here are the results:
OTListIt logfile created on: 2/21/2009 11:37:32 AM - Run
OTListIt2 by OldTimer - Version 2.0.1.0 Folder = C:\Documents and Settings\Dan Mueller\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 61.31% Memory free
2.60 Gb Paging File | 1.73 Gb Available in Paging File | 66.60% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 58.30 Gb Free Space | 52.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MUELLER2-XP
Current User Name: Dan Mueller
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE (F-Secure Corp.)
PRC - C:\Program Files\Charter Security Suite\Common\FSMB32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FCH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FAMEH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsqh.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FSPC\fspc.exe (F-Secure Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe (F-Secure Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe (F-Secure Corp.)
PRC - C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Charter Security Suite\FSAUA\program\fsus.exe (F-Secure Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Charter Security Suite\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Multimedia\main\ATISched.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Charter Security Suite\FSGUI\fsguidll.exe (F-Secure Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\FSGUI\scanwizard.exe (F-Secure Corporation)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (Autodesk Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Diskeeper [Auto | Running]) – C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
SRV - (F-Secure Gatekeeper Handler Starter [Auto | Running]) – C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (FSAUA [On_Demand | Running]) – C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe (F-Secure Corporation)
SRV - (FSDFWD [On_Demand | Running]) – C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (FSMA [Auto | Running]) – C:\Program Files\Charter Security Suite\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSORSPClient [On_Demand | Running]) – C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
========== Driver Services (SafeList) ==========
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdLLD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AmdLLD.sys (AMD, Inc.)
DRV - (ATI Remote Wonder II [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ATIRWVD.SYS (Jungo)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATITUNEP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atintuxx.sys (ATI Technologies Inc.)
DRV - (ativraxx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinxsxx.sys (ATI Technologies Inc.)
DRV - (BS_Flash [On_Demand | Stopped]) – C:\Program Files\Tseries BIOS Update\Award\BS_Flash.sys ()
DRV - (BS_I2cIo [System | Running]) – C:\WINDOWS\system32\drivers\BS_I2cIo.sys (BIOSTAR Group)
DRV - (cmuda [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (F-Secure Filter [Disabled | Stopped]) – C:\Program Files\Charter Security Suite\Anti-Virus\Win2K\FSfilter.sys ()
DRV - (F-Secure Gatekeeper [On_Demand | Running]) – C:\Program Files\Charter Security Suite\Anti-Virus\minifilter\fsgk.sys ()
DRV - (F-Secure HIPS [System | Running]) – C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (F-Secure Recognizer [Disabled | Stopped]) – C:\Program Files\Charter Security Suite\Anti-Virus\Win2K\FSrec.sys ()
DRV - (FETNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (fsbts [Boot | Running]) – C:\WINDOWS\system32\Drivers\fsbts.sys ()
DRV - (FSFW [Boot | Running]) – C:\WINDOWS\System32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (MA8212M [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MA8212M.sys (Mobile Action Technology Inc.)
DRV - (MA8212U [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MA8212U.sys (Mobile Action Technology Inc.)
DRV - (MaRdPnp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys (Mobile Action Technology Inc.)
DRV - (MaVctrl [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MVDCODEC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (NuidFltr [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV - (nvatabus [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENET [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NVENET.sys (NVIDIA Corporation)
DRV - (nvidesm [Boot | Running]) – C:\WINDOWS\system32\drivers\nvidesm.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (PCDCODEC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (Point32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (WinDriver6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (XUIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O1 HOSTS File: (731 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (E-Zsoft VideoDownloaderToolBar) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - C:\Program Files\VersalSoft\InternetDownload\VDTB.dll ()
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD_Display] File not found
O4 - HKLM..\Run: [Amok web bash obj] C:\Documents and Settings\All Users\Application Data\seek film amok web\2 FACE.exe (Tseet sipl isu)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [F-Secure Manager] "C:\Program Files\Charter Security Suite\Common\FSM32.EXE" /splash (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] "C:\Program Files\Charter Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW (F-Secure Corporation)
O4 - HKLM..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [InternetDownload_upgrade] "C:\Program Files\VersalSoft\InternetDownload\InternetDownload.exe" /upgrade File not found
O4 - HKLM..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear (NVIDIA)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [WD Button Manager] WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [admin window] C:\DOCUME~1\DANMUE~1\APPLIC~1\DALESU~1\loudknob.exe (Mass itibre)
O4 - HKCU..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe (ATI Technologies Inc.)
O4 - HKCU..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll (F-Secure Corporation)
O9 - Extra 'Tools' menuitem : Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll (F-Secure Corporation)
O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (ATI Technologies Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1}
https://www.mykohlerco.com/postauthI/epi.cab (Aventail Installer )
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1191095838078 (MUWebControl Class)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737}
http://cid-5756917e812a938f.spaces.live.co…ad/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5}
http://ipgweb.cce.hp.com/rdqaio/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876}
http://charter.net/files/charter/securitysuite/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {9EF34FF2-3396-4527-9D27-04C8C1C67806} - C:\Program Files\Microsoft AntiSpyware\shellextension.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.SOL () - [ NTFS ]
O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe – File not found
O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell - "" = AutoRun
O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell\AutoRun\command - "" = F:\Photokinz.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\Documents and Settings\Dan Mueller\My Documents\*.tmp files]
[2009/02/21 11:35:38 | 00,494,080 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe
[2009/02/21 00:11:33 | 00,004,066 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\computer results.zip
[2009/02/21 00:05:47 | 00,050,688 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Logfile of Trend Micro HJT v2.doc
[2009/02/20 23:24:33 | 00,001,744 | —- | C] () – C:\Documents and Settings\Dan Mueller\Desktop\HijackThis.lnk
[2009/02/20 23:24:32 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/20 20:11:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\Malwarebytes
[2009/02/20 20:11:07 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/20 20:11:07 | 00,000,706 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/20 20:11:04 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/20 20:11:03 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/20 20:11:03 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/20 20:10:00 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Dan Mueller\Desktop\mbam-setup.exe
[2009/02/18 23:41:29 | 00,000,526 | —- | C] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2009/02/18 20:22:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/02/18 20:22:23 | 00,000,790 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/02/18 20:22:21 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/02/18 20:22:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\SUPERAntiSpyware.com
[2009/02/18 20:21:39 | 06,006,816 | —- | C] () – C:\Documents and Settings\Dan Mueller\Desktop\SUPERAntiSpyware.exe
[2009/02/18 07:19:24 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Fitness Friday Weekend.doc
[2009/02/17 19:42:29 | 00,000,000 | —D | C] – C:\Program Files\NoAdware
[2009/02/16 22:50:08 | 00,033,408 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/16 22:30:18 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\F-Secure
[2009/02/16 22:22:26 | 00,079,904 | —- | C] (F-Secure Corporation) – C:\WINDOWS\System32\drivers\fsdfw.sys
[2009/02/16 22:21:02 | 00,000,000 | —D | C] – C:\Program Files\Charter Security Suite
[2009/02/16 22:20:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\fssg
[2009/02/16 20:51:57 | 00,000,000 | —D | C] – C:\fsaua.data
[2009/02/16 20:31:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\f-secure
[2009/02/14 20:18:54 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/02/09 19:38:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\My Documents\My Chat Logs
[2009/02/09 19:16:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/02/09 19:15:43 | 00,000,296 | -H– | C] () – C:\WINDOWS\tasks\21256B95F0F6E1BD.job
[2009/02/09 19:15:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\seek film amok web
[2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Program Files\dalesurfpeak
[2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak
[2009/02/09 19:15:11 | 00,000,000 | —D | C] – C:\Program Files\Circle Dvelopement
[2009/02/09 19:15:07 | 00,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
[2009/02/01 13:46:29 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Mark Marcus's bingo news.doc
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\drivers\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Dan Mueller\My Documents\*.tmp files]
[2009/02/21 11:36:32 | 00,494,080 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe
[2009/02/21 11:34:02 | 00,000,678 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/21 11:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\tasks\21256B95F0F6E1BD.job
[2009/02/21 03:30:00 | 00,000,438 | —- | M] () – C:\WINDOWS\tasks\RegistrySmart Scheduled Scan.job
[2009/02/21 00:11:33 | 00,004,066 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\computer results.zip
[2009/02/21 00:05:48 | 00,050,688 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Logfile of Trend Micro HJT v2.doc
[2009/02/20 23:24:33 | 00,001,744 | —- | M] () – C:\Documents and Settings\Dan Mueller\Desktop\HijackThis.lnk
[2009/02/20 22:03:57 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/20 22:03:45 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/20 22:03:44 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/20 22:00:25 | 02,096,656 | -H– | M] () – C:\Documents and Settings\Dan Mueller\Local Settings\Application Data\IconCache.db
[2009/02/20 20:30:16 | 00,001,100 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/20 20:11:07 | 00,000,706 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/20 20:10:00 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Dan Mueller\Desktop\mbam-setup.exe
[2009/02/20 18:01:02 | 00,000,526 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2009/02/19 19:05:01 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/02/19 19:05:01 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/02/19 19:03:55 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/02/19 19:03:55 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/02/18 20:22:23 | 00,000,790 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/02/18 20:21:51 | 06,006,816 | —- | M] () – C:\Documents and Settings\Dan Mueller\Desktop\SUPERAntiSpyware.exe
[2009/02/18 16:43:49 | 00,020,992 | —- | M] () – C:\Documents and Settings\Dan Mueller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/18 07:19:25 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Fitness Friday Weekend.doc
[2009/02/17 22:13:44 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/02/17 21:22:52 | 00,000,046 | —- | M] () – C:\AUTOEXEC.SOL
[2009/02/16 22:50:08 | 00,033,408 | —- | M] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/16 22:22:36 | 00,535,758 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/16 22:22:36 | 00,451,656 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/16 22:22:36 | 00,075,396 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/16 20:22:34 | 00,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/11 03:01:38 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/10 18:21:50 | 00,000,587 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\My Sharing Folders.lnk
[2009/02/03 17:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/01 19:51:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/02/01 19:51:13 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/02/01 19:39:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/01 19:39:23 | 00,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/01 13:53:26 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Mark Marcus's bingo news.doc
[2009/01/31 14:45:56 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/31 14:45:56 | 00,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/30 18:59:53 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/30 15:51:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/30 15:51:54 | 00,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/30 10:15:48 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/30 10:15:48 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/29 18:31:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/29 18:31:43 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/29 18:30:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/29 18:30:31 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/29 12:47:33 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/01/29 12:47:33 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/01/29 08:08:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/01/29 08:08:00 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/01/28 18:37:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/01/28 18:37:45 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/01/28 18:35:30 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/28 18:35:30 | 00,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/01/28 18:32:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/28 18:32:23 | 00,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/28 18:31:37 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/28 18:31:37 | 00,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/28 18:30:22 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/01/28 18:30:22 | 00,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/28 18:29:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/01/28 18:29:11 | 00,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/28 18:26:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/28 18:26:35 | 00,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/01/28 18:21:48 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/01/28 18:21:48 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/01/28 18:20:50 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/28 18:20:50 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/22 16:23:14 | 00,428,032 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Moms GS Game List.max
========== LOP Check ==========
[2009/02/20 20:11:03 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/10 18:46:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/04/30 09:46:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2007/07/09 14:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/07/09 15:01:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/18 19:19:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI MMC
[2005/06/08 18:55:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/02/16 22:22:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2009/02/16 22:20:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2006/10/16 17:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2006/05/24 21:08:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2006/05/24 19:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/02/23 20:36:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/02/20 20:11:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/16 20:17:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/04/29 17:32:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2009/02/09 19:16:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2008/02/03 16:47:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/01/20 18:14:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2008/11/06 19:53:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/09/11 11:32:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2007/09/29 13:52:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/09 19:15:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\seek film amok web
[2007/09/27 01:19:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2008/04/29 17:42:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/01/20 18:15:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/02/18 20:22:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/01/18 21:31:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/23 20:35:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\WD
[2007/09/29 13:52:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2004/01/10 23:09:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2006/05/22 16:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\X10 Settings
[2009/02/20 21:57:29 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Dan Mueller\Application Data
[2009/02/04 21:25:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Adobe
[2008/09/10 18:27:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\AdobeUM
[2008/04/04 15:45:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Ahead
[2007/07/09 15:01:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Apple Computer
[2005/06/06 11:06:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\ATI
[2008/12/31 15:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\ATI MMC
[2005/06/08 18:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Autodesk
[2007/11/20 21:11:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Aventail
[2009/02/09 19:15:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak
[2009/02/16 22:30:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\F-Secure
[2006/10/16 17:08:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Google
[2006/05/24 21:08:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Dan Mueller\Application Data\GTek
[2005/06/06 10:39:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Help
[2007/09/30 20:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\HP
[2005/06/06 05:29:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Identities
[2008/09/10 20:21:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Image Zone Express
[2008/07/09 20:24:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\InstallShield
[2009/02/16 20:10:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Lavasoft
[2005/06/08 13:09:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Leadertech
[2006/10/25 19:18:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Macromedia
[2009/02/20 20:11:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Malwarebytes
[2008/09/16 19:01:16 | 00,000,000 | –SD | M] – C:\Documents and Settings\Dan Mueller\Application Data\Microsoft
[2008/06/26 12:28:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Move Networks
[2008/11/06 20:57:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Sibelius Software
[2008/09/09 15:30:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Snapfish
[2009/02/18 20:22:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\SUPERAntiSpyware.com
[2009/02/21 11:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\Tasks\21256B95F0F6E1BD.job
[2006/05/08 20:00:01 | 00,000,440 | —- | M] () – C:\WINDOWS\Tasks\Boxing.job
[2004/08/03 19:07:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2006/05/30 18:37:51 | 00,000,632 | —- | M] () – C:\WINDOWS\Tasks\EPG_REC_000.job
[2009/02/21 03:30:00 | 00,000,438 | —- | M] () – C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job
[2009/02/20 22:03:45 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/20 18:01:02 | 00,000,526 | —- | M] () – C:\WINDOWS\Tasks\Scheduled scanning task.job
========== Purity Check ==========
========== Custom Scans ==========
========== Net Services ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\NetSvcs
6to4 - -
AppMgmt - C:\WINDOWS\System32\appmgmts.dll - (Microsoft Corporation)
AudioSrv - C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation)
Browser - C:\WINDOWS\System32\browser.dll - (Microsoft Corporation)
CryptSvc - C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation)
DMServer - C:\WINDOWS\System32\dmserver.dll - (Microsoft Corp.)
DHCP - C:\WINDOWS\System32\dhcpcsvc.dll - (Microsoft Corporation)
ERSvc - C:\WINDOWS\System32\ersvc.dll - (Microsoft Corporation)
EventSystem - C:\WINDOWS\system32\es.dll - (Microsoft Corporation)
FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
HidServ - C:\WINDOWS\System32\hidserv.dll - (Microsoft Corporation)
Ias - -
Iprip - -
Irmon - -
LanmanServer - C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - C:\WINDOWS\System32\wkssvc.dll - (Microsoft Corporation)
Messenger - C:\WINDOWS\System32\msgsvc.dll - (Microsoft Corporation)
Netman - C:\WINDOWS\System32\netman.dll - (Microsoft Corporation)
Nla - C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation)
Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation)
NWCWorkstation - -
Nwsapagent - -
Rasauto - C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation)
Rasman - C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation)
Remoteaccess - C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation)
Schedule - C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation)
Seclogon - C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation)
SENS - C:\WINDOWS\system32\sens.dll - (Microsoft Corporation)
Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll - (Microsoft Corporation)
SRService - C:\WINDOWS\system32\srsvc.dll - (Microsoft Corporation)
Tapisrv - C:\WINDOWS\System32\tapisrv.dll - (Microsoft Corporation)
Themes - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
TrkWks - C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation)
W32Time - C:\WINDOWS\system32\w32time.dll - (Microsoft Corporation)
WZCSVC - C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation)
Wmi - C:\WINDOWS\System32\advapi32.dll - (Microsoft Corporation)
WmdmPmSp - -
winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
wscsvc - C:\WINDOWS\system32\wscsvc.dll - (Microsoft Corporation)
xmlprov - C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation)
BITS - C:\WINDOWS\system32\qmgr.dll - (Microsoft Corporation)
wuauserv - C:\WINDOWS\system32\wuauserv.dll - (Microsoft Corporation)
ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll - (Microsoft Corporation)
========== Disabled MS Config ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
"system.ini" - 0
"win.ini" - 0
"bootini" - 0
"services" - 0
"startup" - 0
========== SafeBoot-Minimal Settings ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
Primary disk - Driver Group
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
System Bus Extender - Driver Group
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
========== SafeBoot-Network Settings ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\
AFD - %SystemRoot%\System32\drivers\afd.sys - (Microsoft Corporation)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
Browser - %SystemRoot%\System32\browser.dll - (Microsoft Corporation)
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
Dhcp - %SystemRoot%\System32\dhcpcsvc.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
DnsCache - %SystemRoot%\System32\dnsrslvr.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
ip6fw.sys - %SystemRoot%\system32\DRIVERS\Ip6Fw.sys - (Microsoft Corporation)
ipnat.sys - %SystemRoot%\system32\DRIVERS\ipnat.sys - (Microsoft Corporation)
LanmanServer - %SystemRoot%\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll - (Microsoft Corporation)
LmHosts - %SystemRoot%\System32\lmhsvc.dll - (Microsoft Corporation)
Messenger - %SystemRoot%\System32\msgsvc.dll - (Microsoft Corporation)
NDIS - %SystemRoot%\System32\drivers\ndis.sys - (Microsoft Corporation)
NDIS Wrapper - Driver Group
Ndisuio - %SystemRoot%\system32\DRIVERS\ndisuio.sys - (Microsoft Corporation)
NetBIOS - %SystemRoot%\system32\DRIVERS\netbios.sys - (Microsoft Corporation)
NetBIOSGroup - Driver Group
NetBT - %SystemRoot%\system32\DRIVERS\netbt.sys - (Microsoft Corporation)
NetDDEGroup - Driver Group
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
NetMan - %SystemRoot%\System32\netman.dll - (Microsoft Corporation)
Network - Driver Group
NetworkProvider - Driver Group
NtLmSsp - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
PNP_TDI - Driver Group
Primary disk - Driver Group
rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys - (Microsoft Corporation)
rdpdd.sys - %SystemRoot%\System32\rdpdd.dll - (Microsoft Corporation)
rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys - (Microsoft Corporation)
rdsessmgr - %SystemRoot%\system32\sessmgr.exe - (Microsoft Corporation)
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
SharedAccess - %SystemRoot%\System32\ipnathlp.dll - (Microsoft Corporation)
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
Streams Drivers - Driver Group
System Bus Extender - Driver Group
Tcpip - %SystemRoot%\system32\DRIVERS\tcpip.sys - (Microsoft Corporation)
TDI - Driver Group
tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys - (Microsoft Corporation)
tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys - (Microsoft Corporation)
termservice - %SystemRoot%\System32\termsrv.dll - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
WZCSVC - %SystemRoot%\System32\wzcsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} - Net
{4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
========== Alternate Data Streams ==========
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dan Mueller\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dan Mueller\Desktop\Thumbs.db:encryptable
< End of report >
Second report:
OTListIt Extras logfile created on: 2/21/2009 11:37:32 AM - Run
OTListIt2 by OldTimer - Version 2.0.1.0 Folder = C:\Documents and Settings\Dan Mueller\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 61.31% Memory free
2.60 Gb Paging File | 1.73 Gb Available in Paging File | 66.60% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 58.30 Gb Free Space | 52.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MUELLER2-XP
Current User Name: Dan Mueller
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:MSI starter (Nero AG)
C:\Program Files\Common Files\Ahead\Nero Web\SetupXu.exe:*:Enabled:MSI starter (Nero AG)
C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime (Nero AG)
C:\Documents and Settings\Dan Mueller\Desktop\HP\setup\HPZnet01.exe:*:Enabled:hpznet01.exe (Hewlett-Packard)
C:\Documents and Settings\Dan Mueller\Desktop\HP\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe (Hewlett-Packard Development Company, L.P.)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease\setup\HPZnet01.exe:*:Enabled:hpznet01.exe (Hewlett-Packard)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe (Hewlett-Packard Development Company, L.P.)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease_\setup\HPZnet01.exe:*:Enabled:hpznet01.exe (Hewlett-Packard)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease_\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe (Hewlett-Packard Development Company, L.P.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )
C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home (Nero AG)
C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing (Microsoft Corporation)
D:\setup\HPZNET01.EXE:*:Enabled:hpznet01.exe File not found
D:\setup\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe File not found
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1505D9B1-6037-4310-815A-4D8A212C5075}" = Nancy Drew: The Phantom of Venice
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A9DEF19-760C-4e01-958F-D9B8E6C61B90}" = c5100_Help
"{1DB2FBA5-D57A-42A7-8E87-5B3EEBED8283}" = Wal-Mart Music Downloads Store
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{24328842-A29C-4FEA-81D3-1929D3A7F1AE}" = Nancy Drew: Legend of the Crystal Skull
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = HydraVision
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{536F7C74-844B-4683-B0C5-EA39E19A6FE3}" = Microsoft AntiSpyware
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5783F2D7-4001-0409-0002-0060B0CE6BBA}" = AutoCAD 2006 - English
"{5AF8C46D-A141-4E69-9EB5-76A43ED29281}" = Charter High Speed Internet Self-Installation Wizard
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{60D8CA34-642C-476F-AB4E-94DECCAEED69}" = The White Wolf of Icicle Creek
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{76E2BCDC-C7F3-4ACE-BC25-50DC7B24D526}" = Microsoft IntelliPoint 5.1
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Pro Trial
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{7FA4C993-5B8A-4AF2-9F2B-BC9CE7386947}" = ATI Decoder
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{8F36E44A-E6E7-41B7-B6F6-4637BF84EFA5}" = ATI Remote Wonder
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{95738B44-49CF-4C62-A620-320F1007B14A}" = SpiralFrog Download Manager 0.8.25
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}" = GUIDE PLUS+™ for Windows® System - ATI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C6F61A3-17C1-43BB-984D-3B26E29532B8}" = Microsoft IntelliType Pro 5.1
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A3DD7BA6-37A6-4245-A167-B3AA137B2157}" = TitanTV Client components for ATI
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A918DE8A-98C8-0900-0000-000000120040}" = Samsung A840 USB - Handset Manager V9
"{A918DE8A-98C8-0900-0001-000000000000}" = Multimedia Samples
"{AA67205C-3E80-4062-9198-253A059DEE38}" = Diskeeper Professional Edition
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B3B9BC18-2A09-4728-9B46-12E85FF3F628}" = C5100
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3D82C0B-3592-4B03-A970-F84C081A8152}" = Nancy Drew: Danger by Design
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D32AF9BC-9BE6-462E-A1B1-03EDB1EF1033}" = Nero 7 Ultra Edition
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E064390A-2F64-4195-9A55-30D4B20B865A}" = WDCSAM Driver
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E8626A59-FD0E-449C-A23A-C52FC0733629}" = Tseries BIOS Update
"{EA1A669B-302B-4E6E-BD23-FA5572A7A85C}" = AMD Power Monitor
"{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}" = ATI Catalyst Control Center
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4EC2FB1-4255-4040-8DE6-5D75FA9D039F}" = Nancy Drew: The Creature of Kapu Cave
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F6B2ED65-7378-4065-802D-F2E5689F3A4E}" = Photo Viewer
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"8A1D0449E9CBCC93DCB0CF47934D695423632CA7" = Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (12/05/2006 1.0.0007.0)
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Canon Camera WIA Driver PowerShot A40" = Canon PowerShot A40 WIA Driver
"CloneDVD.exe_is1" = CloneDVD 3.5
"C-Media Audio Driver" = C-Media WDM Audio Driver
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CoreVorbis Audio Decoder" = CoreVorbis Audio Decoder (remove only)
"Creative Writer 2" = Microsoft Creative Writer 2
"DVD Decrypter" = DVD Decrypter (Remove Only)
"ffdshow" = ffdshow (remove only)
"F-Secure Product 444" = Charter Security Suite
"Google Desktop" = Google Desktop
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"HUFFYUV" = Huffyuv AVI lossless video codec (Remove Only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center 9.08
"InstallShield_{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{7FA4C993-5B8A-4AF2-9F2B-BC9CE7386947}" = ATI Decoder
"InstallShield_{8F36E44A-E6E7-41B7-B6F6-4637BF84EFA5}" = ATI Remote Wonder 3.02
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live & Sponsor (CiD)
"mflGameDay_is1" = myfantasyleague.com Game Day 2008
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"mmswitch" = Morgan Stream Switcher
"Money2005b" = Microsoft Money 2005
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Musicnotes Player_is1" = Musicnotes Player V1.23.2
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OggDS" = Direct Show Ogg Vorbis Filter (remove only)
"Picasa2" = Picasa 2
"PrintMaster 8.0" = PrintMaster® Gold 8.0
"Serif DrawPlus 3.0" = Serif DrawPlus 3.0
"SHRThinkingGamesDeluxe" = Schoolhouse Rock Thinking Games Deluxe
"Sibelius Scorch Plugin" = Sibelius Scorch Plugin
"Smart DVD Creator Pro_is1" = Smart DVD Creator Pro
"UFileDownloadD" = Versal FileDownload ActiveX Control Trial Version
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Web Publishing Wizard
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/17/2009 11:04:21 PM | Computer Name = MUELLER2-XP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 2/17/2009 11:04:59 PM | Computer Name = MUELLER2-XP | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: MUELLER2-XP ExceptionManager.TimeStamp: 2/17/2009
9:04:59 PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement,
Version=1.0.0.0, Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName:
Spiralfrog.exe ExceptionManager.ThreadIdentity: ExceptionManager.WindowsIdentity:
MUELLER2-XP\Dan Mueller 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The BITS service returned an error for the job with
the ID '7ed3304a-5d5c-4acd-8b55-362891a5e529'; the job's name and description are
'Updater job.' and 'Updater: Download the Server XML File.'. The BITS service
error message for this job is 'The server name or address could not be resolved '.
This
job has been canceled, and the DownloaderManager will attempt it again. If you
see this error frequently, you may have a mis-configuration, or another administrator
process/user is canceling BITS jobs. It is also possible that some mis-configuration
of the Manifest file is causing BITS to have trouble with a source or destination
path; be sure that all SOURCE paths are valid URLs, and that all DESTINATION paths
are valid LOCAL UNC paths–__shares are not allowed__. TargetSite: NULL HelpLink:
NULL Source: NULL
Error - 2/17/2009 11:05:09 PM | Computer Name = MUELLER2-XP | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: MUELLER2-XP ExceptionManager.TimeStamp: 2/17/2009
9:05:08 PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement,
Version=1.0.0.0, Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName:
Spiralfrog.exe ExceptionManager.ThreadIdentity: ExceptionManager.WindowsIdentity:
MUELLER2-XP\Dan Mueller 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. TargetSite: NULL HelpLink: NULL Source: NULL 2) Exception Information
*********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F. TargetSite: Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()
Error - 2/18/2009 9:19:58 AM | Computer Name = MUELLER2-XP | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x008e2330.
Error - 2/18/2009 7:24:07 PM | Computer Name = MUELLER2-XP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/18/2009 7:47:06 PM | Computer Name = MUELLER2-XP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/19/2009 1:31:21 AM | Computer Name = MUELLER2-XP | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: MUELLER2-XP ExceptionManager.TimeStamp: 2/18/2009
11:31:20 PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement,
Version=1.0.0.0, Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName:
Spiralfrog.exe ExceptionManager.ThreadIdentity: ExceptionManager.WindowsIdentity:
MUELLER2-XP\Dan Mueller 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. TargetSite: NULL HelpLink: NULL Source: NULL 2) Exception Information
*********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F. TargetSite: Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()
Error - 2/19/2009 9:03:07 PM | Computer Name = MUELLER2-XP | Source = F-Secure Anti-Virus | ID = 103
Description = 1 2009-02-19 19:03:07-05:00 mueller2-xp MUELLER2-XP\Dan Mueller
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Dan
Mueller\Local Settings\Temporary Internet Files\Content.IE5\5QOC925Y\equi[1].htm.
Infection: Packed.JS.Agent.y Action: failed.
Error - 2/20/2009 3:59:10 AM | Computer Name = MUELLER2-XP | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2009-02-20 01:59:10-05:00 mueller2-xp MUELLER2-XP\Dan Mueller
F-Secure Anti-Virus Crash detected.
Error - 2/21/2009 12:11:33 AM | Computer Name = MUELLER2-XP | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x009174fc.
[ System Events ]
Error - 2/20/2009 10:41:28 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:01:45 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:16:33 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:16:53 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:26:06 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:26:32 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:32:33 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/20/2009 11:51:34 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 2/21/2009 12:00:27 AM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 2/21/2009 12:02:01 AM | Computer Name = MUELLER2-XP | Source = Print | ID = 54
Description = Document
http://www.scoutingweb.com/scoutingweb/sub…TrefoilCere.htm
was corrupted and has been deleted. The associated driver is: HP Photosmart C5100
series.
< End of report >