pmaxxx13
2012-01-06, 23:33
Sorry for the delayed response, was traveling
FYI - during combo-fix run I had an error message pop up twice:"PEV.exe stopped working"
Also, internet now works but re-directs
Thanks for your help!
ComboFix 12-01-06.01 - Connor Appleby 01/06/2012 15:00:07.2.8 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8182.4940 [GMT -5:00]
Running from: c:\users\Connor Appleby\Desktop\ComboFix.exe
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe
.
---- Previous Run -------
.
C:\DFREECB.tmp
c:\program files (x86)\LP
c:\program files (x86)\LP\7685\1303.tmp
c:\program files (x86)\LP\7685\871B.tmp
c:\program files (x86)\LP\7685\933.tmp
c:\programdata\054452l2d078j880h735m5rji6p4
c:\programdata\121518b2t827b281r656r4vbi8m1
c:\programdata\48286118k4k7
c:\users\Connor Appleby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore
c:\users\Connor Appleby\AppData\Roaming\Microsoft\Windows\Templates\054452l2d078j880h735m5rji6p4
c:\users\Connor Appleby\AppData\Roaming\Microsoft\Windows\Templates\121518b2t827b281r656r4vbi8m1
c:\users\Connor Appleby\Taskmgr.exe
c:\windows\system32\java.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-12-06 to 2012-01-06 )))))))))))))))))))))))))))))))
.
.
2012-01-06 20:49 . 2012-01-06 20:49 -------- d-----w- c:\users\Sarah\AppData\Local\temp
2012-01-06 20:49 . 2012-01-06 20:49 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2012-01-06 20:49 . 2012-01-06 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-30 14:27 . 2011-12-30 14:27 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\AVG2012
2011-12-28 22:42 . 2011-12-28 22:42 -------- d-----w- c:\users\Sarah\AppData\Roaming\Wacom
2011-12-28 22:41 . 2011-12-28 22:41 -------- d-----w- c:\users\Sarah\AppData\Roaming\WTablet
2011-12-26 21:07 . 2011-12-26 21:07 -------- d-----w- c:\program files (x86)\ERUNT
2011-12-26 19:02 . 2011-12-26 19:02 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Autodesk
2011-12-26 18:55 . 2011-12-26 18:55 -------- d-----w- c:\programdata\Alias
2011-12-26 18:53 . 2011-12-26 18:53 -------- d-----w- c:\program files (x86)\Autodesk
2011-12-26 18:48 . 2011-12-26 18:48 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
2011-12-26 18:47 . 2011-12-26 18:47 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Wacom
2011-12-26 18:47 . 2011-12-27 14:52 -------- d-----w- c:\programdata\Wacom
2011-12-26 18:46 . 2011-12-26 18:47 -------- d-----w- c:\program files (x86)\Bamboo Dock
2011-12-26 18:45 . 2011-12-26 18:45 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\WTablet
2011-12-26 18:32 . 2012-01-06 19:46 -------- d-----w- C:\ComboFix-1
2011-12-26 02:42 . 2011-12-26 02:42 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-12-26 01:25 . 2011-12-26 01:25 -------- d-----w- c:\programdata\ALM
2011-12-26 00:59 . 2011-12-26 00:59 -------- d-----w- c:\program files (x86)\Adobe Story
2011-12-26 00:56 . 2011-12-26 00:56 -------- d-----w- c:\program files (x86)\My Company Name
2011-12-24 07:50 . 2011-12-24 11:10 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Wyga
2011-12-24 07:50 . 2011-12-24 07:50 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Unefti
2011-12-15 02:49 . 2011-10-25 16:09 85504 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-15 02:49 . 2011-11-08 14:58 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 02:49 . 2011-11-08 14:42 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-15 02:49 . 2011-10-14 17:30 559616 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 02:49 . 2011-10-14 16:02 429056 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 02:49 . 2011-11-23 13:57 2764800 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 02:49 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-15 02:49 . 2011-11-08 12:10 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 00:08 . 2011-05-18 00:27 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-24 18:29 . 2011-10-24 18:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 18:29 . 2011-10-24 18:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2011-10-18 06:27 . 2011-11-11 07:00 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A82C839B-8539-4680-989B-B2FCC8B07A95}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{59c6f12b-f004-43e5-9997-08f2123119b6}]
2011-02-09 03:44 81920 ----a-w- c:\program files (x86)\oovootoolbar\oovootoolbarX.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{59c6f12b-f004-43e5-9997-08f2123119b6}"= "c:\program files (x86)\oovootoolbar\oovootoolbarX.dll" [2011-02-09 81920]
.
[HKEY_CLASSES_ROOT\clsid\{59c6f12b-f004-43e5-9997-08f2123119b6}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"ooVoo.exe"="c:\program files (x86)\ooVoo\oovoo.exe" [2011-05-18 22631608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-09-30 148888]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-04-24 250192]
"mcagent_exe"="c:\program files (x86)\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"5-Day Forecast"="c:\program files (x86)\5-Day Forecast\5-Day Forecast\5-Day Forecast.exe" [2010-06-15 876544]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2011-06-24 629848]
"ISTray"="c:\program files (x86)\Spyware Doctor\pctsTray.exe" [2010-01-18 1286608]
.
c:\users\Connor Appleby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
c:\users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Remote Access.lnk - c:\windows\Installer\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut4_F66A31D978314FBABA02C411C0047CC5.exe [2009-9-30 53248]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-02-24 88576]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - PCTSDInjDriver64
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-13 20:35]
.
2012-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-13 20:35]
.
2012-01-06 c:\windows\Tasks\Norton Security Scan for Connor Appleby.job
- c:\progra~2\NORTON~2\Engine\313~1.7\Nss.exe [2011-06-26 04:47]
.
2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{53F3B42F-94F6-43E8-8F18-C7EF3438945E}.job
- c:\windows\system32\msfeedssync.exe [2011-06-15 04:32]
.
2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{F18474AD-0958-4E2A-ABFC-5E8E3C831E2D}.job
- c:\windows\system32\msfeedssync.exe [2011-06-15 04:32]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-02-24 6975520]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-17 16308768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} - hxxp://www1.snapfish.com/SnapfishActivia3.cab
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
Wow6432Node-HKCU-Run-Hyvovv - c:\users\Connor Appleby\AppData\Roaming\Hyvovv.exe
Wow6432Node-HKCU-Run-hUtkqvriAukQ.exe - c:\programdata\hUtkqvriAukQ.exe
Wow6432Node-HKCU-Run-Bamboo Dock - c:\program files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe
HKLM-Run-Skytel - c:\program files\Realtek\Audio\HDA\Skytel.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Dell\DellDock\DockLogin.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe
c:\program files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
c:\progra~2\COMMON~1\McAfee\McProxy\McProxy.exe
c:\program files (x86)\McAfee\MPF\MPFSrv.exe
c:\program files (x86)\McAfee\MSK\MskSrver.exe
c:\program files (x86)\Spyware Doctor\pctsAuxs.exe
c:\program files (x86)\Spyware Doctor\pctsSvc.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\progra~2\McAfee\MSC\mcmscsvc.exe
c:\progra~2\mcafee.com\agent\mcagent.exe
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files (x86)\Dell Remote Access\ezi_ra.exe
c:\progra~2\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files (x86)\Common Files\mcafee\mna\mcnasvc.exe
c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe
.
**************************************************************************
.
Completion time: 2012-01-06 16:25:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-06 21:25
.
Pre-Run: 336,619,831,296 bytes free
Post-Run: 336,161,443,840 bytes free
.
- - End Of File - - 31D8CAAE3FECF46A83413F4119E35D79
pmaxxx13
2012-01-07, 03:13
Internet re-direct is gone, working fine now. I am having trouble with Explorer, so have to use Safari. Explorer says running without add-ons, thing maybe my son my have done something trying to fix internet
I had some issues with anti-virus programs that i was not able to disable, hopefully this did not interfere with the scan
Thanks!
ComboFix 12-01-06.03 - Connor Appleby 01/06/2012 19:32:21.3.8 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.8182.6112 [GMT -5:00]
Running from: c:\users\Connor Appleby\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: McAfee VirusScan *Enabled/Outdated* {86355677-4064-3EA7-ABB3-1B136EB04637}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}
FW: McAfee Personal Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: McAfee VirusScan *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-12-07 to 2012-01-07 )))))))))))))))))))))))))))))))
.
.
2012-01-07 00:56 . 2012-01-07 01:00 -------- d-----w- c:\users\Connor Appleby\AppData\Local\temp
2012-01-07 00:56 . 2012-01-07 00:56 -------- d-----w- c:\users\Sarah\AppData\Local\temp
2012-01-07 00:56 . 2012-01-07 00:56 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2012-01-07 00:56 . 2012-01-07 00:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-30 14:27 . 2011-12-30 14:27 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\AVG2012
2011-12-28 22:42 . 2011-12-28 22:42 -------- d-----w- c:\users\Sarah\AppData\Roaming\Wacom
2011-12-28 22:41 . 2011-12-28 22:41 -------- d-----w- c:\users\Sarah\AppData\Roaming\WTablet
2011-12-26 21:07 . 2011-12-26 21:07 -------- d-----w- c:\program files (x86)\ERUNT
2011-12-26 19:02 . 2011-12-26 19:02 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Autodesk
2011-12-26 18:55 . 2011-12-26 18:55 -------- d-----w- c:\programdata\Alias
2011-12-26 18:53 . 2011-12-26 18:53 -------- d-----w- c:\program files (x86)\Autodesk
2011-12-26 18:48 . 2011-12-26 18:48 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
2011-12-26 18:47 . 2011-12-26 18:47 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Wacom
2011-12-26 18:47 . 2011-12-27 14:52 -------- d-----w- c:\programdata\Wacom
2011-12-26 18:46 . 2011-12-26 18:47 -------- d-----w- c:\program files (x86)\Bamboo Dock
2011-12-26 18:45 . 2011-12-26 18:45 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\WTablet
2011-12-26 18:32 . 2012-01-06 19:46 -------- d-----w- C:\ComboFix-1
2011-12-26 02:42 . 2011-12-26 02:42 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-12-26 01:25 . 2011-12-26 01:25 -------- d-----w- c:\programdata\ALM
2011-12-26 00:59 . 2011-12-26 00:59 -------- d-----w- c:\program files (x86)\Adobe Story
2011-12-26 00:56 . 2011-12-26 00:56 -------- d-----w- c:\program files (x86)\My Company Name
2011-12-24 07:50 . 2011-12-24 11:10 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Wyga
2011-12-24 07:50 . 2011-12-24 07:50 -------- d-----w- c:\users\Connor Appleby\AppData\Roaming\Unefti
2011-12-15 02:49 . 2011-10-25 16:09 85504 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-15 02:49 . 2011-11-08 14:58 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-15 02:49 . 2011-11-08 14:42 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-12-15 02:49 . 2011-10-14 17:30 559616 ----a-w- c:\windows\system32\EncDec.dll
2011-12-15 02:49 . 2011-10-14 16:02 429056 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-12-15 02:49 . 2011-11-23 13:57 2764800 ----a-w- c:\windows\system32\win32k.sys
2011-12-15 02:49 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-15 02:49 . 2011-11-08 12:10 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-01 00:08 . 2011-05-18 00:27 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-24 18:29 . 2011-10-24 18:29 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2011-10-24 18:29 . 2011-10-24 18:29 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2011-10-18 06:27 . 2011-11-11 07:00 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A82C839B-8539-4680-989B-B2FCC8B07A95}\mpengine.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-06_20.59.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 02:23 . 2012-01-07 01:00 62592 c:\windows\system64\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:45 . 2012-01-07 01:00 85398 c:\windows\system64\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-02 22:21 . 2012-01-07 01:00 12112 c:\windows\system64\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1554704811-4091891495-1094212442-1000_UserData.bin
+ 2011-12-26 19:52 . 2012-01-07 00:58 55983 c:\windows\system64\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat
- 2011-12-26 19:52 . 2012-01-06 20:56 55983 c:\windows\system64\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat
- 2009-10-02 22:17 . 2012-01-06 20:59 16384 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-02 22:17 . 2012-01-07 01:01 16384 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-02 22:17 . 2012-01-07 01:01 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-02 22:17 . 2012-01-06 20:59 32768 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-02 22:17 . 2012-01-06 20:59 16384 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-02 22:17 . 2012-01-07 01:01 16384 c:\windows\system64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 02:23 . 2012-01-07 01:00 62592 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:45 . 2012-01-07 01:00 85398 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-02 22:21 . 2012-01-07 01:00 12112 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1554704811-4091891495-1094212442-1000_UserData.bin
- 2011-12-26 19:52 . 2012-01-06 20:56 55983 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat
+ 2011-12-26 19:52 . 2012-01-07 00:58 55983 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat
+ 2009-10-02 22:17 . 2012-01-07 01:01 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-02 22:17 . 2012-01-06 20:59 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-02 22:17 . 2012-01-06 20:59 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-02 22:17 . 2012-01-07 01:01 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-02 22:17 . 2012-01-07 01:01 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-02 22:17 . 2012-01-06 20:59 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-06 15:51 . 2012-01-07 00:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-06 15:51 . 2012-01-06 20:56 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-10-17 17:06 . 2011-12-26 18:32 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2011-10-17 17:06 . 2012-01-06 21:29 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2011-10-17 17:06 . 2012-01-06 21:29 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
- 2011-10-17 17:06 . 2011-12-26 18:32 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2011-10-17 17:06 . 2012-01-06 21:29 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
- 2011-10-17 17:06 . 2011-12-26 18:32 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
+ 2009-12-06 15:51 . 2012-01-07 00:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-06 15:51 . 2012-01-06 20:56 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-06 15:51 . 2012-01-07 00:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-06 15:51 . 2012-01-06 20:56 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-03 01:11 . 2012-01-06 23:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-03 01:11 . 2012-01-02 14:06 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-03 01:11 . 2012-01-06 23:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-03 01:11 . 2012-01-02 14:06 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-01-06 19:39 . 2012-01-06 23:09 1740 c:\windows\SoftwareDistribution\EventCache\{97D814BB-C395-4388-85E4-0026D7BD9996}.bin
+ 2012-01-07 00:57 . 2012-01-07 00:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-06 20:56 . 2012-01-06 20:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-01-06 20:56 . 2012-01-06 20:56 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-07 00:57 . 2012-01-07 00:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-03-05 20:18 . 2012-01-07 01:01 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2010-03-05 20:18 . 2012-01-06 20:59 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2008-01-21 03:20 . 2012-01-06 20:59 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 03:20 . 2012-01-07 01:01 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-21 03:20 . 2012-01-06 20:59 671744 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 03:20 . 2012-01-07 01:01 671744 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 12:46 . 2012-01-06 23:42 604264 c:\windows\system64\perfh009.dat
- 2006-11-02 12:46 . 2012-01-06 19:45 604264 c:\windows\system64\perfh009.dat
- 2006-11-02 12:46 . 2012-01-06 19:45 103964 c:\windows\system64\perfc009.dat
+ 2006-11-02 12:46 . 2012-01-06 23:42 103964 c:\windows\system64\perfc009.dat
- 2009-11-28 15:28 . 2011-12-26 00:31 245760 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-11-28 15:28 . 2012-01-07 00:34 245760 c:\windows\system64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2006-11-02 12:46 . 2012-01-06 23:42 604264 c:\windows\system32\perfh009.dat
- 2006-11-02 12:46 . 2012-01-06 19:45 604264 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2012-01-06 23:42 103964 c:\windows\system32\perfc009.dat
- 2006-11-02 12:46 . 2012-01-06 19:45 103964 c:\windows\system32\perfc009.dat
- 2009-11-28 15:28 . 2011-12-26 00:31 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-11-28 15:28 . 2012-01-07 00:34 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2011-02-14 00:02 . 2012-01-06 20:52 360168 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-02-14 00:02 . 2012-01-07 00:56 360168 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2008-01-21 03:20 . 2012-01-07 01:01 3948544 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-21 03:20 . 2012-01-06 20:59 3948544 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1555968]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
"ooVoo.exe"="c:\program files (x86)\ooVoo\oovoo.exe" [2011-05-18 22631608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Java\jre6\bin\jusched.exe" [2009-09-30 148888]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell DataSafe Online"="c:\program files (x86)\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-04-24 250192]
"mcagent_exe"="c:\program files (x86)\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"AppleSyncNotifier"="c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"5-Day Forecast"="c:\program files (x86)\5-Day Forecast\5-Day Forecast\5-Day Forecast.exe" [2010-06-15 876544]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"BambooCore"="c:\program files (x86)\Bamboo Dock\BambooCore.exe" [2011-06-24 629848]
"ISTray"="c:\program files (x86)\Spyware Doctor\pctsTray.exe" [2010-01-18 1286608]
.
c:\users\Connor Appleby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
c:\users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Remote Access.lnk - c:\windows\Installer\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut4_F66A31D978314FBABA02C411C0047CC5.exe [2009-9-30 53248]
McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-02-24 88576]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - PCTSDInjDriver64
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-13 20:35]
.
2012-01-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2009-11-13 20:35]
.
2012-01-06 c:\windows\Tasks\Norton Security Scan for Connor Appleby.job
- c:\progra~2\NORTON~2\Engine\313~1.7\Nss.exe [2011-06-26 04:47]
.
2012-01-07 c:\windows\Tasks\User_Feed_Synchronization-{53F3B42F-94F6-43E8-8F18-C7EF3438945E}.job
- c:\windows\system32\msfeedssync.exe [2011-06-15 04:32]
.
2012-01-06 c:\windows\Tasks\User_Feed_Synchronization-{F18474AD-0958-4E2A-ABFC-5E8E3C831E2D}.job
- c:\windows\system32\msfeedssync.exe [2011-06-15 04:32]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-02-24 6975520]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [BU]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-17 16308768]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} - hxxp://www1.snapfish.com/SnapfishActivia3.cab
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Dell\DellDock\DockLogin.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe
c:\program files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
c:\progra~2\COMMON~1\McAfee\McProxy\McProxy.exe
c:\program files (x86)\McAfee\MPF\MPFSrv.exe
c:\program files (x86)\McAfee\MSK\MskSrver.exe
c:\program files (x86)\Spyware Doctor\pctsAuxs.exe
c:\program files (x86)\Spyware Doctor\pctsSvc.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe
c:\progra~2\McAfee\MSC\mcmscsvc.exe
c:\progra~2\mcafee.com\agent\mcagent.exe
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files (x86)\Dell Remote Access\ezi_ra.exe
c:\program files (x86)\Common Files\mcafee\mna\mcnasvc.exe
c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe
c:\program files (x86)\Safari\Safari.exe
c:\program files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
.
**************************************************************************
.
Completion time: 2012-01-06 20:10:53 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-07 01:10
ComboFix2.txt 2012-01-06 21:25
.
Pre-Run: 334,196,748,288 bytes free
Post-Run: 333,992,267,776 bytes free
.
- - End Of File - - 80B8325F9D9C6730D52EE5170D5E507C
pmaxxx13
2012-01-07, 14:38
FYI - one microsoft update continues to fail: Cumulative Security Update for Internet Explorer 8 for Windows Vista for x64-based Systems (KB2618444)
I ran the ESET scanner and it found no issues. The default was set to scan files in last 30 days. No log was produced (maybe becuase nothing was fouind)?
OTL Text
OTL logfile created on: 1/7/2012 7:09:51 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Connor Appleby\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.99 Gb Total Physical Memory | 5.22 Gb Available Physical Memory | 65.28% Memory free
16.13 Gb Paging File | 13.54 Gb Available in Paging File | 83.97% Paging File free
Paging file location(s): ?:\pagefile.sys
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.57 Gb Total Space | 307.64 Gb Free Space | 45.00% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 7.84 Gb Free Space | 52.24% Space Free | Partition Type: NTFS
Drive E: | 7.14 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 14.92 Gb Total Space | 7.58 Gb Free Space | 50.80% Space Free | Partition Type: FAT32
Computer Name: CONNORAPPLEB-PC | User Name: Connor Appleby | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Connor Appleby\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\McAfee\MSK\msksrver.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6bc98e9b5eedaa8f71c5454d36a4b772\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6b88a2bf58d8529fc33f8f3437a7ff06\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll ()
========== Win32 Services (SafeList) ==========
SRV:[b]64bit: - (TabletServicePen) -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (TouchServicePen) -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
SRV:64bit: - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (McShield) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (DockLoginService) -- C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (AVGIDSAgent) -- C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (McComponentHostService) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (GoToAssist) -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (hnmsvc) -- c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (MpfService) -- C:\Program Files (x86)\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
SRV - (mcmscsvc) -- C:\Program Files (x86)\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (MSK80Service) -- C:\Program Files (x86)\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (McSysmon) -- C:\Program Files (x86)\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (McProxy) -- C:\Program Files (x86)\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) -- C:\Program Files (x86)\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (wacommousefilter) -- C:\Windows\SysNative\DRIVERS\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) -- C:\Windows\SysNative\DRIVERS\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (TIEHDUSB) -- C:\Windows\SysNative\DRIVERS\tiehdusb.sys (Texas Instruments)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfesmfk) -- C:\Windows\SysNative\drivers\mfesmfk.sys (McAfee, Inc.)
DRV:64bit: - (mfebopk) -- C:\Windows\SysNative\drivers\mfebopk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdk) -- C:\Windows\SysNative\drivers\mferkdk.sys (McAfee, Inc.)
DRV:64bit: - (Packet) -- C:\Windows\SysNative\DRIVERS\packet.sys (SingleClick Systems)
DRV:64bit: - (Tpkd) -- C:\Windows\SysNative\drivers\Tpkd.sys (PACE Anti-Piracy, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (MPFP) -- C:\Windows\SysNative\Drivers\Mpfp.sys (McAfee, Inc.)
DRV:64bit: - (e1yexpress) Intel(R) -- C:\Windows\SysNative\DRIVERS\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iastor.sys (Intel Corporation)
DRV:64bit: - (OA002Vid) -- C:\Windows\SysNative\DRIVERS\OA002Vid.sys (Creative Technology Ltd.)
DRV:64bit: - (OA002Ufd) -- C:\Windows\SysNative\DRIVERS\OA002Ufd.sys (Creative Technology Ltd.)
DRV:64bit: - (Avc) -- C:\Windows\SysNative\DRIVERS\avc.sys (Microsoft Corporation)
DRV:64bit: - (61883) -- C:\Windows\SysNative\DRIVERS\61883.sys (Microsoft Corporation)
DRV:64bit: - (e1express) Intel(R) -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys (Intel Corporation)
DRV:64bit: - (MSDV) -- C:\Windows\SysNative\DRIVERS\msdv.sys (Microsoft Corporation)
DRV:64bit: - (OA002Afx) -- C:\Windows\SysNative\Drivers\OA002Afx.sys (Creative Technology Ltd.)
DRV:64bit: - (R300) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV - (Packet) -- C:\Windows\SysWOW64\drivers\packet.sys (SingleClick Systems)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 68 A7 A1 11 56 6B 1D 46 A4 33 9E 4F 64 B4 06 A6 [binary data]
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 68 A7 A1 11 56 6B 1D 46 A4 33 9E 4F 64 B4 06 A6 [binary data]
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 68 A7 A1 11 56 6B 1D 46 A4 33 9E 4F 64 B4 06 A6 [binary data]
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 68 A7 A1 11 56 6B 1D 46 A4 33 9E 4F 64 B4 06 A6 [binary data]
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A3 93 38 9F DD CC CC 01 [binary data]
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/12/23 09:03:19 | 000,000,000 | ---D | M]
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - Extension: No name found = C:\Users\Connor Appleby\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.1.1_0\
CHR - Extension: No name found = C:\Users\Connor Appleby\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2012/01/06 19:58:48 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files (x86)\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found
O4 - HKLM..\Run: [5-Day Forecast] C:\Program Files (x86)\5-Day Forecast\5-Day Forecast\5-Day Forecast.exe ()
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Connor Appleby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Mcx1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab (DLM Control)
O16 - DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} http://www1.snapfish.com/SnapfishActivia3.cab (Snapfish Activia3)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F6C1251-DE0E-4DF2-9EB9-7943A8261CD9}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Desert Landscape.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/11 19:21:22 | 000,000,055 | R--- | M] () - E:\Autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-1554704811-4091891495-1094212442-1000..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/07 07:08:03 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Connor Appleby\Desktop\OTL.exe
[2012/01/07 06:47:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/01/06 21:17:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2012/01/06 21:17:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/01/06 21:17:22 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2012/01/06 21:17:22 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2012/01/06 21:17:22 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2012/01/06 21:17:22 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2012/01/06 20:10:58 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Local\temp
[2012/01/06 19:59:27 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/01/06 14:45:13 | 004,373,779 | R--- | C] (Swearware) -- C:\Users\Connor Appleby\Desktop\ComboFix.exe
[2012/01/04 17:02:40 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\Desktop\x
[2011/12/30 09:27:14 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\AVG2012
[2011/12/26 16:07:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/12/26 16:07:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2011/12/26 14:02:42 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\Autodesk
[2011/12/26 13:55:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Alias
[2011/12/26 13:55:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
[2011/12/26 13:53:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Autodesk
[2011/12/26 13:48:12 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2011/12/26 13:47:55 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\Wacom
[2011/12/26 13:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Wacom
[2011/12/26 13:47:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bamboo Dock
[2011/12/26 13:46:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bamboo Dock
[2011/12/26 13:45:16 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\WTablet
[2011/12/26 13:45:15 | 001,107,832 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Pen_Touch_Tablet.dll
[2011/12/26 13:45:14 | 001,326,456 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Pen_Touch_Tablet.dll
[2011/12/26 13:45:09 | 000,000,000 | ---D | C] -- C:\ProgramData\AppData
[2011/12/26 13:44:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TabletPlugins
[2011/12/26 13:44:46 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bamboo
[2011/12/26 13:42:43 | 000,012,848 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacommousefilter.sys
[2011/12/26 13:41:28 | 000,016,168 | ---- | C] (Wacom Technology) -- C:\Windows\SysNative\drivers\wacomvhid.sys
[2011/12/26 13:41:25 | 001,401,208 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Wintab32.dll
[2011/12/26 13:41:25 | 001,392,504 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\WacomMT.dll
[2011/12/26 13:41:25 | 001,369,464 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Pen_Tablet.dll
[2011/12/26 13:41:25 | 001,156,472 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\Wintab32.dll
[2011/12/26 13:41:25 | 001,152,888 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysWow64\WacomMT.dll
[2011/12/26 13:41:24 | 001,665,400 | ---- | C] (Wacom Technology, Corp.) -- C:\Windows\SysNative\Pen_Tablet.dll
[2011/12/26 13:41:19 | 000,000,000 | ---D | C] -- C:\Program Files\Tablet
[2011/12/26 13:33:49 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/12/26 13:33:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/12/26 13:33:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/12/26 13:32:16 | 000,000,000 | ---D | C] -- C:\ComboFix-1
[2011/12/26 13:28:20 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/12/26 13:23:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/25 21:42:08 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/25 21:30:56 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\Desktop\Adobe
[2011/12/25 20:25:53 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2011/12/25 19:59:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Story
[2011/12/25 19:56:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2011/12/25 19:54:10 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/12/25 19:52:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Production Premium CS5.5
[2011/12/24 02:50:22 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\Wyga
[2011/12/24 02:50:22 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\AppData\Roaming\Unefti
[2011/12/15 14:48:36 | 000,000,000 | -H-D | C] -- C:\Users\Connor Appleby\Documents\.picasaoriginals
[2011/12/14 21:49:47 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2011/12/14 21:49:29 | 000,559,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011/12/14 21:49:29 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011/12/10 23:09:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2011/12/09 20:29:47 | 000,000,000 | ---D | C] -- C:\Users\Connor Appleby\Documents\Audio
[2010/03/05 13:10:24 | 008,656,832 | ---- | C] (Dell, Inc. ) -- C:\Users\Connor Appleby\AppData\Roaming\DataSafeDotNet.exe
========== Files - Modified Within 30 Days ==========
[2012/01/07 07:15:00 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{53F3B42F-94F6-43E8-8F18-C7EF3438945E}.job
[2012/01/07 07:12:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/07 07:08:13 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Connor Appleby\Desktop\OTL.exe
[2012/01/07 06:41:59 | 000,060,939 | ---- | M] () -- C:\Windows\SysNative\Config.MPF
[2012/01/07 06:37:09 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/07 06:37:09 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/07 04:42:51 | 000,000,452 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{F18474AD-0958-4E2A-ABFC-5E8E3C831E2D}.job
[2012/01/06 23:12:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/06 20:45:34 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/06 20:43:26 | 000,703,388 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/06 20:43:26 | 000,604,264 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/06 20:43:26 | 000,103,964 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/06 20:37:42 | 000,339,840 | ---- | M] () -- C:\ProgramData\nvModes.001
[2012/01/06 20:37:10 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2012/01/06 20:37:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/06 20:37:03 | 4285,718,527 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/06 19:58:48 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/01/06 19:22:45 | 004,373,779 | R--- | M] (Swearware) -- C:\Users\Connor Appleby\Desktop\ComboFix.exe
[2012/01/06 14:39:27 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Connor Appleby.job
[2012/01/02 08:58:00 | 000,008,484 | ---- | M] () -- C:\Users\Connor Appleby\AppData\Local\d3d9caps.dat
[2011/12/28 17:56:39 | 000,002,475 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2011/12/28 17:12:34 | 1051,717,811 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/12/26 17:24:21 | 000,002,301 | ---- | M] () -- C:\Users\Connor Appleby\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/26 16:07:34 | 000,000,725 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\NTREGOPT.lnk
[2011/12/26 16:07:34 | 000,000,706 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\ERUNT.lnk
[2011/12/26 15:49:16 | 002,102,650 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\malware.diagcab
[2011/12/26 13:55:41 | 000,002,037 | ---- | M] () -- C:\Users\Connor Appleby\Application Data\Microsoft\Internet Explorer\Quick Launch\Autodesk SketchBookExpress 2011.lnk
[2011/12/26 13:55:41 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\Autodesk SketchBookExpress 2011.lnk
[2011/12/26 13:47:44 | 000,000,940 | ---- | M] () -- C:\Users\Public\Desktop\Bamboo Dock.lnk
[2011/12/26 12:39:13 | 000,000,134 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Internet Explorer Troubleshooting.url
[2011/12/26 09:24:42 | 085,260,637 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/25 21:25:51 | 000,001,045 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Photoshop CS5.1 (64 Bit).lnk
[2011/12/25 21:25:38 | 000,001,457 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Illustrator CS5.1.lnk
[2011/12/25 20:47:45 | 004,843,568 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/25 20:38:08 | 000,001,046 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Premiere Pro CS5.5.lnk
[2011/12/25 20:32:35 | 000,000,974 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Flash Professional CS5.5.lnk
[2011/12/25 20:28:40 | 000,001,158 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe After Effects CS5.5.lnk
[2011/12/25 20:23:41 | 000,001,116 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Flash Catalyst CS5.5.lnk
[2011/12/25 20:17:59 | 000,001,044 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Audition CS5.5.lnk
[2011/12/25 20:12:36 | 000,001,184 | -HS- | M] () -- C:\Users\Connor Appleby\AppData\Local\48286118k4k7
[2011/12/25 19:59:03 | 000,000,104 | ---- | M] () -- C:\Users\Connor Appleby\Network - Shortcut.lnk
[2011/12/25 19:56:53 | 000,000,988 | ---- | M] () -- C:\Users\Connor Appleby\Desktop\Adobe Bridge CS5.1.lnk
[2011/12/15 18:25:28 | 000,094,162 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/15 15:26:48 | 000,001,414 | -HS- | M] () -- C:\Users\Connor Appleby\AppData\Local\054452l2d078j880h735m5rji6p4
[2011/12/15 14:49:34 | 000,000,913 | ---- | M] () -- C:\Users\Connor Appleby\Documents\.picasa.ini
[2011/12/15 14:48:36 | 002,320,538 | ---- | M] () -- C:\Users\Connor Appleby\Documents\ME AND MY BOO!.jpg
[2011/12/10 23:09:30 | 000,001,773 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2011/12/10 23:09:30 | 000,001,771 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/12/09 20:43:19 | 000,053,194 | ---- | M] () -- C:\Users\Connor Appleby\Documents\sewer man improv.cwp
[2011/12/09 20:36:24 | 003,362,480 | ---- | M] () -- C:\Users\Connor Appleby\sewer mann.mp3
[2011/12/09 10:17:25 | 000,078,336 | ---- | M] () -- C:\Users\Connor Appleby\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2012/01/06 20:45:34 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/02 08:59:16 | 4285,718,527 | -HS- | C] () -- C:\hiberfil.sys
[2011/12/28 14:01:10 | 000,000,452 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{F18474AD-0958-4E2A-ABFC-5E8E3C831E2D}.job
[2011/12/26 16:07:34 | 000,000,725 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\NTREGOPT.lnk
[2011/12/26 16:07:34 | 000,000,706 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\ERUNT.lnk
[2011/12/26 15:49:15 | 002,102,650 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\malware.diagcab
[2011/12/26 13:55:41 | 000,002,037 | ---- | C] () -- C:\Users\Connor Appleby\Application Data\Microsoft\Internet Explorer\Quick Launch\Autodesk SketchBookExpress 2011.lnk
[2011/12/26 13:55:41 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\Autodesk SketchBookExpress 2011.lnk
[2011/12/26 13:47:44 | 000,000,940 | ---- | C] () -- C:\Users\Public\Desktop\Bamboo Dock.lnk
[2011/12/26 13:42:35 | 000,001,738 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Journal.lnk
[2011/12/26 13:42:35 | 000,001,638 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sticky Notes.lnk
[2011/12/26 13:41:19 | 000,000,488 | ---- | C] () -- C:\Windows\SysNative\PenTouchTabletUserDefaults.xml
[2011/12/26 13:41:19 | 000,000,488 | ---- | C] () -- C:\Windows\SysNative\PenTabletUserDefaults.xml
[2011/12/26 13:33:49 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/12/26 13:33:44 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/12/26 13:33:44 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/12/26 13:33:44 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/12/26 13:33:44 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/12/26 12:39:13 | 000,000,134 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Internet Explorer Troubleshooting.url
[2011/12/25 21:25:51 | 000,001,045 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Photoshop CS5.1 (64 Bit).lnk
[2011/12/25 21:25:38 | 000,001,457 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Illustrator CS5.1.lnk
[2011/12/25 20:38:08 | 000,001,046 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Premiere Pro CS5.5.lnk
[2011/12/25 20:32:35 | 000,000,974 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Flash Professional CS5.5.lnk
[2011/12/25 20:28:40 | 000,001,158 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe After Effects CS5.5.lnk
[2011/12/25 20:23:41 | 000,001,116 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Flash Catalyst CS5.5.lnk
[2011/12/25 20:17:59 | 000,001,044 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Audition CS5.5.lnk
[2011/12/25 20:12:24 | 000,001,184 | -HS- | C] () -- C:\Users\Connor Appleby\AppData\Local\48286118k4k7
[2011/12/25 19:59:03 | 000,000,104 | ---- | C] () -- C:\Users\Connor Appleby\Network - Shortcut.lnk
[2011/12/25 19:56:53 | 000,000,988 | ---- | C] () -- C:\Users\Connor Appleby\Desktop\Adobe Bridge CS5.1.lnk
[2011/12/15 15:25:57 | 000,001,414 | -HS- | C] () -- C:\Users\Connor Appleby\AppData\Local\054452l2d078j880h735m5rji6p4
[2011/12/15 14:48:36 | 002,320,538 | ---- | C] () -- C:\Users\Connor Appleby\Documents\ME AND MY BOO!.jpg
[2011/12/09 20:34:50 | 003,362,480 | ---- | C] () -- C:\Users\Connor Appleby\sewer mann.mp3
[2011/12/09 20:30:04 | 000,053,194 | ---- | C] () -- C:\Users\Connor Appleby\Documents\sewer man improv.cwp
[2011/11/29 03:19:49 | 000,012,508 | -HS- | C] () -- C:\Users\Connor Appleby\AppData\Local\uf36os4qiys384hl57ab3al78b64o855v08872ix020cgq
[2011/11/29 03:19:49 | 000,012,508 | -HS- | C] () -- C:\ProgramData\uf36os4qiys384hl57ab3al78b64o855v08872ix020cgq
[2011/11/28 04:02:19 | 000,001,296 | -HS- | C] () -- C:\Users\Connor Appleby\AppData\Local\121518b2t827b281r656r4vbi8m1
[2011/11/26 13:58:06 | 000,000,000 | ---- | C] () -- C:\ProgramData\312yOTHH.exe.b
[2011/11/26 13:55:53 | 000,000,112 | ---- | C] () -- C:\ProgramData\rU4PWC.dat
[2011/11/25 14:59:59 | 000,012,084 | -HS- | C] () -- C:\Users\Connor Appleby\AppData\Local\q54qp10egtn1b47yak1cxuws82656ekrq
[2011/11/25 14:59:59 | 000,012,084 | -HS- | C] () -- C:\ProgramData\q54qp10egtn1b47yak1cxuws82656ekrq
