This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] problem with rogue popups

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am getting popups when IE explorer is closed.

My AV is:

F-Secure Anti-Virus 8.10 build 14240
F-Secure Automatic Update Agent 8.23 build 2876
F-Secure User Interface 7.26 build 1090
F-Secure ISP News 1.00 build 127
F-Secure Management Agent 7.80 build 12726
F-Secure Parental Control 8.10 build 14230
F-Secure Spam Control 1.02 build 7040

I have ran superantispyware 4.25 and Malwarebytes Anti-malware 1.34

Here is HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:13 PM, on 2/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Charter Security Suite\Common\FSMA32.EXE
C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Charter Security Suite\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Charter Security Suite\Common\FCH32.EXE
C:\Program Files\Charter Security Suite\Common\FAMEH32.EXE
C:\Program Files\Charter Security Suite\Anti-Virus\fsqh.exe
C:\Program Files\Charter Security Suite\FSPC\fspc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe
C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe
C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Charter Security Suite\FSAUA\program\fsus.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Charter Security Suite\Common\FSM32.EXE
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\ATI Multimedia\main\ATISched.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Charter Security Suite\FSGUI\fsguidll.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Charter Security Suite\FSGUI\scanwizard.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: E-Zsoft VideoDownloaderToolBar - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - C:\Program Files\VersalSoft\InternetDownload\VDTB.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SpiralFrog] C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe
O4 - HKLM\..\Run: [InternetDownload_upgrade] "C:\Program Files\VersalSoft\InternetDownload\InternetDownload.exe" /upgrade
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Amok web bash obj] C:\Documents and Settings\All Users\Application Data\seek film amok web\2 FACE.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Charter Security Suite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Charter Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [admin window] C:\DOCUME~1\DANMUE~1\APPLIC~1\DALESU~1\loudknob.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://www.mykohlerco.com/postauthI/epi.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191095838078
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-5756917e812a938f.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqaio/downloads/msxml4.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://charter.net/files/charter/securitysuite/fscax.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Charter Security Suite\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 13356 bytes


TIA
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
here are the results:

OTListIt logfile created on: 2/21/2009 11:37:32 AM - Run
OTListIt2 by OldTimer - Version 2.0.1.0 Folder = C:\Documents and Settings\Dan Mueller\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 61.31% Memory free
2.60 Gb Paging File | 1.73 Gb Available in Paging File | 66.60% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 58.30 Gb Free Space | 52.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MUELLER2-XP
Current User Name: Dan Mueller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE (F-Secure Corp.)
PRC - C:\Program Files\Charter Security Suite\Common\FSMB32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FCH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FAMEH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsqh.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FSPC\fspc.exe (F-Secure Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe (F-Secure Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe (F-Secure Corp.)
PRC - C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Charter Security Suite\FSAUA\program\fsus.exe (F-Secure Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Charter Security Suite\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Multimedia\main\ATISched.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Charter Security Suite\FSGUI\fsguidll.exe (F-Secure Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\FSGUI\scanwizard.exe (F-Secure Corporation)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE (Hewlett-Packard Company)
PRC - C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (Autodesk Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Diskeeper [Auto | Running]) – C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
SRV - (F-Secure Gatekeeper Handler Starter [Auto | Running]) – C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (FSAUA [On_Demand | Running]) – C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe (F-Secure Corporation)
SRV - (FSDFWD [On_Demand | Running]) – C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (FSMA [Auto | Running]) – C:\Program Files\Charter Security Suite\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSORSPClient [On_Demand | Running]) – C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdLLD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AmdLLD.sys (AMD, Inc.)
DRV - (ATI Remote Wonder II [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ATIRWVD.SYS (Jungo)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATITUNEP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atintuxx.sys (ATI Technologies Inc.)
DRV - (ativraxx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinxsxx.sys (ATI Technologies Inc.)
DRV - (BS_Flash [On_Demand | Stopped]) – C:\Program Files\Tseries BIOS Update\Award\BS_Flash.sys ()
DRV - (BS_I2cIo [System | Running]) – C:\WINDOWS\system32\drivers\BS_I2cIo.sys (BIOSTAR Group)
DRV - (cmuda [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (F-Secure Filter [Disabled | Stopped]) – C:\Program Files\Charter Security Suite\Anti-Virus\Win2K\FSfilter.sys ()
DRV - (F-Secure Gatekeeper [On_Demand | Running]) – C:\Program Files\Charter Security Suite\Anti-Virus\minifilter\fsgk.sys ()
DRV - (F-Secure HIPS [System | Running]) – C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (F-Secure Recognizer [Disabled | Stopped]) – C:\Program Files\Charter Security Suite\Anti-Virus\Win2K\FSrec.sys ()
DRV - (FETNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (fsbts [Boot | Running]) – C:\WINDOWS\system32\Drivers\fsbts.sys ()
DRV - (FSFW [Boot | Running]) – C:\WINDOWS\System32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (MA8212M [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MA8212M.sys (Mobile Action Technology Inc.)
DRV - (MA8212U [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MA8212U.sys (Mobile Action Technology Inc.)
DRV - (MaRdPnp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys (Mobile Action Technology Inc.)
DRV - (MaVctrl [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MVDCODEC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (NuidFltr [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV - (nvatabus [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENET [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NVENET.sys (NVIDIA Corporation)
DRV - (nvidesm [Boot | Running]) – C:\WINDOWS\system32\drivers\nvidesm.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (PCDCODEC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (Point32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (WinDriver6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (XUIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (731 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (E-Zsoft VideoDownloaderToolBar) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - C:\Program Files\VersalSoft\InternetDownload\VDTB.dll ()
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD_Display] File not found
O4 - HKLM..\Run: [Amok web bash obj] C:\Documents and Settings\All Users\Application Data\seek film amok web\2 FACE.exe (Tseet sipl isu)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [F-Secure Manager] "C:\Program Files\Charter Security Suite\Common\FSM32.EXE" /splash (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] "C:\Program Files\Charter Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW (F-Secure Corporation)
O4 - HKLM..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [InternetDownload_upgrade] "C:\Program Files\VersalSoft\InternetDownload\InternetDownload.exe" /upgrade File not found
O4 - HKLM..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear (NVIDIA)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [WD Button Manager] WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [admin window] C:\DOCUME~1\DANMUE~1\APPLIC~1\DALESU~1\loudknob.exe (Mass itibre)
O4 - HKCU..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe (ATI Technologies Inc.)
O4 - HKCU..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll (F-Secure Corporation)
O9 - Extra 'Tools' menuitem : Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll (F-Secure Corporation)
O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (ATI Technologies Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} https://www.mykohlerco.com/postauthI/epi.cab (Aventail Installer )
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1191095838078 (MUWebControl Class)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://cid-5756917e812a938f.spaces.live.co…ad/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} http://ipgweb.cce.hp.com/rdqaio/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://charter.net/files/charter/securitysuite/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {9EF34FF2-3396-4527-9D27-04C8C1C67806} - C:\Program Files\Microsoft AntiSpyware\shellextension.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.SOL () - [ NTFS ]
O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe – File not found
O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell - "" = AutoRun
O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell\AutoRun\command - "" = F:\Photokinz.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Documents and Settings\Dan Mueller\My Documents\*.tmp files]
[2009/02/21 11:35:38 | 00,494,080 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe
[2009/02/21 00:11:33 | 00,004,066 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\computer results.zip
[2009/02/21 00:05:47 | 00,050,688 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Logfile of Trend Micro HJT v2.doc
[2009/02/20 23:24:33 | 00,001,744 | —- | C] () – C:\Documents and Settings\Dan Mueller\Desktop\HijackThis.lnk
[2009/02/20 23:24:32 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/20 20:11:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\Malwarebytes
[2009/02/20 20:11:07 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/20 20:11:07 | 00,000,706 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/20 20:11:04 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/20 20:11:03 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/20 20:11:03 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/20 20:10:00 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Dan Mueller\Desktop\mbam-setup.exe
[2009/02/18 23:41:29 | 00,000,526 | —- | C] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2009/02/18 20:22:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/02/18 20:22:23 | 00,000,790 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/02/18 20:22:21 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/02/18 20:22:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\SUPERAntiSpyware.com
[2009/02/18 20:21:39 | 06,006,816 | —- | C] () – C:\Documents and Settings\Dan Mueller\Desktop\SUPERAntiSpyware.exe
[2009/02/18 07:19:24 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Fitness Friday Weekend.doc
[2009/02/17 19:42:29 | 00,000,000 | —D | C] – C:\Program Files\NoAdware
[2009/02/16 22:50:08 | 00,033,408 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/16 22:30:18 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\F-Secure
[2009/02/16 22:22:26 | 00,079,904 | —- | C] (F-Secure Corporation) – C:\WINDOWS\System32\drivers\fsdfw.sys
[2009/02/16 22:21:02 | 00,000,000 | —D | C] – C:\Program Files\Charter Security Suite
[2009/02/16 22:20:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\fssg
[2009/02/16 20:51:57 | 00,000,000 | —D | C] – C:\fsaua.data
[2009/02/16 20:31:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\f-secure
[2009/02/14 20:18:54 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/02/09 19:38:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\My Documents\My Chat Logs
[2009/02/09 19:16:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/02/09 19:15:43 | 00,000,296 | -H– | C] () – C:\WINDOWS\tasks\21256B95F0F6E1BD.job
[2009/02/09 19:15:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\seek film amok web
[2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Program Files\dalesurfpeak
[2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak
[2009/02/09 19:15:11 | 00,000,000 | —D | C] – C:\Program Files\Circle Dvelopement
[2009/02/09 19:15:07 | 00,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
[2009/02/01 13:46:29 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Mark Marcus's bingo news.doc

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\drivers\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Dan Mueller\My Documents\*.tmp files]
[2009/02/21 11:36:32 | 00,494,080 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe
[2009/02/21 11:34:02 | 00,000,678 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/21 11:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\tasks\21256B95F0F6E1BD.job
[2009/02/21 03:30:00 | 00,000,438 | —- | M] () – C:\WINDOWS\tasks\RegistrySmart Scheduled Scan.job
[2009/02/21 00:11:33 | 00,004,066 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\computer results.zip
[2009/02/21 00:05:48 | 00,050,688 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Logfile of Trend Micro HJT v2.doc
[2009/02/20 23:24:33 | 00,001,744 | —- | M] () – C:\Documents and Settings\Dan Mueller\Desktop\HijackThis.lnk
[2009/02/20 22:03:57 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/20 22:03:45 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/20 22:03:44 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/20 22:00:25 | 02,096,656 | -H– | M] () – C:\Documents and Settings\Dan Mueller\Local Settings\Application Data\IconCache.db
[2009/02/20 20:30:16 | 00,001,100 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/20 20:11:07 | 00,000,706 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/20 20:10:00 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Dan Mueller\Desktop\mbam-setup.exe
[2009/02/20 18:01:02 | 00,000,526 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2009/02/19 19:05:01 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/02/19 19:05:01 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/02/19 19:03:55 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/02/19 19:03:55 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/02/18 20:22:23 | 00,000,790 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/02/18 20:21:51 | 06,006,816 | —- | M] () – C:\Documents and Settings\Dan Mueller\Desktop\SUPERAntiSpyware.exe
[2009/02/18 16:43:49 | 00,020,992 | —- | M] () – C:\Documents and Settings\Dan Mueller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/18 07:19:25 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Fitness Friday Weekend.doc
[2009/02/17 22:13:44 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/02/17 21:22:52 | 00,000,046 | —- | M] () – C:\AUTOEXEC.SOL
[2009/02/16 22:50:08 | 00,033,408 | —- | M] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/16 22:22:36 | 00,535,758 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/16 22:22:36 | 00,451,656 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/16 22:22:36 | 00,075,396 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/16 20:22:34 | 00,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/11 03:01:38 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/10 18:21:50 | 00,000,587 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\My Sharing Folders.lnk
[2009/02/03 17:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/01 19:51:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/02/01 19:51:13 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/02/01 19:39:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/01 19:39:23 | 00,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/01 13:53:26 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Mark Marcus's bingo news.doc
[2009/01/31 14:45:56 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/31 14:45:56 | 00,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/30 18:59:53 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/30 15:51:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/30 15:51:54 | 00,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/30 10:15:48 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/30 10:15:48 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/29 18:31:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/29 18:31:43 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/29 18:30:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/29 18:30:31 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/29 12:47:33 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/01/29 12:47:33 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/01/29 08:08:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/01/29 08:08:00 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/01/28 18:37:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/01/28 18:37:45 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/01/28 18:35:30 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/28 18:35:30 | 00,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/01/28 18:32:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/28 18:32:23 | 00,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/28 18:31:37 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/28 18:31:37 | 00,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/28 18:30:22 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/01/28 18:30:22 | 00,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/28 18:29:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/01/28 18:29:11 | 00,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/28 18:26:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/28 18:26:35 | 00,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/01/28 18:21:48 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/01/28 18:21:48 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/01/28 18:20:50 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/28 18:20:50 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/22 16:23:14 | 00,428,032 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Moms GS Game List.max

========== LOP Check ==========

[2009/02/20 20:11:03 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/10 18:46:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/04/30 09:46:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2007/07/09 14:59:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/07/09 15:01:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/18 19:19:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI MMC
[2005/06/08 18:55:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/02/16 22:22:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2009/02/16 22:20:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2006/10/16 17:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2006/05/24 21:08:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2006/05/24 19:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/02/23 20:36:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/02/20 20:11:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/16 20:17:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/04/29 17:32:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2009/02/09 19:16:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2008/02/03 16:47:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/01/20 18:14:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2008/11/06 19:53:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/09/11 11:32:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2007/09/29 13:52:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/09 19:15:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\seek film amok web
[2007/09/27 01:19:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2008/04/29 17:42:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/01/20 18:15:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/02/18 20:22:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/01/18 21:31:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/23 20:35:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\WD
[2007/09/29 13:52:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2004/01/10 23:09:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2006/05/22 16:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\X10 Settings
[2009/02/20 21:57:29 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Dan Mueller\Application Data
[2009/02/04 21:25:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Adobe
[2008/09/10 18:27:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\AdobeUM
[2008/04/04 15:45:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Ahead
[2007/07/09 15:01:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Apple Computer
[2005/06/06 11:06:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\ATI
[2008/12/31 15:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\ATI MMC
[2005/06/08 18:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Autodesk
[2007/11/20 21:11:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Aventail
[2009/02/09 19:15:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak
[2009/02/16 22:30:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\F-Secure
[2006/10/16 17:08:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Google
[2006/05/24 21:08:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Dan Mueller\Application Data\GTek
[2005/06/06 10:39:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Help
[2007/09/30 20:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\HP
[2005/06/06 05:29:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Identities
[2008/09/10 20:21:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Image Zone Express
[2008/07/09 20:24:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\InstallShield
[2009/02/16 20:10:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Lavasoft
[2005/06/08 13:09:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Leadertech
[2006/10/25 19:18:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Macromedia
[2009/02/20 20:11:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Malwarebytes
[2008/09/16 19:01:16 | 00,000,000 | –SD | M] – C:\Documents and Settings\Dan Mueller\Application Data\Microsoft
[2008/06/26 12:28:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Move Networks
[2008/11/06 20:57:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Sibelius Software
[2008/09/09 15:30:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\Snapfish
[2009/02/18 20:22:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dan Mueller\Application Data\SUPERAntiSpyware.com
[2009/02/21 11:00:00 | 00,000,296 | -H– | M] () – C:\WINDOWS\Tasks\21256B95F0F6E1BD.job
[2006/05/08 20:00:01 | 00,000,440 | —- | M] () – C:\WINDOWS\Tasks\Boxing.job
[2004/08/03 19:07:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2006/05/30 18:37:51 | 00,000,632 | —- | M] () – C:\WINDOWS\Tasks\EPG_REC_000.job
[2009/02/21 03:30:00 | 00,000,438 | —- | M] () – C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job
[2009/02/20 22:03:45 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/02/20 18:01:02 | 00,000,526 | —- | M] () – C:\WINDOWS\Tasks\Scheduled scanning task.job

========== Purity Check ==========


========== Custom Scans ==========



========== Net Services ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\NetSvcs

6to4 - -
AppMgmt - C:\WINDOWS\System32\appmgmts.dll - (Microsoft Corporation)
AudioSrv - C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation)
Browser - C:\WINDOWS\System32\browser.dll - (Microsoft Corporation)
CryptSvc - C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation)
DMServer - C:\WINDOWS\System32\dmserver.dll - (Microsoft Corp.)
DHCP - C:\WINDOWS\System32\dhcpcsvc.dll - (Microsoft Corporation)
ERSvc - C:\WINDOWS\System32\ersvc.dll - (Microsoft Corporation)
EventSystem - C:\WINDOWS\system32\es.dll - (Microsoft Corporation)
FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
HidServ - C:\WINDOWS\System32\hidserv.dll - (Microsoft Corporation)
Ias - -
Iprip - -
Irmon - -
LanmanServer - C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - C:\WINDOWS\System32\wkssvc.dll - (Microsoft Corporation)
Messenger - C:\WINDOWS\System32\msgsvc.dll - (Microsoft Corporation)
Netman - C:\WINDOWS\System32\netman.dll - (Microsoft Corporation)
Nla - C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation)
Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation)
NWCWorkstation - -
Nwsapagent - -
Rasauto - C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation)
Rasman - C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation)
Remoteaccess - C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation)
Schedule - C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation)
Seclogon - C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation)
SENS - C:\WINDOWS\system32\sens.dll - (Microsoft Corporation)
Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll - (Microsoft Corporation)
SRService - C:\WINDOWS\system32\srsvc.dll - (Microsoft Corporation)
Tapisrv - C:\WINDOWS\System32\tapisrv.dll - (Microsoft Corporation)
Themes - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
TrkWks - C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation)
W32Time - C:\WINDOWS\system32\w32time.dll - (Microsoft Corporation)
WZCSVC - C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation)
Wmi - C:\WINDOWS\System32\advapi32.dll - (Microsoft Corporation)
WmdmPmSp - -
winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
wscsvc - C:\WINDOWS\system32\wscsvc.dll - (Microsoft Corporation)
xmlprov - C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation)
BITS - C:\WINDOWS\system32\qmgr.dll - (Microsoft Corporation)
wuauserv - C:\WINDOWS\system32\wuauserv.dll - (Microsoft Corporation)
ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll - (Microsoft Corporation)


========== Disabled MS Config ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state

"system.ini" - 0
"win.ini" - 0
"bootini" - 0
"services" - 0
"startup" - 0


========== SafeBoot-Minimal Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\

AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
Primary disk - Driver Group
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
System Bus Extender - Driver Group
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices


========== SafeBoot-Network Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\

AFD - %SystemRoot%\System32\drivers\afd.sys - (Microsoft Corporation)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
Browser - %SystemRoot%\System32\browser.dll - (Microsoft Corporation)
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
Dhcp - %SystemRoot%\System32\dhcpcsvc.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
DnsCache - %SystemRoot%\System32\dnsrslvr.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
ip6fw.sys - %SystemRoot%\system32\DRIVERS\Ip6Fw.sys - (Microsoft Corporation)
ipnat.sys - %SystemRoot%\system32\DRIVERS\ipnat.sys - (Microsoft Corporation)
LanmanServer - %SystemRoot%\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - %SystemRoot%\System32\wkssvc.dll - (Microsoft Corporation)
LmHosts - %SystemRoot%\System32\lmhsvc.dll - (Microsoft Corporation)
Messenger - %SystemRoot%\System32\msgsvc.dll - (Microsoft Corporation)
NDIS - %SystemRoot%\System32\drivers\ndis.sys - (Microsoft Corporation)
NDIS Wrapper - Driver Group
Ndisuio - %SystemRoot%\system32\DRIVERS\ndisuio.sys - (Microsoft Corporation)
NetBIOS - %SystemRoot%\system32\DRIVERS\netbios.sys - (Microsoft Corporation)
NetBIOSGroup - Driver Group
NetBT - %SystemRoot%\system32\DRIVERS\netbt.sys - (Microsoft Corporation)
NetDDEGroup - Driver Group
Netlogon - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
NetMan - %SystemRoot%\System32\netman.dll - (Microsoft Corporation)
Network - Driver Group
NetworkProvider - Driver Group
NtLmSsp - %SystemRoot%\system32\lsass.exe - (Microsoft Corporation)
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
PNP_TDI - Driver Group
Primary disk - Driver Group
rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys - (Microsoft Corporation)
rdpdd.sys - %SystemRoot%\System32\rdpdd.dll - (Microsoft Corporation)
rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys - (Microsoft Corporation)
rdsessmgr - %SystemRoot%\system32\sessmgr.exe - (Microsoft Corporation)
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
SharedAccess - %SystemRoot%\System32\ipnathlp.dll - (Microsoft Corporation)
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
Streams Drivers - Driver Group
System Bus Extender - Driver Group
Tcpip - %SystemRoot%\system32\DRIVERS\tcpip.sys - (Microsoft Corporation)
TDI - Driver Group
tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys - (Microsoft Corporation)
tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys - (Microsoft Corporation)
termservice - %SystemRoot%\System32\termsrv.dll - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
WZCSVC - %SystemRoot%\System32\wzcsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} - Net
{4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

========== Alternate Data Streams ==========

@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dan Mueller\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dan Mueller\Desktop\Thumbs.db:encryptable
< End of report >


Second report:
OTListIt Extras logfile created on: 2/21/2009 11:37:32 AM - Run
OTListIt2 by OldTimer - Version 2.0.1.0 Folder = C:\Documents and Settings\Dan Mueller\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 61.31% Memory free
2.60 Gb Paging File | 1.73 Gb Available in Paging File | 66.60% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 58.30 Gb Free Space | 52.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MUELLER2-XP
Current User Name: Dan Mueller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:MSI starter (Nero AG)
C:\Program Files\Common Files\Ahead\Nero Web\SetupXu.exe:*:Enabled:MSI starter (Nero AG)
C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime (Nero AG)
C:\Documents and Settings\Dan Mueller\Desktop\HP\setup\HPZnet01.exe:*:Enabled:hpznet01.exe (Hewlett-Packard)
C:\Documents and Settings\Dan Mueller\Desktop\HP\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe (Hewlett-Packard Development Company, L.P.)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease\setup\HPZnet01.exe:*:Enabled:hpznet01.exe (Hewlett-Packard)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe (Hewlett-Packard Development Company, L.P.)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease_\setup\HPZnet01.exe:*:Enabled:hpznet01.exe (Hewlett-Packard)
C:\Documents and Settings\Dan Mueller\Local Settings\Temp\hp_webrelease_\setup\hponicifs01.exe:*:Enabled:hponicifs01.exe (Hewlett-Packard Development Company, L.P.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe ()
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe (Hewlett-Packard)
C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe ( )
C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) (Microsoft Corporation)
C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Enabled:Nero Home (Nero AG)
C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing (Microsoft Corporation)
D:\setup\HPZNET01.EXE:*:Enabled:hpznet01.exe File not found
D:\setup\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe File not found
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{02DFF6B1-1654-411C-8D7B-FD6052EF016F}" = Apple Software Update
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1505D9B1-6037-4310-815A-4D8A212C5075}" = Nancy Drew: The Phantom of Venice
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A9DEF19-760C-4e01-958F-D9B8E6C61B90}" = c5100_Help
"{1DB2FBA5-D57A-42A7-8E87-5B3EEBED8283}" = Wal-Mart Music Downloads Store
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{24328842-A29C-4FEA-81D3-1929D3A7F1AE}" = Nancy Drew: Legend of the Crystal Skull
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = HydraVision
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{536F7C74-844B-4683-B0C5-EA39E19A6FE3}" = Microsoft AntiSpyware
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5783F2D7-4001-0409-0002-0060B0CE6BBA}" = AutoCAD 2006 - English
"{5AF8C46D-A141-4E69-9EB5-76A43ED29281}" = Charter High Speed Internet Self-Installation Wizard
"{5DE1B7CF-7429-40CA-987F-6BEE09B63787}" = Prime95
"{60D8CA34-642C-476F-AB4E-94DECCAEED69}" = The White Wolf of Icicle Creek
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{76E2BCDC-C7F3-4ACE-BC25-50DC7B24D526}" = Microsoft IntelliPoint 5.1
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Pro Trial
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{7FA4C993-5B8A-4AF2-9F2B-BC9CE7386947}" = ATI Decoder
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{8F36E44A-E6E7-41B7-B6F6-4637BF84EFA5}" = ATI Remote Wonder
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{95738B44-49CF-4C62-A620-320F1007B14A}" = SpiralFrog Download Manager 0.8.25
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}" = GUIDE PLUS+™ for Windows® System - ATI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C6F61A3-17C1-43BB-984D-3B26E29532B8}" = Microsoft IntelliType Pro 5.1
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A3DD7BA6-37A6-4245-A167-B3AA137B2157}" = TitanTV Client components for ATI
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A918DE8A-98C8-0900-0000-000000120040}" = Samsung A840 USB - Handset Manager V9
"{A918DE8A-98C8-0900-0001-000000000000}" = Multimedia Samples
"{AA67205C-3E80-4062-9198-253A059DEE38}" = Diskeeper Professional Edition
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}" = Windows Live Sign-in Assistant
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B3B9BC18-2A09-4728-9B46-12E85FF3F628}" = C5100
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3D82C0B-3592-4B03-A970-F84C081A8152}" = Nancy Drew: Danger by Design
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D32AF9BC-9BE6-462E-A1B1-03EDB1EF1033}" = Nero 7 Ultra Edition
"{D7A6C517-11F2-419F-B5BB-27772B939698}" = NvMixer
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E064390A-2F64-4195-9A55-30D4B20B865A}" = WDCSAM Driver
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E8626A59-FD0E-449C-A23A-C52FC0733629}" = Tseries BIOS Update
"{EA1A669B-302B-4E6E-BD23-FA5572A7A85C}" = AMD Power Monitor
"{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}" = ATI Catalyst Control Center
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F4EC2FB1-4255-4040-8DE6-5D75FA9D039F}" = Nancy Drew: The Creature of Kapu Cave
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F6B2ED65-7378-4065-802D-F2E5689F3A4E}" = Photo Viewer
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FE7E1DD7-EBCE-4696-ADE2-22BDBF2372DA}" = DocumentViewer
"8A1D0449E9CBCC93DCB0CF47934D695423632CA7" = Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM (12/05/2006 1.0.0007.0)
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Canon Camera WIA Driver PowerShot A40" = Canon PowerShot A40 WIA Driver
"CloneDVD.exe_is1" = CloneDVD 3.5
"C-Media Audio Driver" = C-Media WDM Audio Driver
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CoreVorbis Audio Decoder" = CoreVorbis Audio Decoder (remove only)
"Creative Writer 2" = Microsoft Creative Writer 2
"DVD Decrypter" = DVD Decrypter (Remove Only)
"ffdshow" = ffdshow (remove only)
"F-Secure Product 444" = Charter Security Suite
"Google Desktop" = Google Desktop
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 7.0
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"HUFFYUV" = Huffyuv AVI lossless video codec (Remove Only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3CBA0E30-6F54-47EF-910E-1D4D450AFE45}" = ATI Multimedia Center 9.08
"InstallShield_{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{7FA4C993-5B8A-4AF2-9F2B-BC9CE7386947}" = ATI Decoder
"InstallShield_{8F36E44A-E6E7-41B7-B6F6-4637BF84EFA5}" = ATI Remote Wonder 3.02
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live & Sponsor (CiD)
"mflGameDay_is1" = myfantasyleague.com Game Day 2008
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"mmswitch" = Morgan Stream Switcher
"Money2005b" = Microsoft Money 2005
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Musicnotes Player_is1" = Musicnotes Player V1.23.2
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OggDS" = Direct Show Ogg Vorbis Filter (remove only)
"Picasa2" = Picasa 2
"PrintMaster 8.0" = PrintMaster® Gold 8.0
"Serif DrawPlus 3.0" = Serif DrawPlus 3.0
"SHRThinkingGamesDeluxe" = Schoolhouse Rock Thinking Games Deluxe
"Sibelius Scorch Plugin" = Sibelius Scorch Plugin
"Smart DVD Creator Pro_is1" = Smart DVD Creator Pro
"UFileDownloadD" = Versal FileDownload ActiveX Control Trial Version
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Web Publishing Wizard
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/17/2009 11:04:21 PM | Computer Name = MUELLER2-XP | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.

Error - 2/17/2009 11:04:59 PM | Computer Name = MUELLER2-XP | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: MUELLER2-XP ExceptionManager.TimeStamp: 2/17/2009
9:04:59 PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement,
Version=1.0.0.0, Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName:
Spiralfrog.exe ExceptionManager.ThreadIdentity: ExceptionManager.WindowsIdentity:
MUELLER2-XP\Dan Mueller 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The BITS service returned an error for the job with
the ID '7ed3304a-5d5c-4acd-8b55-362891a5e529'; the job's name and description are
'Updater job.' and 'Updater: Download the Server XML File.'. The BITS service
error message for this job is 'The server name or address could not be resolved '.
This
job has been canceled, and the DownloaderManager will attempt it again. If you
see this error frequently, you may have a mis-configuration, or another administrator
process/user is canceling BITS jobs. It is also possible that some mis-configuration
of the Manifest file is causing BITS to have trouble with a source or destination
path; be sure that all SOURCE paths are valid URLs, and that all DESTINATION paths
are valid LOCAL UNC paths–__shares are not allowed__. TargetSite: NULL HelpLink:
NULL Source: NULL

Error - 2/17/2009 11:05:09 PM | Computer Name = MUELLER2-XP | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: MUELLER2-XP ExceptionManager.TimeStamp: 2/17/2009
9:05:08 PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement,
Version=1.0.0.0, Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName:
Spiralfrog.exe ExceptionManager.ThreadIdentity: ExceptionManager.WindowsIdentity:
MUELLER2-XP\Dan Mueller 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. TargetSite: NULL HelpLink: NULL Source: NULL 2) Exception Information
*********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F. TargetSite: Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

Error - 2/18/2009 9:19:58 AM | Computer Name = MUELLER2-XP | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x008e2330.

Error - 2/18/2009 7:24:07 PM | Computer Name = MUELLER2-XP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/18/2009 7:47:06 PM | Computer Name = MUELLER2-XP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/19/2009 1:31:21 AM | Computer Name = MUELLER2-XP | Source = Spiralfrog | ID = 0
Description = General Information ********************************************* Additional
Info: ExceptionManager.MachineName: MUELLER2-XP ExceptionManager.TimeStamp: 2/18/2009
11:31:20 PM ExceptionManager.FullName: Microsoft.ApplicationBlocks.ExceptionManagement,
Version=1.0.0.0, Culture=neutral, PublicKeyToken=null ExceptionManager.AppDomainName:
Spiralfrog.exe ExceptionManager.ThreadIdentity: ExceptionManager.WindowsIdentity:
MUELLER2-XP\Dan Mueller 1) Exception Information *********************************************
Exception
Type: System.Exception Message: The metadata file (the Server Manifest) can't be
downloaded for the application 'SpiralfrogClient'. Either the manifest is unavailable
(check download URL in Updater config file), the downloader failed, or the Manifest
failed validation. TargetSite: NULL HelpLink: NULL Source: NULL 2) Exception Information
*********************************************
Exception
Type: System.Runtime.InteropServices.COMException ErrorCode: -2145386481 Message:
Exception from HRESULT: 0x8020000F. TargetSite: Void GetError(Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundC
opyError
ByRef) HelpLink: NULL Source: Microsoft.ApplicationBlocks.ApplicationUpdater StackTrace
Information ********************************************* at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.IBackgroundCopyJob.Ge
tError(IBackgroundCopyError&
ppError) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Handle
DownloadErrorCancelJob(IBackgroundCopyJob
copyJob, String& errMessage) at Microsoft.ApplicationBlocks.ApplicationUpdater.Downloaders.BITSDownloader.Micros
oft.ApplicationBlocks.ApplicationUpdater.Interfaces.IDownloader.Download(String
sourceFile, String destFile, TimeSpan maxTimeWait) at Microsoft.ApplicationBlocks.ApplicationUpdater.DownloaderManager.IsServerManifes
tDownloaded()

Error - 2/19/2009 9:03:07 PM | Computer Name = MUELLER2-XP | Source = F-Secure Anti-Virus | ID = 103
Description = 1 2009-02-19 19:03:07-05:00 mueller2-xp MUELLER2-XP\Dan Mueller
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Dan
Mueller\Local Settings\Temporary Internet Files\Content.IE5\5QOC925Y\equi[1].htm.
Infection: Packed.JS.Agent.y Action: failed.

