i cant get MBAM to run a scan even if i point it to itself when the Open With dialogue pops up.
i did run an extra ESET scan with definitions for today and it came up clean.
thanks for the help!
here is the OTL.Txt
OTL logfile created on: 2012-01-03 11:03:01 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\John Nolan\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 60.77% Memory free
3.85 Gb Paging File | 3.21 Gb Available in Paging File | 83.51% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.15 Gb Total Space | 46.38 Gb Free Space | 49.79% Space Free | Partition Type: NTFS
Computer Name: LAPPY | User Name: John Nolan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-01-03 11:01:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John Nolan\Desktop\OTL.exe
PRC - [2011-11-12 19:18:07 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008-04-13 16:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-03-01 03:54:52 | 001,443,072 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2007-12-21 07:21:16 | 000,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2007-10-07 19:39:46 | 000,450,560 | ---- | M] (Duality Software) -- C:\Program Files\DS Clock\dsclock.exe
PRC - [2006-11-03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2005-04-20 09:34:12 | 000,487,936 | ---- | M] (Webroot Software, Inc.) -- C:\WINDOWS\system32\wwSecure.exe
PRC - [2005-03-14 11:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004-09-07 16:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2004-09-07 16:08:02 | 000,389,120 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2004-09-07 16:03:40 | 000,245,760 | ---- | M] (Intel) -- C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
========== Modules (No Company Name) ==========
MOD - [2011-11-12 19:18:05 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011-11-04 06:54:16 | 000,930,304 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\[email protected]\platform\WINNT_x86-msvc\components\lpxpcom.dll
MOD - [2011-07-09 22:17:03 | 006,271,648 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2005-09-08 16:58:00 | 001,466,368 | ---- | M] () -- C:\WINDOWS\system32\nview.dll
MOD - [2005-09-08 16:58:00 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2004-09-07 16:03:46 | 000,073,728 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL
========== Win32 Services (SafeList) ==========
SRV - [2008-03-01 03:58:08 | 000,019,200 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2007-12-21 07:21:16 | 000,468,224 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2006-11-03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005-04-20 09:34:12 | 000,487,936 | ---- | M] (Webroot Software, Inc.) [Auto | Running] -- C:\WINDOWS\system32\wwSecure.exe -- (wwSecSvc)
SRV - [2005-03-14 11:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2004-09-07 16:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
========== Driver Services (SafeList) ==========
DRV - [2008-03-01 03:56:36 | 000,054,280 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi)
DRV - [2008-03-01 03:56:34 | 000,030,728 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2008-03-01 03:56:30 | 000,071,176 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw)
DRV - [2008-03-01 03:53:16 | 000,029,704 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv)
DRV - [2008-03-01 03:52:30 | 000,039,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2005-05-03 15:09:28 | 001,033,728 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.SYS -- (HSF_DPV)
DRV - [2005-05-03 15:08:50 | 000,208,384 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005-05-03 15:08:44 | 000,705,408 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005-03-10 16:56:06 | 000,273,168 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
DRV - [2005-01-25 15:55:08 | 000,121,472 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2004-10-21 15:56:04 | 003,210,496 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel®
DRV - [2004-08-31 08:53:04 | 000,011,354 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2004-08-12 08:44:04 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iwca.sys -- (IWCA)
DRV - [2004-06-17 15:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
DRV - [2001-08-22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {63df8e21-711c-4074-a257-b065cadc28d8}:1.9.3
FF - prefs.js..extensions.enabledItems: {9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA}:0.6.0.3
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.3
FF - prefs.js..extensions.enabledItems: [email protected]:3.4
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {582195F5-92E7-40a0-A127-DB71295901D7}:0.6.4.1.3
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:5.0.3
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {dc0fa13c-3dae-73eb-e852-912722c852f9}:0.3
FF - prefs.js..extensions.enabledItems: {1ced4832-f06e-413f-aa14-9eb63ad40ace}:1.0.2
FF - prefs.js..extensions.enabledItems: {C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9}:0.6.0.10
FF - prefs.js..extensions.enabledItems: {d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904}:2.0.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.15.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.74.0
FF - prefs.js..extensions.enabledItems: {de5809e0-2b07-11dd-bd0b-0800200c9a66}:1.2.0
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\PDF-XChange\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.3: C:\Program Files\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-11-12 19:18:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-10-17 21:07:08 | 000,000,000 | ---D | M]
[2008-08-31 23:54:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Extensions
[2011-12-29 17:05:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions
[2011-12-08 19:51:38 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-04-08 09:35:34 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2010-03-14 17:45:30 | 000,000,000 | ---D | M] (Nuke Anything Enhanced) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\{1ced4832-f06e-413f-aa14-9eb63ad40ace}
[2011-07-21 17:47:38 | 000,000,000 | ---D | M] (Flashblock) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011-07-09 21:24:09 | 000,000,000 | ---D | M] (QuickNote) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\{C0CB8BA3-6C1B-47e8-A6AB-1FAB889562D9}
[2011-10-18 08:38:51 | 000,000,000 | ---D | M] (Fast Dial Fx6) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\[email protected]
[2011-11-17 20:29:14 | 000,000,000 | ---D | M] (LastPass) -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\extensions\[email protected]
[2011-12-29 16:35:17 | 000,001,932 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\searchplugins\ancestry---surnames.xml
[2011-12-29 16:35:21 | 000,006,240 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\searchplugins\bible-gateway.xml
[2011-12-29 16:35:18 | 000,001,103 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\searchplugins\buycom.xml
[2011-12-29 16:35:20 | 000,002,580 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\searchplugins\imdb.xml
[2011-12-29 16:35:20 | 000,002,728 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\searchplugins\newegg.xml
[2011-12-29 16:35:21 | 000,002,431 | ---- | M] () -- C:\Documents and Settings\John Nolan\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\searchplugins\youtube.xml
[2011-11-12 19:18:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\{54BB9F3F-07E5-486C-9B39-C7398B99391C}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\{582195F5-92E7-40A0-A127-DB71295901D7}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\{EF522540-89F5-46B9-B6FE-1829E2B572C6}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\JOHN NOLAN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\7OMDHF4A.DEFAULT\EXTENSIONS\[email protected]
[2011-11-12 19:18:07 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011-05-04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007-05-11 16:41:00 | 000,200,704 | ---- | M] (Ancestry.com) -- C:\Program Files\mozilla firefox\plugins\npImgCtl.dll
[2011-04-12 08:55:08 | 000,167,704 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2011-09-28 16:26:50 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011-11-12 19:18:07 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011-07-09 17:56:45 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [DS Clock] C:\Program Files\DS Clock\dsclock.exe (Duality Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky...can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoft...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/b...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1209536045436 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 138.210.82.250 71.2.28.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93E7C5D4-5D61-42DA-B736-22737225A470}: DhcpNameServer = 138.210.82.250 71.2.28.14
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\John Nolan\Application Data\nView_Wallpaper\PerMonitorWallpaper0.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John Nolan\Application Data\nView_Wallpaper\PerMonitorWallpaper0.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-23 18:27:07 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = F2T] -- "C:\DOCUME~1\JOHNNO~1\LOCALS~1\Temp\321.exe" -a "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012-01-03 11:01:14 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\John Nolan\Desktop\OTL.exe
[2011-12-15 18:51:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John Nolan\Local Settings\Application Data\Nero
[2011-12-15 18:50:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John Nolan\My Documents\Nero
========== Files - Modified Within 30 Days ==========
[2012-01-03 11:01:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John Nolan\Desktop\OTL.exe
[2012-01-03 10:25:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-01-03 07:51:29 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012-01-03 07:30:10 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-01-03 07:30:09 | 000,140,151 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2012-01-03 07:29:49 | 000,013,348 | -HS- | M] () -- C:\Documents and Settings\John Nolan\Local Settings\Application Data\7lad6plo25p28rt7b2clsb
[2012-01-03 07:29:49 | 000,013,348 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\7lad6plo25p28rt7b2clsb
[2012-01-03 07:29:46 | 000,029,940 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2012-01-03 07:29:46 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-01-03 07:29:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-01-03 07:29:36 | 2146,922,496 | -HS- | M] () -- C:\hiberfil.sys
[2012-01-02 15:00:38 | 140,144,640 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\VERTZ5~4.FBK
[2012-01-02 14:58:03 | 332,923,392 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\VERTZ5~2_exported errors fixed2.FTW
[2012-01-02 07:49:08 | 000,000,082 | ---- | M] () -- C:\WINDOWS\MPLAYER.INI
[2011-12-31 07:18:29 | 000,503,348 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-12-31 07:18:29 | 000,087,266 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-12-15 21:35:53 | 000,142,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-12-15 19:05:12 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011-12-15 18:51:57 | 000,001,024 | ---- | M] () -- C:\Documents and Settings\John Nolan\.rnd
[2011-12-13 19:09:01 | 000,000,422 | ---- | M] () -- C:\WINDOWS\tasks\Auslogics Disk Defrag Sheduled Defragmentation.job
[2011-12-05 13:35:00 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
========== Files Created - No Company Name ==========
[2012-01-02 14:56:02 | 000,013,348 | -HS- | C] () -- C:\Documents and Settings\John Nolan\Local Settings\Application Data\7lad6plo25p28rt7b2clsb
[2012-01-02 14:56:02 | 000,013,348 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\7lad6plo25p28rt7b2clsb
[2010-01-30 20:35:08 | 000,025,596 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009-09-25 11:05:28 | 000,105,166 | ---- | C] () -- C:\WINDOWS\HPFins09.dat.temp
[2009-09-25 11:05:28 | 000,003,732 | ---- | C] () -- C:\WINDOWS\hpfmdl09.dat.temp
[2009-01-18 23:30:09 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\John Nolan\Application Data\PnkBstrK.sys
[2008-05-26 20:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008-05-26 20:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
[2008-05-05 19:30:05 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-03-21 17:57:15 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008-03-21 17:57:06 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2008-03-21 17:56:20 | 000,000,732 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2008-03-21 16:07:31 | 000,102,833 | ---- | C] () -- C:\WINDOWS\HPFins09.dat
[2008-03-21 16:07:31 | 000,003,732 | ---- | C] () -- C:\WINDOWS\hpfmdl09.dat
[2008-03-13 06:34:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008-02-28 09:01:50 | 000,001,808 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2008-02-25 21:42:46 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008-02-23 21:35:52 | 000,000,082 | ---- | C] () -- C:\WINDOWS\MPLAYER.INI
[2008-02-23 21:32:38 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-02-23 21:20:27 | 000,000,059 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2008-02-23 21:00:34 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\John Nolan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008-02-23 18:53:45 | 000,140,151 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2008-02-23 18:51:25 | 001,519,616 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008-02-23 18:51:25 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008-02-23 18:51:24 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008-02-23 18:51:24 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008-02-23 18:51:22 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-02-23 18:51:22 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008-02-23 18:51:19 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008-02-23 18:51:17 | 000,393,216 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2008-02-23 18:42:04 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2008-02-23 18:29:39 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2008-02-23 18:23:49 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008-02-23 10:17:50 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008-02-23 10:16:35 | 000,142,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008-02-11 08:39:26 | 000,253,952 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLA.dll
[2008-02-11 08:39:18 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerDLLW.dll
[2008-02-08 12:53:46 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerLang.dll
[2008-02-05 07:48:04 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\OnlineScannerUninstaller.exe
[2007-12-14 11:32:52 | 000,012,632 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2007-09-27 09:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007-09-27 09:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007-09-27 09:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007-07-27 13:49:02 | 000,225,355 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiW.dll
[2007-07-27 13:49:02 | 000,196,683 | ---- | C] () -- C:\WINDOWS\System32\lnod32apiA.dll
[2005-12-05 18:25:22 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\lnod32umc.dll
[2005-12-05 11:37:10 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\lnod32upd.dll
[2005-03-21 17:48:05 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2005-03-21 17:48:05 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004-08-12 08:44:10 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\iwca.dll
[2004-08-04 04:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004-08-04 04:00:00 | 000,503,348 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004-08-04 04:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004-08-04 04:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004-08-04 04:00:00 | 000,087,266 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004-08-04 04:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004-08-04 04:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004-08-04 04:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004-08-04 04:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004-08-04 04:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2001-07-06 15:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2008-08-14 11:56:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2008-02-23 20:40:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2008-04-22 18:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ktetifmn
[2009-09-03 15:40:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009-03-25 17:19:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2011-05-28 06:58:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010-01-29 17:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009-05-07 11:14:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008-04-12 21:08:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\Amazon
[2011-04-21 23:15:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\Auslogics
[2008-03-23 19:39:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\drms
[2008-02-23 22:09:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\Duality Software
[2008-08-14 11:57:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\ESET
[2010-07-24 14:09:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\id Software
[2009-09-24 16:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\Image Zone Express
[2011-07-09 22:21:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\IrfanView
[2008-02-23 21:35:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\MyFamily.com
[2012-01-03 07:30:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\nView_Wallpaper
[2009-07-04 14:18:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\SystemRequirementsLab
[2009-03-22 23:25:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\Windows Desktop Search
[2009-03-27 09:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\Windows Search
[2008-04-28 17:22:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Nolan\Application Data\WinPatrol
[2011-12-13 19:09:01 | 000,000,422 | ---- | M] () -- C:\WINDOWS\Tasks\Auslogics Disk Defrag Sheduled Defragmentation.job
[2012-01-03 07:51:29 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:66E02052
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >