Hi oldrailroadgeek,
No need to "attach" logs, paste them directly to the forum. I'm pasting yours directly to the forum so everything is in one place saves a few steps. I'll take a look and get back to you. At a quick glance there is no malware in your log just a few left overs, and certainly nothing to do with any E-Mail and or virus...
Re-run OTL once more so we can re-create the
Extras .txt log, before you run the scan I need you to do this--> under the
Extra Registry section please put a check mark in
"All" then hit
Runscan, when OTL is done scanning 2 logs will be generated, the first log will pop up in front of you, the second log will be minimized to the task bar down by the clock area, called
Extras .txt please post that log. Really don't need to post the first one as we already have that one.
I'm in training and will need to report to my instructor before any file movement is conducted, so a small delay in response is possible.OTL logfile created on: 11/20/2013 9:30:59 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Sid Bailey\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.37 Gb Total Physical Memory | 0.60 Gb Available Physical Memory | 43.93% Memory free
5.22 Gb Paging File | 4.37 Gb Available in Paging File | 83.70% Paging File free
Paging file location(s): C:\pagefile.sys 4095 4095 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.04 Gb Total Space | 112.49 Gb Free Space | 80.90% Space Free | Partition Type: NTFS
Computer Name: YOUR-0C81E70C58 | User Name: Sid Bailey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2013/11/07 15:22:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sid Bailey\Desktop\OTL.exe
PRC - [2013/10/25 23:45:12 | 002,445,816 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2013/10/25 23:07:48 | 000,073,832 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2013/10/15 05:38:52 | 000,050,704 | ---- | M] (Check Point Software Technologies, Ltd.) -- C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
PRC - [2013/09/06 12:30:16 | 000,273,296 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
PRC - [2013/08/27 16:16:14 | 001,028,896 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
PRC - [2013/08/27 16:15:38 | 002,155,296 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/04/04 13:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 13:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 13:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/04/03 12:33:00 | 000,940,168 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Quick Menu\CNQMSWCS.EXE
PRC - [2012/04/03 12:27:16 | 001,087,608 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
PRC - [2012/04/03 12:26:14 | 001,273,448 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
PRC - [2012/01/17 16:21:53 | 000,012,800 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2011/12/07 17:31:00 | 000,303,360 | ---- | M] () -- C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe
PRC - [2011/04/19 16:39:30 | 000,935,744 | ---- | M] (SonicWALL, Inc.) -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mantispm.exe
PRC - [2010/03/11 11:02:06 | 000,042,512 | ---- | M] (Pro Softnet Corp.) -- C:\Program Files\ZoneAlarmBackup\ZABackupBackground.exe
PRC - [2010/03/11 11:01:32 | 000,149,008 | ---- | M] (Pro Softnet Corporation) -- C:\Program Files\ZoneAlarmBackup\ZABackup Service.exe
PRC - [2010/03/11 11:00:50 | 002,000,400 | ---- | M] (Pro Softnet Corp.) -- C:\Program Files\ZoneAlarmBackup\ZABackupTray.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2013/10/17 05:33:48 | 000,065,936 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\Community.CsharpSqlite.SQLiteClient.dll
MOD - [2013/10/10 02:37:14 | 000,978,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\1b7600e7fe5e152f21ba6d79f3c0c3b6\System.Configuration.ni.dll
MOD - [2013/10/10 02:34:14 | 002,295,808 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\83cd19e8259b8dd9435c1c3f8f31b60c\System.Core.ni.dll
MOD - [2013/10/10 02:11:12 | 002,933,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2013/09/22 02:08:48 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\9b6e07791d63f180b725744b37edfd39\System.Runtime.Remoting.ni.dll
MOD - [2013/08/16 02:29:00 | 001,781,760 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\04326608ac9ad05c2a1e8bd46a068a91\System.Xaml.ni.dll
MOD - [2013/08/16 02:24:04 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\21071fcc838660d96f10920c4c3cd206\System.Xml.ni.dll
MOD - [2013/08/16 02:23:56 | 000,980,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\363b05dd092178671e56531a9c4999b6\System.Configuration.ni.dll
MOD - [2013/08/16 02:23:51 | 017,671,168 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\b72152b4330e2f009a868aa16c47acb4\PresentationFramework.ni.dll
MOD - [2013/08/16 02:23:22 | 011,106,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\ed36e9ff00f2fb0f33f1c08b20a7afc0\PresentationCore.ni.dll
MOD - [2013/08/16 02:23:00 | 003,798,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\ff4ecc058f27a9c36136e5d38e43fb59\WindowsBase.ni.dll
MOD - [2013/08/16 02:22:53 | 000,656,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\942a5e3ee871f5f4a323d95505f9667c\PresentationFramework.Luna.ni.dll
MOD - [2013/08/16 02:22:41 | 013,137,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f28df9c2988724883cf19532d7f9f151\System.Windows.Forms.ni.dll
MOD - [2013/08/16 02:22:24 | 001,652,736 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\2ff57b810eb920860469184dd683cb8a\System.Drawing.ni.dll
MOD - [2013/08/16 02:22:10 | 007,054,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\a2b1103ad3d9f329e0c9164994137c81\System.Core.ni.dll
MOD - [2013/08/16 02:21:55 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\3ff4657a86a0e14b4be577969e0ec762\System.ni.dll
MOD - [2013/08/16 02:21:41 | 014,407,680 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\52f4f785f7cf45a64606a8e13c8cf04c\mscorlib.ni.dll
MOD - [2013/08/15 02:32:40 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\15fd2d2f4e709154b44187a6915db244\System.ServiceProcess.ni.dll
MOD - [2013/08/15 02:32:25 | 000,141,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\cab8d2f8933390bab32c35c5c6a479bd\System.Configuration.Install.ni.dll
MOD - [2013/08/15 02:21:14 | 005,462,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f93600ac836b9140e1df13bb0f6bfccf\System.Xml.ni.dll
MOD - [2013/08/15 02:20:20 | 006,616,576 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\5013900c3c0610c88059fcb8f1f4acb4\System.Data.ni.dll
MOD - [2013/08/15 02:05:00 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\10df39542df7d48462451fc39bce8418\System.ni.dll
MOD - [2013/07/13 02:14:20 | 011,497,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\b14359470744c840c59fbe4e58034fd6\mscorlib.ni.dll
MOD - [2013/01/02 01:49:10 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2012/11/19 19:15:22 | 000,074,928 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\fde\fde_api.dll
MOD - [2011/12/07 17:31:00 | 000,303,360 | ---- | M] () -- C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe
MOD - [2011/08/18 10:22:38 | 000,323,584 | ---- | M] () -- C:\Program Files\NETGEAR\WNA3100\WifiLib.dll
MOD - [2011/04/19 16:40:06 | 000,088,896 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\crsrpt.dll
MOD - [2011/04/19 16:39:34 | 000,013,120 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\MlfHook.dll
MOD - [2011/04/19 16:39:32 | 000,290,112 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mtdsdk.dll
MOD - [2011/04/19 16:39:24 | 000,222,016 | ---- | M] () -- C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\resources\mbzaenu.dll
MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
MOD - [2008/04/13 19:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 19:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
========== Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2013/11/19 20:50:14 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/10/30 09:39:02 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/10/25 23:45:12 | 002,445,816 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2013/10/15 05:38:52 | 000,050,704 | ---- | M] (Check Point Software Technologies, Ltd.) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe -- (ZAPrivacyService)
SRV - [2013/09/06 12:29:38 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe -- (McComponentHostService)
SRV - [2013/08/27 16:15:38 | 002,155,296 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/04/04 13:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 13:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/01/17 16:21:53 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2011/12/07 17:31:00 | 000,303,360 | ---- | M] () [Auto | Running] -- C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe -- (WSWNA3100)
SRV - [2010/03/11 11:01:32 | 000,149,008 | ---- | M] (Pro Softnet Corporation) [Auto | Running] -- C:\Program Files\ZoneAlarmBackup\ZABackup Service.exe -- (ZoneAlarmBackup Service)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | Disabled | Stop_Pending] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/10/25 23:07:48 | 000,529,128 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant)
DRV - [2013/10/08 05:48:30 | 000,482,912 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2013/09/10 22:18:17 | 000,013,464 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SWDUMon.sys -- (SWDUMon)
DRV - [2013/07/17 02:02:10 | 000,144,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stop_Pending] -- C:\WINDOWS\system32\drivers\kneps.sys -- (kneps)
DRV - [2013/07/17 02:02:08 | 000,135,776 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (KL1)
DRV - [2013/04/04 13:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/11/15 21:06:08 | 000,043,608 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kltdi.sys -- (kltdi)
DRV - [2012/11/15 21:06:06 | 000,035,672 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2012/11/02 13:17:16 | 000,027,056 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2012/01/17 16:21:53 | 001,203,808 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2012/01/17 16:20:05 | 004,800,000 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2011/12/12 16:43:00 | 001,034,240 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bcmwlhigh5.sys -- (BCMH43XX)
DRV - [2010/10/14 17:08:38 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2010/02/03 10:21:56 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2008/01/29 12:37:48 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2008/01/29 12:37:46 | 000,054,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/01/25 20:01:06 | 000,132,096 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
DRV - [2006/11/10 14:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2001/08/17 08:49:32 | 000,019,968 | ---- | M] (Macronix International Co., Ltd. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mxnic.sys -- (mxnic)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = ${SEARCH_URL_IE7}
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRCIE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comIE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{5C5360F5-5F2D-4E4A-84B1-ABD053DB35A9}: "URL" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40zonealarm.com:1.6.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/11/30 18:49:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2012/01/19 16:36:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Sid Bailey\Application Data\Mozilla\Extensions
[2013/11/06 11:08:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Sid Bailey\Application Data\Mozilla\Firefox\Profiles\x8d4t8u3.default-1381283562814\extensions
[2013/11/06 11:08:37 | 000,000,000 | ---D | M] (zonealarm.com) -- C:\Documents and Settings\Sid Bailey\Application Data\Mozilla\Firefox\Profiles\x8d4t8u3.default-1381283562814\extensions\
[email protected][2013/03/21 02:15:42 | 000,007,919 | ---- | M] () (No name found) -- C:\Documents and Settings\Sid Bailey\Application Data\Mozilla\Firefox\Profiles\x8d4t8u3.default-1381283562814\extensions\
[email protected]\content\Abine\chrome\content\ff\view_expiry.js
[2013/10/30 09:38:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions(2)
[2013/10/30 09:38:46 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions(2)\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
[2013/10/30 09:38:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/10/30 09:39:05 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ========== CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
http://www.google.comCHR - Extension: No name found = C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: No name found = C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: No name found = C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: No name found = C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: No name found = C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2004/08/10 14:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Zonealarm Helper Object) - {2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\1.8.22.0\bh\zonealarm.dll (Check Point Software Technologies LTD)
O2 - BHO: (no name) - {2CEBF6C7-2B40-469B-B5D5-CD3F3676C3C4} - No CLSID value found.
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59} - C:\Program Files\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmTlbr.dll (Check Point Software Technologies LTD)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ISW] File not found
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Nvtmru] C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [ZoneAlarm Backup Startup] C:\Program Files\ZoneAlarmBackup\ZABackupStartup.exe (Pro Softnet Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Sid Bailey\Start Menu\Programs\Startup\ZoneAlarm Backup Tray.lnk = C:\Program Files\ZoneAlarmBackup\ZABackupReg2ini.exe (Pro Softnet Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe (Hewlett-Packard)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.mi...b?1365637437500 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4 209.55.27.13
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BBDECE2E-1A23-498B-A6C9-C37C6CEEDAD4}: DhcpNameServer = 8.8.8.8 8.8.4.4 209.55.27.13
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/09 20:13:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2013/11/18 23:41:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2013/11/17 19:08:12 | 000,360,775 | ---- | C] (Farbar) -- C:\Documents and Settings\Sid Bailey\Desktop\FSS.exe
[2013/11/17 10:52:57 | 000,760,937 | ---- | C] (Farbar) -- C:\Documents and Settings\Sid Bailey\Desktop\MiniToolBox.exe
[2013/11/15 12:27:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Auslogics
[2013/11/15 12:27:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2013/11/15 12:27:39 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2013/11/15 11:12:57 | 005,647,256 | ---- | C] (Auslogics Labs Pty Ltd ) -- C:\Documents and Settings\Sid Bailey\Desktop\disk-defrag-setup.exe
[2013/11/15 11:11:47 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Documents and Settings\Sid Bailey\Desktop\ATF-Cleaner.exe
[2013/11/14 15:18:44 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamregps.dll
[2013/11/14 15:18:32 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\s3legacy.dll
[2013/11/14 15:18:16 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetsloc.dll
[2013/11/14 15:18:16 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.exe
[2013/11/14 15:18:15 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisui.dll
[2013/11/14 15:18:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstap.dll
[2013/11/14 15:18:13 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisreset.exe
[2013/11/14 15:18:12 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2013/11/14 15:18:01 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certmap.ocx
[2013/11/13 22:15:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sid Bailey\Desktop\Autoruns
[2013/11/11 10:56:44 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sid Bailey\Desktop\TFC.exe
[2013/11/10 18:46:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013/11/10 18:42:20 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/11/10 18:34:48 | 001,034,531 | ---- | C] (Thisisu) -- C:\Documents and Settings\Sid Bailey\Desktop\JRT.exe
[2013/11/07 15:22:34 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sid Bailey\Desktop\OTL.exe
[2013/11/06 10:50:10 | 000,144,352 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\kneps.sys
[2013/11/06 10:50:08 | 000,043,608 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\kltdi.sys
[2013/11/06 10:49:53 | 000,035,672 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\klim5.sys
[2013/11/06 10:48:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Check Point
[2013/10/30 09:38:45 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/10/29 23:29:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sid Bailey\My Documents\Copy of Downloads
[2013/10/29 22:45:26 | 000,229,376 | ---- | C] (Pro-SoftNet Corporation, USA) -- C:\WINDOWS\System32\IDrLocale.dll
[2013/10/29 22:45:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sid Bailey\Start Menu\Programs\ZoneAlarmBackup
[2013/10/29 22:45:22 | 000,526,184 | ---- | C] (Xceed Software Inc (450) 442-2626
[email protected] www.xceedsoft.com) -- C:\WINDOWS\System32\XceedCry.dll
[2013/10/29 22:45:21 | 001,245,184 | ---- | C] (Pro Soft Net Corporation) -- C:\WINDOWS\System32\ZABackupService.dll
[2013/10/29 22:45:21 | 000,135,168 | ---- | C] (Pro-Softnet Corporation) -- C:\WINDOWS\System32\LogMail.dll
[2013/10/29 22:45:21 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Msstdfmt.dll
[2013/10/29 22:45:21 | 000,109,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSWINSCK.OCX
[2013/10/29 22:45:20 | 001,388,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSVBVM60.DLL
[2013/10/29 22:45:20 | 000,644,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSCOMCT2.OCX
[2013/10/29 22:45:20 | 000,608,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\COMCTL32.OCX
[2013/10/29 22:45:20 | 000,164,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\COMCT232.OCX
[2013/10/29 22:45:20 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\COMDLG32.OCX
[2013/10/29 22:45:20 | 000,086,016 | ---- | C] (Streamnet India) -- C:\WINDOWS\System32\IBwinUtil.ocx
[2013/10/29 22:45:20 | 000,026,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\FM20ENU.DLL
[2013/10/29 22:45:20 | 000,024,576 | ---- | C] (Streamnet India) -- C:\WINDOWS\System32\IBcalendarser.ocx
[2013/10/29 22:45:19 | 001,129,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\FM20.DLL
[2013/10/29 22:45:19 | 000,143,360 | ---- | C] (Herman & Associates) -- C:\WINDOWS\System32\HLButton.ocx
[2013/10/29 22:45:19 | 000,028,672 | ---- | C] (Checks Unlimited) -- C:\WINDOWS\System32\Disable_X.ocx
[2013/10/29 22:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\ZoneAlarmBackup
[2013/10/25 23:07:48 | 000,529,128 | ---- | C] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys
========== Files - Modified Within 30 Days ========== [2013/11/20 22:03:10 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/11/20 20:40:08 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2013/11/20 19:49:38 | 000,000,697 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\PCTuneUp.config
[2013/11/20 14:00:07 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2013/11/20 12:02:03 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2013/11/20 10:10:04 | 000,000,464 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2013/11/20 08:46:47 | 000,000,974 | ---- | M] () -- C:\WINDOWS\MVPBR.INI
[2013/11/19 20:50:14 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/11/19 20:50:14 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/11/19 13:48:28 | 000,020,480 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\mob check 2013-11.xlr
[2013/11/19 13:48:28 | 000,013,834 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Application Data\wklnhst.dat
[2013/11/18 23:54:44 | 000,502,772 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/11/18 23:54:44 | 000,088,296 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/11/18 23:50:19 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/11/18 23:50:17 | 1474,809,856 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/18 23:41:22 | 000,001,769 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/11/18 23:41:21 | 000,001,775 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2013/11/18 20:00:07 | 000,012,800 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Memory Tree 2013 Orders.wps
[2013/11/18 15:42:44 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\mob check 2013-10.xlr
[2013/11/18 01:06:12 | 000,000,018 | ---- | M] () -- C:\UserName.ini
[2013/11/17 19:08:13 | 000,360,775 | ---- | M] (Farbar) -- C:\Documents and Settings\Sid Bailey\Desktop\FSS.exe
[2013/11/17 10:52:57 | 000,760,937 | ---- | M] (Farbar) -- C:\Documents and Settings\Sid Bailey\Desktop\MiniToolBox.exe
[2013/11/16 10:52:28 | 000,040,448 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\MOB Blood Press.xlr
[2013/11/15 12:27:42 | 000,000,822 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\Auslogics DiskDefrag.lnk
[2013/11/15 11:12:59 | 005,647,256 | ---- | M] (Auslogics Labs Pty Ltd ) -- C:\Documents and Settings\Sid Bailey\Desktop\disk-defrag-setup.exe
[2013/11/15 11:11:47 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Documents and Settings\Sid Bailey\Desktop\ATF-Cleaner.exe
[2013/11/14 20:46:41 | 000,017,920 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 11-17-2013.wps
[2013/11/13 22:16:19 | 000,000,852 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\Shortcut to autoruns.exe.lnk
[2013/11/13 22:06:18 | 000,073,732 | ---- | M] () -- C:\WINDOWS\System32\perfmon.msc
[2013/11/13 21:58:23 | 000,550,371 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\Autoruns.zip
[2013/11/13 03:05:08 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/11/12 21:15:15 | 000,051,200 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Beginning of Iaeger.wps
[2013/11/12 08:31:25 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sid Bailey\Desktop\TFC.exe
[2013/11/10 18:38:29 | 001,073,262 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\adwcleaner(1).exe
[2013/11/10 18:34:48 | 001,034,531 | ---- | M] (Thisisu) -- C:\Documents and Settings\Sid Bailey\Desktop\JRT.exe
[2013/11/10 13:20:50 | 000,000,967 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\Shortcut to JavaRa.lnk
[2013/11/08 12:32:29 | 000,015,872 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\ssb deposit ticket.wps
[2013/11/08 10:54:59 | 000,015,360 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 11-10-2013.wps
[2013/11/07 16:19:44 | 000,000,540 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\checkup.lnk
[2013/11/07 15:29:00 | 000,891,184 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\SecurityCheck.exe
[2013/11/07 15:22:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sid Bailey\Desktop\OTL.exe
[2013/11/06 10:57:21 | 000,418,108 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2013/11/06 10:48:51 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoneAlarm Security.lnk
[2013/11/01 13:53:10 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Roast Cornish Hens.wdb
[2013/11/01 08:26:50 | 000,014,336 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 11-03-2013.wps
[2013/10/29 22:45:24 | 000,001,676 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Application Data\Microsoft\Internet Explorer\Quick Launch\ZoneAlarmBackup.lnk
[2013/10/29 22:45:24 | 000,001,670 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Start Menu\Programs\Startup\ZoneAlarm Backup Tray.lnk
[2013/10/29 22:45:24 | 000,001,658 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\Desktop\ZoneAlarm Backup Powered by IDrive.lnk
[2013/10/29 22:30:55 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Default.rdp
[2013/10/25 23:07:48 | 000,529,128 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys
[2013/10/24 12:18:18 | 000,013,824 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 10-27-2013.wps
[2013/10/24 10:49:04 | 000,013,312 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\IUMC Check Reg 10-2013.xlr
[2013/10/24 10:47:48 | 000,013,312 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\IUMC Collect Report 11-2013.xlr
[2013/10/24 10:09:57 | 000,013,312 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\IUMC Collect Report 10-13.xlr
[2013/10/22 22:16:12 | 000,010,752 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD 1956-1957 T1.xlr
[2013/10/22 21:23:46 | 000,010,752 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD1954-1955 T1.xlr
[2013/10/22 21:23:14 | 000,010,752 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD 1954-1955 T2.xlr
[2013/10/22 21:20:38 | 000,010,752 | ---- | M] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD 1954-1955.xlr
[2013/10/22 20:45:17 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
========== Files Created - No Company Name ========== [2013/11/18 19:48:43 | 000,012,800 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Memory Tree 2013 Orders.wps
[2013/11/16 11:08:39 | 000,020,480 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\mob check 2013-11.xlr
[2013/11/15 12:27:41 | 000,000,822 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\Auslogics DiskDefrag.lnk
[2013/11/14 20:42:47 | 000,017,920 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 11-17-2013.wps
[2013/11/13 22:16:19 | 000,000,852 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\Shortcut to autoruns.exe.lnk
[2013/11/13 21:58:20 | 000,550,371 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\Autoruns.zip
[2013/11/11 01:05:56 | 000,000,018 | ---- | C] () -- C:\UserName.ini
[2013/11/10 18:38:28 | 001,073,262 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\adwcleaner(1).exe
[2013/11/10 13:20:50 | 000,000,967 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\Shortcut to JavaRa.lnk
[2013/11/08 10:43:09 | 000,015,360 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 11-10-2013.wps
[2013/11/07 16:19:44 | 000,000,540 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\checkup.lnk
[2013/11/07 15:29:00 | 000,891,184 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\SecurityCheck.exe
[2013/11/06 22:44:37 | 1474,809,856 | -HS- | C] () -- C:\hiberfil.sys
[2013/11/01 13:39:02 | 000,026,624 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Roast Cornish Hens.wdb
[2013/10/30 10:39:02 | 000,014,336 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 11-03-2013.wps
[2013/10/29 22:45:24 | 000,001,676 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Application Data\Microsoft\Internet Explorer\Quick Launch\ZoneAlarmBackup.lnk
[2013/10/29 22:45:24 | 000,001,670 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Start Menu\Programs\Startup\ZoneAlarm Backup Tray.lnk
[2013/10/29 22:45:24 | 000,001,658 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Desktop\ZoneAlarm Backup Powered by IDrive.lnk
[2013/10/29 22:45:23 | 000,569,368 | ---- | C] () -- C:\WINDOWS\System32\olelib.tlb
[2013/10/29 22:45:23 | 000,022,212 | ---- | C] () -- C:\WINDOWS\System32\olelib2.tlb
[2013/10/29 22:45:23 | 000,003,841 | ---- | C] () -- C:\WINDOWS\System32\server.pem
[2013/10/29 22:45:21 | 000,147,130 | ---- | C] () -- C:\WINDOWS\System32\CRYPT32.LIB
[2013/10/29 22:45:21 | 000,117,982 | ---- | C] () -- C:\WINDOWS\System32\ADVAPI32.LIB
[2013/10/29 22:45:21 | 000,055,808 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2013/10/29 22:45:21 | 000,026,128 | ---- | C] () -- C:\WINDOWS\System32\ZABackupXceedCryReg.exe
[2013/10/29 22:45:21 | 000,000,096 | ---- | C] () -- C:\WINDOWS\System32\RegisterZABackupDll.bat
[2013/10/29 22:45:20 | 000,441,705 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll
[2013/10/29 22:45:20 | 000,000,730 | ---- | C] () -- C:\WINDOWS\System32\rootcert.pem
[2013/10/29 22:45:19 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\IBColIml.ocx
[2013/10/29 22:30:55 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Default.rdp
[2013/10/24 10:53:18 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\Bulletin 10-27-2013.wps
[2013/10/24 10:47:48 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\IUMC Collect Report 11-2013.xlr
[2013/10/24 10:31:16 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\IUMC Check Reg 10-2013.xlr
[2013/10/24 10:09:57 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\IUMC Collect Report 10-13.xlr
[2013/10/22 21:29:31 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD 1956-1957 T1.xlr
[2013/10/22 21:23:45 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD1954-1955 T1.xlr
[2013/10/22 21:23:14 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD 1954-1955 T2.xlr
[2013/10/22 21:20:38 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\My Documents\CD 1954-1955.xlr
[2013/09/07 18:06:12 | 000,000,200 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2013/08/15 02:24:20 | 000,308,815 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1576569892-3062952477-2378348150-1006-0.dat
[2013/08/15 02:24:13 | 000,149,430 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013/08/06 18:12:30 | 000,000,426 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2013/07/29 11:02:26 | 000,000,057 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Ament.ini
[2013/07/07 11:16:26 | 000,013,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\SWDUMon.sys
[2013/03/29 00:38:54 | 000,149,992 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/03/07 14:21:28 | 002,005,969 | ---- | C] () -- C:\WINDOWS\Delete.exe
[2012/12/26 08:23:59 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/12/05 11:19:22 | 000,000,569 | -H-- | C] () -- C:\WINDOWS\System32\BTImages.dat
[2012/09/09 14:38:51 | 000,000,697 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\PCTuneUp.config
[2012/07/03 17:29:41 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2012/04/24 18:16:15 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2012/02/15 18:31:26 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/11 18:26:30 | 000,043,784 | ---- | C] () -- C:\WINDOWS\System32\drivers\EUBKMON.sys
[2012/02/11 12:12:54 | 000,000,144 | ---- | C] () -- C:\WINDOWS\System32\lkfl.dat
[2012/02/11 12:12:54 | 000,000,128 | ---- | C] () -- C:\WINDOWS\System32\pdfl.dat
[2012/02/11 12:12:54 | 000,000,080 | ---- | C] () -- C:\WINDOWS\System32\ibfl.dat
[2012/01/31 10:41:43 | 000,000,133 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Local Settings\Application Data\fusioncache.dat
[2012/01/25 10:49:50 | 000,000,159 | ---- | C] () -- C:\WINDOWS\MVPSPADE.INI
[2012/01/24 15:07:00 | 000,000,974 | ---- | C] () -- C:\WINDOWS\MVPBR.INI
[2012/01/17 17:28:09 | 000,000,060 | ---- | C] () -- C:\WINDOWS\System32\SYSDRV.DAT
[2012/01/17 17:22:59 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2012/01/17 17:22:47 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2012/01/17 17:22:47 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2012/01/17 17:22:44 | 000,005,151 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2012/01/17 17:22:42 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2012/01/17 17:22:37 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2012/01/17 17:22:15 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2012/01/17 17:22:14 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2012/01/17 17:21:29 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2012/01/17 17:21:11 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2012/01/17 16:33:30 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012/01/17 16:33:30 | 001,072,544 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012/01/17 16:33:30 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012/01/17 16:21:13 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2012/01/17 16:15:05 | 000,003,948 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2012/01/17 16:07:06 | 000,013,834 | ---- | C] () -- C:\Documents and Settings\Sid Bailey\Application Data\wklnhst.dat
========== ZeroAccess Check ========== [2005/01/09 20:08:17 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2013/10/12 09:54:28 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 19:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >