Malware log:
Malwarebytes' Anti-Malware 1.30
Database version: 1358
Windows 5.0.2195 Service Pack 4
3/14/2009 7:35:50 PM
mbam-log-2009-03-14 (19-35-50).txt
Scan type: Quick Scan
Objects scanned: 56226
Time elapsed: 57 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OT Listit Log
OTListIt logfile created on: 3/14/2009 7:40:03 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.8 Folder = C:\Documents and Settings\Administrator\Desktop
Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.47 Mb Total Physical Memory | 84.60 Mb Available Physical Memory | 33.11% Memory free
617.04 Mb Paging File | 266.63 Mb Available in Paging File | 43.21% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 16.64 Gb Total Space | 4.01 Gb Free Space | 24.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 111.76 Gb Total Space | 91.14 Gb Free Space | 81.55% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
Drive G: | 976.13 Mb Total Space | 589.11 Mb Free Space | 60.35% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OEM-6W9RM1BTAAS
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINNT\System32\Ati2evxx.exe ()
PRC - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.)
PRC - C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
PRC - C:\WINNT\system32\MSTask.exe (Microsoft Corporation)
PRC - C:\WINNT\system32\UAService7.exe ()
PRC - C:\WINNT\System32\WBEM\WinMgmt.exe (Microsoft Corporation)
PRC - C:\WINNT\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe ()
PRC - C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe ()
PRC - C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINNT\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINNT\System32\Ati2evxx.exe ()
SRV - (dmadmin [On_Demand | Stopped]) – C:\WINNT\System32\dmadmin.exe (VERITAS Software Corp.)
SRV - (dvpapi [Auto | Running]) – C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (Authentium, Inc.)
SRV - (Fax [On_Demand | Stopped]) – C:\WINNT\system32\faxsvc.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ioloFileInfoList [Auto | Running]) – C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
SRV - (ioloSystemService [Auto | Running]) – C:\Program Files\iolo\common\lib\ioloServiceManager.exe ()
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (MSSQLServerADHelper [On_Demand | Stopped]) – File not found
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RemoteRegistry [Disabled | Stopped]) – C:\WINNT\system32\regsvc.exe (Microsoft Corporation)
SRV - (Schedule [Auto | Running]) – C:\WINNT\system32\MSTask.exe (Microsoft Corporation)
SRV - (UserAccess7 [Auto | Running]) – C:\WINNT\system32\UAService7.exe ()
SRV - (UtilMan [On_Demand | Stopped]) – C:\WINNT\System32\UtilMan.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Disabled | Stopped]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinMgmt [Auto | Running]) – C:\WINNT\System32\WBEM\WinMgmt.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ati2mtai [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ati2mtai.sys (ATI Technologies Inc.)
DRV - (Cdr4_2K [System | Running]) – C:\WINNT\System32\drivers\cdr4_2K.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINNT\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (CSS DVP [Auto | Running]) – C:\WINNT\system32\DRIVERS\css-dvp.sys (Authentium, Inc.)
DRV - (Diskperf [Boot | Running]) – C:\WINNT\System32\drivers\diskperf.sys (Microsoft Corporation)
DRV - (dmboot [Disabled | Stopped]) – C:\WINNT\System32\drivers\dmboot.sys (VERITAS Software Corp.)
DRV - (dmio [Boot | Running]) – C:\WINNT\System32\drivers\dmio.sys (VERITAS Software Corp.)
DRV - (dmload [Disabled | Stopped]) – C:\WINNT\System32\drivers\dmload.sys (VERITAS Software Corp.)
DRV - (EFS [Disabled | Running]) – C:\WINNT\System32\drivers\efs.sys (Microsoft Corporation)
DRV - (EL556 [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\EL556ND5.sys (3Com Corporation)
DRV - (EL90BC [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (FileDisk [System | Running]) – C:\WINNT\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINNT\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (gmer [On_Demand | Stopped]) – C:\WINNT\System32\DRIVERS\gmer.sys (GMER)
DRV - (maestro [On_Demand | Running]) – C:\WINNT\system32\drivers\es198xdl.sys (ESS Technology, Inc.)
DRV - (MPE [On_Demand | Stopped]) – C:\WINNT\system32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (NetDetect [On_Demand | Stopped]) – C:\WINNT\system32\drivers\netdtect.sys (Microsoft Corporation)
DRV - (Parallel [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\parallel.sys (Microsoft Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINNT\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RCA [On_Demand | Stopped]) – C:\WINNT\system32\drivers\RCA.sys (Microsoft Corporation)
DRV - (SbcpHid [On_Demand | Stopped]) – C:\WINNT\system32\Drivers\SbcpHid.sys ()
DRV - (uhcd [On_Demand | Running]) – C:\WINNT\System32\DRIVERS\uhcd.sys (Microsoft Corporation)
DRV - (WDHABBG [On_Demand | Running]) – C:\WINNT\system32\DRIVERS\WDHABBG.sys (3Com Corporation)
DRV - (XPacket [Boot | Running]) – C:\WINNT\System32\xpacket.sys (iolo technologies, LLC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FOXFIRE 3.0.1\COMPONENTS [2009/03/07 13:06:16 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FOXFIRE 3.0.1\PLUGINS [2009/03/07 13:06:15 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.3.3\Extensions\\Components: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\COMPONENTS [2008/09/13 16:03:57 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.3.3\Extensions\\Plugins: C:\PROGRAM FILES\NETSCAPE\NETSCAPE BROWSER\PLUGINS [2009/02/03 23:31:24 | 00,000,000 | —D | M]
[2008/08/30 16:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions
[2008/08/30 16:08:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/14 18:27:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\vwa91ztv.default\extensions
[2008/12/16 22:36:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\vwa91ztv.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/11/13 02:52:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\mozilla\Firefox\Profiles\vwa91ztv.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2008/08/30 16:39:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/08/30 16:39:19 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/08/04 19:16:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2008/02/17 21:40:18 | 00,110,592 | —- | M] () – C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
O1 HOSTS File: (25 bytes) - C:\WINNT\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (MSN Search Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
O2 - BHO: (BHO) - {C9C42510-9B21-41c1-9DCD-8382A2D07C61} - C:\WINNT\system32\iehelper.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (The Weather Channel Toolbar) - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINNT\system32\TwcToolbarIe7.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1033,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (MSN Search Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe" ()
O4 - HKLM..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe" ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Synchronization Manager] mobsync.exe /logon (Microsoft Corporation)
O4 - HKCU..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [rundll32.exe] File not found
O4 - HKLM..\RunOnce: [SMRequiresRestart] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - Reg Error: Value error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINNT\System32\rnr20.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINNT\system32\iavlsp.dll (iolo technologies, LLC)
O12 - Plugin for: .htm - C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll (Netscape Communications Corp.)
O15 - HKCU\..Trusted Sites: turbotax.com ([]https in Trusted sites)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} https://disneyblast.go.com/v3/setup/activex…wareControl.cab (Walt Disney Internet Group Hardware Control)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc…OnlineGames.cab (Disney Online Games ActiveX Control)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…8313.4545717593 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\System32\msdxm.ocx ()
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\mkesfg: DllName - mkesfg.dll - File not found
O20 - Winlogon\Notify\wzcnotif: DllName - wzcdlg.dll - C:\WINNT\system32\wzcdlg.dll (Microsoft Corporation)
O21 - SSODL: Network.ConnectionTray - {7007ACCF-3202-11D1-AAD2-00805FC1270E} - C:\WINNT\system32\NETSHELL.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {e6adaaf0-79b2-4cf1-a660-50a0b33991a1} - didymiums - Reg Error: Key error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - G:\auto track mitsu.xls () - [ FAT ]
========== Files/Folders - Created Within 30 Days ==========
[2009/03/14 19:37:30 | 00,498,176 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/14 18:30:54 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/03/12 15:40:23 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_688.dat
[2009/03/08 20:43:54 | 00,001,590 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/08 20:43:52 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/08 20:43:41 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe
[2009/03/08 15:12:38 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_3a0.dat
[2009/03/08 09:18:45 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_348.dat
[2009/03/08 07:08:38 | 00,044,032 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\karl terms 032009.doc
[2009/03/07 10:13:18 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_398.dat
[2009/03/03 17:40:06 | 00,009,728 | —- | C] () – C:\WINNT\System32\iehelper.dll
[2009/02/27 15:42:33 | 00,016,384 | —- | C] () – C:\WINNT\System32\Perflib_Perfdata_3c0.dat
[2009/02/26 22:19:05 | 00,201,216 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Johannes Kepler.ppt
[2009/02/26 16:29:38 | 00,020,480 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Work Cited Cal..doc
[2009/02/26 16:23:09 | 00,021,504 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Niels Abel.doc
[2009/02/25 17:23:14 | 00,023,552 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Cal. Project.doc
[2009/02/25 15:27:45 | 00,024,576 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Essays for english lit.doc
[2009/02/22 20:51:51 | 00,019,968 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Crazy Horse.doc
[2009/02/21 18:00:10 | 00,000,842 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Home Inventory.lnk
[2009/02/21 18:00:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Administrator\My Documents\iiiHomeInventory Projects
[2009/02/21 18:00:06 | 00,000,000 | —D | C] – C:\Program Files\Insurance Information Institute
[2009/02/20 16:28:23 | 00,000,005 | —- | C] () – C:\WINNT\System32\_id.dat
[2009/02/20 16:28:16 | 00,023,553 | —- | C] () – C:\WINNT\System32\servises.dll
[2009/02/16 21:43:01 | 00,023,040 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Welcome to Hell.doc
[2009/02/15 16:22:52 | 03,700,736 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Dante Project.ppt
[2009/02/14 16:23:18 | 00,021,504 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\The Lost World.doc
[2009/02/14 14:43:19 | 00,025,088 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\outline3.doc
[2009/02/14 14:42:58 | 00,020,480 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Work Cited page.doc
[2009/02/12 20:45:18 | 00,028,672 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\rough draft 3.doc
========== Files - Modified Within 30 Days ==========
[4 C:\WINNT\*.tmp files]
[2009/03/14 19:37:27 | 00,498,176 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTListIt2.exe
[2009/03/14 18:31:01 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup.exe
[2009/03/12 15:40:23 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_688.dat
[2009/03/12 15:37:04 | 00,000,006 | -H– | M] () – C:\WINNT\tasks\SA.DAT
[2009/03/12 14:58:53 | 01,010,338 | -H– | M] () – C:\WINNT\ShellIconCache
[2009/03/12 14:35:20 | 01,202,688 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\auto track mitsu.xls
[2009/03/09 20:06:18 | 00,000,284 | —- | M] () – C:\WINNT\tasks\AppleSoftwareUpdate.job
[2009/03/08 21:36:26 | 00,001,465 | —- | M] () – C:\WINNT\QUICKEN.INI
[2009/03/08 20:43:54 | 00,001,590 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/03/08 20:43:39 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HJTInstall.exe
[2009/03/08 20:07:14 | 00,044,032 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\karl terms 032009.doc
[2009/03/08 15:12:38 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_3a0.dat
[2009/03/08 15:10:56 | 00,023,553 | —- | M] () – C:\WINNT\System32\servises.dll
[2009/03/08 15:05:25 | 00,000,726 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\System Mechanic Professional.lnk
[2009/03/08 09:24:33 | 00,009,728 | —- | M] () – C:\WINNT\System32\iehelper.dll
[2009/03/08 09:18:45 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_348.dat
[2009/03/08 08:27:51 | 00,001,531 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/03/08 07:49:33 | 00,000,025 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2009/03/07 14:02:10 | 00,000,053 | —- | M] () – C:\WINNT\iPlayer.INI
[2009/03/07 10:13:18 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_398.dat
[2009/02/27 15:42:33 | 00,016,384 | —- | M] () – C:\WINNT\System32\Perflib_Perfdata_3c0.dat
[2009/02/27 00:24:07 | 00,021,504 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Niels Abel.doc
[2009/02/27 00:23:55 | 00,023,552 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Cal. Project.doc
[2009/02/27 00:20:03 | 00,201,216 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Johannes Kepler.ppt
[2009/02/26 16:29:38 | 00,020,480 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Work Cited Cal..doc
[2009/02/25 16:37:41 | 00,024,576 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Essays for english lit.doc
[2009/02/22 20:52:35 | 00,019,968 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Crazy Horse.doc
[2009/02/21 18:00:10 | 00,000,842 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Home Inventory.lnk
[2009/02/20 16:28:48 | 00,000,005 | —- | M] () – C:\WINNT\System32\_id.dat
[2009/02/16 21:44:34 | 00,023,040 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Welcome to Hell.doc
[2009/02/15 16:22:55 | 03,700,736 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Dante Project.ppt
[2009/02/15 12:14:36 | 00,007,952 | —- | M] (Microsoft Corporation) – C:\WINNT\System32\svchost.exe
[2009/02/14 16:23:20 | 00,021,504 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\The Lost World.doc
[2009/02/14 14:43:36 | 00,028,672 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\rough draft 3.doc
[2009/02/14 14:43:21 | 00,025,088 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\outline3.doc
[2009/02/14 14:43:08 | 00,020,480 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Work Cited page.doc
========== LOP Check ==========
[2009/03/07 10:14:32 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data
[2009/02/04 00:04:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Adobe
[2009/03/07 10:14:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AdobeUM
[2005/09/09 17:59:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Apple Computer
[2006/07/18 06:35:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Digital Album Organizer
[2006/07/17 14:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\F-Secure
[2004/11/22 12:36:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Help
[2004/11/22 11:53:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Identities
[2007/03/18 17:15:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\InstallShield
[2005/02/12 22:25:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Intuit
[2009/03/08 14:58:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\iolo
[2005/09/02 21:13:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ispnews
[2009/03/03 17:29:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2008/11/03 07:58:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2008/01/22 00:03:45 | 00,000,000 | –SD | M] – C:\Documents and Settings\Administrator\Application Data\Microsoft
[2005/11/17 17:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Mozilla
[2005/09/01 08:17:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\MSN Search Toolbar
[2005/09/01 08:22:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Netscape
[2005/09/02 21:21:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\PEX
[2005/10/03 07:03:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Sun
[2008/12/16 05:22:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\U3
[2007/12/15 23:41:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Viewpoint
[2008/03/09 17:57:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wal-Mart Digital Photo Manager
[2007/07/15 17:40:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wal-Mart Digital Photo Viewer
[2008/12/15 17:34:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Yahoo!
[2009/02/03 22:45:35 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/03 23:31:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/10/09 13:47:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/10/08 12:51:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/06/18 08:36:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/08/04 21:05:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2007/11/25 13:11:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2007/11/07 21:04:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2005/03/13 16:40:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/03/08 14:59:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2008/11/03 07:57:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2005/02/12 20:00:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/09/01 08:15:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Search Toolbar
[2007/03/12 17:46:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/11/03 09:06:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\qtydqhwp
[2007/04/05 17:29:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/10/08 12:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/29 18:19:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/12/16 15:18:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/03/09 20:06:18 | 00,000,284 | —- | M] () – C:\WINNT\Tasks\AppleSoftwareUpdate.job
[2001/05/08 06:00:00 | 00,000,065 | RH– | M] () – C:\WINNT\Tasks\desktop.ini
[2007/12/02 08:44:20 | 00,000,448 | —- | M] () – C:\WINNT\Tasks\Registry Repair 5.job
[2009/03/12 15:37:04 | 00,000,006 | -H– | M] () – C:\WINNT\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 7784 bytes -> C:\Documents and Settings\Administrator\My Documents\Map.gif:Q30lsldxJoudresxAaaqpcawXc
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Administrator\My Documents\Map.gif:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
< End of report >
OTListIt Extras logfile created on: 3/14/2009 7:40:03 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.3.8 Folder = C:\Documents and Settings\Administrator\Desktop
Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.47 Mb Total Physical Memory | 84.60 Mb Available Physical Memory | 33.11% Memory free
617.04 Mb Paging File | 266.63 Mb Available in Paging File | 43.21% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 16.64 Gb Total Space | 4.01 Gb Free Space | 24.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 111.76 Gb Total Space | 91.14 Gb Free Space | 81.55% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
Drive G: | 976.13 Mb Total Space | 589.11 Mb Free Space | 60.35% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OEM-6W9RM1BTAAS
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla FoxFire 3.0.1\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{36495C59-089C-49D1-BD15-9E5BD86DC9A1}" = ItsDeductible Express
"{41FE2866-7D7D-4EDF-9C7A-F1F6A346BA83}" = Wal-Mart Digital Photo Manager
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{6F716D8C-398F-11D3-85E1-005004838609}" = WebFldrs
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7D1DCBBA-F6F5-42B4-B90B-F04ACE4DFD6C}" = MSN Search Toolbar
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{ABCE1C63-56ED-41FF-BEAF-57321F70DC49}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}" = Google SketchUp 6
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BBD3F66B-1180-4785-B679-3F91572CD3B4}_is1" = iolo technologies' System Mechanic Professional
"{C67DF120-4DD3-11D4-A3CA-005004AD2A5B}" = Authentium AntiVirus SDK - 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Ask Toolbar_is1" = Ask Toolbar
"ATI Display Driver" = ATI Display Driver Utilities
"bcMPEG2dec" = bitcontrol® MPEG-2 Video Decoder v2.0
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Disney Pirates of the Caribbean Online" = Disney Pirates of the Caribbean Online
"Google Desktop" = Google Desktop
"Higher Score on the ACT_is1" = Higher Score on the ACT
"Higher Score on the SAT/PSAT_is1" = Higher Score on the SAT/PSAT
"HijackThis" = HijackThis 2.0.2
"I.I.I. Home Inventory" = I.I.I. Home Inventory 3.08
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"InterActual Player" = InterActual Player
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"Netscape Browser" = Netscape Browser (remove only)
"Picasa2" = Picasa 2
"PrivateVideo" = PrivateVideo
"Q818043" = Windows 2000 Hotfix (SP5) Q818043
"Q828026" = Windows Media Player Hotfix [See Q828026 for more information]
"Registry Repair 55" = Migo Registry Repair 5
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"TurboTax Deluxe 2004" = TurboTax Deluxe 2004
"TurboTax Premier 2005" = TurboTax Premier 2005
"TurboTax Premier Investments 2006" = TurboTax Premier Investments 2006
"Update Rollup 1" = Update Rollup 1 for Windows 2000 SP4
"ViewpointMediaPlayer" = Viewpoint Media Player
"WDHABBG" = 3Com 56K V.90 Mini PCI Modem
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WMP7" = Windows Media Player system update (9 Series)
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"yqnfqokcnoa" = RON Tool Offersfortoday
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/6/2009 6:23:32 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Microsoft Internet Explorer | ID = 1000
Description =
Error - 3/7/2009 12:42:00 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/7/2009 1:08:00 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/7/2009 1:19:06 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/7/2009 1:27:55 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/7/2009 1:30:15 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/7/2009 2:16:17 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
Error - 3/8/2009 11:20:09 AM | Computer Name = OEM-6W9RM1BTAAS | Source = EventSystem | ID = 4100
Description = The COM+ Event System ran out of memory during its internal processing,
at line 60 of .\eventsystemobj.cp
Error - 3/8/2009 7:27:32 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Userenv | ID = 1000
Description = Windows cannot unload your registry file. If you have a roaming profile,
your settings are not replicated. Contact your administrator. DETAIL - Access
is denied. , Build number ((2195)).
Error - 3/11/2009 9:32:59 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfProc"
in
the "C:\WINNT\system32\perfproc.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.
[ System Events ]
Error - 11/18/2008 4:47:48 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 11/18/2008 8:00:06 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 11/18/2008 8:00:21 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 11/19/2008 7:58:53 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 11/19/2008 7:59:02 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 11/21/2008 11:08:48 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 11/21/2008 11:09:09 PM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
Error - 12/1/2008 12:15:48 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 000476403DDE has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
Error - 12/1/2008 12:16:46 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.10
on the Network Card with network address 000476403DDE.
Error - 12/2/2008 1:32:19 AM | Computer Name = OEM-6W9RM1BTAAS | Source = Removable Storage Service | ID = 262161
Description = RSM cannot manage library PhysicalDrive2. It encountered an unspecified
error. This can be caused by a number of problems including, but not limited to,
database corruption, failure communicating with the library, or insufficient system
resources.
< End of report >