Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OTL Extras logfile created on: 12/9/2012 7:04:23 AM - Run 1
- OTL by OldTimer - Version 3.2.69.0 Folder = C:\downloads\MalwareFix12-8-2012\otl
- Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
- Internet Explorer (Version = 8.0.6001.18702)
- Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
- 3.00 Gb Total Physical Memory | 2.46 Gb Available Physical Memory | 81.97% Memory free
- 4.84 Gb Paging File | 4.42 Gb Available in Paging File | 91.41% Paging File free
- Paging file location(s): C:\pagefile.sys 2046 4092E:\pagefile.sys 0 0 [binary data]
- %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
- Drive C: | 465.76 Gb Total Space | 349.63 Gb Free Space | 75.07% Space Free | Partition Type: NTFS
- Drive D: | 298.09 Gb Total Space | 266.02 Gb Free Space | 89.24% Space Free | Partition Type: NTFS
- Computer Name: UPSTAIRSHP | User Name: Dad | Logged in as Administrator.
- Boot Mode: Normal | Scan Mode: All users
- Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days
- [color=#E56717]========== Extra Registry (SafeList) ==========[/color]
- [color=#E56717]========== File Associations ==========[/color]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
- .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
- [color=#E56717]========== Shell Spawning ==========[/color]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
- batfile [open] -- "%1" %*
- cmdfile [open] -- "%1" %*
- comfile [open] -- "%1" %*
- cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
- exefile [open] -- "%1" %*
- piffile [open] -- "%1" %*
- regfile [merge] -- Reg Error: Key error.
- scrfile [config] -- "%1"
- scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
- scrfile [open] -- "%1" /S
- txtfile [edit] -- Reg Error: Key error.
- Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
- Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
- Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
- Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
- [color=#E56717]========== Security Center Settings ==========[/color]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
- "AntiVirusDisableNotify" = 0
- "FirewallDisableNotify" = 0
- "UpdatesDisableNotify" = 0
- "AntiVirusOverride" = 0
- "FirewallOverride" = 0
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
- "DisableMonitoring" = 1
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
- "DisableMonitoring" = 1
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
- [color=#E56717]========== System Restore Settings ==========[/color]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
- "DisableSR" = 0
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
- "Start" = 0
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
- "Start" = 2
- [color=#E56717]========== Firewall Settings ==========[/color]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
- "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
- "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
- "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
- "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
- "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
- "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
- "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
- "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
- [color=#E56717]========== Authorized Applications List ==========[/color]
- [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
- "{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
- "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
- "{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
- "{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}" = Epson FAX Utility
- "{0DFB3DE8-65B9-44FF-AA0A-3BECC5A2BFD1}" = Adobe Flash Player 10 Plugin
- "{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
- "{0F33250B-7C59-5A14-6ED5-FCC251A962D0}" = Skins
- "{14378007-ACD5-2482-33A1-F79289A452E7}" = Catalyst Control Center Graphics Full Existing
- "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
- "{1945A4B5-73B6-4DE9-99A3-05261B7FDED0}" = Shared C Run-time for x86
- "{1B2DBF55-05D4-4072-87D8-689141E262BD}" = Creative ZEN
- "{1E1CB0CC-50E9-2618-5D7C-03BE0A27E118}" = Catalyst Control Center Core Implementation
- "{1EBB57D4-63FF-87CC-A0F0-D73982CF6008}" = Adobe Media Player
- "{205140F6-F3AC-45CE-9627-9CF35C6E1C2E}" = Mall Tycoon 3
- "{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel(R) Network Connections 13.0.42.0
- "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
- "{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
- "{26A24AE4-039D-4CA4-87B4-2F83216037FF}" = Java(TM) 6 Update 37
- "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
- "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
- "{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
- "{4641532D-5636-006A-76A7-A758B70B0300}" = Ask Toolbar
- "{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
- "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
- "{4CA9EA31-65E6-00E2-3DBB-19AF01D51C8D}" = Catalyst Control Center Graphics Light
- "{5EF19AD3-1873-9072-D526-E8F4E6A9EE59}" = Catalyst Control Center Graphics Full New
- "{68C83D63-C661-C444-7E60-E0328D842ECB}" = ccc-core-preinstall
- "{710BF966-43C8-4216-A8EC-BC4E169FF7C1}" = MobileMe Control Panel
- "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
- "{72D07FDD-94B7-A4EE-8C28-888C55D33831}" = ccc-core-static
- "{7316A38B-0B88-4DBC-BAB9-3F522EB6C20B}" = Windows Media Format 9.5 SDK
- "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
- "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
- "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
- "{7FFC95A3-A514-E94D-72A1-B0FF80656519}" = CCC Help English
- "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
- "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
- "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
- "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
- "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
- "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
- "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
- "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
- "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
- "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
- "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
- "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
- "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
- "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
- "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
- "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
- "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
- "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
- "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
- "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
- "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
- "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
- "{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
- "{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
- "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
- "{97FA9DC8-B4AF-84EE-DA97-B13FE28381BA}" = ccc-utility
- "{98EABC7F-B1A1-43A5-B505-5B4EC3908DCD}" = Microsoft Security Client
- "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
- "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
- "{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
- "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
- "{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}" = PixiePack Codec Pack
- "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
- "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
- "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
- "{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
- "{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
- "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
- "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
- "{F73920B1-FD39-6893-4E9B-748311B666AF}" = Catalyst Control Center Graphics Previews Common
- "{FD71E2F7-B9FC-4072-88DB-AC19E2464D82}" = LightScribe System Software
- "Adobe AIR" = Adobe AIR
- "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
- "All ATI Software" = ATI - Software Uninstall Utility
- "ATI Display Driver" = ATI Display Driver
- "AudibleManager" = AudibleManager
- "Belarc Advisor" = Belarc Advisor 7.2
- "CCleaner" = CCleaner
- "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
- "EaseUS Partition Master Home Edition_is1" = EaseUS Partition Master 9.1.1 Home Edition
- "ENTERPRISER" = Microsoft Office Enterprise 2007
- "EPSON PC-FAX Driver 2" = Epson PC-FAX Driver
- "EPSON Scanner" = EPSON Scan
- "EPSON WorkForce 610 Series" = EPSON WorkForce 610 Series Printer Uninstall
- "Google Updater" = Google Updater
- "ie7" = Windows Internet Explorer 7
- "ie8" = Windows Internet Explorer 8
- "LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
- "LameACM" = Lame ACM MP3 Codec
- "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
- "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
- "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
- "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
- "Microsoft Security Client" = Microsoft Security Essentials
- "Mozilla Firefox (3.5.13)" = Mozilla Firefox (3.5.13)
- "NVIDIA Drivers" = NVIDIA Drivers
- "Origin" = Origin
- "SysInfo" = Creative System Information
- "SystemRequirementsLab" = System Requirements Lab
- "Windows Media Format Runtime" = Windows Media Format 11 runtime
- "Windows Media Player" = Windows Media Player 11
- "WinRAR archiver" = WinRAR archiver
- [color=#E56717]========== Last 20 Event Log Errors ==========[/color]
- [ OSession Events ]
- Error - 2/9/2012 9:11:17 PM | Computer Name = HPA6042N | Source = Microsoft Office 12 Sessions | ID = 7001
- Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
- Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6425.1000. This session
- lasted 1508 seconds with 1320 seconds of active time. This session ended with a
- crash.
- [ System Events ]
- Error - 12/8/2012 9:51:20 AM | Computer Name = UPSTAIRSHP | Source = ati2mtag | ID = 45062
- Description = CRT invalid display type
- Error - 12/8/2012 9:51:35 AM | Computer Name = UPSTAIRSHP | Source = SRService | ID = 104
- Description = The System Restore initialization process failed.
- Error - 12/8/2012 9:52:46 AM | Computer Name = UPSTAIRSHP | Source = Service Control Manager | ID = 7000
- Description = The MCSTRM service failed to start due to the following error: %%2
- Error - 12/8/2012 9:52:46 AM | Computer Name = UPSTAIRSHP | Source = Service Control Manager | ID = 7023
- Description = The Computer Browser service terminated with the following error:
- %%1060
- Error - 12/8/2012 9:52:46 AM | Computer Name = UPSTAIRSHP | Source = Service Control Manager | ID = 7023
- Description = The System Restore Service service terminated with the following error:
- %%5
- Error - 12/8/2012 9:08:40 PM | Computer Name = UPSTAIRSHP | Source = SRService | ID = 104
- Description = The System Restore initialization process failed.
- Error - 12/8/2012 9:08:42 PM | Computer Name = UPSTAIRSHP | Source = ati2mtag | ID = 45062
- Description = CRT invalid display type
- Error - 12/8/2012 9:09:59 PM | Computer Name = UPSTAIRSHP | Source = Service Control Manager | ID = 7000
- Description = The MCSTRM service failed to start due to the following error: %%2
- Error - 12/8/2012 9:09:59 PM | Computer Name = UPSTAIRSHP | Source = Service Control Manager | ID = 7023
- Description = The System Restore Service service terminated with the following error:
- %%5
- Error - 12/8/2012 9:09:59 PM | Computer Name = UPSTAIRSHP | Source = Service Control Manager | ID = 7023
- Description = The Computer Browser service terminated with the following error:
- %%1060
- < End of report >
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement