OTL logfile created on: 12/17/2011 10:21:30 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Ruth\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 47.84% Memory free
5.98 Gb Paging File | 4.73 Gb Available in Paging File | 79.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.56 Gb Total Space | 106.86 Gb Free Space | 61.22% Space Free | Partition Type: NTFS
Drive D: | 11.75 Gb Total Space | 1.97 Gb Free Space | 16.79% Space Free | Partition Type: NTFS
Computer Name: RUTH-PC | User Name: Ruth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - C:\Users\Ruth\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\egrFltGUc9Arat.exe ()
PRC - C:\ProgramData\POLStitgmwobI.exe ()
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Password Safe\pwsafe.exe (SourceForge.net)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Microsoft Money\System\mnyexpr.exe (Microsoft Corp.)
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - C:\ProgramData\egrFltGUc9Arat.exe ()
MOD - C:\ProgramData\POLStitgmwobI.exe ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\OpenOffice.org 3\program\libxslt.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (McAfee SiteAdvisor Service) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TomTomHOMEService) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (SBSDWSCService) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Com4Qlb) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - (sbapifs) -- C:\WINDOWS\System32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (nvlddmkm) -- C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (CnxtHdAudService) -- C:\WINDOWS\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (athr) -- C:\WINDOWS\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (XAudio) -- C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HdAudAddService) -- C:\WINDOWS\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpqRemHid) -- C:\WINDOWS\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqKbFiltr) -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (rismxdp) -- C:\WINDOWS\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\WINDOWS\System32\drivers\rimmptsk.sys (REDC)
DRV - (nvsmu) -- C:\WINDOWS\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (rimsptsk) -- C:\WINDOWS\System32\drivers\rimsptsk.sys (REDC)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wunderground.com/cgi-bin/findweather/hdfForecast?query=08312+-+Clayton%2C+NJ
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1418455&SearchSource=3&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.flylady.net/|http://classic.wunderground.com/cgi-bin/findweather/getForecast?query=08312&wuSelect=WEATHER"
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems:
[email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: {1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}:2.12.21.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
[email protected]:4.5.2.0
FF - prefs.js..extensions.enabledItems:
[email protected]:4.5
FF - prefs.js..extensions.enabledItems:
[email protected]:3.11.3.15590
FF - prefs.js..extensions.enabledItems:
[email protected]:1.2
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=FXTV5&o=101703&locale=en_US&apn_uid=73545EDE-2185-45D7-AEAD-D5E4407FAADD&apn_ptnrs=F3&apn_sauid=01E6FC1D-EC0C-4678-9645-A7743F1E55FD&apn_dtid=YYYYYYYYUS&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/08/24 08:41:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/11/09 13:36:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/09 21:10:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/29 19:41:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/09/01 13:08:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/08/24 08:41:20 | 000,000,000 | ---D | M]
[2011/08/18 12:00:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Extensions
[2011/08/18 12:00:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Extensions\
[email protected]
[2011/12/13 15:17:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions
[2011/10/20 07:36:17 | 000,000,000 | ---D | M] (IE Tab 2 (FF 3.6+)) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
[2011/08/08 19:55:27 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/13 15:17:44 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/08/08 19:55:27 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2011/08/08 19:55:24 | 000,000,000 | ---D | M] (20-20 3D Viewer) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\
[email protected]
[2011/08/20 22:55:59 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\
[email protected]
[2011/08/08 19:55:24 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\
[email protected]
[2011/12/15 10:30:02 | 000,000,000 | ---D | M] ("Foxit PDF Creator Toolbar") -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\extensions\
[email protected]
[2011/12/17 10:18:12 | 000,002,571 | ---- | M] () -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\searchplugins\askcom.xml
[2007/07/21 10:23:32 | 000,002,386 | ---- | M] () -- C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Profiles\sg3ui63v.default\searchplugins\siteadvisor.xml
[2011/11/09 21:10:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\RUTH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SG3UI63V.DEFAULT\EXTENSIONS\
[email protected]
[2011/11/09 21:10:25 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/19 10:39:39 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2011/11/09 21:10:25 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [POLStitgmwobI.exe] C:\ProgramData\POLStitgmwobI.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MoneyAgent] C:\Program Files\Microsoft Money\System\mnyexpr.exe (Microsoft Corp.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Password Safe.lnk = C:\Program Files\Password Safe\pwsafe.exe (SourceForge.net)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 71.250.0.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5303E5E5-D779-49F4-B3BE-E1A7759CBAF0}: DhcpNameServer = 192.168.1.1 71.250.0.12
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Users\Ruth\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/24 21:23:11 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011/12/16 20:58:40 | 004,341,424 | ---- | C] (Swearware) -- C:\Users\Ruth\Desktop\ComboFix.exe
[2011/12/16 18:21:59 | 000,000,000 | ---D | C] -- C:\Users\Ruth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Fix
[2011/12/16 18:19:06 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/12/16 03:07:22 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/12/16 03:07:20 | 001,798,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/12/16 03:07:20 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/12/16 03:07:20 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/12/16 03:07:19 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/12/16 03:07:16 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2011/12/15 16:11:05 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011/12/15 16:11:03 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/12/15 16:11:01 | 003,602,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011/12/15 16:11:01 | 003,550,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011/12/15 16:10:54 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011/12/15 16:10:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2011/12/12 22:13:29 | 000,000,000 | ---D | C] -- C:\Users\Ruth\Documents\My Scans
[2011/11/29 19:40:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/11/29 19:39:10 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/11/29 19:39:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2011/11/29 19:34:59 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011/12/17 09:43:16 | 000,003,344 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/17 09:43:16 | 000,003,344 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/17 09:11:09 | 000,001,085 | ---- | M] () -- C:\Users\Ruth\Desktop\Spybot - Search & Destroy.lnk
[2011/12/17 08:32:55 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2011/12/17 08:32:55 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2011/12/16 22:21:06 | 000,617,702 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/16 22:21:06 | 000,108,772 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/16 21:55:46 | 000,000,258 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2011/12/16 21:43:32 | 000,135,568 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/12/16 21:43:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/16 21:43:09 | 3085,815,808 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/16 20:58:29 | 004,341,424 | ---- | M] (Swearware) -- C:\Users\Ruth\Desktop\ComboFix.exe
[2011/12/16 20:57:36 | 000,000,512 | ---- | M] () -- C:\Users\Ruth\Documents\MBR.dat
[2011/12/16 18:23:42 | 000,000,456 | ---- | M] () -- C:\ProgramData\egrFltGUc9Arat
[2011/12/16 18:22:01 | 000,000,304 | ---- | M] () -- C:\ProgramData\~egrFltGUc9Arat
[2011/12/16 18:22:01 | 000,000,208 | ---- | M] () -- C:\ProgramData\~egrFltGUc9Aratr
[2011/12/16 18:21:59 | 000,000,625 | ---- | M] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/12/16 18:21:59 | 000,000,601 | ---- | M] () -- C:\Users\Ruth\Desktop\System Fix.lnk
[2011/12/16 18:21:49 | 000,350,472 | ---- | M] () -- C:\ProgramData\egrFltGUc9Arat.exe
[2011/12/16 18:19:14 | 000,442,632 | ---- | M] () -- C:\ProgramData\POLStitgmwobI.exe
[2011/12/16 03:33:27 | 000,333,888 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/16 03:30:22 | 000,000,042 | ---- | M] () -- C:\Users\Ruth\Documents\Home_pwsafe.plk
[2011/12/12 17:25:31 | 000,000,680 | ---- | M] () -- C:\Users\Ruth\AppData\Local\d3d9caps.dat
[2011/12/11 17:42:10 | 010,559,488 | ---- | M] () -- C:\Users\Ruth\Documents\My Money.mny
[2011/12/03 11:04:17 | 000,008,392 | ---- | M] () -- C:\Users\Ruth\Documents\Home_pwsafe.psafe3
[2011/12/03 11:02:03 | 000,008,312 | ---- | M] () -- C:\Users\Ruth\Documents\Home_pwsafe.ibak
[2011/11/29 19:49:38 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/11/29 19:41:36 | 000,001,892 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/11/23 08:37:27 | 002,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011/12/16 20:57:36 | 000,000,512 | ---- | C] () -- C:\Users\Ruth\Documents\MBR.dat
[2011/12/16 20:39:05 | 000,002,152 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Office - 60 Day Trial.lnk
[2011/12/16 20:39:05 | 000,002,055 | ---- | C] () -- C:\Users\Public\Desktop\eBay.lnk
[2011/12/16 20:39:05 | 000,002,045 | ---- | C] () -- C:\Users\Public\Desktop\MSN.lnk
[2011/12/16 20:39:05 | 000,002,033 | ---- | C] () -- C:\Users\Public\Desktop\My HP Games.lnk
[2011/12/16 20:39:05 | 000,002,026 | ---- | C] () -- C:\Users\Public\Desktop\Launch Slingbox Flash Tour.lnk
[2011/12/16 20:39:05 | 000,001,907 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2011/12/16 20:39:05 | 000,001,892 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/12/16 20:39:05 | 000,001,883 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2011/12/16 20:39:05 | 000,001,883 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird (2).lnk
[2011/12/16 20:39:05 | 000,001,871 | ---- | C] () -- C:\Users\Public\Desktop\HP Help and Support.lnk
[2011/12/16 20:39:05 | 000,001,865 | ---- | C] () -- C:\Users\Public\Desktop\HP Total Care Advisor.lnk
[2011/12/16 20:39:05 | 000,001,851 | ---- | C] () -- C:\Users\Public\Desktop\Internet & Digital Services.lnk
[2011/12/16 20:39:05 | 000,001,719 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2011/12/16 20:39:05 | 000,001,614 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Calculator.lnk
[2011/12/16 20:39:05 | 000,001,537 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk
[2011/12/16 20:39:05 | 000,001,176 | ---- | C] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2011/12/16 20:39:05 | 000,001,013 | ---- | C] () -- C:\Users\Public\Desktop\Microsoft Money 2004.lnk
[2011/12/16 20:39:05 | 000,000,985 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk
[2011/12/16 20:39:05 | 000,000,943 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/16 20:39:05 | 000,000,938 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/12/16 20:39:05 | 000,000,937 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/12/16 20:39:05 | 000,000,870 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/12/16 20:39:05 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/12/16 20:39:05 | 000,000,846 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2011/12/16 20:39:05 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\MozBackup.lnk
[2011/12/16 20:39:05 | 000,000,625 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/12/16 20:39:05 | 000,000,258 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/12/16 20:39:05 | 000,000,240 | ---- | C] () -- C:\Users\Ruth\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/12/16 20:39:05 | 000,000,159 | ---- | C] () -- C:\Users\Public\Desktop\MSN Money.url
[2011/12/16 20:38:55 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/12/16 20:38:55 | 000,001,717 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/12/16 20:38:48 | 000,002,061 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
[2011/12/16 20:38:48 | 000,001,950 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Photo Gallery.lnk
[2011/12/16 20:38:48 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2011/12/16 20:38:48 | 000,001,895 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011/12/16 20:38:48 | 000,001,865 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Total Care Advisor.lnk
[2011/12/16 20:38:48 | 000,001,852 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Collaboration.lnk
[2011/12/16 20:38:48 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/12/16 20:38:48 | 000,001,803 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/12/16 20:38:48 | 000,001,770 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Calendar.lnk
[2011/12/16 20:38:48 | 000,001,769 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPlay Manager.lnk
[2011/12/16 20:38:48 | 000,001,768 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker.lnk
[2011/12/16 20:38:48 | 000,001,757 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Defender.lnk
[2011/12/16 20:38:48 | 000,001,743 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2011/12/16 20:38:48 | 000,001,728 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPlay.lnk
[2011/12/16 20:38:48 | 000,001,703 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Contacts.lnk
[2011/12/16 20:38:48 | 000,001,630 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/12/16 20:38:48 | 000,001,025 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Money 2004.lnk
[2011/12/16 20:38:48 | 000,001,016 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2011/12/16 20:38:48 | 000,000,858 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/12/16 20:38:48 | 000,000,855 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/12/16 20:38:48 | 000,000,185 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pandora Internet Radio.url
[2011/12/16 18:22:01 | 000,000,304 | ---- | C] () -- C:\ProgramData\~egrFltGUc9Arat
[2011/12/16 18:22:01 | 000,000,208 | ---- | C] () -- C:\ProgramData\~egrFltGUc9Aratr
[2011/12/16 18:21:59 | 000,000,601 | ---- | C] () -- C:\Users\Ruth\Desktop\System Fix.lnk
[2011/12/16 18:21:55 | 000,000,456 | ---- | C] () -- C:\ProgramData\egrFltGUc9Arat
[2011/12/16 18:21:49 | 000,350,472 | ---- | C] () -- C:\ProgramData\egrFltGUc9Arat.exe
[2011/12/16 18:19:16 | 000,442,632 | ---- | C] () -- C:\ProgramData\POLStitgmwobI.exe
[2011/10/29 22:53:58 | 000,000,680 | ---- | C] () -- C:\Users\Ruth\AppData\Local\d3d9caps.dat
[2011/09/15 12:08:29 | 000,016,432 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2011/08/24 08:24:31 | 000,205,118 | ---- | C] () -- C:\Windows\hpwins26.dat
[2011/08/10 21:26:15 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011/08/10 21:26:15 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/08/07 20:58:10 | 000,135,568 | ---- | C] () -- C:\ProgramData\nvModes.001
[2011/08/07 20:58:09 | 000,135,568 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2011/08/07 06:50:22 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/08/07 06:50:21 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/08/07 01:16:22 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/08/18 01:31:57 | 000,000,370 | ---- | C] () -- C:\Windows\hpwmdl26.dat
[2008/08/21 04:05:33 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/08/21 04:01:54 | 000,004,984 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2008/04/24 21:38:18 | 000,101,605 | ---- | C] () -- C:\Windows\hpqins13.dat
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,333,888 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 000,617,702 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,108,772 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/03/09 04:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[color=#E56717]========== LOP Check ==========[/color]
[2011/08/10 21:55:16 | 000,000,000 | ---D | M] -- C:\Users\Ruth\AppData\Roaming\OpenOffice.org
[2011/08/08 17:51:04 | 000,000,000 | ---D | M] -- C:\Users\Ruth\AppData\Roaming\Thunderbird
[2011/08/18 11:59:58 | 000,000,000 | ---D | M] -- C:\Users\Ruth\AppData\Roaming\TomTom
[2011/08/09 19:46:14 | 000,000,000 | ---D | M] -- C:\Users\Ruth\AppData\Roaming\WildTangent
[2011/12/16 21:41:59 | 000,032,200 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 1159 bytes -> C:\Users\Ruth\Desktop\FlyLady Repost Laundry Solution Wardrobe Simplification.eml:OECustomProperty
< End of report >