OK - I think I did everything you asked me to do.
System Restore point set.
Ran Rogue Killer - here is log
RogueKiller V8.6.3 [Jul 17 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
http://www.adlice.com/forum/Website :
http://www.adlice.co...es/roguekiller/Blog :
http://tigzyrk.blogspot.com/Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Dawn [Admin rights]
Mode : Scan -- Date : 07/19/2013 08:19:32
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 4 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : ganukdyxypyx (C:\Documents and Settings\Dawn\ganukdyxypyx.exe [-]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-866049194-2568044671-1873219407-1011\[...]\Run : ganukdyxypyx (C:\Documents and Settings\Dawn\ganukdyxypyx.exe [-]) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[BROK VAL] HKCR\[...]\command : () -> MISSING
¤¤¤ Scheduled tasks : 1 ¤¤¤
[V1][SUSP PATH] At1.job : C:\DOCUME~1\Dawn\APPLIC~1\DSite\UPDATE~1\UPDATE~1.EXE - /Check [x] -> FOUND
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
[Address] SSDT[12] : NtAlertResumeThread @ 0x805D4C0C -> HOOKED (Unknown @ 0x8AFF9B30)
[Address] SSDT[13] : NtAlertThread @ 0x805D4BBC -> HOOKED (Unknown @ 0x8A81EE08)
[Address] SSDT[17] : NtAllocateVirtualMemory @ 0x805A8AEE -> HOOKED (Unknown @ 0x8A8242D8)
[Address] SSDT[31] : NtConnectPort @ 0x805A4604 -> HOOKED (Unknown @ 0x8B0C99A8)
[Address] SSDT[43] : NtCreateMutant @ 0x80617822 -> HOOKED (Unknown @ 0x8A620178)
[Address] SSDT[53] : NtCreateThread @ 0x805D1068 -> HOOKED (Unknown @ 0x8AD99FB0)
[Address] SSDT[83] : NtFreeVirtualMemory @ 0x805B2FE6 -> HOOKED (Unknown @ 0x8A82FB60)
[Address] SSDT[89] : NtImpersonateAnonymousToken @ 0x805F9362 -> HOOKED (Unknown @ 0x8B0D6788)
[Address] SSDT[91] : NtImpersonateThread @ 0x805D7890 -> HOOKED (Unknown @ 0x8ADDF8B0)
[Address] SSDT[108] : NtMapViewOfSection @ 0x805B206E -> HOOKED (Unknown @ 0x8A605278)
[Address] SSDT[114] : NtOpenEvent @ 0x8060F1E0 -> HOOKED (Unknown @ 0x8B182CF0)
[Address] SSDT[123] : NtOpenProcessToken @ 0x805EE030 -> HOOKED (Unknown @ 0x8ADB20A8)
[Address] SSDT[129] : NtOpenThreadToken @ 0x805EE04E -> HOOKED (Unknown @ 0x8A6811E0)
[Address] SSDT[206] : NtResumeThread @ 0x805D4A48 -> HOOKED (Unknown @ 0x8ADEB500)
[Address] SSDT[213] : NtSetContextThread @ 0x805D2C4A -> HOOKED (Unknown @ 0x8AFFFBB0)
[Address] SSDT[228] : NtSetInformationProcess @ 0x805CDED0 -> HOOKED (Unknown @ 0x8AAC6328)
[Address] SSDT[229] : NtSetInformationThread @ 0x805CC154 -> HOOKED (Unknown @ 0x8A678280)
[Address] SSDT[253] : NtSuspendProcess @ 0x805D4B10 -> HOOKED (Unknown @ 0x8A82EBD8)
[Address] SSDT[254] : NtSuspendThread @ 0x805D4982 -> HOOKED (Unknown @ 0x8B09DD90)
[Address] SSDT[257] : NtTerminateProcess @ 0x805D2308 -> HOOKED (Unknown @ 0x8B0D2050)
[Address] SSDT[258] : NtTerminateThread @ 0x805D2502 -> HOOKED (Unknown @ 0x8B06BA18)
[Address] SSDT[267] : NtUnmapViewOfSection @ 0x805B2E7C -> HOOKED (Unknown @ 0x8ADFF0A8)
[Address] SSDT[277] : NtWriteVirtualMemory @ 0x805B4400 -> HOOKED (Unknown @ 0x8A8972D8)
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : Root.MBR ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST3500620AS +++++
--- User ---
[MBR] d7825e316abf122148cf5785ecce63f9
[BSP] 11d467b9f31927f29d49c85858b51038 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 47 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 476890 Mo
Error reading LL1 MBR!
User != LL2 ... KO!
--- LL2 ---
[MBR] 7f50e826c0ef0a2ff3ce6105dd7fb502
[BSP] a8a451c2750507abfb88d59c59f028eb : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 47 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 476890 Mo
Finished : << RKreport[0]_S_07192013_081932.txt >>
RKreport[0]_S_07182013_135452.txt
And the other log:
RogueKiller V8.6.3 [Jul 17 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
http://www.adlice.com/forum/Website :
http://www.adlice.co...es/roguekiller/Blog :
http://tigzyrk.blogspot.com/Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Dawn [Admin rights]
Mode : Shortcuts HJfix -- Date : 07/19/2013 08:20:21
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 0 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 5 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 12 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 3 / Fail 0
Backup: [NOT FOUND]
Drives:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped
[S:] \Device\LanmanRedirector\;S:000000000001717c\Tim1\SHARED -- 0x4 --> Skipped
¤¤¤ Infection : Root.MBR ¤¤¤
Finished : << RKreport[0]_SC_07192013_082021.txt >>
RKreport[0]_D_07192013_081939.txt;RKreport[0]_S_07182013_135452.txt;RKreport[0]_S_07192013_081932.txt
Then I downloaded and ran TDSSKiller:
No Threats were found here is log
08:22:20.0703 8648 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
08:22:21.0265 8648 ============================================================
08:22:21.0265 8648 Current date / time: 2013/07/19 08:22:21.0265
08:22:21.0265 8648 SystemInfo:
08:22:21.0265 8648
08:22:21.0265 8648 OS Version: 5.1.2600 ServicePack: 3.0
08:22:21.0265 8648 Product type: Workstation
08:22:21.0265 8648 ComputerName: GINA1
08:22:21.0265 8648 UserName: Dawn
08:22:21.0265 8648 Windows directory: C:\WINDOWS
08:22:21.0265 8648 System windows directory: C:\WINDOWS
08:22:21.0265 8648 Processor architecture: Intel x86
08:22:21.0265 8648 Number of processors: 4
08:22:21.0265 8648 Page size: 0x1000
08:22:21.0265 8648 Boot type: Normal boot
08:22:21.0265 8648 ============================================================
08:22:23.0046 8648 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
08:22:23.0046 8648 ============================================================
08:22:23.0046 8648 \Device\Harddisk0\DR0:
08:22:23.0046 8648 MBR partitions:
08:22:23.0046 8648 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0x3A36D3BB
08:22:23.0046 8648 ============================================================
08:22:23.0062 8648 Initialize success
08:22:23.0062 8648 ============================================================
08:22:54.0437 11160 ============================================================
08:22:54.0437 11160 Scan started
08:22:54.0437 11160 Mode: Manual; SigCheck; TDLFS;
08:22:54.0437 11160 ============================================================
08:22:54.0437 11160 ================ Scan system memory ========================
08:22:56.0546 11160 System memory - ok
08:22:56.0546 11160 ================ Scan services =============================
08:22:56.0562 11160 Abiosdsk - ok
08:22:56.0562 11160 abp480n5 - ok
08:22:56.0562 11160 ACPI - ok
08:22:56.0562 11160 ACPIEC - ok
08:22:56.0562 11160 AdobeFlashPlayerUpdateSvc - ok
08:22:56.0578 11160 adpu160m - ok
08:22:56.0578 11160 aec - ok
08:22:56.0578 11160 AFD - ok
08:22:56.0578 11160 agp440 - ok
08:22:56.0578 11160 agpCPQ - ok
08:22:56.0578 11160 Aha154x - ok
08:22:56.0578 11160 aic78u2 - ok
08:22:56.0578 11160 aic78xx - ok
08:22:56.0578 11160 Alerter - ok
08:22:56.0593 11160 ALG - ok
08:22:56.0593 11160 AliIde - ok
08:22:56.0593 11160 alim1541 - ok
08:22:56.0593 11160 amdagp - ok
08:22:56.0593 11160 amsint - ok
08:22:56.0593 11160 AppMgmt - ok
08:22:56.0593 11160 ArchiveService - ok
08:22:56.0593 11160 asc - ok
08:22:56.0609 11160 asc3350p - ok
08:22:56.0609 11160 asc3550 - ok
08:22:56.0609 11160 aspnet_state - ok
08:22:56.0609 11160 AsyncMac - ok
08:22:56.0609 11160 atapi - ok
08:22:56.0609 11160 Atdisk - ok
08:22:56.0609 11160 Atmarpc - ok
08:22:56.0625 11160 AudioSrv - ok
08:22:56.0625 11160 audstub - ok
08:22:56.0625 11160 BcmSqlStartupSvc - ok
08:22:56.0625 11160 Beep - ok
08:22:56.0625 11160 BITS - ok
08:22:56.0625 11160 Browser - ok
08:22:56.0625 11160 cbidf - ok
08:22:56.0625 11160 cbidf2k - ok
08:22:56.0640 11160 ccEvtMgr - ok
08:22:56.0640 11160 ccSetMgr - ok
08:22:56.0640 11160 cd20xrnt - ok
08:22:56.0640 11160 Cdaudio - ok
08:22:56.0640 11160 Cdfs - ok
08:22:56.0640 11160 Cdrom - ok
08:22:56.0640 11160 Changer - ok
08:22:56.0640 11160 CiSvc - ok
08:22:56.0640 11160 ClipSrv - ok
08:22:56.0656 11160 clr_optimization_v2.0.50727_32 - ok
08:22:56.0656 11160 clr_optimization_v4.0.30319_32 - ok
08:22:56.0656 11160 CmdIde - ok
08:22:56.0656 11160 COMSysApp - ok
08:22:56.0656 11160 Cpqarray - ok
08:22:56.0656 11160 cpudrv - ok
08:22:56.0656 11160 CryptSvc - ok
08:22:56.0656 11160 dac2w2k - ok
08:22:56.0671 11160 dac960nt - ok
08:22:56.0671 11160 DcomLaunch - ok
08:22:56.0671 11160 Dhcp - ok
08:22:56.0671 11160 Disk - ok
08:22:56.0703 11160 dmadmin - ok
08:22:56.0703 11160 dmboot - ok
08:22:56.0703 11160 dmio - ok
08:22:56.0703 11160 dmload - ok
08:22:56.0703 11160 dmserver - ok
08:22:56.0718 11160 DMusic - ok
08:22:56.0718 11160 Dnscache - ok
08:22:56.0718 11160 Dot3svc - ok
08:22:56.0718 11160 dpti2o - ok
08:22:56.0718 11160 drmkaud - ok
08:22:56.0718 11160 E100B - ok
08:22:56.0718 11160 e1express - ok
08:22:56.0718 11160 EapHost - ok
08:22:56.0734 11160 eeCtrl - ok
08:22:56.0734 11160 EraserUtilRebootDrv - ok
08:22:56.0734 11160 ERSvc - ok
08:22:56.0750 11160 Eventlog - ok
08:22:56.0750 11160 EventSystem - ok
08:22:56.0750 11160 Fastfat - ok
08:22:56.0750 11160 FastUserSwitchingCompatibility - ok
08:22:56.0750 11160 Fax - ok
08:22:56.0750 11160 Fdc - ok
08:22:56.0765 11160 Fips - ok
08:22:56.0765 11160 Flpydisk - ok
08:22:56.0765 11160 FltMgr - ok
08:22:56.0765 11160 FontCache3.0.0.0 - ok
08:22:56.0765 11160 FoxAwdWINFLASH - ok
08:22:56.0765 11160 Fs_Rec - ok
08:22:56.0765 11160 Ftdisk - ok
08:22:56.0765 11160 GoToAssist - ok
08:22:56.0765 11160 Gpc - ok
08:22:56.0781 11160 gupdate - ok
08:22:56.0781 11160 gupdatem - ok
08:22:56.0781 11160 HDAudBus - ok
08:22:56.0781 11160 helpsvc - ok
08:22:56.0781 11160 HidServ - ok
08:22:56.0781 11160 HidUsb - ok
08:22:56.0781 11160 hkmsvc - ok
08:22:56.0781 11160 hpn - ok
08:22:56.0781 11160 HTTP - ok
08:22:56.0796 11160 HTTPFilter - ok
08:22:56.0796 11160 i2omgmt - ok
08:22:56.0796 11160 i2omp - ok
08:22:56.0796 11160 i8042prt - ok
08:22:56.0796 11160 ialm - ok
08:22:56.0796 11160 iaStor - ok
08:22:56.0796 11160 IDriverT - ok
08:22:56.0796 11160 idsvc - ok
08:22:56.0796 11160 Imapi - ok
08:22:56.0812 11160 ImapiService - ok
08:22:56.0812 11160 ini910u - ok
08:22:56.0812 11160 IntcAzAudAddService - ok
08:22:56.0812 11160 Intel® PROSet Monitoring Service - ok
08:22:56.0812 11160 IntelIde - ok
08:22:56.0812 11160 intelppm - ok
08:22:56.0812 11160 Ip6Fw - ok
08:22:56.0812 11160 IpFilterDriver - ok
08:22:56.0828 11160 IpInIp - ok
08:22:56.0828 11160 IpNat - ok
08:22:56.0828 11160 IPSec - ok
08:22:56.0828 11160 IRENUM - ok
08:22:56.0828 11160 isapnp - ok
08:22:56.0828 11160 JavaQuickStarterService - ok
08:22:56.0828 11160 Kbdclass - ok
08:22:56.0828 11160 kbdhid - ok
08:22:56.0843 11160 kmixer - ok
08:22:56.0843 11160 KSecDD - ok
08:22:56.0843 11160 lanmanserver - ok
08:22:56.0843 11160 lanmanworkstation - ok
08:22:56.0843 11160 Lbd - ok
08:22:56.0843 11160 lbrtfdc - ok
08:22:56.0843 11160 LiveUpdate - ok
08:22:56.0843 11160 LmHosts - ok
08:22:56.0859 11160 MDM - ok
08:22:56.0859 11160 Messenger - ok
08:22:56.0859 11160 mnmdd - ok
08:22:56.0859 11160 mnmsrvc - ok
08:22:56.0859 11160 Modem - ok
08:22:56.0859 11160 Mouclass - ok
08:22:56.0859 11160 mouhid - ok
08:22:56.0859 11160 MountMgr - ok
08:22:56.0859 11160 mraid35x - ok
08:22:56.0875 11160 MRxDAV - ok
08:22:56.0875 11160 MRxSmb - ok
08:22:56.0875 11160 MSDTC - ok
08:22:56.0875 11160 Msfs - ok
08:22:56.0875 11160 MSIServer - ok
08:22:56.0875 11160 MSKSSRV - ok
08:22:56.0875 11160 MSPCLOCK - ok
08:22:56.0875 11160 MSPQM - ok
08:22:56.0890 11160 mssmbios - ok
08:22:56.0890 11160 MSSQL$MSSMLBIZ - ok
08:22:56.0890 11160 MSSQLServerADHelper - ok
08:22:56.0890 11160 Mup - ok
08:22:56.0890 11160 NAL - ok
08:22:56.0890 11160 napagent - ok
08:22:56.0890 11160 NAVENG - ok
08:22:56.0890 11160 NAVEX15 - ok
08:22:56.0890 11160 NDIS - ok
08:22:56.0906 11160 NdisTapi - ok
08:22:56.0906 11160 Ndisuio - ok
08:22:56.0906 11160 NdisWan - ok
08:22:56.0906 11160 NDProxy - ok
08:22:56.0906 11160 NetBIOS - ok
08:22:56.0906 11160 NetBT - ok
08:22:56.0906 11160 NetDDE - ok
08:22:56.0906 11160 NetDDEdsdm - ok
08:22:56.0921 11160 Netlogon - ok
08:22:56.0921 11160 Netman - ok
08:22:56.0921 11160 NetTcpPortSharing - ok
08:22:56.0921 11160 Nla - ok
08:22:56.0921 11160 Npfs - ok
08:22:56.0921 11160 Ntfs - ok
08:22:56.0921 11160 NtLmSsp - ok
08:22:56.0921 11160 NtmsSvc - ok
08:22:56.0921 11160 Null - ok
08:22:56.0937 11160 nv - ok
08:22:56.0937 11160 NwlnkFlt - ok
08:22:56.0937 11160 NwlnkFwd - ok
08:22:56.0937 11160 odserv - ok
08:22:56.0937 11160 ose - ok
08:22:56.0937 11160 Parport - ok
08:22:56.0937 11160 PartMgr - ok
08:22:56.0937 11160 ParVdm - ok
08:22:56.0953 11160 PCI - ok
08:22:56.0953 11160 PCIDump - ok
08:22:56.0953 11160 PCIIde - ok
08:22:56.0953 11160 Pcmcia - ok
08:22:56.0953 11160 PDCOMP - ok
08:22:56.0953 11160 PDFRAME - ok
08:22:56.0953 11160 PDRELI - ok
08:22:56.0953 11160 PDRFRAME - ok
08:22:56.0953 11160 perc2 - ok
08:22:56.0968 11160 perc2hib - ok
08:22:56.0968 11160 PinFile - ok
08:22:56.0968 11160 PlugPlay - ok
08:22:56.0968 11160 PolicyAgent - ok
08:22:56.0968 11160 PptpMiniport - ok
08:22:56.0968 11160 ProtectedStorage - ok
08:22:56.0968 11160 PSched - ok
08:22:56.0984 11160 Ptilink - ok
08:22:56.0984 11160 PxHelp20 - ok
08:22:56.0984 11160 ql1080 - ok
08:22:56.0984 11160 Ql10wnt - ok
08:22:56.0984 11160 ql12160 - ok
08:22:56.0984 11160 ql1240 - ok
08:22:56.0984 11160 ql1280 - ok
08:22:56.0984 11160 RasAcd - ok
08:22:56.0984 11160 RasAuto - ok
08:22:57.0000 11160 Rasl2tp - ok
08:22:57.0000 11160 RasMan - ok
08:22:57.0000 11160 RasPppoe - ok
08:22:57.0000 11160 Raspti - ok
08:22:57.0000 11160 Rdbss - ok
08:22:57.0000 11160 RDPCDD - ok
08:22:57.0000 11160 rdpdr - ok
08:22:57.0015 11160 RDPWD - ok
08:22:57.0015 11160 RDSessMgr - ok
08:22:57.0015 11160 redbook - ok
08:22:57.0015 11160 RemoteAccess - ok
08:22:57.0015 11160 RemoteRegistry - ok
08:22:57.0015 11160 RpcLocator - ok
08:22:57.0015 11160 RpcSs - ok
08:22:57.0015 11160 RSVP - ok
08:22:57.0015 11160 SamSs - ok
08:22:57.0031 11160 SBRE - ok
08:22:57.0031 11160 SCardSvr - ok
08:22:57.0031 11160 Schedule - ok
08:22:57.0031 11160 SDDisk2K - ok
08:22:57.0031 11160 SDDToki - ok
08:22:57.0031 11160 SDDVD - ok
08:22:57.0031 11160 SDUPC - ok
08:22:57.0031 11160 Secdrv - ok
08:22:57.0046 11160 seclogon - ok
08:22:57.0046 11160 SENS - ok
08:22:57.0046 11160 serenum - ok
08:22:57.0046 11160 Serial - ok
08:22:57.0046 11160 Sfloppy - ok
08:22:57.0046 11160 SharedAccess - ok
08:22:57.0062 11160 ShellHWDetection - ok
08:22:57.0062 11160 Simbad - ok
08:22:57.0062 11160 sisagp - ok
08:22:57.0062 11160 SmcService - ok
08:22:57.0062 11160 SNAC - ok
08:22:57.0062 11160 Sparrow - ok
08:22:57.0062 11160 SPBBCDrv - ok
08:22:57.0078 11160 splitter - ok
08:22:57.0078 11160 Spooler - ok
08:22:57.0078 11160 sprtsvc_DellSupportCenter - ok
08:22:57.0078 11160 SQLBrowser - ok
08:22:57.0078 11160 SQLWriter - ok
08:22:57.0078 11160 sr - ok
08:22:57.0078 11160 srservice - ok
08:22:57.0078 11160 SRTSP - ok
08:22:57.0078 11160 SRTSPL - ok
08:22:57.0093 11160 SRTSPX - ok
08:22:57.0093 11160 Srv - ok
08:22:57.0093 11160 SSDPSRV - ok
08:22:57.0093 11160 stisvc - ok
08:22:57.0093 11160 stllssvr - ok
08:22:57.0093 11160 swenum - ok
08:22:57.0093 11160 swmidi - ok
08:22:57.0093 11160 SwPrv - ok
08:22:57.0093 11160 Symantec AntiVirus - ok
08:22:57.0109 11160 symc810 - ok
08:22:57.0109 11160 symc8xx - ok
08:22:57.0109 11160 SymEvent - ok
08:22:57.0109 11160 SYMREDRV - ok
08:22:57.0109 11160 SYMTDI - ok
08:22:57.0109 11160 sym_hi - ok
08:22:57.0109 11160 sym_u3 - ok
08:22:57.0109 11160 sysaudio - ok
08:22:57.0125 11160 SysmonLog - ok
08:22:57.0125 11160 TapiSrv - ok
08:22:57.0125 11160 Tcpip - ok
08:22:57.0125 11160 TDPIPE - ok
08:22:57.0125 11160 TDTCP - ok
08:22:57.0125 11160 TermDD - ok
08:22:57.0125 11160 TermService - ok
08:22:57.0125 11160 Themes - ok
08:22:57.0125 11160 TlntSvr - ok
08:22:57.0140 11160 TosIde - ok
08:22:57.0140 11160 TrkWks - ok
08:22:57.0140 11160 Udfs - ok
08:22:57.0140 11160 ultra - ok
08:22:57.0140 11160 Update - ok
08:22:57.0140 11160 upnphost - ok
08:22:57.0140 11160 UPS - ok
08:22:57.0156 11160 usbccgp - ok
08:22:57.0156 11160 usbehci - ok
08:22:57.0156 11160 usbhub - ok
08:22:57.0156 11160 usbprint - ok
08:22:57.0156 11160 USBSTOR - ok
08:22:57.0156 11160 usbuhci - ok
08:22:57.0156 11160 VgaSave - ok
08:22:57.0156 11160 viaagp - ok
08:22:57.0156 11160 ViaIde - ok
08:22:57.0171 11160 VolSnap - ok
08:22:57.0171 11160 VSS - ok
08:22:57.0171 11160 w32time - ok
08:22:57.0171 11160 Wanarp - ok
08:22:57.0171 11160 WDICA - ok
08:22:57.0171 11160 wdmaud - ok
08:22:57.0171 11160 WebClient - ok
08:22:57.0187 11160 WinMagic SecureDoc Service - ok
08:22:57.0187 11160 winmgmt - ok
08:22:57.0187 11160 WmdmPmSN - ok
08:22:57.0187 11160 Wmi - ok
08:22:57.0187 11160 WmiApSrv - ok
08:22:57.0187 11160 WMPNetworkSvc - ok
08:22:57.0187 11160 WPFFontCache_v0400 - ok
08:22:57.0203 11160 wscsvc - ok
08:22:57.0203 11160 WSearch - ok
08:22:57.0203 11160 wuauserv - ok
08:22:57.0203 11160 WudfPf - ok
08:22:57.0203 11160 WudfRd - ok
08:22:57.0203 11160 WudfSvc - ok
08:22:57.0203 11160 WZCSVC - ok
08:22:57.0203 11160 xmlprov - ok
08:22:57.0218 11160 ================ Scan global ===============================
08:22:57.0218 11160 [Global] - ok
08:22:57.0218 11160 ================ Scan MBR ==================================
08:22:57.0234 11160 [ E1ED835465E42A176B4910C2CCA1E9A4 ] \Device\Harddisk0\DR0
08:22:57.0234 11160 Suspicious mbr (Forged): \Device\Harddisk0\DR0
08:22:57.0531 11160 \Device\Harddisk0\DR0 - ok
08:22:57.0531 11160 ================ Scan VBR ==================================
08:22:57.0531 11160 [ E22F4FDC9CF7A873F47DD876419BD773 ] \Device\Harddisk0\DR0\Partition1
08:22:57.0531 11160 \Device\Harddisk0\DR0\Partition1 - ok
08:22:57.0531 11160 ============================================================
08:22:57.0531 11160 Scan finished
08:22:57.0531 11160 ============================================================
08:22:57.0531 6792 Detected object count: 0
08:22:57.0531 6792 Actual detected object count: 0
08:23:38.0703 3544 ============================================================
08:23:38.0703 3544 Scan started
08:23:38.0703 3544 Mode: Manual; SigCheck; TDLFS;
08:23:38.0703 3544 ============================================================
08:23:38.0703 3544 ================ Scan system memory ========================
08:23:39.0171 3544 System memory - ok
08:23:39.0171 3544 ================ Scan services =============================
08:23:39.0187 3544 Abiosdsk - ok
08:23:39.0187 3544 abp480n5 - ok
08:23:39.0187 3544 ACPI - ok
08:23:39.0187 3544 ACPIEC - ok
08:23:39.0187 3544 AdobeFlashPlayerUpdateSvc - ok
08:23:39.0203 3544 adpu160m - ok
08:23:39.0203 3544 aec - ok
08:23:39.0203 3544 AFD - ok
08:23:39.0203 3544 agp440 - ok
08:23:39.0203 3544 agpCPQ - ok
08:23:39.0203 3544 Aha154x - ok
08:23:39.0203 3544 aic78u2 - ok
08:23:39.0203 3544 aic78xx - ok
08:23:39.0203 3544 Alerter - ok
08:23:39.0218 3544 ALG - ok
08:23:39.0218 3544 AliIde - ok
08:23:39.0218 3544 alim1541 - ok
08:23:39.0218 3544 amdagp - ok
08:23:39.0218 3544 amsint - ok
08:23:39.0218 3544 AppMgmt - ok
08:23:39.0218 3544 ArchiveService - ok
08:23:39.0218 3544 asc - ok
08:23:39.0218 3544 asc3350p - ok
08:23:39.0234 3544 asc3550 - ok
08:23:39.0234 3544 aspnet_state - ok
08:23:39.0234 3544 AsyncMac - ok
08:23:39.0234 3544 atapi - ok
08:23:39.0234 3544 Atdisk - ok
08:23:39.0234 3544 Atmarpc - ok
08:23:39.0234 3544 AudioSrv - ok
08:23:39.0250 3544 audstub - ok
08:23:39.0250 3544 BcmSqlStartupSvc - ok
08:23:39.0250 3544 Beep - ok
08:23:39.0250 3544 BITS - ok
08:23:39.0250 3544 Browser - ok
08:23:39.0250 3544 cbidf - ok
08:23:39.0250 3544 cbidf2k - ok
08:23:39.0250 3544 ccEvtMgr - ok
08:23:39.0265 3544 ccSetMgr - ok
08:23:39.0265 3544 cd20xrnt - ok
08:23:39.0265 3544 Cdaudio - ok
08:23:39.0265 3544 Cdfs - ok
08:23:39.0265 3544 Cdrom - ok
08:23:39.0265 3544 Changer - ok
08:23:39.0265 3544 CiSvc - ok
08:23:39.0265 3544 ClipSrv - ok
08:23:39.0265 3544 clr_optimization_v2.0.50727_32 - ok
08:23:39.0281 3544 clr_optimization_v4.0.30319_32 - ok
08:23:39.0281 3544 CmdIde - ok
08:23:39.0281 3544 COMSysApp - ok
08:23:39.0281 3544 Cpqarray - ok
08:23:39.0281 3544 cpudrv - ok
08:23:39.0281 3544 CryptSvc - ok
08:23:39.0281 3544 dac2w2k - ok
08:23:39.0281 3544 dac960nt - ok
08:23:39.0296 3544 DcomLaunch - ok
08:23:39.0296 3544 Dhcp - ok
08:23:39.0296 3544 Disk - ok
08:23:39.0296 3544 dmadmin - ok
08:23:39.0296 3544 dmboot - ok
08:23:39.0296 3544 dmio - ok
08:23:39.0296 3544 dmload - ok
08:23:39.0296 3544 dmserver - ok
08:23:39.0296 3544 DMusic - ok
08:23:39.0312 3544 Dnscache - ok
08:23:39.0312 3544 Dot3svc - ok
08:23:39.0312 3544 dpti2o - ok
08:23:39.0312 3544 drmkaud - ok
08:23:39.0312 3544 E100B - ok
08:23:39.0312 3544 e1express - ok
08:23:39.0312 3544 EapHost - ok
08:23:39.0312 3544 eeCtrl - ok
08:23:39.0312 3544 EraserUtilRebootDrv - ok
08:23:39.0328 3544 ERSvc - ok
08:23:39.0328 3544 Eventlog - ok
08:23:39.0328 3544 EventSystem - ok
08:23:39.0328 3544 Fastfat - ok
08:23:39.0328 3544 FastUserSwitchingCompatibility - ok
08:23:39.0328 3544 Fax - ok
08:23:39.0328 3544 Fdc - ok
08:23:39.0328 3544 Fips - ok
08:23:39.0328 3544 Flpydisk - ok
08:23:39.0343 3544 FltMgr - ok
08:23:39.0343 3544 FontCache3.0.0.0 - ok
08:23:39.0343 3544 FoxAwdWINFLASH - ok
08:23:39.0343 3544 Fs_Rec - ok
08:23:39.0343 3544 Ftdisk - ok
08:23:39.0343 3544 GoToAssist - ok
08:23:39.0343 3544 Gpc - ok
08:23:39.0343 3544 gupdate - ok
08:23:39.0343 3544 gupdatem - ok
08:23:39.0359 3544 HDAudBus - ok
08:23:39.0359 3544 helpsvc - ok
08:23:39.0359 3544 HidServ - ok
08:23:39.0359 3544 HidUsb - ok
08:23:39.0359 3544 hkmsvc - ok
08:23:39.0359 3544 hpn - ok
08:23:39.0359 3544 HTTP - ok
08:23:39.0359 3544 HTTPFilter - ok
08:23:39.0359 3544 i2omgmt - ok
08:23:39.0375 3544 i2omp - ok
08:23:39.0375 3544 i8042prt - ok
08:23:39.0375 3544 ialm - ok
08:23:39.0375 3544 iaStor - ok
08:23:39.0375 3544 IDriverT - ok
08:23:39.0375 3544 idsvc - ok
08:23:39.0375 3544 Imapi - ok
08:23:39.0375 3544 ImapiService - ok
08:23:39.0390 3544 ini910u - ok
08:23:39.0390 3544 IntcAzAudAddService - ok
08:23:39.0390 3544 Intel® PROSet Monitoring Service - ok
08:23:39.0390 3544 IntelIde - ok
08:23:39.0390 3544 intelppm - ok
08:23:39.0390 3544 Ip6Fw - ok
08:23:39.0390 3544 IpFilterDriver - ok
08:23:39.0390 3544 IpInIp - ok
08:23:39.0390 3544 IpNat - ok
08:23:39.0406 3544 IPSec - ok
08:23:39.0406 3544 IRENUM - ok
08:23:39.0406 3544 isapnp - ok
08:23:39.0406 3544 JavaQuickStarterService - ok
08:23:39.0406 3544 Kbdclass - ok
08:23:39.0406 3544 kbdhid - ok
08:23:39.0406 3544 kmixer - ok
08:23:39.0406 3544 KSecDD - ok
08:23:39.0421 3544 lanmanserver - ok
08:23:39.0421 3544 lanmanworkstation - ok
08:23:39.0421 3544 Lbd - ok
08:23:39.0421 3544 lbrtfdc - ok
08:23:39.0421 3544 LiveUpdate - ok
08:23:39.0421 3544 LmHosts - ok
08:23:39.0421 3544 MDM - ok
08:23:39.0421 3544 Messenger - ok
08:23:39.0437 3544 mnmdd - ok
08:23:39.0437 3544 mnmsrvc - ok
08:23:39.0437 3544 Modem - ok
08:23:39.0437 3544 Mouclass - ok
08:23:39.0437 3544 mouhid - ok
08:23:39.0437 3544 MountMgr - ok
08:23:39.0437 3544 mraid35x - ok
08:23:39.0437 3544 MRxDAV - ok
08:23:39.0453 3544 MRxSmb - ok
08:23:39.0453 3544 MSDTC - ok
08:23:39.0453 3544 Msfs - ok
08:23:39.0453 3544 MSIServer - ok
08:23:39.0453 3544 MSKSSRV - ok
08:23:39.0453 3544 MSPCLOCK - ok
08:23:39.0453 3544 MSPQM - ok
08:23:39.0468 3544 mssmbios - ok
08:23:39.0468 3544 MSSQL$MSSMLBIZ - ok
08:23:39.0468 3544 MSSQLServerADHelper - ok
08:23:39.0468 3544 Mup - ok
08:23:39.0468 3544 NAL - ok
08:23:39.0468 3544 napagent - ok
08:23:39.0468 3544 NAVENG - ok
08:23:39.0468 3544 NAVEX15 - ok
08:23:39.0468 3544 NDIS - ok
08:23:39.0484 3544 NdisTapi - ok
08:23:39.0484 3544 Ndisuio - ok
08:23:39.0484 3544 NdisWan - ok
08:23:39.0484 3544 NDProxy - ok
08:23:39.0484 3544 NetBIOS - ok
08:23:39.0484 3544 NetBT - ok
08:23:39.0484 3544 NetDDE - ok
08:23:39.0484 3544 NetDDEdsdm - ok
08:23:39.0484 3544 Netlogon - ok
08:23:39.0500 3544 Netman - ok
08:23:39.0500 3544 NetTcpPortSharing - ok
08:23:39.0500 3544 Nla - ok
08:23:39.0500 3544 Npfs - ok
08:23:39.0500 3544 Ntfs - ok
08:23:39.0500 3544 NtLmSsp - ok
08:23:39.0500 3544 NtmsSvc - ok
08:23:39.0500 3544 Null - ok
08:23:39.0500 3544 nv - ok
08:23:39.0515 3544 NwlnkFlt - ok
08:23:39.0515 3544 NwlnkFwd - ok
08:23:39.0515 3544 odserv - ok
08:23:39.0515 3544 ose - ok
08:23:39.0515 3544 Parport - ok
08:23:39.0515 3544 PartMgr - ok
08:23:39.0515 3544 ParVdm - ok
08:23:39.0515 3544 PCI - ok
08:23:39.0531 3544 PCIDump - ok
08:23:39.0531 3544 PCIIde - ok
08:23:39.0531 3544 Pcmcia - ok
08:23:39.0531 3544 PDCOMP - ok
08:23:39.0531 3544 PDFRAME - ok
08:23:39.0531 3544 PDRELI - ok
08:23:39.0531 3544 PDRFRAME - ok
08:23:39.0531 3544 perc2 - ok
08:23:39.0531 3544 perc2hib - ok
08:23:39.0546 3544 PinFile - ok
08:23:39.0546 3544 PlugPlay - ok
08:23:39.0546 3544 PolicyAgent - ok
08:23:39.0546 3544 PptpMiniport - ok
08:23:39.0546 3544 ProtectedStorage - ok
08:23:39.0546 3544 PSched - ok
08:23:39.0546 3544 Ptilink - ok
08:23:39.0562 3544 PxHelp20 - ok
08:23:39.0562 3544 ql1080 - ok
08:23:39.0562 3544 Ql10wnt - ok
08:23:39.0562 3544 ql12160 - ok
08:23:39.0562 3544 ql1240 - ok
08:23:39.0562 3544 ql1280 - ok
08:23:39.0562 3544 RasAcd - ok
08:23:39.0562 3544 RasAuto - ok
08:23:39.0562 3544 Rasl2tp - ok
08:23:39.0578 3544 RasMan - ok
08:23:39.0578 3544 RasPppoe - ok
08:23:39.0578 3544 Raspti - ok
08:23:39.0578 3544 Rdbss - ok
08:23:39.0578 3544 RDPCDD - ok
08:23:39.0578 3544 rdpdr - ok
08:23:39.0578 3544 RDPWD - ok
08:23:39.0578 3544 RDSessMgr - ok
08:23:39.0593 3544 redbook - ok
08:23:39.0593 3544 RemoteAccess - ok
08:23:39.0593 3544 RemoteRegistry - ok
08:23:39.0593 3544 RpcLocator - ok
08:23:39.0593 3544 RpcSs - ok
08:23:39.0593 3544 RSVP - ok
08:23:39.0593 3544 SamSs - ok
08:23:39.0593 3544 SBRE - ok
08:23:39.0593 3544 SCardSvr - ok
08:23:39.0609 3544 Schedule - ok
08:23:39.0609 3544 SDDisk2K - ok
08:23:39.0609 3544 SDDToki - ok
08:23:39.0609 3544 SDDVD - ok
08:23:39.0609 3544 SDUPC - ok
08:23:39.0609 3544 Secdrv - ok
08:23:39.0609 3544 seclogon - ok
08:23:39.0609 3544 SENS - ok
08:23:39.0625 3544 serenum - ok
08:23:39.0625 3544 Serial - ok
08:23:39.0625 3544 Sfloppy - ok
08:23:39.0625 3544 SharedAccess - ok
08:23:39.0625 3544 ShellHWDetection - ok
08:23:39.0625 3544 Simbad - ok
08:23:39.0640 3544 sisagp - ok
08:23:39.0640 3544 SmcService - ok
08:23:39.0640 3544 SNAC - ok
08:23:39.0640 3544 Sparrow - ok
08:23:39.0640 3544 SPBBCDrv - ok
08:23:39.0640 3544 splitter - ok
08:23:39.0640 3544 Spooler - ok
08:23:39.0656 3544 sprtsvc_DellSupportCenter - ok
08:23:39.0656 3544 SQLBrowser - ok
08:23:39.0656 3544 SQLWriter - ok
08:23:39.0656 3544 sr - ok
08:23:39.0656 3544 srservice - ok
08:23:39.0656 3544 SRTSP - ok
08:23:39.0656 3544 SRTSPL - ok
08:23:39.0656 3544 SRTSPX - ok
08:23:39.0656 3544 Srv - ok
08:23:39.0671 3544 SSDPSRV - ok
08:23:39.0671 3544 stisvc - ok
08:23:39.0671 3544 stllssvr - ok
08:23:39.0671 3544 swenum - ok
08:23:39.0671 3544 swmidi - ok
08:23:39.0671 3544 SwPrv - ok
08:23:39.0671 3544 Symantec AntiVirus - ok
08:23:39.0671 3544 symc810 - ok
08:23:39.0687 3544 symc8xx - ok
08:23:39.0687 3544 SymEvent - ok
08:23:39.0687 3544 SYMREDRV - ok
08:23:39.0687 3544 SYMTDI - ok
08:23:39.0687 3544 sym_hi - ok
08:23:39.0687 3544 sym_u3 - ok
08:23:39.0687 3544 sysaudio - ok
08:23:39.0687 3544 SysmonLog - ok
08:23:39.0687 3544 TapiSrv - ok
08:23:39.0703 3544 Tcpip - ok
08:23:39.0703 3544 TDPIPE - ok
08:23:39.0703 3544 TDTCP - ok
08:23:39.0703 3544 TermDD - ok
08:23:39.0703 3544 TermService - ok
08:23:39.0703 3544 Themes - ok
08:23:39.0703 3544 TlntSvr - ok
08:23:39.0703 3544 TosIde - ok
08:23:39.0703 3544 TrkWks - ok
08:23:39.0718 3544 Udfs - ok
08:23:39.0718 3544 ultra - ok
08:23:39.0718 3544 Update - ok
08:23:39.0718 3544 upnphost - ok
08:23:39.0718 3544 UPS - ok
08:23:39.0718 3544 usbccgp - ok
08:23:39.0718 3544 usbehci - ok
08:23:39.0734 3544 usbhub - ok
08:23:39.0734 3544 usbprint - ok
08:23:39.0734 3544 USBSTOR - ok
08:23:39.0734 3544 usbuhci - ok
08:23:39.0734 3544 VgaSave - ok
08:23:39.0734 3544 viaagp - ok
08:23:39.0734 3544 ViaIde - ok
08:23:39.0734 3544 VolSnap - ok
08:23:39.0734 3544 VSS - ok
08:23:39.0750 3544 w32time - ok
08:23:39.0750 3544 Wanarp - ok
08:23:39.0750 3544 WDICA - ok
08:23:39.0750 3544 wdmaud - ok
08:23:39.0750 3544 WebClient - ok
08:23:39.0750 3544 WinMagic SecureDoc Service - ok
08:23:39.0765 3544 winmgmt - ok
08:23:39.0765 3544 WmdmPmSN - ok
08:23:39.0765 3544 Wmi - ok
08:23:39.0765 3544 WmiApSrv - ok
08:23:39.0765 3544 WMPNetworkSvc - ok
08:23:39.0765 3544 WPFFontCache_v0400 - ok
08:23:39.0781 3544 wscsvc - ok
08:23:39.0781 3544 WSearch - ok
08:23:39.0781 3544 wuauserv - ok
08:23:39.0781 3544 WudfPf - ok
08:23:39.0781 3544 WudfRd - ok
08:23:39.0781 3544 WudfSvc - ok
08:23:39.0781 3544 WZCSVC - ok
08:23:39.0781 3544 xmlprov - ok
08:23:39.0781 3544 ================ Scan global ===============================
08:23:39.0796 3544 [Global] - ok
08:23:39.0796 3544 ================ Scan MBR ==================================
08:23:39.0812 3544 [ E1ED835465E42A176B4910C2CCA1E9A4 ] \Device\Harddisk0\DR0
08:23:39.0812 3544 Suspicious mbr (Forged): \Device\Harddisk0\DR0
08:23:40.0046 3544 \Device\Harddisk0\DR0 - ok
08:23:40.0046 3544 ================ Scan VBR ==================================
08:23:40.0062 3544 [ E22F4FDC9CF7A873F47DD876419BD773 ] \Device\Harddisk0\DR0\Partition1
08:23:40.0062 3544 \Device\Harddisk0\DR0\Partition1 - ok
08:23:40.0062 3544 ============================================================
08:23:40.0062 3544 Scan finished
08:23:40.0062 3544 ============================================================
08:23:40.0062 8140 Detected object count: 0
08:23:40.0062 8140 Actual detected object count: 0
08:25:49.0968 12016 Deinitialize success
Then I ran AdwCleaner again:
# AdwCleaner v2.305 - Logfile created 07/19/2013 at 08:32:13
# Updated 11/07/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Dawn - GINA1
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Dawn\Desktop\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
File Found : C:\END
Folder Found : C:\Documents and Settings\Dawn\Application Data\DSite
Folder Found : C:\Documents and Settings\Gina Dorr\Application Data\adawaretb
Folder Found : C:\Documents and Settings\Gina Dorr\Application Data\blekko
Folder Found : C:\Program Files\Common Files\AVG Secure Search
Folder Found : C:\Program Files\SaveValet
***** [Registry] *****
Key Found : HKCU\Software\Crossrider
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKCU\Software\SocialBit
Key Found : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Google Chrome v28.0.1500.72
File : C:\Documents and Settings\Gina Dorr\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Documents and Settings\Dawn\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [2076 octets] - [18/07/2013 14:02:12]
AdwCleaner[R2].txt - [2136 octets] - [19/07/2013 08:27:36]
AdwCleaner[R3].txt - [2196 octets] - [19/07/2013 08:29:31]
AdwCleaner[R4].txt - [2256 octets] - [19/07/2013 08:30:56]
AdwCleaner[R5].txt - [2187 octets] - [19/07/2013 08:32:13]
########## EOF - C:\AdwCleaner[R5].txt - [2247 octets] ##########
and after hitting delete and rebooting the computer (Please note that Symantec stopped something I think) Here is the S1 report:
# AdwCleaner v2.305 - Logfile created 07/19/2013 at 08:32:34
# Updated 11/07/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Dawn - GINA1
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Dawn\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\END
Folder Deleted : C:\Documents and Settings\Dawn\Application Data\DSite
Folder Deleted : C:\Documents and Settings\Gina Dorr\Application Data\adawaretb
Folder Deleted : C:\Documents and Settings\Gina Dorr\Application Data\blekko
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files\SaveValet
***** [Registry] *****
Key Deleted : HKCU\Software\Crossrider
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\SocialBit
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.18702
[OK] Registry is clean.
-\\ Google Chrome v28.0.1500.72
File : C:\Documents and Settings\Gina Dorr\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
File : C:\Documents and Settings\Dawn\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [2076 octets] - [18/07/2013 14:02:12]
AdwCleaner[R2].txt - [2136 octets] - [19/07/2013 08:27:36]
AdwCleaner[R3].txt - [2196 octets] - [19/07/2013 08:29:31]
AdwCleaner[R4].txt - [2256 octets] - [19/07/2013 08:30:56]
AdwCleaner[R5].txt - [2316 octets] - [19/07/2013 08:32:13]
AdwCleaner[S1].txt - [2275 octets] - [19/07/2013 08:32:34]
########## EOF - C:\AdwCleaner[S1].txt - [2335 octets] ##########
Then I copied what you requested and ran OTL. Here is log:
OTL logfile created on: 7/19/2013 8:42:41 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Dawn\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.24 Gb Total Physical Memory | 2.64 Gb Available Physical Memory | 81.55% Memory free
6.32 Gb Paging File | 5.87 Gb Available in Paging File | 92.86% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.71 Gb Total Space | 318.52 Gb Free Space | 68.39% Space Free | Partition Type: NTFS
Drive S: | 465.72 Gb Total Space | 431.55 Gb Free Space | 92.66% Space Free | Partition Type: NTFS
Computer Name: GINA1 | User Name: Dawn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2013/07/19 08:40:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\OTL (1).exe
PRC - [2013/04/05 03:53:30 | 000,121,600 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\IPROSetMonitor.exe
PRC - [2013/01/11 17:16:44 | 000,530,488 | ---- | M] (Gillware Data Services, LLC) -- C:\Program Files\Gillware Remote Backup\ArchiveService.exe
PRC - [2013/01/02 12:21:37 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2010/08/05 20:11:44 | 001,885,488 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Smc.exe
PRC - [2010/08/05 20:05:52 | 001,459,568 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\SmcGui.exe
PRC - [2010/07/01 18:17:24 | 001,832,072 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PRC - [2010/05/06 18:21:14 | 000,108,392 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/11/27 17:05:30 | 000,641,024 | ---- | M] (WinMagic Inc.) -- C:\Program Files\WinMagic\SecureDoc-NT\SDService.exe
PRC - [2008/10/04 14:58:04 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/11 18:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
========== Modules (No Company Name) ========== MOD - [2013/01/11 17:16:44 | 000,057,400 | ---- | M] () -- C:\Program Files\Gillware Remote Backup\zlib_gw.dll
MOD - [2013/01/11 17:16:34 | 000,031,800 | ---- | M] () -- C:\Program Files\Gillware Remote Backup\ArchiveTypesPS.dll
MOD - [2009/11/27 17:05:12 | 000,018,432 | ---- | M] () -- C:\WINDOWS\system32\SDXML.dll
MOD - [2009/11/27 17:05:02 | 000,527,360 | ---- | M] () -- C:\WINDOWS\system32\sdck.dll
========== Services (SafeList) ========== SRV - [2013/07/11 14:46:38 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/05 03:53:30 | 000,121,600 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\WINDOWS\system32\IPROSetMonitor.exe -- (Intel®
SRV - [2013/01/11 17:16:44 | 000,530,488 | ---- | M] (Gillware Data Services, LLC) [Auto | Running] -- C:\Program Files\Gillware Remote Backup\ArchiveService.exe -- (ArchiveService)
SRV - [2013/01/02 12:21:37 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011/10/31 09:55:49 | 000,013,160 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe -- (GoToAssist)
SRV - [2010/08/05 20:11:44 | 001,885,488 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\Smc.exe -- (SmcService)
SRV - [2010/07/01 18:17:24 | 001,832,072 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- (Symantec AntiVirus)
SRV - [2010/07/01 17:24:02 | 000,357,704 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Symantec AntiVirus\SNAC.EXE -- (SNAC)
SRV - [2010/05/06 18:21:14 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2010/05/06 18:21:14 | 000,108,392 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2010/02/17 11:53:18 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2009/11/27 17:05:30 | 000,641,024 | ---- | M] (WinMagic Inc.) [Auto | Running] -- C:\Program Files\WinMagic\SecureDoc-NT\SDService.exe -- (WinMagic SecureDoc Service)
SRV - [2008/10/04 14:58:04 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter)
SRV - [2008/01/11 18:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\SBREdrv.sys -- (SBRE)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [File_System | Boot | Stopped] -- system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\GINADO~1\LOCALS~1\Temp\_B0E3.tmp\FoxAwdWINFLASH.sys -- (FoxAwdWINFLASH)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/06/17 03:00:00 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20130718.033\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/06/17 03:00:00 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20130718.033\NAVENG.SYS -- (NAVENG)
DRV - [2013/04/05 05:11:04 | 000,031,048 | ---- | M] (Intel Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\iqvw32.sys -- (NAL)
DRV - [2012/08/15 03:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/08/10 03:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2011/06/02 10:08:34 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2011/02/21 10:09:38 | 000,125,488 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/03/08 13:59:14 | 000,320,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2010/03/08 13:59:14 | 000,283,184 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\srtsp.sys -- (SRTSP)
DRV - [2010/03/08 13:59:14 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2009/12/18 16:42:12 | 000,421,424 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2009/11/18 16:07:12 | 000,179,200 | ---- | M] (WinMagic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SDDisk2K.sys -- (SDDisk2K)
DRV - [2009/09/28 11:53:00 | 000,020,224 | ---- | M] (WinMagic, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\PinFile.sys -- (PinFile)
DRV - [2009/09/25 15:57:24 | 000,117,120 | ---- | M] (WinMagic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SDDToki.sys -- (SDDToki)
DRV - [2009/09/25 15:57:24 | 000,075,520 | ---- | M] (WinMagic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SDDVD.sys -- (SDDVD)
DRV - [2009/09/03 17:03:48 | 000,188,080 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI)
DRV - [2009/09/03 17:03:48 | 000,026,416 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV)
DRV - [2009/03/05 14:03:34 | 000,016,512 | ---- | M] (WinMagic Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SDUPC.sys -- (SDUPC)
DRV - [2007/07/16 20:48:54 | 004,403,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?}IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.co...g}&sourceid=ie7 IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1081208
IE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.co...html?channel=usIE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.co...html?channel=usIE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.excite.com/IE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRCIE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRCIE - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
http://www.excite.com/CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Wajam (Enabled) = C:\Documents and Settings\Dawn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\plugins/PriamNPAPI.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 7 (Enabled) = C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Dawn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\Dawn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Documents and Settings\Dawn\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-866049194-2568044671-1873219407-1011\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {123FE8C9-0BDC-4946-A854-DDBA7398CF64}
https://www.fts.newy...ftwebupdate.cab (Reg Error: Key error.)
O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} Reg Error: Key error. (ERPageAddin Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F4D662B4-C5C2-4337-8824-C04913A6029F}: DhcpNameServer = 10.0.0.1
O18 - Protocol\Handler\sds {79E0F14C-9C52-4218-89A7-7C4B0563D121} - C:\Program Files\SHARP\Sharpdesk\ExplorerExtensions.dll (SHARP CORPORATION)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (SDocGina.dll) - C:\WINDOWS\System32\SDocGina.dll (Winmagic Inc.)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\615\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\dell.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{a0ca232a-9564-11e2-a5b9-00219b06268b}\Shell - "" = AutoRun
O33 - MountPoints2\{a0ca232a-9564-11e2-a5b9-00219b06268b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a0ca232a-9564-11e2-a5b9-00219b06268b}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ========== [2013/07/19 08:40:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\OTL (1).exe
[2013/07/19 08:21:52 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Dawn\Desktop\tdsskiller.exe
[2013/07/19 03:00:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT
[2013/07/18 14:04:08 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Dawn\Desktop\aswMBR.exe
[2013/07/18 13:51:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Desktop\RK_Quarantine
[2013/07/18 11:01:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2013/07/18 08:36:07 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Dawn\Recent
[2013/07/17 13:43:29 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2013/07/17 13:43:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Application Data\SystemRequirementsLab
[2013/07/17 11:32:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\Local Settings\Application Data\Deployment
[2013/07/17 11:32:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2013/07/17 11:31:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2013/07/17 11:30:45 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013/07/17 08:10:18 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2013/07/16 13:16:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dawn\My Documents\temp
========== Files - Modified Within 30 Days ========== [2013/07/19 08:40:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dawn\Desktop\OTL (1).exe
[2013/07/19 08:35:32 | 000,001,864 | ---- | M] () -- C:\Documents and Settings\Dawn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/19 08:35:30 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/07/19 08:35:29 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/19 08:35:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/07/19 08:35:09 | 3478,274,048 | -HS- | M] () -- C:\hiberfil.sys
[2013/07/19 08:21:58 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Dawn\Desktop\tdsskiller.exe
[2013/07/19 08:05:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/19 07:34:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/07/19 02:00:00 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - DefaultCritical.job
[2013/07/18 18:30:00 | 000,000,382 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - DefaultHigh.job
[2013/07/18 18:15:00 | 000,000,386 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - DefaultMedium.job
[2013/07/18 15:13:00 | 000,000,308 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - Remote Backup Updater.job
[2013/07/18 15:04:02 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - Upload Event Log.job
[2013/07/18 14:05:42 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\MBR.dat
[2013/07/18 14:04:22 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Dawn\Desktop\aswMBR.exe
[2013/07/18 14:01:42 | 000,662,345 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\adwcleaner.exe
[2013/07/18 13:51:01 | 000,915,968 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\RogueKiller (1).exe
[2013/07/18 11:01:15 | 000,001,846 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/07/18 10:50:53 | 000,005,032 | ---- | M] () -- C:\WINDOWS\wcds.ini
[2013/07/18 10:35:44 | 000,000,105 | ---- | M] () -- C:\prefs.js
[2013/07/18 10:28:56 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2013/07/18 08:29:02 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/17 14:55:00 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2013/07/17 08:10:40 | 000,001,637 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2013/07/16 18:49:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/07/16 18:45:03 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - DefaultLow.job
[2013/07/16 07:24:28 | 000,040,448 | ---- | M] () -- C:\Documents and Settings\Dawn\ganukdyxypyx.exe
[2013/07/15 23:04:03 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\Gillware Remote Backup - Audit.job
[2013/07/12 09:28:24 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\Microsoft Office PowerPoint 2007.lnk
[2013/07/11 16:15:44 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\TempWmicBatchFile.bat
[2013/07/11 14:46:33 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/07/11 14:46:32 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/07/11 07:54:37 | 000,269,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/07/10 16:55:05 | 000,599,624 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/07/10 16:55:05 | 000,121,790 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/07/10 14:57:02 | 000,000,833 | ---- | M] () -- C:\Documents and Settings\Dawn\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2013/07/10 14:57:02 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Dawn\Desktop\Windows Media Player.lnk
========== Files Created - No Company Name ========== [2013/07/18 14:05:42 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\MBR.dat
[2013/07/18 14:01:40 | 000,662,345 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\adwcleaner.exe
[2013/07/18 13:51:00 | 000,915,968 | ---- | C] () -- C:\Documents and Settings\Dawn\Desktop\RogueKiller (1).exe
[2013/07/18 11:01:15 | 000,001,846 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2013/07/18 11:00:16 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/18 11:00:15 | 000,000,878 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/18 10:35:44 | 000,000,105 | ---- | C] () -- C:\prefs.js
[2013/07/17 13:46:34 | 000,001,904 | ---- | C] () -- C:\WINDOWS\System32\SetupBD.din
[2013/07/17 08:10:40 | 000,001,637 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2013/07/16 07:24:54 | 000,040,448 | ---- | C] () -- C:\Documents and Settings\Dawn\ganukdyxypyx.exe
[2013/07/10 14:57:02 | 000,000,833 | ---- | C] () -- C:\Documents and Settings\Dawn\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2013/04/03 12:52:36 | 000,004,608 | ---- | C] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/27 08:01:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\BackupServiceFormView.INI
[2013/03/25 08:59:52 | 000,000,120 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2012/10/10 12:17:07 | 000,000,027 | ---- | C] () -- C:\WINDOWS\FTSL.INI
[2012/02/15 19:05:04 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/09/22 16:28:01 | 000,000,049 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2011/09/15 12:52:11 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/02/06 11:56:26 | 000,000,278 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
========== ZeroAccess Check ========== [2004/08/11 18:21:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 19:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 19:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ========== [2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\New York Life
[2013/06/04 12:13:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG SafeGuard toolbar
[2009/03/10 17:00:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2013/06/04 12:12:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/07/11 07:57:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GFI Software
[2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\New York Life
[2008/12/07 22:58:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2008/12/07 22:58:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCDr
[2013/02/13 13:39:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RICOH
[2010/01/14 12:24:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sharp
[2010/01/14 12:29:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2008/12/07 22:58:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/12/07 22:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/09/21 12:04:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2013/06/04 12:13:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\AVG SafeGuard toolbar
[2013/07/16 07:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Enpiqu
[2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\New York Life
[2013/07/17 13:43:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\SystemRequirementsLab
[2013/04/01 11:16:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Windows Search
[2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\New York Life
[2012/07/06 07:59:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Ad-Aware Antivirus
[2011/12/08 11:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Catalina Marketing Corp
[2009/02/17 14:57:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Centra
[2009/07/31 11:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\eRoom
[2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\New York Life
[2010/10/08 09:56:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Saba
[2009/01/22 16:18:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Sharpdesk
[2009/01/21 13:08:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Windows Desktop Search
[2009/01/21 13:09:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gina Dorr\Application Data\Windows Search
[2012/06/04 09:14:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Ad-Aware Antivirus
[2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\New York Life
[2009/01/21 15:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\New York Life
========== Purity Check ========== ========== Custom Scans ========== ========== Base Services ==========SRV - [2008/04/13 19:12:12 | 000,044,544 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\alg.exe -- (ALG)
SRV - [2008/04/13 19:12:11 | 000,006,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv)
SRV - [2008/04/13 19:12:03 | 000,409,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\qmgr.dll -- (BITS)
SRV - [2012/07/06 08:58:51 | 000,078,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\browser.dll -- (Browser)
SRV - [2008/04/13 19:11:51 | 000,062,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\cryptsvc.dll -- (CryptSvc)
SRV - [2008/04/13 19:11:51 | 000,126,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\dhcpcsvc.dll -- (Dhcp)
SRV - [2009/04/20 12:17:26 | 000,045,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\dnsrslvr.dll -- (Dnscache)
SRV - [2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\services.exe -- (Eventlog)
SRV - [2008/04/13 19:11:52 | 000,033,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\eapsvc.dll -- (EapHost)
SRV - [2009/07/27 18:17:41 | 000,135,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (FastUserSwitchingCompatibility)
SRV - [2008/04/13 19:12:08 | 000,015,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\w3ssl.dll -- (HTTPFilter)
SRV - [2008/04/13 19:11:54 | 000,021,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\hidserv.dll -- (HidServ)
SRV - [2008/04/13 19:12:22 | 000,150,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\imapi.exe -- (ImapiService)
SRV - [2008/04/13 19:12:24 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lsass.exe -- (PolicyAgent)
SRV - [2008/04/13 19:11:52 | 000,023,552 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\WINDOWS\system32\dmserver.dll -- (dmserver)
SRV - [2008/04/13 19:12:17 | 000,224,768 | ---- | M] (Microsoft Corp., Veritas Software) [On_Demand | Stopped] -- C:\WINDOWS\System32\dmadmin.exe -- (dmadmin)
SRV - [2008/04/13 19:12:17 | 000,005,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\System32\dllhost.exe -- (SwPrv)
SRV - [2008/04/13 19:12:24 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\lsass.exe -- (Netlogon)
SRV - [2008/04/13 19:12:01 | 000,198,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\netman.dll -- (Netman)
SRV - [2008/06/20 11:02:47 | 000,245,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\mswsock.dll -- (Nla)
SRV - [2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\services.exe -- (PlugPlay)
SRV - [2010/08/17 08:17:06 | 000,058,880 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\spoolsv.exe -- (Spooler)
SRV - [2008/04/13 19:12:24 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lsass.exe -- (ProtectedStorage)
SRV - [2008/04/13 19:12:03 | 000,088,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\rasauto.dll -- (RasAuto)
SRV - [2008/04/13 19:12:03 | 000,186,368 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\rasmans.dll -- (RasMan)
SRV - [2009/02/09 07:10:48 | 000,401,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\rpcss.dll -- (RpcSs)
SRV - [2008/04/13 19:12:02 | 000,435,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\ntmssvc.dll -- (NtmsSvc)
SRV - [2008/04/13 19:12:05 | 000,018,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\seclogon.dll -- (seclogon)
SRV - [2008/04/13 19:12:24 | 000,013,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lsass.exe -- (SamSs)
SRV - [2008/04/13 19:12:10 | 000,080,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wscsvc.dll -- (wscsvc)
SRV - [2010/08/27 00:57:43 | 000,099,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\srvsvc.dll -- (lanmanserver)
SRV - [2009/07/27 18:17:41 | 000,135,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (ShellHWDetection)
SRV - [2008/04/13 19:12:07 | 000,171,008 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\srsvc.dll -- (srservice)
SRV - [2008/04/13 19:12:05 | 000,192,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\schedsvc.dll -- (Schedule)
SRV - [2008/04/13 19:11:56 | 000,013,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\lmhsvc.dll -- (LmHosts)
SRV - [2008/04/13 19:12:07 | 000,249,856 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\tapisrv.dll -- (TapiSrv)
SRV - [2008/04/13 19:12:07 | 000,295,424 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\system32\termsrv.dll -- (TermService)
SRV - [2009/07/27 18:17:41 | 000,135,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\shsvcs.dll -- (Themes)
SRV - [2008/04/13 19:12:38 | 000,289,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\vssvc.exe -- (VSS)
SRV - [2008/04/13 19:11:50 | 000,042,496 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\audiosrv.dll -- (AudioSrv)
SRV - [2008/04/13 19:11:55 | 000,331,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\ipnathlp.dll -- (SharedAccess)
SRV - [2008/04/13 19:12:08 | 000,333,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\wiaservc.dll -- (stisvc)
SRV - [2008/04/13 19:12:28 | 000,078,848 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\WINDOWS\System32\msiexec.exe -- (MSIServer)
SRV - [2008/04/13 19:12:09 | 000,144,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wbem\wmisvc.dll -- (winmgmt)
SRV - [2009/02/09 07:10:48 | 000,617,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\advapi32.dll -- (Wmi)
SRV - [2008/04/13 19:11:52 | 000,132,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\dot3svc.dll -- (Dot3svc)
SRV - [2008/04/13 19:12:11 | 000,483,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wzcsvc.dll -- (WZCSVC)
SRV - [2009/06/10 01:14:49 | 000,132,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wkssvc.dll -- (lanmanworkstation)
< %SYSTEMDRIVE%\*.exe >[1999/06/25 10:55:30 | 000,149,504 | ---- | M] () -- C:\UNWISE.EXE
[2009/07/17 12:15:13 | 004,523,520 | ---- | M] () -- C:\WDSync_v7_1_020.exe
< MD5 for: EXPLORER.EXE >[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\i386\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 01:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\explorer.exe
< MD5 for: REGEDIT.EXE >[2008/04/13 19:12:32 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=058710B720282CA82B909912D3EF28DB -- C:\WINDOWS\regedit.exe
[2008/04/13 19:12:32 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=058710B720282CA82B909912D3EF28DB -- C:\WINDOWS\regedit.exe
[2008/04/13 19:12:32 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=058710B720282CA82B909912D3EF28DB -- C:\WINDOWS\ServicePackFiles\i386\regedit.exe
[2008/04/13 19:12:32 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=058710B720282CA82B909912D3EF28DB -- C:\WINDOWS\ServicePackFiles\i386\regedit.exe
[2004/08/04 06:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=783AFC80383C176B22DBF8333343992D -- C:\i386\REGEDIT.EXE
[2004/08/04 06:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=783AFC80383C176B22DBF8333343992D -- C:\i386\REGEDIT.EXE
[2004/08/04 06:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=783AFC80383C176B22DBF8333343992D -- C:\WINDOWS\$NtServicePackUninstall$\regedit.exe
[2004/08/04 06:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=783AFC80383C176B22DBF8333343992D -- C:\WINDOWS\$NtServicePackUninstall$\regedit.exe
[2004/08/04 06:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=783AFC80383C176B22DBF8333343992D -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\regedit.exe
[2004/08/04 06:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) MD5=783AFC80383C176B22DBF8333343992D -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\regedit.exe
< MD5 for: SERVICES >[2004/08/04 06:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\i386\services
[2004/08/04 06:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES.CFG >[2013/05/10 02:57:30 | 000,558,879 | ---- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.CSS >[2011/09/16 19:47:38 | 000,000,093 | ---- | M] () MD5=F15FB82C578490B209442B8C1D5076CC -- C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
[2011/09/16 19:47:38 | 000,000,093 | ---- | M] () MD5=F15FB82C578490B209442B8C1D5076CC -- C:\Documents and Settings\Dawn May 2012 Restore\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
< MD5 for: SERVICES.EXE >[2009/02/06 06:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 19:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 05:22:21 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe
[2004/08/04 06:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\i386\services.exe
[2004/08/04 06:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\services.exe
< MD5 for: SERVICES.INI >[2011/09/16 19:47:38 | 000,000,012 | ---- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 -- C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
[2011/09/16 19:47:38 | 000,000,012 | ---- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 -- C:\Documents and Settings\Dawn May 2012 Restore\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
< MD5 for: SERVICES.LNK >[2009/04/02 18:15:46 | 000,001,602 | ---- | M] () MD5=53C6322711BF72BA10A1FAD83567C3AF -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
[2004/08/11 18:15:06 | 000,001,506 | ---- | M] () MD5=C04255E822F6017251E30CE1481EB38E -- C:\Documents and Settings\Dawn May 2012 Restore\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MOCHIADS.COM.SOL >[2012/01/13 14:29:04 | 000,000,351 | ---- | M] () MD5=4DF5734FFC8C89FB609F70719934A943 -- C:\Documents and Settings\Dawn May 2012 Restore\My Documents\Application Data\Macromedia\Flash Player\#SharedObjects\7HY3SE2W\mochiads.com\services.mochiads.com.sol
< MD5 for: SERVICES.MSC >[2004/08/04 06:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\i386\services.msc
[2004/08/04 06:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS\system32\services.msc
< MD5 for: SVCHOST.EXE >[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- C:\WINDOWS\system32\svchost.exe
[2004/08/04 06:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\i386\svchost.exe
[2004/08/04 06:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2004/08/04 06:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >[2004/08/04 06:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\i386\userinit.exe
[2004/08/04 06:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004/08/04 06:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2011/11/15 13:28:33 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2004/08/04 06:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\i386\winlogon.exe
[2004/08/04 06:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/04 06:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\backup\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
< MD5 for: WINSOCK.DLL >[2004/08/04 06:00:00 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\i386\winsock.dll
[2004/08/04 06:00:00 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\WINDOWS\system32\winsock.dll
< dir "%systemdrive%\*" /S /A:L /C > Volume in drive C has no label.
Volume Serial Number is A42C-9027
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
07/10/2013 04:48 PM <JUNCTION> 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
07/10/2013 04:48 PM <JUNCTION> 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices
07/10/2013 04:55 PM <JUNCTION> v4.0_4.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler
01/12/2013 04:21 AM <JUNCTION> v4.0_4.0.0.0__31bf3856ad364e35
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
4 Dir(s) 341,965,529,088 bytes free
========== Drive Information ========== Physical Drives
---------------
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: ST3500620AS
Partitions: 2
Status: OK
Status Info: 0
Partitions
---------------
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 47.00MB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 49351680
Hidden sectors: 0
< type c:\diskreport.txt /c >Microsoft DiskPart version 5.1.3565
Copyright © 1999-2003 Microsoft Corporation.
On computer: GINA1
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
Volume 0 D DVD-ROM 0 B
Volume 1 C NTFS Partition 466 GB Healthy System
< End of report >
I think I did everything you asked...and it appears to be running better. I connected it to the internet yesterday and the provider sent me an email this morning telling me it appeared to be running fine - no spam being sent.
Let me know if there is anything else you want me to do.
Thanks!
Roxie