[2011/10/15 07:53:02 | 000,000,296 | ---- | C] () -- C:\ProgramData\~1kAlMiG2Kb7FzP
[2011/10/15 07:53:02 | 000,000,224 | ---- | C] () -- C:\ProgramData\~1kAlMiG2Kb7FzPr
[2011/10/15 07:52:54 | 000,000,440 | ---- | C] () -- C:\ProgramData\1kAlMiG2Kb7FzP
[2011/05/26 12:36:33 | 000,012,114 | -HS- | C] () -- C:\Users\Connor Appleby\AppData\Local\n8ph4jrwihupnmj32kp3qhs85iiqqew
[2011/05/26 12:36:33 | 000,012,114 | -HS- | C] () -- C:\ProgramData\n8ph4jrwihupnmj32kp3qhs85iiqqew
[2011/05/11 12:05:36 | 000,000,160 | ---- | C] () -- C:\ProgramData\~48619256r
[2011/05/11 12:05:36 | 000,000,152 | ---- | C] () -- C:\ProgramData\~48619256
[2011/05/11 12:05:14 | 000,000,328 | ---- | C] () -- C:\ProgramData\48619256
[2011/05/09 17:57:29 | 000,000,000 | ---- | C] () -- C:\Users\Connor Appleby\AppData\Local\{93F58D26-DC2D-441C-B29E-11FAAE8C6512}
[2011/02/20 10:18:30 | 000,000,732 | ---- | C] () -- C:\Users\Connor Appleby\AppData\Local\d3d9caps64.dat
[2010/08/10 21:42:04 | 000,000,056 | ---- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/03/05 14:11:04 | 000,763,832 | ---- | C] () -- C:\Windows\BDTSupport.dll.old
[2009/10/19 16:37:25 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/10/19 16:37:10 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/10/19 16:36:55 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/10/03 07:51:33 | 000,008,484 | ---- | C] () -- C:\Users\Connor Appleby\AppData\Local\d3d9caps.dat
[2009/10/02 17:25:26 | 000,078,336 | ---- | C] () -- C:\Users\Connor Appleby\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/30 10:20:21 | 000,339,840 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/09/30 10:20:21 | 000,339,840 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/09/30 06:10:56 | 000,146,432 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2009/09/30 06:10:56 | 000,072,704 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2009/07/21 05:57:10 | 000,233,472 | ---- | C] () -- C:\Windows\SysWow64\DSPlayer.dll
[2009/04/24 22:58:05 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007/03/15 14:48:04 | 000,450,560 | ---- | C] () -- C:\Windows\SysWow64\mcs_cor1.dll
[2006/11/02 10:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
========== LOP Check ==========
[2011/11/26 12:34:00 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\5CB13
[2009/11/13 18:09:22 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\acccore
[2009/12/06 11:15:48 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Antares
[2011/10/23 14:18:15 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\asssQQJ6dEK8R
[2011/02/17 19:57:36 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Audacity
[2011/12/26 14:02:42 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Autodesk
[2011/12/30 09:27:14 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\AVG2012
[2011/11/25 12:30:55 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Cakewalk
[2010/10/19 20:55:25 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Canon
[2011/12/25 21:42:08 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/10/14 21:20:37 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/10/18 17:06:33 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\EVVVellIBtzPy
[2011/10/18 17:06:39 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\fJJ66dWWK8fL9
[2011/11/26 09:42:11 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\hNtxP0ucSiDoGaH
[2011/11/26 09:42:20 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\JjYCwkIVrOtPuSi
[2011/10/18 17:06:38 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\lAAA1uuvS2ob3pG
[2011/01/28 12:26:28 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\MAXON
[2011/11/26 09:42:27 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\nBtzP0ycAiDoFpH
[2011/10/18 17:06:34 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\OFFF3ppnG5aQ6dK
[2011/02/08 22:45:29 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\ooVoo Details
[2009/12/06 11:24:44 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\PACE Anti-Piracy
[2011/11/26 09:42:19 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\pobF3pmG5Q6W8R9
[2010/09/26 17:45:42 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Publish Providers
[2011/11/26 10:05:13 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\pxA0uvS2iFpGaHd
[2010/06/10 15:25:57 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Sony
[2011/10/23 14:18:15 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\tJJ77dEEK8RZ9YX
[2011/11/26 09:42:13 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\UJ7dEK8gR9Y
[2011/12/24 02:50:22 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Unefti
[2011/12/26 13:47:55 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Wacom
[2011/12/26 13:48:12 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2011/12/24 06:10:20 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Wyga
[2011/11/26 09:42:26 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\Z8gRZqhYXkVl
[2011/10/23 14:13:06 | 000,000,000 | ---D | M] -- C:\Users\Connor Appleby\AppData\Roaming\ZcAA11ivD2on4pH
[2009/11/19 18:37:09 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\acccore
[2010/02/28 10:48:05 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\Facebook
[2009/10/25 16:58:00 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\Publish Providers
[2009/10/25 17:00:11 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\Sony
[2011/12/28 17:42:03 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\Wacom
[2012/01/06 20:36:06 | 000,032,610 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/07 07:15:00 | 000,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{53F3B42F-94F6-43E8-8F18-C7EF3438945E}.job
[2012/01/07 04:42:51 | 000,000,452 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{F18474AD-0958-4E2A-ABFC-5E8E3C831E2D}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >
>