Error - 2/20/2009 3:59:10 AM | Computer Name = MUELLER2-XP | Source = F-Secure Anti-Virus | ID = 103
Description = 2 2009-02-20 01:59:10-05:00 mueller2-xp MUELLER2-XP\Dan Mueller
F-Secure Anti-Virus Crash detected.

Error - 2/21/2009 12:11:33 AM | Computer Name = MUELLER2-XP | Source = Application Error | ID = 1000
Description = Faulting application hpqste08.exe, version 70.0.170.0, faulting module
unknown, version 0.0.0.0, fault address 0x009174fc.

[ System Events ]
Error - 2/20/2009 10:41:28 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:01:45 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:16:33 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:16:53 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:26:06 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:26:32 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:32:33 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/20/2009 11:51:34 PM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 2/21/2009 12:00:27 AM | Computer Name = MUELLER2-XP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/21/2009 12:02:01 AM | Computer Name = MUELLER2-XP | Source = Print | ID = 54
Description = Document http://www.scoutingweb.com/scoutingweb/sub…TrefoilCere.htm
was corrupted and has been deleted. The associated driver is: HP Photosmart C5100
series.


< End of report >
hello


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [] File not found
    O4 - HKCU..\Run: [admin window] C:\DOCUME~1\DANMUE~1\APPLIC~1\DALESU~1\loudknob.exe (Mass itibre)
    O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\Shell\AutoRun\command - "" = D:\Autorun.exe – File not found
    O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell - "" = AutoRun
    O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\Shell\AutoRun\command - "" = F:\Photokinz.exe – File not found
    [2009/02/09 19:16:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    [2009/02/09 19:15:43 | 00,000,296 | -H– | C] () – C:\WINDOWS\tasks\21256B95F0F6E1BD.job
    [2009/02/09 19:15:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\seek film amok web
    [2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Program Files\dalesurfpeak
    [2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak
    [2009/02/09 19:15:11 | 00,000,000 | —D | C] – C:\Program Files\Circle Dvelopement
    [2009/02/09 19:15:07 | 00,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
    [2009/02/09 19:16:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    @Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5
    @Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
    @Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dan Mueller\My Documents\Thumbs.db:encryptable
    @Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dan Mueller\Desktop\Thumbs.db:encryptable
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
Here is the latest OLTI: ========== OTLISTIT ========== Process explorer.exe killed successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\admin window deleted successfully. C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak\loudknob.exe moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7078b842-d5ef-11d9-b568-806d6172696f}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7078b842-d5ef-11d9-b568-806d6172696f}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7078b842-d5ef-11d9-b568-806d6172696f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7078b842-d5ef-11d9-b568-806d6172696f}\ not found. File D:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8c5eb092-6adf-11dd-b3c1-0050707445f9}\ not found. File F:\Photokinz.exe not found. Folder C:\Documents and Settings\All Users\Application Data\Messenger Plus! not found. C:\WINDOWS\tasks\21256B95F0F6E1BD.job moved successfully. Folder C:\Documents and Settings\All Users\Application Data\seek film amok web not found. Folder C:\Program Files\dalesurfpeak not found. Folder C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak not found. Folder C:\Program Files\Circle Dvelopement not found. Folder C:\Program Files\Messenger Plus! Live not found. Folder C:\Documents and Settings\All Users\Application Data\Messenger Plus! not found. ADS C:\Documents and Settings\All Users\Application Data\TEMP:C39E55C5 deleted successfully. ADS C:\WINDOWS\Thumbs.db:encryptable deleted successfully. ADS C:\Documents and Settings\Dan Mueller\My Documents\Thumbs.db:encryptable deleted successfully. ADS C:\Documents and Settings\Dan Mueller\Desktop\Thumbs.db:encryptable deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\Perflib_Perfdata_102c.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\Perflib_Perfdata_123c.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\Perflib_Perfdata_b48.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DF2899.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DF592A.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DF7804.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DFAEBB.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DFAED2.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.1.0 log created on 02212009_133719 Files moved on Reboot… File C:\Documents and Settings\Dan Mueller\Local Settings\Temp\Perflib_Perfdata_102c.dat not found! File C:\Documents and Settings\Dan Mueller\Local Settings\Temp\Perflib_Perfdata_123c.dat not found! File C:\Documents and Settings\Dan Mueller\Local Settings\Temp\Perflib_Perfdata_b48.dat not found! C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DF2899.tmp moved successfully. C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DF592A.tmp moved successfully. File C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DF7804.tmp not found! C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DFAEBB.tmp moved successfully. File C:\Documents and Settings\Dan Mueller\Local Settings\Temp\~DFAED2.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_5c8.dat not found! Registry entries deleted on Reboot…
Here is the new log. I am still getting the popups.

TIA for all your help….Bookem130

OTListIt logfile created on: 2/21/2009 1:54:48 PM - Run 3
OTListIt2 by OldTimer - Version 2.0.1.0 Folder = C:\Documents and Settings\Dan Mueller\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.26 Gb Available Physical Memory | 62.95% Memory free
2.60 Gb Paging File | 1.78 Gb Available in Paging File | 68.46% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 62.60 Gb Free Space | 56.00% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MUELLER2-XP
Current User Name: Dan Mueller
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\FSGK32.EXE (F-Secure Corp.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FSMB32.EXE (F-Secure Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FCH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Common\FAMEH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsqh.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FSPC\fspc.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fssm32.exe (F-Secure Corp.)
PRC - C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Security Suite\FSAUA\program\fsus.exe (F-Secure Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\WgaTray.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Microsoft IntelliType Pro\type32.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\WDBtnMgr.exe (Western Digital Technologies, Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe (SpiralFrog)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Charter Security Suite\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Multimedia\main\ATISched.EXE (ATI Technologies Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\FSGUI\fsguidll.exe (F-Secure Corporation)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe (Microsoft Corporation)
PRC - C:\Program Files\Charter Security Suite\FSGUI\scanwizard.exe (F-Secure Corporation)
PRC - C:\WINDOWS\system32\HPZinw12.exe (HP)
PRC - C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (Autodesk Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Diskeeper [Auto | Running]) – C:\Program Files\Executive Software\Diskeeper\DkService.exe (Executive Software International, Inc.)
SRV - (F-Secure Gatekeeper Handler Starter [Auto | Running]) – C:\Program Files\Charter Security Suite\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (FSAUA [On_Demand | Running]) – C:\Program Files\Charter Security Suite\FSAUA\program\fsaua.exe (F-Secure Corporation)
SRV - (FSDFWD [On_Demand | Running]) – C:\Program Files\Charter Security Suite\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (FSMA [Auto | Running]) – C:\Program Files\Charter Security Suite\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSORSPClient [On_Demand | Running]) – C:\Program Files\Charter Security Suite\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Stopped]) – C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE (Hewlett-Packard Company)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NBService [On_Demand | Stopped]) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdLLD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\AmdLLD.sys (AMD, Inc.)
DRV - (ATI Remote Wonder II [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ATIRWVD.SYS (Jungo)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATITUNEP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atintuxx.sys (ATI Technologies Inc.)
DRV - (ativraxx [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinraxx.sys (ATI Technologies Inc.)
DRV - (ATIXSAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinxsxx.sys (ATI Technologies Inc.)
DRV - (BS_Flash [On_Demand | Stopped]) – C:\Program Files\Tseries BIOS Update\Award\BS_Flash.sys ()
DRV - (BS_I2cIo [System | Running]) – C:\WINDOWS\system32\drivers\BS_I2cIo.sys (BIOSTAR Group)
DRV - (cmuda [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (F-Secure Filter [Disabled | Stopped]) – C:\Program Files\Charter Security Suite\Anti-Virus\Win2K\FSfilter.sys ()
DRV - (F-Secure Gatekeeper [On_Demand | Running]) – C:\Program Files\Charter Security Suite\Anti-Virus\minifilter\fsgk.sys ()
DRV - (F-Secure HIPS [System | Running]) – C:\Program Files\Charter Security Suite\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (F-Secure Recognizer [Disabled | Stopped]) – C:\Program Files\Charter Security Suite\Anti-Virus\Win2K\FSrec.sys ()
DRV - (FETNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (fsbts [Boot | Running]) – C:\WINDOWS\system32\Drivers\fsbts.sys ()
DRV - (FSFW [Boot | Running]) – C:\WINDOWS\System32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (MA8212M [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MA8212M.sys (Mobile Action Technology Inc.)
DRV - (MA8212U [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MA8212U.sys (Mobile Action Technology Inc.)
DRV - (MaRdPnp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys (Mobile Action Technology Inc.)
DRV - (MaVctrl [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (ms_mpu401 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MVDCODEC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (NuidFltr [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV - (nvatabus [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (nvax [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (NVENET [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\NVENET.sys (NVIDIA Corporation)
DRV - (nvidesm [Boot | Running]) – C:\WINDOWS\system32\drivers\nvidesm.sys (NVIDIA Corporation)
DRV - (nvnforce [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (PCDCODEC [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\atinpdxx.sys (ATI Technologies Inc.)
DRV - (Point32 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (WinDriver6 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (XUIF [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\x10ufx2.sys (X10 Wireless Technology, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = Reg Error: Invalid data type.
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (731 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (E-Zsoft VideoDownloaderToolBar) - {4322A444-92F8-4C3E-BD4C-013BA51E2871} - C:\Program Files\VersalSoft\InternetDownload\VDTB.dll ()
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD_Display] File not found
O4 - HKLM..\Run: [Amok web bash obj] C:\Documents and Settings\All Users\Application Data\seek film amok web\2 FACE.exe (Tseet sipl isu)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [F-Secure Manager] "C:\Program Files\Charter Security Suite\Common\FSM32.EXE" /splash (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] "C:\Program Files\Charter Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW (F-Secure Corporation)
O4 - HKLM..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [InternetDownload_upgrade] "C:\Program Files\VersalSoft\InternetDownload\InternetDownload.exe" /upgrade File not found
O4 - HKLM..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear (NVIDIA)
O4 - HKLM..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpiralFrog] C:\Program Files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe (SpiralFrog)
O4 - HKLM..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [WD Button Manager] WDBtnMgr.exe (Western Digital Technologies, Inc.)
O4 - HKCU..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe (ATI Technologies Inc.)
O4 - HKCU..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE (ATI Technologies Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll (F-Secure Corporation)
O9 - Extra 'Tools' menuitem : Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Charter Security Suite\FSPC\fspcmsie.dll (F-Secure Corporation)
O9 - Extra Button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (ATI Technologies Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Charter Security Suite\FSPS\program\FSLSP.DLL (F-Secure Corporation)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} https://www.mykohlerco.com/postauthI/epi.cab (Aventail Installer )
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1191095838078 (MUWebControl Class)
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://cid-5756917e812a938f.spaces.live.co…ad/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} http://ipgweb.cce.hp.com/rdqaio/downloads/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://charter.net/files/charter/securitysuite/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {9EF34FF2-3396-4527-9D27-04C8C1C67806} - C:\Program Files\Microsoft AntiSpyware\shellextension.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.SOL () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Documents and Settings\Dan Mueller\My Documents\*.tmp files]
[2009/02/21 13:37:19 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/21 11:35:38 | 00,494,080 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe
[2009/02/21 00:11:33 | 00,004,066 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\computer results.zip
[2009/02/21 00:05:47 | 00,050,688 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Logfile of Trend Micro HJT v2.doc
[2009/02/20 23:24:33 | 00,001,744 | —- | C] () – C:\Documents and Settings\Dan Mueller\Desktop\HijackThis.lnk
[2009/02/20 23:24:32 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/20 20:11:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\Malwarebytes
[2009/02/20 20:11:07 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/20 20:11:07 | 00,000,706 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/20 20:11:04 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/20 20:11:03 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/20 20:11:03 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/02/20 20:10:00 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Dan Mueller\Desktop\mbam-setup.exe
[2009/02/18 23:41:29 | 00,000,526 | —- | C] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2009/02/18 20:22:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/02/18 20:22:23 | 00,000,790 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/02/18 20:22:21 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/02/18 20:22:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\SUPERAntiSpyware.com
[2009/02/18 20:21:39 | 06,006,816 | —- | C] () – C:\Documents and Settings\Dan Mueller\Desktop\SUPERAntiSpyware.exe
[2009/02/18 07:19:24 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Fitness Friday Weekend.doc
[2009/02/17 19:42:29 | 00,000,000 | —D | C] – C:\Program Files\NoAdware
[2009/02/16 22:50:08 | 00,033,408 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/16 22:30:18 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\F-Secure
[2009/02/16 22:22:26 | 00,079,904 | —- | C] (F-Secure Corporation) – C:\WINDOWS\System32\drivers\fsdfw.sys
[2009/02/16 22:21:02 | 00,000,000 | —D | C] – C:\Program Files\Charter Security Suite
[2009/02/16 22:20:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\fssg
[2009/02/16 20:51:57 | 00,000,000 | —D | C] – C:\fsaua.data
[2009/02/16 20:31:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\f-secure
[2009/02/14 20:18:54 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/02/09 19:38:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\My Documents\My Chat Logs
[2009/02/09 19:16:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2009/02/09 19:15:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\seek film amok web
[2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Program Files\dalesurfpeak
[2009/02/09 19:15:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Dan Mueller\Application Data\dalesurfpeak
[2009/02/09 19:15:11 | 00,000,000 | —D | C] – C:\Program Files\Circle Dvelopement
[2009/02/09 19:15:07 | 00,000,000 | —D | C] – C:\Program Files\Messenger Plus! Live
[2009/02/01 13:46:29 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dan Mueller\My Documents\Mark Marcus's bingo news.doc

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\drivers\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Dan Mueller\My Documents\*.tmp files]
[2009/02/21 13:43:46 | 00,000,678 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/21 13:40:47 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/21 13:40:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/21 13:40:23 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/21 13:38:55 | 03,236,252 | -H– | M] () – C:\Documents and Settings\Dan Mueller\Local Settings\Application Data\IconCache.db
[2009/02/21 11:36:32 | 00,494,080 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dan Mueller\Desktop\OTListIt2.exe
[2009/02/21 03:30:00 | 00,000,438 | —- | M] () – C:\WINDOWS\tasks\RegistrySmart Scheduled Scan.job
[2009/02/21 00:11:33 | 00,004,066 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\computer results.zip
[2009/02/21 00:05:48 | 00,050,688 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Logfile of Trend Micro HJT v2.doc
[2009/02/20 23:24:33 | 00,001,744 | —- | M] () – C:\Documents and Settings\Dan Mueller\Desktop\HijackThis.lnk
[2009/02/20 20:30:16 | 00,001,100 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/20 20:11:07 | 00,000,706 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/02/20 20:10:00 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Dan Mueller\Desktop\mbam-setup.exe
[2009/02/20 18:01:02 | 00,000,526 | —- | M] () – C:\WINDOWS\tasks\Scheduled scanning task.job
[2009/02/19 19:05:01 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/02/19 19:05:01 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/02/19 19:03:55 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/02/19 19:03:55 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/02/18 20:22:23 | 00,000,790 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/02/18 20:21:51 | 06,006,816 | —- | M] () – C:\Documents and Settings\Dan Mueller\Desktop\SUPERAntiSpyware.exe
[2009/02/18 16:43:49 | 00,020,992 | —- | M] () – C:\Documents and Settings\Dan Mueller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/18 07:19:25 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Fitness Friday Weekend.doc
[2009/02/17 22:13:44 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/02/17 21:22:52 | 00,000,046 | —- | M] () – C:\AUTOEXEC.SOL
[2009/02/16 22:50:08 | 00,033,408 | —- | M] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2009/02/16 22:22:36 | 00,535,758 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/16 22:22:36 | 00,451,656 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/16 22:22:36 | 00,075,396 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/16 20:22:34 | 00,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/11 03:01:38 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/10 18:21:50 | 00,000,587 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\My Sharing Folders.lnk
[2009/02/03 17:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/01 19:51:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/02/01 19:51:13 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/02/01 19:39:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/01 19:39:23 | 00,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/01 13:53:26 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Mark Marcus's bingo news.doc
[2009/01/31 14:45:56 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/31 14:45:56 | 00,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/30 18:59:53 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/30 15:51:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/30 15:51:54 | 00,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/30 10:15:48 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/30 10:15:48 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/29 18:31:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/29 18:31:43 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/29 18:30:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/29 18:30:31 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/29 12:47:33 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/01/29 12:47:33 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/01/29 08:08:00 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/01/29 08:08:00 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/01/28 18:37:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/01/28 18:37:45 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/01/28 18:35:30 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/28 18:35:30 | 00,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/01/28 18:32:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/28 18:32:23 | 00,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/28 18:31:37 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/28 18:31:37 | 00,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/28 18:30:22 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/01/28 18:30:22 | 00,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/28 18:29:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/01/28 18:29:11 | 00,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/28 18:26:35 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/28 18:26:35 | 00,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/01/28 18:21:48 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/01/28 18:21:48 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/01/28 18:20:50 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/28 18:20:50 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/22 16:23:14 | 00,428,032 | —- | M] () – C:\Documents and Settings\Dan Mueller\My Documents\Moms GS Game List.max
< End of report >
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Here is the combofix report:

ComboFix 09-02-19.01 - Dan Mueller 2009-02-21 14:06:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1452 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Charter Security Suite 8.00 *On-access scanning disabled* (Updated)
FW: Charter Security Suite 8.00 *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\d3d8caps.dat

—– BITS: Possible infected sites —–

hxxp://www.spiralfrog.com
.
((((((((((((((((((((((((( Files Created from 2009-01-21 to 2009-02-21 )))))))))))))))))))))))))))))))
.

2009-02-21 13:37 . 2009-02-21 13:37 d——– C:\_OTListIt
2009-02-20 23:24 . 2009-02-20 23:24 d——– c:\program files\Trend Micro
2009-02-20 20:11 . 2009-02-20 20:11 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-20 20:11 . 2009-02-20 20:11 d——– c:\documents and settings\Dan Mueller\Application Data\Malwarebytes
2009-02-20 20:11 . 2009-02-20 20:11 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-20 20:11 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-20 20:11 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-18 20:22 . 2009-02-18 20:22 d——– c:\program files\SUPERAntiSpyware
2009-02-18 20:22 . 2009-02-18 20:22 d——– c:\documents and settings\Dan Mueller\Application Data\SUPERAntiSpyware.com
2009-02-18 20:22 . 2009-02-18 20:22 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-02-17 19:42 . 2009-02-17 20:58 d——– c:\program files\NoAdware
2009-02-16 22:50 . 2009-02-16 22:50 33,408 –a—— c:\windows\system32\drivers\fsbts.sys
2009-02-16 22:30 . 2009-02-16 22:30 d——– c:\documents and settings\Dan Mueller\Application Data\F-Secure
2009-02-16 22:22 . 2008-09-23 07:35 79,904 –a—— c:\windows\system32\drivers\fsdfw.sys
2009-02-16 22:21 . 2009-02-21 05:07 d——– c:\program files\Charter Security Suite
2009-02-16 22:20 . 2009-02-16 22:20 d——– c:\documents and settings\All Users\Application Data\fssg
2009-02-16 20:51 . 2009-02-16 20:51 d——– C:\fsaua.data
2009-02-16 20:31 . 2009-02-16 22:22 d——– c:\documents and settings\All Users\Application Data\f-secure
2009-02-14 20:18 . 2009-02-14 20:18 d——– c:\program files\Alwil Software
2009-02-09 19:16 . 2009-02-09 19:16 d——– c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-09 19:15 . 2009-02-09 19:15 d——– c:\program files\Messenger Plus! Live
2009-02-09 19:15 . 2009-02-09 19:15 d——– c:\program files\dalesurfpeak
2009-02-09 19:15 . 2009-02-09 19:15 d——– c:\program files\Circle Dvelopement
2009-02-09 19:15 . 2009-02-21 13:37 d——– c:\documents and settings\Dan Mueller\Application Data\dalesurfpeak
2009-02-09 19:15 . 2009-02-09 19:15 d——– c:\documents and settings\All Users\Application Data\seek film amok web

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-21 20:11 ——— d—–w c:\program files\Maria's KEEP OUT MY PRIVATE FILES
2009-02-21 20:10 ——— d—–w c:\program files\Microsoft AntiSpyware
2009-02-19 02:21 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-17 02:17 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee.com
2009-02-17 02:10 ——— d—–w c:\documents and settings\Dan Mueller\Application Data\Lavasoft
2009-01-19 03:31 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-19 01:19 ——— d—–w c:\documents and settings\All Users\Application Data\ATI MMC
2009-01-10 15:47 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-10 15:47 ——— d—–w c:\program files\Nancy Drew
2009-01-01 20:44 ——— d—–w c:\program files\myfantasyleague
2008-12-31 21:47 ——— d—–w c:\documents and settings\Dan Mueller\Application Data\ATI MMC
2008-12-24 16:57 ——— d—–w c:\program files\HOJY TECH
2008-12-20 23:15 826,368 —-a-w c:\windows\system32\wininet.dll
2005-06-08 19:10 56 –sh–r c:\windows\system32\93C4B05468.sys
2005-06-08 19:10 1,682 –sha-w c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

2008-04-13 18:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
2004-08-03 19:07 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\svchost.exe
2004-08-03 19:07 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\dllcache\svchost.exe

2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
2004-08-03 19:07 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-08-03 19:07 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\dllcache\ws2_32.dll

2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2004-08-03 19:07 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\winlogon.exe
2004-08-03 19:07 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\dllcache\winlogon.exe

2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
2004-08-03 19:07 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2004-08-03 19:07 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys

2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
2004-08-03 19:07 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\dllcache\ip6fw.sys
2004-08-03 19:07 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys

2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2004-08-03 19:07 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe
2004-08-03 19:07 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\dllcache\services.exe

2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2004-08-03 19:07 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2004-08-03 19:07 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\dllcache\lsass.exe

2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-03 19:07 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2004-08-03 19:07 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\dllcache\ctfmon.exe

2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-03 19:07 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-03 19:07 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\dllcache\userinit.exe

2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
2004-08-03 19:07 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\termsrv.dll
2004-08-03 19:07 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll

2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
2004-08-03 19:07 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
2004-08-03 19:07 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\dllcache\powrprof.dll

2008-04-13 18:11 110080 0da85218e92526972a821587e6a8bf8f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\imm32.dll
2004-08-03 19:07 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\system32\imm32.dll
2004-08-03 19:07 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\system32\dllcache\imm32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2006-01-05 1622016]
"ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2006-07-12 57344]
"ATI Scheduler"="c:\program files\ATI Multimedia\main\ATISched.EXE" [2006-07-12 26624]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-02-10 473920]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 131072]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\\nTune.exe" [2005-03-18 589824]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-10-12 294912]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-03-18 184320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-03-18 212992]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-29 29744]
"SpiralFrog"="c:\program files\Maria's KEEP OUT MY PRIVATE FILES\Spiralfrog.exe" [2008-03-12 163128]
"InternetDownload_upgrade"="c:\program files\VersalSoft\InternetDownload\InternetDownload.exe" [2008-08-16 356352]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Amok web bash obj"="c:\documents and settings\All Users\Application Data\seek film amok web\2 FACE.exe" [2009-02-21 839680]
"F-Secure Manager"="c:\program files\Charter Security Suite\Common\FSM32.EXE" [2008-09-23 182936]
"F-Secure TNB"="c:\program files\Charter Security Suite\FSGUI\TNBUtil.exe" [2008-09-23 957024]
"WD Button Manager"="WDBtnMgr.exe" [2008-02-23 c:\windows\system32\WDBtnMgr.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 10872]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YU12"= ATIYUV12.DLL
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= c:\program files\ffdshow\ffdshow.ax

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupXu.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Documents and Settings\\Dan Mueller\\Desktop\\HP\\setup\\HPZnet01.exe"=
"c:\\Documents and Settings\\Dan Mueller\\Desktop\\HP\\setup\\hponicifs01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9290:TCP"= 9290:TCP:SCAN_TCP_9290
"161:TCP"= 161:TCP:SNMP
"427:TCP"= 427:TCP:SRVLOC
"9220:TCP"= 9220:TCP:GENERIC GATEWAY
"9110:TCP"= 9110:TCP:PCL

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-02-16 33408]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-02-16 79904]
R1 BS_I2cIo;BS_I2cIo;c:\windows\system32\drivers\BS_I2cIo.sys [2008-10-21 16768]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Charter Security Suite\HIPS\drivers\fshs.sys [2009-02-16 66720]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Charter Security Suite\Anti-Virus\minifilter\fsgk.sys [2009-02-16 84096]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Charter Security Suite\ORSP Client\fsorsp.exe [2009-02-16 55904]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S3 BS_Flash;BS_Flash;c:\program files\Tseries BIOS Update\Award\BS_Flash.sys [2008-10-21 3604]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-02-23 29744]
S3 MA8212M;MA8212M;c:\windows\system32\drivers\MA8212M.sys [2006-08-14 25300]
S3 MA8212U;MA8212U;c:\windows\system32\drivers\MA8212U.sys [2006-08-14 49106]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Charter Security Suite\Anti-Virus\win2k\fsfilter.sys [2009-02-16 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Charter Security Suite\Anti-Virus\win2k\fsrec.sys [2009-02-16 25184]
.
Contents of the 'Scheduled Tasks' folder

2006-05-09 c:\windows\Tasks\Boxing.job
- c:\progra~1\ATIMUL~1\main\ATISchedInvoke.exe [2006-07-12 21:29]

2006-05-31 c:\windows\Tasks\EPG_REC_000.job
- c:\progra~1\ATIMUL~1\main\ATISchedInvoke.exe [2006-07-12 21:29]

2009-02-21 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart\RegistrySmart.exe []

2009-02-21 c:\windows\Tasks\RegistrySmart Scheduled Scan.job
- c:\program files\RegistrySmart []

2009-02-21 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\CHARTE~1\ANTI-V~1\fsav.exe [2008-09-23 07:35]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-AMD_Display - (no file)


.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
LSP: c:\program files\Charter Security Suite\FSPS\program\FSLSP.DLL
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-21 14:10:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(664)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(720)
c:\program files\Charter Security Suite\FSPS\program\FSLSP.DLL
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Executive Software\Diskeeper\DkService.exe
c:\program files\Charter Security Suite\Anti-Virus\fsgk32st.exe
c:\program files\Charter Security Suite\Common\FSMA32.EXE
c:\program files\Charter Security Suite\Anti-Virus\fsgk32.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Charter Security Suite\Common\FSMB32.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\Charter Security Suite\Common\FCH32.EXE
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WgaTray.exe
c:\program files\Charter Security Suite\Common\FAMEH32.EXE
c:\program files\Charter Security Suite\Anti-Virus\fsqh.exe
c:\program files\Charter Security Suite\FSPC\fspc.exe
c:\program files\Charter Security Suite\FSAUA\program\fsaua.exe
c:\program files\Charter Security Suite\FWES\program\fsdfwd.exe
c:\program files\Charter Security Suite\Anti-Virus\fssm32.exe
c:\program files\Charter Security Suite\FSAUA\program\fsus.exe
c:\progra~1\CHARTE~1\ANTI-V~1\fsav32.exe
c:\program files\Microsoft AntiSpyware\gcasDtServ.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Charter Security Suite\FSGUI\fsguidll.exe
c:\windows\system32\rundll32.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\HPZinw12.exe
.
**************************************************************************
.
Completion time: 2009-02-21 14:15:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-21 20:15:28

Pre-Run: 67,095,769,088 bytes free
Post-Run: 67,145,388,032 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

295 — E O F — 2009-02-11 09:04:07
hello



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\Tasks\Boxing.job
c:\progra~1\ATIMUL~1\main\ATISchedInvoke.exe
c:\windows\Tasks\EPG_REC_000.job

folder::
c:\documents and settings\All Users\Application Data\Messenger Plus!
c:\program files\Messenger Plus! Live
c:\program files\dalesurfpeak
c:\program files\Circle Dvelopement
c:\documents and settings\Dan Mueller\Application Data\dalesurfpeak
c:\documents and settings\All Users\Application Data\seek film amok web


Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
do this

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    c:\windows\Tasks\Boxing.job
    c:\progra~1\ATIMUL~1\main\ATISchedInvoke.exe
    c:\windows\Tasks\EPG_REC_000.job
    c:\documents and settings\All Users\Application Data\Messenger Plus!
    c:\program files\Messenger Plus! Live
    c:\program files\dalesurfpeak
    c:\program files\Circle Dvelopement
    c:\documents and settings\Dan Mueller\Application Data\dalesurfpeak
    c:\documents and settings\All Users\Application Data\seek film amok web
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Here is the results window: ========== FILES ========== c:\windows\Tasks\Boxing.job moved successfully. c:\progra~1\ATIMUL~1\main\ATISchedInvoke.exe moved successfully. c:\windows\Tasks\EPG_REC_000.job moved successfully. c:\documents and settings\All Users\Application Data\Messenger Plus! moved successfully. c:\program files\Messenger Plus! Live\Skins moved successfully. c:\program files\Messenger Plus! Live\Scripts moved successfully. c:\program files\Messenger Plus! Live\Languages moved successfully. c:\program files\Messenger Plus! Live\Interface moved successfully. c:\program files\Messenger Plus! Live moved successfully. c:\program files\dalesurfpeak moved successfully. c:\program files\Circle Dvelopement moved successfully. c:\documents and settings\Dan Mueller\Application Data\dalesurfpeak moved successfully. c:\documents and settings\All Users\Application Data\seek film amok web moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\Perflib_Perfdata_1300.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\Perflib_Perfdata_133c.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\Perflib_Perfdata_de8.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\~DF38ED.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\~DF426D.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\DANMUE~1\LOCALS~1\Temp\~DF89CB.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be deleted on reboot. Windows Temp folder emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02212009_172654
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Malwarebyte's Report Malwarebytes' Anti-Malware 1.34 Database version: 1790 Windows 5.1.2600 Service Pack 2 2/21/2009 9:08:07 PM mbam-log-2009-02-21 (21-08-07).txt Scan type: Full Scan (C:\|Z:\|) Objects scanned: 186909 Time elapsed: 49 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\$NtUninstallKB887472$\msmsgs.exe (Trojan.Autorun) -> Quarantined and deleted successfully. Kaspersky Report: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Sunday, February 22, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, February 22, 2009 03:02:00 Records in database: 1828990 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Z:\ Scan statistics: Files scanned: 110855 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:38:54 File name / Threat name / Threats count C:\Documents and Settings\Dan Mueller\My Documents\email\Outlook Express\Mail\Inbox.mbx Infected: Email-Worm.Win32.Magistr.b 1 The selected area was scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI