\Intel\WiFi\bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) Intel® -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV - (getPlusHelper) getPlus® -- C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)
SRV - (p2pgasvc) -- C:\WINDOWS\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (BBWatcherService) -- C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe (CMS Products™, Inc.)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (Seagate Sync Service) -- C:\Program Files\Seagate\Sync\SeaSyncServices.exe (Seagate Technology LLC)
SRV - (bgsvc) -- C:\Program Files\B's Recorder GOLD8\bgsvc.exe (B.H.A Corporation)
SRV - (PcInfoSV) -- C:\Program Files\Panasonic\pcinfo\PCInfoSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (EpsonBidirectionalService) -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)
SRV - (PcInfoPi) -- C:\Program Files\Panasonic\pcinfo\PCInfoPi.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (DVD-RAM_Service) -- C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (PhnxPsaService) -- C:\WINDOWS\system32\PhxPsSvr.exe (Phoenix Technologies Ltd.)
========== Driver Services (SafeList) ==========
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) -- C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfendiskmp) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) -- C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (VVBackd5) -- C:\WINDOWS\System32\drivers\VVBackd5.sys ()
DRV - (BsUDFbk) -- C:\WINDOWS\System32\drivers\BsUDFbk.sys (SOURCENEXT CORPORATION)
DRV - (SmartDefragDriver) -- C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys ()
DRV - (RITFSD) -- C:\WINDOWS\System32\drivers\RITFSD.sys ()
DRV - (NETwLx32) Intel® -- C:\WINDOWS\system32\drivers\NETwLx32.sys (Intel Corporation)
DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (Tcpip6) -- C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (NETw5x32) Intel® -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (cpudrv) -- C:\Program Files\SystemRequirementsLab\cpudrv.sys ()
DRV - (mfesmfk) -- C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) -- C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (btwhid) -- C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (NewMisc) -- C:\WINDOWS\system32\drivers\newmisc.sys (Panasonic Corporation)
DRV - (BsStor) -- C:\WINDOWS\System32\drivers\BsStor.sys (B.H.A Co.,Ltd.)
DRV - (KMWDFILTER) -- C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (WDC_SAM) -- C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (NETw4x32) Intel® -- C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (BANTExt) -- C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) -- C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (portio) -- C:\WINDOWS\system32\drivers\portd64.sys (CMS Products, Inc.)
DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HOTKEY) -- C:\WINDOWS\system32\drivers\hotkey.sys (Matsushita Electric Industrial Co., Ltd.)
DRV - (meiudf) -- C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (GTWINSER) -- C:\WINDOWS\system32\drivers\GTwinSER.sys (Gemplus)
DRV - (Rcfilter) -- C:\WINDOWS\system32\drivers\Rcfilter.sys (Phoenix Technologies Ltd.)
DRV - (PhnxVcd) -- C:\WINDOWS\system32\drivers\phnxvcd.sys (Phoenix Technologies Ltd.)
DRV - (cdrbsdrv) -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (miscfp1) -- C:\Program Files\Panasonic\MiscFp\miscfp1.sys (Panasonic)
DRV - (FBAPI) -- C:\WINDOWS\system32\drivers\FBAPI.sys ()
DRV - (IFXTPM) -- C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (ptpd) -- C:\WINDOWS\system32\drivers\ptpd.sys (Phoenix Technologies Ltd.)
DRV - (DCDisk) -- C:\WINDOWS\System32\drivers\DCDisk.sys ()
DRV - (SDKEY) -- C:\Program Files\Panasonic\SDKEY\SDKEY.sys (Matsushita Electric Industrial Co., Ltd.)
DRV - (exdisk) -- C:\WINDOWS\system32\drivers\exdisk.sys ()
DRV - (Machnm32) -- C:\WINDOWS\System32\Machnm32.sys ()
DRV - (MrFilter) -- C:\WINDOWS\System32\drivers\MRFilter.sys (Roxio)
DRV - (CA561) ICatch (VI) -- C:\WINDOWS\system32\drivers\spca561.sys (SP)
DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (EL3C589) -- C:\WINDOWS\system32\drivers\el589nd5.sys (3Com Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.facebook.com/pilgrimcb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:5.8.2.6158.3.6
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3
FF - prefs.js..extensions.enabledItems: {987311C6-B504-4aa2-90BF-60CC49808D42}:2.2
FF - prefs.js..extensions.enabledItems: {ab91efd4-6975-4081-8552-1b3922ed79e2}:1.0.5.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.1
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.0.3
FF - prefs.js..keyword.URL: "http://search.yahoo....h?fr=mcafee&p="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@fileplanet.com/fpdlm: C:\Program Files\Download Manager\npfpdlm.dll (IGN Entertainment)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Administrator\Application Data\Move Networks\plugins\npqmp071706000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.660: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.660: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.660: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Administrator\Application Data\Move Networks\plugins\npqmp071706000001.dll (Move Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/08/16 12:25:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/11/09 16:27:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2011/11/21 12:09:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 20:18:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/09 20:18:28 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\Administrator\Application Data\Move Networks [2011/08/08 16:08:40 | 000,000,000 | ---D | M]
[2009/02/06 12:49:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/11/21 10:30:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\extensions
[2011/08/31 08:38:22 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2009/10/25 20:13:27 | 000,000,000 | ---D | M] (BugMeNot) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2011/11/12 21:41:44 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/04/17 12:29:59 | 000,000,000 | ---D | M] (Password Bank) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\extensions\[email protected]
[2011/11/21 10:30:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\extensions\staged
[2011/02/01 19:05:08 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\searchplugins\askcom.xml
[2011/05/24 00:56:18 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\searchplugins\daemon-search.xml
[2011/10/22 07:48:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/07 15:53:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/17 11:05:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/19 01:56:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/05 11:31:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/09/11 13:58:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/10/22 07:48:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\6CYXSIRZ.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\6CYXSIRZ.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
[2011/08/16 12:25:00 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/11/21 12:09:39 | 000,000,000 | ---D | M] (McAfee ScriptScan for Firefox) -- C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE
[2009/06/07 23:00:42 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/11/09 16:27:52 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2009/06/25 08:19:00 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/09/29 18:19:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
[2009/11/06 10:37:19 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/06 10:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/01/01 02:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/11/27 20:45:34 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
O1 HOSTS File: ([2011/11/18 18:13:24 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111113171143.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BtcMouseMaestro] C:\Program Files\HP Optical 4 Button USB Mouse\KMaestro.exe (Kmaestro)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [FUFAXSTM] C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Panasonic Hotkey Manager] C:\Program Files\Panasonic\Hotkey Appendix\hkeyapp.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - HKLM..\Run: [PCinfo] C:\Program Files\Panasonic\pcinfo\PcInfoUt.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite QL\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [Recover Pro] C:\Program Files\Phoenix Technologies\Applications\RPro\XP\VBPTASK.EXE ()
O4 - HKLM..\Run: [StxTrayMenu] C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [WSwitch] C:\Program Files\Panasonic\WSwitch\WSwitch.exe (Matsushita Electric Industrial Co., Ltd.)
O4 - HKCU..\Run: [Flash Cookie Cop] C:\Program Files\PC Magazine Utilities\Flash Cookie Cop\FlashCookieCop.exe (Ziff Davis Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMAsst.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane..._2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} https://wimpro.cce.h...ads/sysinfo.cab (SysData Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1238311588281 (MUWebControl Class)
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} http://das.microsoft...tail/DASAct.cab (DASWebDownload Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.ado...obat/nos/gp.cab (Reg Error: Value error.)
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.syste...el_4.4.21.0.cab (SysInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60F46D8F-46F5-451D-9764-63291296C139}: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) -C:\WINDOWS\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\psfus: DllName - (C:\Program Files\Protector Suite QL\psqlpwd.dll) - C:\Program Files\Protector Suite QL\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\ACD_SeaSet2r.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\ACD_SeaSet2r.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/12 18:55:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/21 12:10:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/11/21 10:33:03 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\My Documents\mbam-setup-1.51.2.1300.exe
[2011/11/19 21:04:52 | 000,065,808 | ---- | C] (trend_company_name) -- C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/11/18 21:51:56 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/11/18 17:59:58 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/11/18 17:54:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/11/18 17:54:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/11/18 17:54:44 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/11/18 17:54:44 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/11/18 17:07:11 | 024,434,232 | ---- | C] (Google Inc.) -- C:\Documents and Settings\Administrator\My Documents\chrome_installer.exe
[2011/11/18 17:04:37 | 004,300,722 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\My Documents\ComboFix.exe
[2011/11/18 15:47:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/18 14:39:19 | 007,333,952 | ---- | C] (McAfee Inc.) -- C:\Documents and Settings\Administrator\My Documents\stinger.exe
[2011/11/18 13:16:42 | 075,441,352 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\msert.exe
[2011/11/18 13:02:52 | 000,450,352 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\FixitCenter_Run.exe
[2011/11/18 08:29:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\Tasks_OLD
[2011/11/18 08:18:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/11/17 17:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\TDSSKiller_2.exe
[2011/11/17 16:05:22 | 000,606,544 | ---- | C] (Google Inc.) -- C:\Documents and Settings\Administrator\My Documents\ChromeSetup.exe
[2011/11/16 12:21:12 | 001,564,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\TDSSKiller.exe
[2011/11/16 11:54:25 | 000,463,080 | ---- | C] (CNET Download.com) -- C:\Documents and Settings\Administrator\My Documents\cnet_fretpro-setup201_exe.exe
[2011/11/16 07:07:48 | 029,891,024 | ---- | C] (IObit ) -- C:\Documents and Settings\Administrator\My Documents\asc5-setup-cnet.exe
[2011/11/15 23:52:50 | 003,511,776 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Administrator\My Documents\ccsetup312.exe
[2011/11/15 16:08:14 | 000,428,088 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys.bad2
[2011/11/15 13:39:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2011/11/15 13:39:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Security Task Manager
[2011/11/15 13:39:46 | 000,000,000 | ---D | C] -- C:\Program Files\Security Task Manager
[2011/11/14 23:38:48 | 000,000,000 | ---D | C] -- C:\rootkit
[2011/11/14 18:14:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\TMRBLog
[2011/11/14 18:13:44 | 000,205,072 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/11/14 18:13:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\log
[2011/11/14 17:11:24 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2011/11/14 10:52:37 | 000,581,632 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/11/13 17:27:00 | 015,134,664 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\windows-kb890830-v4.2b.exe
[2011/11/13 17:05:30 | 015,134,664 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\windows-kb890830-v4.2.exe
[2011/11/11 15:48:16 | 001,564,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/11/09 20:18:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/11/09 20:16:51 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/11/02 07:13:33 | 000,000,000 | ---D | C] -- C:\Program Files\HiJackThis
[2011/11/01 23:43:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
[2011/11/01 23:43:29 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/10/31 07:15:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\ChrDownload
[2011/10/27 06:19:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Applied Recognition Inc
[2011/10/27 06:18:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\com.appliedrec.Fotobounce
[2011/10/27 06:18:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Fotobounce Family
[2011/10/27 06:17:05 | 000,000,000 | ---D | C] -- C:\Program Files\Fotobounce Family
[2011/10/26 20:03:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\LizImelPics
[2011/10/24 14:29:02 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2011/10/24 14:29:02 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
========== Files - Modified Within 30 Days ==========
[2011/11/21 12:10:32 | 000,001,606 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2011/11/21 12:06:56 | 000,000,004 | ---- | M] () -- C:\WINDOWS\Twain001.Mtx
[2011/11/21 12:06:28 | 000,000,156 | ---- | M] () -- C:\WINDOWS\Twunk001.MTX
[2011/11/21 12:06:05 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1770423292-768891911-228603953-500.job
[2011/11/21 12:05:55 | 000,000,442 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/11/21 12:05:50 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/11/21 12:04:58 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/11/21 11:36:36 | 000,132,597 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Flash_Disinfector.exe
[2011/11/21 11:35:41 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\gmer_11212011.zip
[2011/11/21 11:16:34 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1770423292-768891911-228603953-500.job
[2011/11/21 11:03:54 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Administrator\My Documents\mbam-setup-1.51.2.1300.exe
[2011/11/21 10:46:58 | 000,617,584 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\G2gMal_AccountHijacked.rtf
[2011/11/21 10:40:59 | 000,116,649 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\G2gMaFakeMalScan.rtf
[2011/11/21 10:40:27 | 000,005,675 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\G2gMalRemovalGuide.rtf
[2011/11/21 10:17:15 | 000,000,328 | RHS- | M] () -- C:\boot.ini
[2011/11/21 10:12:39 | 000,000,820 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/11/21 08:45:06 | 000,067,516 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\cc_20111121_084433.reg
[2011/11/19 21:04:53 | 000,065,808 | ---- | M] (trend_company_name) -- C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/11/19 21:03:51 | 000,004,470 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Protector_Plus_Windows_Vulnerability_Scan.htm
[2011/11/18 18:13:24 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/18 17:51:00 | 000,000,283 | ---- | M] () -- C:\Boot.bak
[2011/11/18 17:35:29 | 015,134,664 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\windows-kb890830-v4.2.exe
[2011/11/18 17:08:33 | 024,434,232 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Administrator\My Documents\chrome_installer.exe
[2011/11/18 17:04:54 | 004,300,722 | R--- | M] (Swearware) -- C:\Documents and Settings\Administrator\My Documents\ComboFix.exe
[2011/11/18 15:34:36 | 000,046,196 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Daily11182011Done.jpg
[2011/11/18 15:15:58 | 000,000,008 | RH-- | M] () -- C:\Documents and Settings\Administrator\My Documents\stinger.opt
[2011/11/18 14:41:43 | 002,190,050 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\rp-inside-password-stealing-biz.pdf
[2011/11/18 14:39:33 | 007,333,952 | ---- | M] (McAfee Inc.) -- C:\Documents and Settings\Administrator\My Documents\stinger.exe
[2011/11/18 14:37:06 | 075,441,352 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\msert.exe
[2011/11/18 13:03:50 | 000,450,352 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\FixitCenter_Run.exe
[2011/11/18 10:16:29 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011/11/18 10:16:28 | 000,133,632 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 08:18:48 | 000,001,926 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/11/18 07:47:40 | 000,023,624 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2011/11/17 16:41:59 | 000,231,390 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\RootkitRevealer.zip
[2011/11/17 16:06:50 | 000,606,544 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Administrator\My Documents\ChromeSetup.exe
[2011/11/17 12:54:22 | 000,000,622 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_Nov_REGCUT!.reg
[2011/11/16 21:00:39 | 000,000,693 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/11/16 20:48:44 | 000,115,660 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\KJ_FFoxbookmarks-2011-11-16.json
[2011/11/16 20:48:03 | 000,238,948 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_FFoxbookmarks.html
[2011/11/16 12:21:12 | 001,564,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\TDSSKiller.exe
[2011/11/16 11:56:53 | 000,463,080 | ---- | M] (CNET Download.com) -- C:\Documents and Settings\Administrator\My Documents\cnet_fretpro-setup201_exe.exe
[2011/11/16 09:36:47 | 001,535,850 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_HKCU_IESettings.reg
[2011/11/16 08:41:14 | 029,891,024 | ---- | M] (IObit ) -- C:\Documents and Settings\Administrator\My Documents\asc5-setup-cnet.exe
[2011/11/16 07:15:23 | 000,003,520 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_HKCU_IEIDS.reg
[2011/11/16 00:06:53 | 000,002,920 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_RUNMRU_KHCU2.reg
[2011/11/16 00:02:36 | 003,511,776 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Administrator\My Documents\ccsetup312.exe
[2011/11/16 00:00:57 | 000,002,920 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_RUNMRU_KHCU.reg
[2011/11/15 18:00:02 | 000,000,500 | ---- | M] () -- C:\WINDOWS\PKZIPW.INI
[2011/11/15 17:25:09 | 000,294,195 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\gmer_MajGeek.zip
[2011/11/15 17:17:18 | 003,503,857 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Microsoft_Security_Intelligence_Report_volume_11_English.pdf
[2011/11/15 16:59:41 | 000,097,935 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\gmer.zip
[2011/11/15 16:33:27 | 000,097,963 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\hfqli7skGMMEERR.exe
[2011/11/15 13:46:26 | 000,650,538 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\SecurityTaskManager_Manual.pdf
[2011/11/15 12:51:54 | 000,001,102 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_DEL_SPTD_Legacy.reg
[2011/11/15 12:33:22 | 002,086,240 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\SecurityTaskManager_Setup.exe
[2011/11/15 11:44:15 | 000,506,174 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/11/15 11:44:15 | 000,089,870 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/11/15 00:23:18 | 000,200,178 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_DEL_sptd.jpg
[2011/11/15 00:19:04 | 000,002,152 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_DEL_SPTD.reg
[2011/11/14 18:13:41 | 000,205,072 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/11/14 14:04:38 | 000,001,953 | ---- | M] () -- C:\MCScan.tzt
[2011/11/13 18:05:51 | 015,134,664 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Administrator\My Documents\windows-kb890830-v4.2b.exe
[2011/11/13 12:20:51 | 000,001,405 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\KJ_SongPutYourSweetLips.rtf
[2011/11/13 11:51:54 | 000,003,713 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\yahoo_Dougab.csv
[2011/11/13 02:48:53 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/12 23:09:10 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/11/11 15:48:16 | 001,564,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Administrator\Desktop\TDSSKiller.exe
[2011/11/07 14:49:17 | 000,001,745 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/11/07 01:10:17 | 000,000,199 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Files named [email protected]
[2011/11/01 17:49:56 | 000,007,076 | ---- | M] () -- C:\KJDELOCT.bat
[2011/10/27 06:53:15 | 000,074,412 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/10/27 06:18:16 | 000,000,797 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Fotobounce.lnk
[2011/10/24 14:29:02 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
[2011/10/24 14:29:02 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
[2011/10/23 21:25:38 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
========== Files Created - No Company Name ==========
[2011/11/21 11:36:20 | 000,132,597 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Flash_Disinfector.exe
[2011/11/21 11:35:40 | 000,294,216 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\gmer_11212011.zip
[2011/11/21 11:16:34 | 000,000,294 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1770423292-768891911-228603953-500.job
[2011/11/21 11:16:33 | 000,000,302 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1770423292-768891911-228603953-500.job
[2011/11/21 10:46:58 | 000,617,584 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\G2gMal_AccountHijacked.rtf
[2011/11/21 10:40:59 | 000,116,649 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\G2gMaFakeMalScan.rtf
[2011/11/21 10:40:27 | 000,005,675 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\G2gMalRemovalGuide.rtf
[2011/11/21 10:12:39 | 000,000,820 | ---- | C] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/11/21 08:44:38 | 000,067,516 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\cc_20111121_084433.reg
[2011/11/19 16:06:45 | 000,046,196 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\Daily11182011Done.jpg
[2011/11/18 17:54:44 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/11/18 17:54:44 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/11/18 17:54:44 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/11/18 17:54:44 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/11/18 17:54:44 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/11/18 15:15:58 | 000,000,008 | RH-- | C] () -- C:\Documents and Settings\Administrator\My Documents\stinger.opt
[2011/11/18 14:41:42 | 002,190,050 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\rp-inside-password-stealing-biz.pdf
[2011/11/18 08:18:48 | 000,001,926 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011/11/17 16:41:34 | 000,231,390 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\RootkitRevealer.zip
[2011/11/17 12:54:22 | 000,000,622 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_Nov_REGCUT!.reg
[2011/11/16 21:00:39 | 000,000,693 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/11/16 20:48:44 | 000,115,660 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\KJ_FFoxbookmarks-2011-11-16.json
[2011/11/16 20:48:03 | 000,238,948 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_FFoxbookmarks.html
[2011/11/16 09:36:46 | 001,535,850 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_HKCU_IESettings.reg
[2011/11/16 07:15:23 | 000,003,520 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_HKCU_IEIDS.reg
[2011/11/16 00:06:53 | 000,002,920 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_RUNMRU_KHCU2.reg
[2011/11/16 00:00:57 | 000,002,920 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_RUNMRU_KHCU.reg
[2011/11/15 17:26:11 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\gmer.exe
[2011/11/15 17:24:55 | 000,294,195 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\gmer_MajGeek.zip
[2011/11/15 16:56:50 | 000,097,935 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\gmer.zip
[2011/11/15 16:32:24 | 003,503,857 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Microsoft_Security_Intelligence_Report_volume_11_English.pdf
[2011/11/15 16:29:57 | 000,097,963 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\hfqli7skGMMEERR.exe
[2011/11/15 13:46:25 | 000,650,538 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\SecurityTaskManager_Manual.pdf
[2011/11/15 12:51:54 | 000,001,102 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_DEL_SPTD_Legacy.reg
[2011/11/15 12:24:50 | 002,086,240 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\SecurityTaskManager_Setup.exe
[2011/11/15 00:23:18 | 000,200,178 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_DEL_sptd.jpg
[2011/11/15 00:19:03 | 000,002,152 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_DEL_SPTD.reg
[2011/11/14 14:04:35 | 000,001,953 | ---- | C] () -- C:\MCScan.tzt
[2011/11/13 12:20:50 | 000,001,405 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\KJ_SongPutYourSweetLips.rtf
[2011/11/13 11:51:54 | 000,003,713 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\yahoo_Dougab.csv
[2011/11/13 09:11:07 | 000,004,470 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Protector_Plus_Windows_Vulnerability_Scan.htm
[2011/11/07 14:49:17 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/11/07 14:49:17 | 000,001,745 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/11/07 01:10:16 | 000,000,199 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Files named [email protected]
[2011/11/01 17:48:42 | 000,007,076 | ---- | C] () -- C:\KJDELOCT.bat
[2011/10/27 06:53:15 | 000,074,412 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011/10/27 06:18:16 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Fotobounce.lnk
[2011/10/11 09:58:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EEventManager.INI
[2011/10/02 22:30:15 | 000,073,220 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2011/10/02 22:30:15 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2011/10/02 22:30:15 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2011/10/02 22:30:15 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2011/10/02 22:30:15 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2011/10/02 22:30:15 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2011/10/02 22:30:15 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2011/10/02 22:30:15 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2011/10/02 22:30:14 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2011/10/02 22:30:14 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2011/10/02 22:30:14 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2011/10/02 22:30:14 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2011/10/02 22:30:14 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2011/10/02 22:30:14 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2011/10/02 22:30:14 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2011/10/02 22:30:14 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2011/10/02 22:23:22 | 000,000,079 | ---- | C] () -- C:\WINDOWS\EWF630.ini
[2011/09/19 14:34:25 | 000,106,804 | ---- | C] () -- C:\WINDOWS\hpqins05.dat
[2011/09/19 14:00:12 | 000,108,055 | ---- | C] () -- C:\WINDOWS\hpqins01.dat
[2011/09/19 12:36:58 | 000,025,944 | ---- | C] () -- C:\WINDOWS\System32\SmartDefragBootTime.exe
[2011/09/19 12:36:52 | 000,014,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartDefragDriver.sys
[2011/08/11 16:05:29 | 000,917,952 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/05/24 11:09:08 | 000,000,751 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
[2011/05/24 11:09:08 | 000,000,028 | ---- | C] () -- C:\WINDOWS\Msdevctl.ini
[2011/05/23 19:53:52 | 000,001,065 | ---- | C] () -- C:\Program Files\AcroPro.swtag
[2011/05/02 16:30:50 | 001,144,147 | ---- | C] () -- C:\WINDOWS\System32\ffmpegmt.dll
[2011/05/02 16:27:54 | 003,935,545 | ---- | C] () -- C:\WINDOWS\System32\ffmpeg.dll
[2011/05/02 14:23:46 | 000,324,096 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2011/05/02 14:19:34 | 000,100,352 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2011/05/02 14:19:20 | 000,080,896 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2011/04/14 04:50:06 | 000,000,704 | ---- | C] () -- C:\WINDOWS\HEARTS.INI
[2011/03/18 15:32:44 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2011/03/18 15:29:56 | 000,181,248 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2011/03/18 15:28:30 | 001,557,504 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2011/03/18 15:27:08 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2011/03/18 15:26:44 | 000,484,864 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2011/03/18 15:25:38 | 000,257,024 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2011/03/18 15:25:24 | 000,141,312 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2011/03/05 13:40:12 | 003,717,344 | ---- | C] () -- C:\Program Files\Paint.NET.3.5.8.Install.exe
[2011/03/03 05:40:08 | 000,150,528 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2011/03/03 05:39:56 | 000,109,568 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2011/03/03 05:39:46 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2011/03/03 05:39:34 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2011/03/03 05:39:02 | 000,113,152 | ---- | C] () -- C:\WINDOWS\System32\dsmux.exe
[2011/03/03 05:38:54 | 000,154,112 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2011/03/03 05:38:40 | 000,249,856 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2011/03/03 05:38:10 | 000,097,792 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2011/03/03 05:38:04 | 000,137,728 | ---- | C] () -- C:\WINDOWS\System32\mkv2vfr.exe
[2011/03/03 05:37:50 | 000,093,184 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2011/03/03 05:37:40 | 000,358,400 | ---- | C] () -- C:\WINDOWS\System32\gdsmux.exe
[2011/03/03 05:35:32 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2011/03/03 05:35:26 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2011/02/22 13:39:04 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/02/22 13:37:30 | 000,650,752 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/10/31 18:36:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NPE.INI
[2010/10/17 12:43:39 | 000,460,800 | ---- | C] () -- C:\WINDOWS\snap.dat
[2010/10/16 16:03:30 | 000,070,144 | ---- | C] () -- C:\WINDOWS\unlite.exe
[2010/10/16 16:03:13 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\wddx_com.dll
[2010/10/16 16:03:12 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\CFFileProxy.dll
[2010/10/16 16:02:35 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2010/10/16 16:02:35 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\cfmsg.dll
[2010/10/16 16:02:35 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2010/10/16 16:00:52 | 000,000,036 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2010/10/16 15:59:52 | 000,307,200 | ---- | C] () -- C:\WINDOWS\System32\I3tif32.dll
[2010/10/16 15:59:52 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\I3spec32.dll
[2010/10/16 15:59:51 | 000,430,080 | ---- | C] () -- C:\WINDOWS\System32\Crde96v3.dll
[2010/10/16 15:59:49 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
[2010/10/16 15:59:48 | 000,009,136 | ---- | C] () -- C:\WINDOWS\System32\Inetwh16.dll
[2010/10/16 15:59:48 | 000,004,528 | ---- | C] () -- C:\WINDOWS\System32\Setbrows.exe
[2010/10/16 15:59:36 | 000,295,936 | ---- | C] () -- C:\WINDOWS\System32\HDprev.dll
[2010/10/16 15:59:36 | 000,243,712 | ---- | C] () -- C:\WINDOWS\System32\uafdll.dll
[2010/10/16 15:59:36 | 000,017,408 | ---- | C] () -- C:\WINDOWS\System32\delphimm.dll
[2010/10/14 11:23:22 | 000,000,553 | ---- | C] () -- C:\WINDOWS\BSWIN.INI
[2010/08/18 13:56:38 | 000,000,151 | ---- | C] () -- C:\WINDOWS\System32\Registration.ini
[2010/06/22 08:40:27 | 000,165,694 | ---- | C] () -- C:\WINDOWS\hpqins00.dat.temp
[2010/06/17 16:32:31 | 000,023,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/06/15 12:51:27 | 000,001,100 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2010/06/11 14:17:44 | 001,308,860 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\System Backup - 20091025213007-4375.BB
[2010/05/28 11:16:47 | 000,000,044 | ---- | C] () -- C:\WINDOWS\Ezphoto.ini
[2010/04/21 13:46:46 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/12/16 14:51:22 | 000,118,784 | ---- | C] () -- C:\WINDOWS\ShowBmp.exe
[2009/12/16 14:51:22 | 000,000,081 | ---- | C] () -- C:\WINDOWS\Setup8a.ini
[2009/12/16 14:51:21 | 000,014,385 | ---- | C] () -- C:\WINDOWS\Tw561a.ini
[2009/12/02 22:26:59 | 001,498,560 | ---- | C] () -- C:\WINDOWS\System32\igkrng400.bin
[2009/11/17 14:59:24 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2009/10/28 19:16:19 | 000,116,839 | ---- | C] () -- C:\WINDOWS\hpqins00.dat
[2009/10/28 13:12:14 | 000,122,994 | ---- | C] () -- C:\WINDOWS\hpoins15.dat.temp
[2009/10/28 13:12:14 | 000,001,037 | ---- | C] () -- C:\WINDOWS\hpomdl15.dat.temp
[2009/10/25 21:00:15 | 000,035,520 | ---- | C] () -- C:\WINDOWS\System32\BBUninstall.exe
[2009/08/14 11:47:34 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2009/08/11 15:21:26 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\ac3config.exe
[2009/08/11 15:21:20 | 001,021,440 | ---- | C] () -- C:\WINDOWS\System32\ac3filter_intl.dll
[2009/08/10 17:34:00 | 000,000,051 | ---- | C] () -- C:\WINDOWS\WWWBATCH.INI
[2009/07/23 13:53:46 | 000,000,072 | ---- | C] () -- C:\WINDOWS\sstools.ini
[2009/05/27 12:08:12 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\GIF89.DLL
[2009/05/27 12:05:08 | 000,000,472 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/05/22 17:13:15 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/12 15:15:46 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/05/09 09:01:43 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2009/04/19 19:06:22 | 000,083,480 | ---- | C] () -- C:\WINDOWS\System32\MmRemove.exe
[2009/03/28 00:21:53 | 000,000,770 | ---- | C] () -- C:\WINDOWS\aolback.exe.lnk
[2009/02/28 21:41:44 | 000,002,365 | ---- | C] () -- C:\WINDOWS\CDex.ini
[2009/02/21 21:00:26 | 000,001,565 | ---- | C] () -- C:\WINDOWS\2xExplorer.INI
[2009/02/17 12:46:21 | 000,000,051 | ---- | C] () -- C:\WINDOWS\wps.ini
[2009/02/06 12:49:20 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/01/29 15:56:00 | 000,000,500 | ---- | C] () -- C:\WINDOWS\PKZIPW.INI
[2009/01/27 00:57:36 | 000,185,344 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2009/01/22 20:41:50 | 000,248,832 | ---- | C] () -- C:\WINDOWS\System32\ECircles.dll
[2009/01/22 20:41:50 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\SoyWeb.dll
[2009/01/22 20:40:16 | 000,065,864 | ---- | C] () -- C:\WINDOWS\System32\Digita.sys
[2009/01/22 20:40:15 | 000,007,808 | ---- | C] () -- C:\WINDOWS\System32\dc240u.sys
[2009/01/22 20:40:07 | 000,048,640 | ---- | C] () -- C:\WINDOWS\catalogSubInstaller.exe
[2009/01/22 19:54:37 | 000,000,823 | ---- | C] () -- C:\WINDOWS\System32\unins000.dat
[2009/01/22 19:04:14 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/01/19 14:26:36 | 000,245,266 | ---- | C] () -- C:\WINDOWS\System32\drivers\VVBackd5.sys
[2009/01/19 14:26:32 | 000,042,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\DCDisk.sys
[2009/01/19 14:26:31 | 000,045,056 | ---- | C] () -- C:\WINDOWS\DxpAppEx.exe
[2009/01/19 14:26:31 | 000,034,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\RITFSD.sys
[2009/01/19 14:26:31 | 000,014,074 | ---- | C] () -- C:\WINDOWS\System32\drivers\exdisk.sys
[2009/01/19 14:26:25 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\RitShell.dll
[2009/01/19 14:26:23 | 000,008,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\FBAPI.sys
[2009/01/19 14:26:15 | 000,000,307 | ---- | C] () -- C:\WINDOWS\System32\phnxPsa.ini
[2009/01/19 14:26:06 | 000,002,304 | ---- | C] () -- C:\WINDOWS\System32\Machnm32.sys
[2009/01/18 02:30:19 | 000,000,074 | ---- | C] () -- C:\WINDOWS\OPENTRAP.INI
[2009/01/17 11:11:13 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll
[2009/01/17 01:10:49 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2009/01/17 01:10:49 | 000,000,177 | ---- | C] () -- C:\WINDOWS\kpcms.ini
[2009/01/17 01:10:47 | 000,100,864 | ---- | C] () -- C:\WINDOWS\System32\Dc50ip32.dll
[2009/01/17 01:10:47 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\ImgLibLead.dll
[2009/01/16 18:43:31 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2009/01/10 18:40:48 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2009/01/10 18:35:09 | 000,000,389 | ---- | C] () -- C:\WINDOWS\pdf2word.INI
[2009/01/08 19:58:33 | 000,001,565 | ---- | C] () -- C:\WINDOWS\2XEXPL~1.INI
[2009/01/06 10:24:56 | 000,000,525 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2009/01/03 12:15:55 | 000,000,002 | ---- | C] () -- C:\WINDOWS\PhotoSuite.ini
[2009/01/03 12:15:49 | 000,458,752 | ---- | C] () -- C:\WINDOWS\System32\Fpl.dll
[2009/01/03 12:15:48 | 000,332,800 | ---- | C] () -- C:\WINDOWS\System32\Fpxlib.dll
[2009/01/03 12:15:48 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\Jpeglib.dll
[2009/01/03 12:15:48 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\Cpuinf32.dll
[2009/01/02 19:40:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2009/01/02 17:08:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2009/01/01 12:24:14 | 000,271,264 | ---- | C] () -- C:\WINDOWS\System32\VBRUN100.DLL
[2008/12/26 10:18:07 | 000,133,632 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/22 13:30:15 | 000,000,008 | RHS- | C] () -- C:\WINDOWS\neoqaz2.dll
[2008/11/19 12:05:19 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008/11/06 09:37:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/06/20 15:58:54 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/06/13 12:42:49 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4814.dll
[2007/06/13 12:42:48 | 000,910,304 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2007/06/13 11:26:26 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2007/06/13 11:26:26 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2007/06/13 11:26:26 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2007/06/13 11:26:26 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2007/06/13 11:26:26 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2007/06/13 11:26:26 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2007/06/12 20:53:42 | 000,000,000 | ---- | C] () -- C:\WINDOWS\tosOBEX.INI
[2007/06/12 20:17:06 | 000,000,102 | ---- | C] () -- C:\WINDOWS\System32\softkbd.exe.config
[2007/06/12 20:01:55 | 000,000,052 | ---- | C] () -- C:\WINDOWS\DMIVIEW.INI
[2007/06/12 18:57:08 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2007/06/12 18:53:35 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2007/06/12 11:51:44 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2007/06/12 11:51:13 | 000,532,544 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2007/06/12 11:23:06 | 000,002,190 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2007/06/12 11:21:12 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2007/06/12 11:20:59 | 000,506,174 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2007/06/12 11:20:59 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2007/06/12 11:20:59 | 000,089,870 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2007/06/12 11:20:59 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2007/06/12 11:20:55 | 000,004,484 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2007/06/12 11:20:51 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2007/06/12 11:20:43 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2007/06/12 11:20:22 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2007/06/12 11:20:22 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2007/06/12 11:19:42 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2007/06/12 11:19:23 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2006/03/03 22:52:00 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\OptimFROG.dll
[2002/03/21 14:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL
[2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1996/11/21 02:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1996/11/21 02:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1995/10/21 10:37:52 | 000,035,328 | ---- | C] () -- C:\WINDOWS\INETWH32.DLL
========== LOP Check ==========
[2010/04/21 12:51:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ACD Systems
[2011/10/27 06:19:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Applied Recognition Inc
[2009/03/22 14:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\B.H.A
[2010/04/27 16:03:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Canon
[2008/12/26 18:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Ceedo
[2011/10/27 06:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\com.appliedrec.Fotobounce
[2010/04/26 13:12:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Cool Record Edit Pro
[2011/11/21 08:12:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Lite
[2010/10/18 01:13:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Disk Cleaner
[2011/10/17 14:09:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Epson
[2010/06/22 06:54:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Free Sound Recorder
[2010/04/27 09:35:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FreeFLVConverter
[2011/04/10 18:17:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GARMIN
[2009/03/05 21:12:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\InterVideo
[2011/05/19 17:06:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IObit
[2011/10/03 08:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leader Technologies
[2011/10/02 23:21:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Leadertech
[2009/04/04 10:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Learn2.com
[2009/01/17 07:43:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MGI
[2011/10/05 13:35:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\MP42MPEG
[2009/04/06 22:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\OfficeUpdate12
[2010/07/28 12:03:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\OverDrive
[2010/07/18 15:58:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PC Magazine Utilities
[2010/04/29 10:52:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PCMagazine
[2009/04/13 01:29:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Protector Suite
[2009/01/19 14:26:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Recover Pro
[2009/01/06 10:24:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ScanSoft
[2011/05/11 16:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
[2009/01/27 00:57:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ubi.com
[2009/04/14 19:35:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Windows Search
[2010/04/21 12:50:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2011/09/27 13:27:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astroburn Pro
[2011/05/24 23:49:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/02/26 11:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2011/10/02 23:22:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2010/06/17 16:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2011/05/11 15:26:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2011/10/07 23:32:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2009/03/30 18:18:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/11/18 12:48:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/01/06 10:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/01/06 10:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2011/10/02 22:53:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2009/04/13 00:56:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UIB
[2009/03/28 00:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\vb.ini.OLD:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\ws2_32.dll:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\lsass.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\VVBackd5.sys:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\RITFSD.sys:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\BsUDFbk.sys:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\System32\drivers\BsUDF.sys:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\WINDOWS\DxpAppEx.exe:SummaryInformation
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Administrator\My Documents\corphome_13910_en-us_12m_r1.exe:SummaryInformation
@Alternate Data Stream - 8 bytes -> C:\WINDOWS:
< End of report >
================================================================================
ADDENDA:::
Previously Run: 11/18/2001
ComboFix Ver. 11.11.18.2
ComboFix-quarantined-files.txt
2011-11-19 00:15:13 . 2011-11-19 00:15:13 638 ----a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-DAEMON Tools Lite.reg.dat
2011-11-19 00:15:11 . 2011-11-19 00:15:11 276 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Notify-AtiExtEvent.reg.dat
2011-11-19 00:15:04 . 2011-11-19 00:15:04 186 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Recover Pro.reg.dat
2011-11-19 00:15:02 . 2011-11-19 00:15:02 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440}.reg.dat
2011-11-19 00:10:17 . 2011-11-19 00:10:17 16,466 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-11-18 23:53:10 . 2011-11-18 23:54:40 102 ----a-w- C:\Qoobox\Quarantine\catchme.log
2010-05-02 14:43:11 . 2011-01-19 15:02:49 50,176 ----a-w- C:\Qoobox\Quarantine\C\Thumbs.db.vir
2009-10-28 19:56:48 . 2009-07-13 10:20:33 505,176 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\AutoRun.inf.vir
2009-01-09 15:08:06 . 2009-01-09 15:08:06 21,504 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\jestertb.dll.vir
2009-01-03 18:15:48 . 1999-08-04 20:00:00 522,752 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\DC120fc7_32.dll.vir
2009-01-01 20:12:15 . 2009-01-01 20:12:15 47,122 ----atw- C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\DIO3.tmp.vir
2003-03-24 21:09:04 . 2003-03-24 21:09:04 40,199 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\xpvss-readme.htm.vir
2002-03-20 01:30:00 . 2002-03-20 01:30:00 5,528 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\PowerToyReadme.htm.vir
============================================
ComboFix 11-11-18.02 - Administrator 11/18/2011 18:04:29.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1051 [GMT -6:00]
Running from: c:\documents and settings\Administrator\My Documents\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\DIO3.tmp
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
C:\Thumbs.db
c:\windows\CSC\d6
c:\windows\jestertb.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\DC120fc7_32.dll
c:\windows\system32\PowerToyReadme.htm
c:\windows\system32\xpvss-readme.htm
.
.
((((((((((((((((((((((((( Files Created from 2011-10-19 to 2011-11-19 )))))))))))))))))))))))))))))))
.
.
2011-11-18 14:29 . 2011-11-18 14:30 -------- d-----w- c:\windows\Tasks_OLD
2011-11-16 18:21 . 2011-11-16 18:21 1564976 ----a-w- C:\TDSSKiller.exe
2011-11-15 22:08 . 2011-11-15 22:08 428088 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-11-15 19:39 . 2011-11-18 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2011-11-15 19:39 . 2011-11-15 19:39 -------- d-----w- c:\program files\Security Task Manager
2011-11-15 05:38 . 2011-11-15 05:38 -------- d-----w- C:\rootkit
2011-11-15 00:13 . 2011-11-15 00:13 205072 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-11-14 23:11 . 2011-11-14 23:11 -------- d-----w- C:\TDSSKiller_Quarantine
2011-11-02 13:13 . 2011-11-02 13:13 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-02 05:43 . 2011-11-02 05:43 -------- d-----w- c:\program files\Trend Micro
2011-11-01 23:48 . 2011-11-01 23:49 7076 ----a-w- C:\KJDELOCT.bat
2011-10-27 12:19 . 2011-10-27 12:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\Applied Recognition Inc
2011-10-27 12:18 . 2011-10-27 12:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\com.appliedrec.Fotobounce
2011-10-27 12:17 . 2011-10-27 12:17 -------- d-----w- c:\program files\Fotobounce Family
2011-10-24 20:29 . 2011-10-24 20:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 20:29 . 2011-10-24 20:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-22 13:48 . 2011-10-03 08:37 73728 ----a-w- c:\windows\system32\javacpl.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-18 13:47 . 2010-06-17 22:32 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-13 08:48 . 2011-05-14 19:15 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 20:32 . 2011-01-11 09:10 150856 ----a-w- c:\windows\system32\mfevtps.exe
2011-10-15 19:16 . 2011-01-11 09:10 9608 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-10-15 19:16 . 2011-01-11 09:10 89792 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-10-15 19:16 . 2011-01-11 09:10 87656 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-10-15 19:16 . 2011-01-11 09:10 83856 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2011-10-15 19:16 . 2011-01-11 09:10 57600 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-10-15 19:16 . 2011-01-11 09:10 338176 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-10-15 19:16 . 2011-01-11 09:10 180816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-10-15 19:16 . 2011-01-11 09:10 121256 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-10-15 19:16 . 2008-12-26 16:52 59456 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2011-10-15 19:16 . 2008-12-26 16:52 464176 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-10-11 02:55 . 2011-10-11 02:50 209 ----a-w- C:\dIRdOWNLDS.BAT
2011-10-10 14:22 . 2007-06-13 00:53 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 11:06 . 2010-05-07 21:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-28 07:06 . 2007-06-12 17:19 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 17:41 . 2008-07-30 03:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 17:41 . 2007-06-12 17:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 17:41 . 2007-06-12 17:20 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 19:29 . 2009-01-19 20:26 245266 ----a-w- c:\windows\system32\drivers\VVBackd5.sys
2011-09-06 13:20 . 2007-06-12 17:21 1858944 ------w- c:\windows\system32\win32k.sys
2011-08-31 23:00 . 2010-06-15 08:12 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48 . 2007-06-12 17:21 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2007-06-12 17:20 43520 ------w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2007-06-12 17:20 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2007-06-12 17:19 385024 ------w- c:\windows\system32\html.iec
2011-03-05 19:40 . 2011-03-05 19:40 3717344 ----a-w- c:\program files\Paint.NET.3.5.8.Install.exe
2011-09-30 00:19 . 2011-05-07 00:40 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 20:01 . 2011-01-11 09:10 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2008-09-15 23:25 4233480 ------w- c:\program files\Protector Suite QL\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2008-09-15 23:25 4233480 ------w- c:\program files\Protector Suite QL\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"Flash Cookie Cop"="c:\program files\PC Magazine Utilities\Flash Cookie Cop\FlashCookieCop.exe" [2010-10-19 515072]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-28 39408]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-04-15 402832]
"ltcmScheduler"="c:\program files\LTCM Client\ltcmScheduler.exe" [2009-08-05 105664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WSwitch"="c:\program files\Panasonic\WSwitch\WSwitch.exe" [2007-03-20 726672]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-02 729177]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-18 190008]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 868352]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2008-09-15 49928]
"PCinfo"="c:\program files\Panasonic\pcinfo\PcInfoUt.exe" [2006-11-30 87696]
"Panasonic Hotkey Manager"="c:\program files\Panasonic\Hotkey Appendix\HKEYAPP.EXE" [2006-12-16 976528]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"BtcMouseMaestro"="c:\program files\HP Optical 4 Button USB Mouse\KMaestro.exe" [2007-08-24 344064]
"gemstrmw"="c:\windows\system32\gemstrmw.exe" [2006-08-24 24576]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-17 1318552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-01-13 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-01-13 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-01-13 135680]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-08-16 273544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-01-12 1400832]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-01-12 1210640]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-03 847872]
"LTCM Client"="c:\program files\LTCM Client\ltcmClient.exe" [2009-08-05 1596096]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMAsst.exe [2007-6-13 163840]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-09-18 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2008-09-15 23:12 96520 ------w- c:\program files\Protector Suite QL\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Protector Suite QL\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Driver performer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Driver performer.lnk
backup=c:\windows\pss\Driver performer.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-12 04:43 640376 ------w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2008-06-12 08:25 37232 ------w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 18:55 937920 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\B'sCLiP]
2008-12-24 11:54 708608 ------w- c:\progra~1\B'SCLI~1\Win2K\BsCLiP.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-13 22:12 110592 ----a-w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
2009-10-27 17:18 1103216 ------w- c:\program files\Download Manager\DLM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
2002-06-03 19:38 49152 ------w- c:\program files\ScanSoft\OmniPageSE\opware32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-11-13 03:40 4617600 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
"BthServ"=2 (0x2)
"bgsvc"=2 (0x2)
"AdvancedSystemCareService"=2 (0x2)
"ABBYY.Licensing.FineReader.Sprint.9.0"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"5985:TCP"= 5985:TCP:Windows Remote Management
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [6/13/2007 11:24 AM 17192]
R0 MrFilter;EasyWrite Driver;c:\windows\system32\drivers\MRFilter.sys [4/14/2009 10:33 PM 12992]
R0 ptpd;Disk Filter Driver;c:\windows\system32\drivers\ptpd.sys [1/19/2009 2:26 PM 8320]
R0 RITFSD;RITFSD;c:\windows\system32\drivers\RITFSD.sys [1/19/2009 2:26 PM 34944]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [9/19/2011 12:36 PM 14776]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R0 VVBackd5;VVBackd5;c:\windows\system32\drivers\VVBackd5.sys [1/19/2009 2:26 PM 245266]
R1 DCDisk;DCDisk;c:\windows\system32\drivers\DCDisk.sys [1/19/2009 2:26 PM 42240]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [1/11/2011 3:10 AM 89792]
R1 miscfp1;Panasonic FP1 Device Driver;c:\program files\Panasonic\MiscFp\miscfp1.sys [6/12/2007 8:40 PM 4736]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2010 12:25 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [5/4/2011 11:54 AM 116608]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [6/15/2011 5:33 PM 249648]
R2 BBWatcherService;BBWatcherService;c:\program files\CMS Products\BounceBack Professional\BBWatcherService.exe [10/25/2009 9:00 PM 36864]
R2 BsUDFbk;BsUDFbk;c:\windows\system32\drivers\BsUDFbk.sys [5/24/2011 2:00 PM 196144]
R2 FBAPI;FBAPI;c:\windows\system32\drivers\FBAPI.sys [1/19/2009 2:26 PM 8832]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/7/2009 1:33 AM 94880]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [1/11/2011 3:10 AM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [1/11/2011 3:10 AM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [1/11/2011 3:11 AM 160608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [1/11/2011 3:10 AM 150856]
R2 PcInfoPi;Panasonic PC Information Viewer Service 2;c:\program files\Panasonic\pcinfo\PCInfoPi.exe [6/12/2007 8:24 PM 54928]
R2 PcInfoSV;Panasonic PC Information Viewer;c:\program files\Panasonic\pcinfo\PCInfoSV.exe [6/12/2007 8:24 PM 186000]
R2 PhnxPsaService;Phoenix PSA Service;c:\windows\system32\PhxPsSvr.exe [1/19/2009 2:26 PM 40960]
R2 Rcfilter;Rcfilter;c:\windows\system32\drivers\Rcfilter.sys [1/19/2009 2:26 PM 36224]
R2 SDKEY;Panasonic SD Misc. Function Driver;c:\program files\Panasonic\SDKEY\SDKEY.sys [6/12/2007 8:05 PM 8192]
R2 Seagate Sync Service;Seagate Sync Service;c:\program files\Seagate\Sync\SeaSyncServices.exe [1/18/2007 4:20 PM 24120]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [1/11/2011 3:10 AM 57600]
R3 exdisk;Express Disk Service;c:\windows\system32\drivers\exdisk.sys [1/19/2009 2:26 PM 14074]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [6/12/2007 11:27 AM 36352]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [1/11/2011 3:10 AM 338176]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [1/11/2011 3:10 AM 83856]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [9/21/2011 12:31 PM 6609920]
R3 NewMisc;Panasonic Misc Driver;c:\windows\system32\drivers\newmisc.sys [6/12/2007 11:27 AM 51520]
R3 PhnxVcd;PhnxVcd;c:\windows\system32\drivers\phnxvcd.sys [6/12/2007 11:35 AM 47488]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate1c9b70045225732;Google Update Service (gupdate1c9b70045225732);c:\program files\Google\Update\GoogleUpdate.exe [4/6/2009 3:39 PM 133104]
S3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [7/7/2011 7:31 PM 195336]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 10:58 AM 11336]
S3 EL3C589;3Com Megahertz LAN PC Card Driver;c:\windows\system32\drivers\el589nd5.sys [1/5/2009 3:08 PM 26141]
S3 GTWINSER;GTWINSER;c:\windows\system32\drivers\GTwinSER.sys [6/12/2007 6:59 PM 66912]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/6/2009 3:39 PM 133104]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [11/16/2010 1:10 AM 267568]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 6:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [1/11/2011 3:10 AM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [1/11/2011 3:10 AM 87656]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [6/12/2007 11:21 AM 14336]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/6/2008 3:06 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [6/12/2007 11:21 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [5/14/2009 5:07 PM 759048]
S4 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [5/11/2011 2:36 PM 352144]
S4 bgsvc;B's Recorder GOLD Service;c:\program files\B's Recorder GOLD8\bgsvc.exe [6/13/2007 11:21 AM 122512]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
getPlusHelper REG_MULTI_SZ getPlusHelper
WINRM REG_MULTI_SZ WINRM
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-27 16:58]
.
2011-11-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1770423292-768891911-228603953-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 16:47]
.
2011-11-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1770423292-768891911-228603953-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 16:47]
.
2011-11-18 c:\windows\Tasks\User_Feed_Synchronization-{B9D06C9F-3055-4E23-A84A-970EE71F03E7}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = https://www.facebook.com/pilgrimcb
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6cyxsirz.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 4
FF - user.js: yahoo.homepage.dontask - true
.
.
------- File Associations -------
.
.txt=PFE32
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Recover Pro - c:\program files\Phoenix Technologies\Applications\RPro\XP\VBPTASK.EXE
Notify-AtiExtEvent - (no file)
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\DTLite.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-18 18:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1770423292-768891911-228603953-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1c,b4,76,0c,f8,1a,ff,40,84,ad,ef,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1c,b4,76,0c,f8,1a,ff,40,84,ad,ef,\
.
[HKEY_USERS\S-1-5-21-1770423292-768891911-228603953-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1868)
c:\windows\system32\vrlogon.dll
c:\windows\system32\IWPDGINA.DLL
c:\program files\Intel\WiFi\bin\LangResources\ENU\SsoGnENU.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Protector Suite QL\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infql2.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\bio.dll
c:\program files\Protector Suite QL\qlbase.dll
c:\windows\system32\l3codeca.acm
c:\windows\system32\sirenacm.dll
c:\windows\system32\dvacm.acm
c:\windows\system32\ac3filter.acm
c:\windows\system32\DivXa32.acm
c:\windows\system32\LameACM.acm
c:\windows\system32\IEFRAME.dll
c:\program files\Protector Suite QL\biokmd.dll
c:\windows\system32\netprovcredman.dll
c:\program files\Protector Suite QL\otp.dll
c:\program files\Protector Suite QL\psqltray.dll
.
- - - - - - - > 'lsass.exe'(1924)
c:\program files\Protector Suite QL\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infql2.dll
.
Completion time: 2011-11-18 18:16:57
ComboFix-quarantined-files.txt 2011-11-19 00:16
.
Pre-Run: 13,714,468,864 bytes free
Post-Run: 13,788,999,680 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut
.
- - End Of File - - F731BB332F1E2EF06F53B8423F5089F6