OTL logfile created on: 12/17/2012 12:13:01 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.93 Gb Available Physical Memory | 83.79% Memory free
4.09 Gb Paging File | 3.71 Gb Available in Paging File | 90.61% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 53.71 Gb Free Space | 72.09% Space Free | Partition Type: NTFS
Computer Name: GX620 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/12/17 00:05:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2012/10/10 20:29:13 | 000,143,928 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Management\Engine\3.2.0.19\ccsvchst.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/06/15 20:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\6.4.0.9\ccsvchst.exe
PRC - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV - [2012/12/12 11:32:26 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/01 12:07:23 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/10 20:29:13 | 000,143,928 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Management\Engine\3.2.0.19\ccSvcHst.exe -- (MCLIENT)
SRV - [2012/09/29 19:54:26 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/24 22:12:59 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/06/15 20:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\6.4.0.9\ccSvcHst.exe -- (N360)
SRV - [2008/11/09 14:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2012/10/23 17:34:24 | 000,995,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20121130.005\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/10/03 19:19:14 | 000,134,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\MCLIENT\0302000.013\ccsetx86.sys -- (ccSet_MCLIENT)
DRV - [2012/09/29 19:54:26 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/09/14 09:26:00 | 001,601,184 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121216.007\NAVEX15.SYS -- (NAVEX15)
DRV - [2012/09/14 09:26:00 | 000,092,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20121216.007\NAVENG.SYS -- (NAVENG)
DRV - [2012/09/06 03:54:30 | 000,373,728 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20121214.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2012/08/09 06:48:37 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/08/09 06:48:37 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/05 20:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 20:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\srtspx.sys -- (SRTSPX)
DRV - [2012/07/04 00:54:32 | 007,874,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2012/07/01 17:56:17 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012/06/06 22:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\ccsetx86.sys -- (ccSet_N360)
DRV - [2012/05/21 19:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\symefa.sys -- (SymEFA)
DRV - [2012/05/14 00:12:12 | 000,103,040 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
DRV - [2012/03/29 00:28:38 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\symtdi.sys -- (SYMTDI)
DRV - [2012/03/29 00:28:25 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\symds.sys -- (SymDS)
DRV - [2012/03/29 00:06:25 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604000.009\ironx86.sys -- (SymIRON)
DRV - [2010/04/27 17:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2010/04/27 17:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2010/04/27 17:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2010/04/27 15:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2005/03/17 15:30:10 | 000,132,608 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2004/09/17 08:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes\{271AB670-473B-4EDC-8036-15E5194F33A9}: "URL" =
http://search.yahoo.com/search?p={s...ype=W3i_DS,136,0_0,Search,20121251,6901,0,8,0
IE - HKU\S-1-5-21-790525478-796845957-725345543-500\..\SearchScopes\{988AA950-1F62-48B2-A8DA-EFE0B23C8875}: "URL" =
http://www.mysearchresults.com/search?&c=2650&t=03&q={searchTerms}
IE - HKU\S-1-5-21-790525478-796845957-725345543-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.yahoo.com/"
FF - prefs.js..extensions.enabledAddons: %7B20a82645-c095-46ed-80e3-08825760534b%7D:0.0.0
FF - prefs.js..extensions.enabledAddons: %7BBBDA0591-3099-440a-AA10-41764D9DB4DB%7D:11.1.1.5%20-%203
FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:3.8.1
FF - prefs.js..extensions.enabledAddons: %7B2D3F3651-74B9-4795-BDEC-6DA2F431CB62%7D:2012.5.8.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPlgn\ [2012/07/01 17:59:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\coFFPlgn\ [2012/12/17 00:09:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/01 12:07:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/12/01 12:07:16 | 000,000,000 | ---D | M]
[2010/04/07 16:35:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2012/12/16 15:56:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ga180uks.default\extensions
[2012/12/16 15:56:25 | 000,234,972 | ---- | M] () (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ga180uks.default\extensions\
artur.dubovoy@gmail.com.xpi
[2012/12/01 12:07:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/12/17 00:09:39 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\COFFPLGN
[2012/07/01 17:59:49 | 000,000,000 | ---D | M] (Norton Vulnerability Protection) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPLGN
[2011/07/04 08:31:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/12/01 12:07:23 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/29 09:25:25 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/12 17:01:44 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/12/16 19:40:44 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\6.4.0.9\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - No CLSID value found.
O3 - HKU\S-1-5-21-790525478-796845957-725345543-500\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\6.4.0.9\coieplg.dll (Symantec Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-790525478-796845957-725345543-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1340484126046 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1350846574421 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.217.0.5 24.217.201.67 24.247.15.53
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2225B3BB-99B4-43AD-B80C-7B7402075F2B}: DhcpNameServer = 24.217.0.5 24.217.201.67 24.247.15.53
O18 - Protocol\Handler\mhtml - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/04/07 16:13:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/12/16 19:31:14 | 005,011,996 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2012/12/16 17:38:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\RK_Quarantine
[2012/12/16 09:58:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Optimizer Pro
[2012/12/16 09:58:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Yahoo!
[2012/12/16 09:45:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Slender v0.9.7
[2012/12/16 09:28:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2012/12/16 09:28:23 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2012/12/14 10:29:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\NPE
[2012/12/09 17:03:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\LightScribe Direct Disc Labeling
[2012/12/09 17:03:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LightScribe
[2012/12/09 15:51:23 | 000,000,000 | ---D | C] -- C:\HOME2
[2012/12/01 12:07:13 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/12/17 00:09:05 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/12/17 00:08:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/12/16 23:32:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/12/16 23:21:57 | 000,004,625 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/12/16 23:21:50 | 000,432,838 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/12/16 23:21:50 | 000,067,794 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/12/16 22:51:08 | 005,011,996 | R--- | M] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2012/12/16 19:40:44 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/12/16 18:26:15 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7F981BCB-ABC9-4C36-9EBA-E7880CC42B20}.job
[2012/12/16 18:07:36 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2012/12/16 14:21:44 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/12/16 13:43:53 | 000,106,484 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559867574_7095613_n.jpg
[2012/12/16 13:43:34 | 000,075,678 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559862574_6188948_n.jpg
[2012/12/16 13:43:19 | 000,080,971 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559857574_334677_n.jpg
[2012/12/16 13:14:25 | 000,059,706 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\261_1062181270983_8081_n.jpg
[2012/12/16 10:53:14 | 000,085,576 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\198723_246654008692257_3722898_n.jpg
[2012/12/16 10:34:55 | 000,100,854 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\527968_10151082408668579_1144189974_n.jpg
[2012/12/16 10:05:56 | 000,111,328 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\575143_10151496327190174_908941605_n.jpg
[2012/12/16 09:43:43 | 065,812,970 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Slender_v0_9_7.zip
[2012/12/16 02:03:35 | 000,044,575 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\253_20287805827_5281_n.jpg
[2012/12/16 01:54:28 | 000,154,897 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\556064_10150917674280828_1381619199_n.jpg
[2012/12/16 01:43:07 | 000,039,697 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\581594_185262564942140_1908392838_n.jpg
[2012/12/16 01:36:03 | 000,071,971 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157315130478_2968909_n.jpg
[2012/12/16 01:35:47 | 000,089,247 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157311865478_7692424_n.jpg
[2012/12/16 01:03:23 | 000,058,984 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796901319_769025_n.jpg
[2012/12/16 01:03:18 | 000,060,869 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796941320_5306665_n.jpg
[2012/12/15 23:42:09 | 000,071,459 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\248781_2144181005483_5042624_n.jpg
[2012/12/15 23:41:12 | 000,094,800 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\267583_2249405116020_2639995_n.jpg
[2012/12/15 23:21:45 | 000,085,011 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\396614_1820614511340_316881020_n.jpg
[2012/12/15 23:10:23 | 000,084,725 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\206767_10150154363369039_6466081_n.jpg
[2012/12/15 23:10:02 | 000,103,964 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\215679_10150154363429039_2434430_n.jpg
[2012/12/15 23:02:44 | 000,053,307 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\9021_126017333602_4267830_n.jpg
[2012/12/12 11:32:24 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/12/12 11:32:24 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/12/11 21:48:40 | 000,064,808 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\560781_210920942374896_1376037402_n.jpg
[2012/12/10 22:01:05 | 000,053,036 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\205769_110753989007984_1569016_n.jpg
[2012/12/10 21:44:31 | 000,038,682 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\269811_104812279614250_4588483_n.jpg
[2012/12/09 20:59:05 | 014,117,417 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 4.mp3
[2012/12/09 20:58:58 | 014,457,374 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 3.mp3
[2012/12/09 20:58:50 | 014,501,103 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 2.mp3
[2012/12/09 20:58:38 | 015,049,699 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 1.mp3
[2012/12/09 17:03:49 | 000,001,774 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\LightScribe.lnk
[2012/12/09 16:43:35 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/12/09 15:02:25 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/09 14:38:47 | 000,115,768 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/02 12:25:44 | 163,910,310 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\BF3_Premium_Bonus_Art_EN_v2.pdf
[2012/11/30 12:35:48 | 000,100,383 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\ovw001-checklist.pdf
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/12/16 18:07:36 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\MBR.dat
[2012/12/16 13:43:53 | 000,106,484 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559867574_7095613_n.jpg
[2012/12/16 13:43:34 | 000,075,678 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559862574_6188948_n.jpg
[2012/12/16 13:43:19 | 000,080,971 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\28238_465559857574_334677_n.jpg
[2012/12/16 13:14:24 | 000,059,706 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\261_1062181270983_8081_n.jpg
[2012/12/16 10:53:13 | 000,085,576 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\198723_246654008692257_3722898_n.jpg
[2012/12/16 10:34:55 | 000,100,854 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\527968_10151082408668579_1144189974_n.jpg
[2012/12/16 10:05:55 | 000,111,328 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\575143_10151496327190174_908941605_n.jpg
[2012/12/16 09:43:43 | 065,812,970 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Slender_v0_9_7.zip
[2012/12/16 02:03:35 | 000,044,575 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\253_20287805827_5281_n.jpg
[2012/12/16 01:54:28 | 000,154,897 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\556064_10150917674280828_1381619199_n.jpg
[2012/12/16 01:43:07 | 000,039,697 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\581594_185262564942140_1908392838_n.jpg
[2012/12/16 01:36:03 | 000,071,971 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157315130478_2968909_n.jpg
[2012/12/16 01:35:47 | 000,089,247 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\23472_10150157311865478_7692424_n.jpg
[2012/12/16 01:03:23 | 000,058,984 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796901319_769025_n.jpg
[2012/12/16 01:03:18 | 000,060,869 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\3180_1149796941320_5306665_n.jpg
[2012/12/15 23:42:08 | 000,071,459 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\248781_2144181005483_5042624_n.jpg
[2012/12/15 23:41:11 | 000,094,800 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\267583_2249405116020_2639995_n.jpg
[2012/12/15 23:21:45 | 000,085,011 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\396614_1820614511340_316881020_n.jpg
[2012/12/15 23:10:23 | 000,084,725 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\206767_10150154363369039_6466081_n.jpg
[2012/12/15 23:10:02 | 000,103,964 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\215679_10150154363429039_2434430_n.jpg
[2012/12/15 23:02:43 | 000,053,307 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\9021_126017333602_4267830_n.jpg
[2012/12/11 21:48:40 | 000,064,808 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\560781_210920942374896_1376037402_n.jpg
[2012/12/10 22:01:04 | 000,053,036 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\205769_110753989007984_1569016_n.jpg
[2012/12/10 21:44:30 | 000,038,682 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\269811_104812279614250_4588483_n.jpg
[2012/12/09 20:58:57 | 014,117,417 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 4.mp3
[2012/12/09 20:58:50 | 014,457,374 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 3.mp3
[2012/12/09 20:58:39 | 014,501,103 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 2.mp3
[2012/12/09 20:58:30 | 015,049,699 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Coast to Coast - Nov 27 2012 - Hour 1.mp3
[2012/12/09 17:03:49 | 000,001,774 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\LightScribe.lnk
[2012/12/02 12:24:04 | 163,910,310 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\BF3_Premium_Bonus_Art_EN_v2.pdf
[2012/11/30 12:35:44 | 000,100,383 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\ovw001-checklist.pdf
[2012/03/14 16:30:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/06 17:34:59 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/06 17:34:59 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/06 17:34:59 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/02/06 17:34:59 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/02/06 17:34:59 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/02/01 17:35:55 | 000,199,307 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\census.cache
[2012/02/01 17:35:52 | 000,165,959 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\ars.cache
[2012/02/01 17:27:17 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\housecall.guid.cache
[2011/08/03 18:48:56 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/07/13 20:42:30 | 000,140,024 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/07/13 20:42:29 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys
[2011/07/13 20:41:51 | 000,280,768 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2011/07/13 20:41:49 | 002,434,856 | ---- | C] () -- C:\WINDOWS\System32\pbsvc_bc2.exe
[2011/07/13 20:41:49 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2011/07/07 22:37:28 | 000,053,760 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
[2011/06/19 09:53:07 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2011/06/19 09:53:07 | 000,618,823 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2011/06/19 09:53:07 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2011/06/17 16:27:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
========== ZeroAccess Check ==========
[2011/06/17 16:24:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 18:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 06:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 18:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >