This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hijackthislog different computer

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:03:53 AM, on 3/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Documents and Settings\All Users\Application Data\SearchIn1Step\searchin1177.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\procgdfa32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SearchIn1Step\searchin1.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\DOCUME~1\Owner\LOCALS~1\TempImages\IEPR.exe
C:\DOCUME~1\Owner\LOCALS~1\TempImages\iOmem101.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.freevideomaster.com/search.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AudioGizmo Toolbar Helper - {5980B104-CA68-4A9F-9E78-80ADBD2CA53B} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll (file missing)
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AudioGizmo Toolbar - {C6BB606F-232D-4957-8AFF-7D4F4A220F67} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Gjuvoxoyiviyifan] rundll32.exe "C:\WINDOWS\Ipisuru.dll",e
O4 - HKLM\..\Run: [Rxibaxuwibiqor] rundll32.exe "C:\WINDOWS\onixoxiw.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKCU\..\Run: [IEPR] C:\DOCUME~1\Owner\LOCALS~1\TempImages\IEPR.exe
O4 - HKCU\..\Run: [iOmem] C:\DOCUME~1\Owner\LOCALS~1\TempImages\iOmem101.exe
O4 - HKCU\..\Policies\Explorer\Run: [procgdfa32.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\procgdfa32.exe
O4 - HKCU\..\Policies\Explorer\Run: [iv] "C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe"
O4 - Startup: FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1216677254796
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SearchIn1Step Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\SearchIn1Step\searchin1177.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

–
End of file - 11000 bytes
Hi there lets see if we can fix you up

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O4 - HKLM\..\Run: [Gjuvoxoyiviyifan] rundll32.exe "C:\WINDOWS\Ipisuru.dll",e
O4 - HKLM\..\Run: [Rxibaxuwibiqor] rundll32.exe "C:\WINDOWS\onixoxiw.dll",e
O23 - Service: SearchIn1Step Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\SearchIn1Step\searchin1177.exe

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

THEN

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    procgdfa32.exe
    IEPR.exe
    iOmem101.exe
    
    :Services
    "SearchIn1Step Service" 
    
    :Files
    C:\WINDOWS\Ipisuru.dll
    C:\WINDOWS\onixoxiw.dll
    C:\Documents and Settings\All Users\Application Data\SearchIn1Step
    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\procgdfa32.exe
    C:\DOCUME~1\Owner\LOCALS~1\TempImages\IEPR.exe
    C:\DOCUME~1\Owner\LOCALS~1\TempImages\iOmem101.exe
    
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

FINALY FOR NOW

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Logs required : OTMoveit and OTScanit (attached)
Ok well here this the info you told me to copy.and when i ran the OTSacn it did come up with anything . ========== PROCESSES ========== Process procgdfa32.exe killed successfully. Process IEPR.exe killed successfully. Process iOmem101.exe killed successfully. ========== SERVICES/DRIVERS ========== Unable to stop service "SearchIn1Step Service" . ========== FILES ========== DllUnregisterServer procedure not found in C:\WINDOWS\Ipisuru.dll C:\WINDOWS\Ipisuru.dll NOT unregistered. C:\WINDOWS\Ipisuru.dll moved successfully. C:\WINDOWS\onixoxiw.dll NOT unregistered. C:\WINDOWS\onixoxiw.dll moved successfully. C:\Documents and Settings\All Users\Application Data\SearchIn1Step moved successfully. C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\procgdfa32.exe moved successfully. C:\DOCUME~1\Owner\LOCALS~1\TempImages\IEPR.exe moved successfully. C:\DOCUME~1\Owner\LOCALS~1\TempImages\iOmem101.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_LQQINGahBmAwZubihdOu scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\4nsjqrgj.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\4nsjqrgj.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\4nsjqrgj.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\4nsjqrgj.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\4nsjqrgj.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\4nsjqrgj.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03162009_075940
Was there no log in the oldtimer directory ?

OK lets run another analysis tool

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
here is the scan you wanted.
OTListIt logfile created on: 3/16/2009 1:26:24 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.5.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 71.67% Memory free
3.79 Gb Paging File | 3.34 Gb Available in Paging File | 88.10% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 58.23 Gb Free Space | 78.13% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-864E4A49F
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 12:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/07/01 10:02:28 | 00,468,224 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2008/12/08 18:01:58 | 00,533,344 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe
PRC - [2006/12/14 17:49:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/10/04 03:14:00 | 00,155,716 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2005/08/07 23:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2008/12/04 17:03:00 | 00,226,640 | —- | M] (Microsoft Corp.) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/07/21 13:45:34 | 01,097,216 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2007/09/10 15:12:44 | 00,069,632 | —- | M] (Software 2000 Limited) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
PRC - [2007/04/30 20:43:54 | 03,450,608 | —- | M] (Stardock) – C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
PRC - [2008/04/14 06:00:00 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/08/20 01:38:02 | 16,384,512 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTHDCPL.EXE
PRC - [2008/07/21 13:45:33 | 02,957,824 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
PRC - [2008/07/01 10:01:04 | 01,447,168 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008/12/08 18:01:58 | 00,453,984 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Family Safety\fsui.exe
PRC - [2009/01/05 17:18:48 | 00,413,696 | —- | M] (Apple Inc.) – C:\Program Files\QuickTime\QTTask.exe
PRC - [2009/01/06 14:06:36 | 00,290,088 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2008/12/02 23:41:54 | 03,882,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2006/11/13 13:39:52 | 01,289,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2006/11/13 13:39:34 | 00,199,464 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft ActiveSync\rapimgr.exe
PRC - [2008/04/14 05:42:30 | 01,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
PRC - [2008/07/07 09:46:45 | 00,416,768 | —- | M] (Stardock Corporation) – C:\Program Files\Stardock\CursorFX\CursorFX.exe
PRC - [2008/01/03 18:28:08 | 01,392,640 | R— | M] (PalmSource, Inc) – C:\Program Files\Palm\Hotsync.exe
PRC - [2009/01/06 14:06:24 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2008/12/02 22:09:52 | 00,027,496 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2009/03/06 16:18:05 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/03/16 13:26:06 | 00,499,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 15:28:16 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2007/04/13 03:20:52 | 00,033,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2008/12/12 12:17:38 | 00,238,888 | —- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - [2007/04/13 03:21:18 | 00,068,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/01 10:08:00 | 00,019,200 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EhttpSrv [On_Demand | Stopped])
SRV - [2008/07/01 10:02:28 | 00,468,224 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn [Auto | Running])
SRV - [2008/12/08 18:01:58 | 00,533,344 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe – (fsssvc [Auto | Running])
SRV - [2008/04/14 06:00:00 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2009/01/06 14:06:24 | 00,536,872 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2006/12/14 17:49:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2006/12/23 17:54:04 | 00,262,144 | —- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe – (NMIndexingService [On_Demand | Stopped])
SRV - [2007/10/04 03:14:00 | 00,155,716 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
SRV - [2007/08/24 03:19:12 | 00,443,776 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2005/08/07 23:54:00 | 00,167,936 | —- | M] () – C:\Program Files\CyberLink\Shared Files\RichVideo.exe – (RichVideo [Auto | Running])
SRV - [2008/12/04 17:03:00 | 00,226,640 | —- | M] (Microsoft Corp.) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort [Auto | Running])
SRV - File not found – – (SearchIn1Step Service [Disabled | Stopped])
SRV - [2008/07/21 13:45:34 | 01,097,216 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe – (sp_rssrv [Auto | Running])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2008/07/01 09:56:22 | 00,039,944 | —- | M] (ESET) – C:\WINDOWS\system32\DRIVERS\eamon.sys – (eamon [Auto | Running])
DRV - [2008/07/01 09:57:14 | 00,053,256 | —- | M] (ESET) – C:\WINDOWS\system32\DRIVERS\easdrv.sys – (easdrv [System | Running])
DRV - [2008/07/01 10:04:40 | 00,034,312 | —- | M] () – C:\WINDOWS\system32\DRIVERS\epfwtdir.sys – (epfwtdir [System | Running])
DRV - [2008/12/08 18:01:56 | 00,055,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys – (fssfltr [Auto | Running])
DRV - [2008/04/17 14:12:54 | 00,015,464 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2008/04/14 06:00:00 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2007/08/28 02:55:10 | 04,609,024 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2007/10/04 03:14:00 | 06,854,464 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Running])
DRV - [2007/09/20 05:07:38 | 00,053,632 | R— | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys – (NVENETFD [On_Demand | Running])
DRV - [2007/09/20 05:07:40 | 00,022,016 | R— | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys – (nvnetbus [On_Demand | Running])
DRV - [2007/07/07 01:13:10 | 00,012,032 | R— | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nvsmu.sys – (nvsmu [On_Demand | Running])
DRV - [2007/12/04 17:10:30 | 00,016,640 | R— | M] (PalmSource, Inc.) – C:\WINDOWS\system32\drivers\PalmUSBD.sys – (PalmUSBD [On_Demand | Stopped])
DRV - [2008/04/14 06:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2008/04/14 06:00:00 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008/07/21 13:45:33 | 00,138,752 | —- | M] () – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys – (sp_rsdrv2 [System | Running])
DRV - [2008/11/07 15:23:30 | 00,032,000 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2008/04/14 00:26:50 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\usb8023x.sys – (usb_rndisx [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8A CC F1 96 53 98 C9 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {8771569D-6C8B-45B5-8D74-5A80DDDF668D}:1.0
FF - prefs.js..extensions.enabledItems: {E1DB40F6-4763-4285-BD9B-18A3C599D561}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.1.20080205
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=IEFM1&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{E1DB40F6-4763-4285-BD9B-18A3C599D561}: C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\{E1DB40F6-4763-4285-BD9B-18A3C599D561} [2009/03/05 16:38:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/06 16:18:15 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/06 16:18:15 | 00,000,000 | —D | M]

[2008/12/11 18:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/12/11 18:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/16 08:47:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\4nsjqrgj.default\extensions
[2009/03/06 16:18:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\4nsjqrgj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/01/08 16:08:37 | 00,001,632 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\4nsjqrgj.default\searchplugins\live-search.xml
[2009/03/12 17:08:23 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/02 11:31:26 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{8771569D-6C8B-45B5-8D74-5A80DDDF668D}
[2009/03/06 16:18:15 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/06 16:18:04 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/06 16:18:04 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/06 16:18:11 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/06 16:18:11 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/06 16:18:11 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/06 16:18:11 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/06 16:18:11 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/02 11:31:24 | 00,002,415 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\searchin1.xml
[2009/03/02 11:33:46 | 00,002,420 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\searchin1172.xml
[2009/03/04 16:32:56 | 00,002,420 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\searchin1177.xml
[2009/03/06 16:18:11 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/06 16:18:11 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (253037 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8814 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AudioGizmo Toolbar Helper) - {5980B104-CA68-4A9F-9E78-80ADBD2CA53B} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll File not found
O2 - BHO: (Click-to-Call BHO) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (AudioGizmo Toolbar) - {C6BB606F-232D-4957-8AFF-7D4F4A220F67} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C6BB606F-232D-4957-8AFF-7D4F4A220F67} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice (ESET)
O4 - HKLM..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun (Microsoft Corporation)
O4 - HKLM..\Run: [Gjuvoxoyiviyifan] rundll32.exe "C:\WINDOWS\Ipisuru.dll",e File not found
O4 - HKLM..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1 ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Rxibaxuwibiqor] rundll32.exe "C:\WINDOWS\onixoxiw.dll",e File not found
O4 - HKLM..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" (Crawler.com)
O4 - HKCU..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe" (Stardock Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (Microsoft Corporation)
O4 - HKCU..\Run: [IEPR] C:\DOCUME~1\Owner\LOCALS~1\TempImages\IEPR.exe File not found
O4 - HKCU..\Run: [iOmem] C:\DOCUME~1\Owner\LOCALS~1\TempImages\iOmem101.exe File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe (FrostWire Group)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1216677254796 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WBSrv: DllName - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll (Stardock Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\explorer.exe: Debugger - C:\Program Files\Microsoft Common\svchost.exe ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/22 03:33:25 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\Explore\command - "" = I:\system.exe – File not found
O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\Open\command - "" = I:\system.exe – File not found
O33 - MountPoints2\{e589a2f6-7a89-11dd-b5a8-001d92b405b9}\Shell - "" = AutoRun
O33 - MountPoints2\{e589a2f6-7a89-11dd-b5a8-001d92b405b9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e589a2f6-7a89-11dd-b5a8-001d92b405b9}\Shell\AutoRun\command - "" = I:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/03/16 13:26:05 | 00,499,712 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/03/16 08:29:48 | 00,000,316 | —- | C] () – C:\WINDOWS\tasks\HP WEP.job
[2009/03/16 08:02:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\OTScanIt2
[2009/03/16 08:02:19 | 00,661,370 | —- | C] () – C:\Documents and Settings\Owner\Desktop\OTScanIt2.exe
[2009/03/16 07:59:40 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/03/16 07:57:46 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/03/11 10:03:46 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/10 13:36:46 | 00,000,868 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk
[2009/03/10 13:36:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\FrostWire
[2009/03/10 13:36:20 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2009/03/10 13:35:46 | 00,000,000 | —D | C] – C:\Program Files\FrostWire
[2009/03/10 13:29:14 | 00,000,000 | —D | C] – C:\unblock websites proxy tool
[2009/03/05 16:41:40 | 00,450,560 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioTransform2.dll
[2009/03/05 16:41:40 | 00,335,872 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioVisualization2.dll
[2009/03/05 16:41:40 | 00,196,608 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTWMAFile2.dll
[2009/03/05 16:41:39 | 01,843,200 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioFile2.dll
[2009/03/05 16:41:39 | 01,040,384 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioInformation2.dll
[2009/03/05 16:41:39 | 00,835,584 | —- | C] (NCT) – C:\WINDOWS\System32\NCTAudioCDGrabber2.dll
[2009/03/05 16:41:39 | 00,344,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr70.dll
[2009/03/05 16:41:39 | 00,315,392 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioPlayer2.dll
[2009/03/05 16:41:39 | 00,311,296 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioRecord2.dll
[2009/03/05 16:41:39 | 00,270,336 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioDisplay2.dll
[2009/03/05 16:41:39 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2009/03/05 16:41:38 | 04,057,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmfdist.exe
[2009/03/05 16:41:38 | 00,000,000 | —D | C] – C:\Program Files\FreeCDRipper
[2009/03/05 16:38:42 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\{E1DB40F6-4763-4285-BD9B-18A3C599D561}
[2009/03/05 16:25:59 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Common
[2009/03/03 15:31:11 | 00,000,000 | —D | C] – C:\Program Files\Bonjour
[2009/03/03 14:33:39 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/03/03 14:33:37 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/03/03 14:33:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/03/03 14:11:37 | 00,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/03 14:11:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Apple
[2009/03/03 14:11:35 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2009/03/03 14:11:14 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2009/03/03 14:11:14 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/03/02 16:54:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Google
[2009/03/02 16:54:06 | 00,029,697 | —- | C] () – C:\Documents and Settings\Owner\Application Data\upd.exe
[2009/03/02 11:31:35 | 00,000,000 | —D | C] – C:\Program Files\DVD Ripper Suite
[2009/03/02 11:31:24 | 00,000,000 | —D | C] – C:\Program Files\SearchIn1Step
[2009/03/02 11:31:24 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2009/02/20 19:10:04 | 00,000,000 | —- | C] () – C:\WINDOWS\WB.ini
[2009/02/20 16:14:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2009/02/20 16:11:49 | 00,000,000 | —D | C] – C:\Program Files\GIMP-2.0
[2009/02/19 18:44:39 | 00,903,168 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Ice Crystal.scr
[2009/02/19 18:44:39 | 00,495,104 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Ice Crystal.exe
[2009/02/19 18:44:39 | 00,023,558 | —- | C] () – C:\WINDOWS\Ice Crystal.ico
[2009/02/19 18:44:39 | 00,002,551 | —- | C] () – C:\WINDOWS\Ice Crystal.c2
[2009/02/19 18:44:39 | 00,001,712 | —- | C] () – C:\WINDOWS\Ice Crystal.swf
[2009/02/19 18:44:39 | 00,000,676 | —- | C] () – C:\WINDOWS\Ice Crystal.c3
[2009/02/19 18:44:39 | 00,000,676 | —- | C] () – C:\WINDOWS\Ice Crystal.c1
[2009/02/19 18:44:39 | 00,000,639 | —- | C] () – C:\WINDOWS\Ice Crystal.c4
[2009/02/19 18:44:39 | 00,000,000 | —D | C] – C:\WINDOWS\Ice Crystal Uninstaller
[2009/02/19 18:44:39 | 00,000,000 | —- | C] () – C:\WINDOWS\Ice Crystal.ini
[2009/02/19 17:59:44 | 00,042,672 | —- | C] (Stardock.Net, Inc) – C:\WINDOWS\System32\wbsys.dll
[2009/02/19 16:09:36 | 01,280,512 | —- | C] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\TheMatrixTrilogy.scr
[2009/02/19 14:48:05 | 00,001,727 | —- | C] () – C:\WINDOWS\unins000.dat
[2009/02/19 14:24:54 | 01,008,128 | —- | C] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\The Matrix Trilogy.scr
[2009/02/19 14:24:54 | 00,161,280 | —- | C] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2009/02/18 15:59:46 | 00,000,000 | —D | C] – C:\Program Files\PhotoScape
[2009/02/17 19:35:33 | 00,495,104 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Pulsing Orb.exe
[2009/02/17 19:35:33 | 00,270,398 | —- | C] () – C:\WINDOWS\Pulsing Orb.ico
[2009/02/17 19:35:33 | 00,161,078 | —- | C] () – C:\WINDOWS\Pulsing Orb.bmp
[2009/02/17 19:35:33 | 00,000,676 | —- | C] () – C:\WINDOWS\Pulsing Orb.c3
[2009/02/17 19:35:33 | 00,000,676 | —- | C] () – C:\WINDOWS\Pulsing Orb.c1
[2009/02/17 19:35:33 | 00,000,639 | —- | C] () – C:\WINDOWS\Pulsing Orb.c4
[2009/02/17 19:35:33 | 00,000,000 | —- | C] () – C:\WINDOWS\Pulsing Orb.ini
[2009/02/17 19:35:32 | 00,903,680 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Pulsing Orb.scr
[2009/02/17 19:35:32 | 00,610,162 | —- | C] () – C:\WINDOWS\Pulsing Orb.swf
[2009/02/17 19:35:32 | 00,000,000 | —D | C] – C:\WINDOWS\Pulsing Orb Uninstaller
[2009/02/17 17:20:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Mat's Stuff
[2009/02/17 16:40:13 | 00,001,685 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
[2009/02/17 16:40:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Stardock
[2009/02/17 16:39:48 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Stardock
[2009/02/17 16:37:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Stardock
[2009/02/17 16:37:16 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\{DE032019-B933-4DF4-9174-48C52613DA13}
[2009/02/17 16:37:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Stardock
[2009/02/17 16:37:14 | 00,000,000 | —D | C] – C:\Program Files\Stardock

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/03/16 13:26:06 | 00,499,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/03/16 12:03:33 | 00,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{33E247AF-18E5-4228-8CB2-028C36BDBD3B}.job
[2009/03/16 11:30:03 | 00,000,316 | —- | M] () – C:\WINDOWS\tasks\HP WEP.job
[2009/03/16 08:18:06 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/16 08:06:39 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/16 08:06:38 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/16 08:02:23 | 00,661,370 | —- | M] () – C:\Documents and Settings\Owner\Desktop\OTScanIt2.exe
[2009/03/16 07:57:46 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/03/11 08:42:56 | 00,475,154 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/11 08:42:56 | 00,404,630 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/11 08:42:56 | 00,063,740 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/11 03:07:32 | 00,146,016 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 03:01:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/10 14:19:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/10 13:36:46 | 00,000,868 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk
[2009/03/09 16:31:18 | 00,010,988 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Building 2.xlsx
[2009/03/03 14:11:58 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/03/02 16:54:06 | 00,029,697 | —- | M] () – C:\Documents and Settings\Owner\Application Data\upd.exe
[2009/02/27 16:11:57 | 00,000,650 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/20 19:10:04 | 00,000,000 | —- | M] () – C:\WINDOWS\WB.ini
[2009/02/19 16:09:36 | 01,280,512 | —- | M] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\TheMatrixTrilogy.scr
[2009/02/19 16:09:36 | 00,161,280 | —- | M] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2009/02/19 15:57:24 | 01,008,128 | —- | M] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\The Matrix Trilogy.scr
[2009/02/19 14:48:05 | 00,001,727 | —- | M] () – C:\WINDOWS\unins000.dat
[2009/02/17 16:40:13 | 00,001,685 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
< End of report >
sorry didn't click on all the stuff you told me to click but this the fixed one with everything clicked on.
OTListIt logfile created on: 3/16/2009 1:30:38 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.5.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 68.91% Memory free
3.79 Gb Paging File | 3.30 Gb Available in Paging File | 87.09% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 58.23 Gb Free Space | 78.13% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-864E4A49F
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Program Files\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Stardock\CursorFX\CursorFX.exe (Stardock Corporation)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (EhttpSrv [On_Demand | Stopped]) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn [Auto | Running]) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (fsssvc [Auto | Running]) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NMIndexingService [On_Demand | Stopped]) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (SearchIn1Step Service [Disabled | Stopped]) – File not found
SRV - (sp_rssrv [Auto | Running]) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (eamon [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\eamon.sys (ESET)
DRV - (easdrv [System | Running]) – C:\WINDOWS\system32\DRIVERS\easdrv.sys (ESET)
DRV - (epfwtdir [System | Running]) – C:\WINDOWS\system32\DRIVERS\epfwtdir.sys ()
DRV - (fssfltr [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (nvsmu [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvsmu.sys (NVIDIA Corporation)
DRV - (PalmUSBD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sp_rsdrv2 [System | Running]) – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usb_rndisx [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usb8023x.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8A CC F1 96 53 98 C9 01 [binary data]
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\S-1-5-21-1327264716-1179530476-597651651-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\S-1-5-21-1327264716-1179530476-597651651-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157"
FF - prefs.js..extensions.enabledItems: {8771569D-6C8B-45B5-8D74-5A80DDDF668D}:1.0
FF - prefs.js..extensions.enabledItems: {E1DB40F6-4763-4285-BD9B-18A3C599D561}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.1.20080205
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=IEFM1&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{E1DB40F6-4763-4285-BD9B-18A3C599D561}: C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\{E1DB40F6-4763-4285-BD9B-18A3C599D561} [2009/03/05 16:38:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/06 16:18:15 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/06 16:18:15 | 00,000,000 | —D | M]

[2008/12/11 18:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/12/11 18:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/16 08:47:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\4nsjqrgj.default\extensions
[2009/03/06 16:18:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\4nsjqrgj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/01/08 16:08:37 | 00,001,632 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\4nsjqrgj.default\searchplugins\live-search.xml
[2009/03/12 17:08:23 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/02 11:31:26 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{8771569D-6C8B-45B5-8D74-5A80DDDF668D}
[2009/03/06 16:18:15 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/06 16:18:04 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/06 16:18:04 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/06 16:18:11 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/06 16:18:11 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/06 16:18:11 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/06 16:18:11 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/06 16:18:11 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/02 11:31:24 | 00,002,415 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\searchin1.xml
[2009/03/02 11:33:46 | 00,002,420 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\searchin1172.xml
[2009/03/04 16:32:56 | 00,002,420 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\searchin1177.xml
[2009/03/06 16:18:11 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/06 16:18:11 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (253037 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8814 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AudioGizmo Toolbar Helper) - {5980B104-CA68-4A9F-9E78-80ADBD2CA53B} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll File not found
O2 - BHO: (Click-to-Call BHO) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (AudioGizmo Toolbar) - {C6BB606F-232D-4957-8AFF-7D4F4A220F67} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll File not found
O3 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\..\Toolbar\WebBrowser: (no name) - {C6BB606F-232D-4957-8AFF-7D4F4A220F67} - C:\Program Files\AudioGizmo Extension\v3.2.0.0\AudioGizmo_Toolbar.dll File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice (ESET)
O4 - HKLM..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun (Microsoft Corporation)
O4 - HKLM..\Run: [Gjuvoxoyiviyifan] rundll32.exe "C:\WINDOWS\Ipisuru.dll",e File not found
O4 - HKLM..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe 1 ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Rxibaxuwibiqor] rundll32.exe "C:\WINDOWS\onixoxiw.dll",e File not found
O4 - HKLM..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" (Crawler.com)
O4 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe" (Stardock Corporation)
O4 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" (Microsoft Corporation)
O4 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003..\Run: [IEPR] C:\DOCUME~1\Owner\LOCALS~1\TempImages\IEPR.exe File not found
O4 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003..\Run: [iOmem] C:\DOCUME~1\Owner\LOCALS~1\TempImages\iOmem101.exe File not found
O4 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk = C:\Program Files\FrostWire\FrostWire.exe (FrostWire Group)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1327264716-1179530476-597651651-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\.DEFAULT\..Trusted Domains: 40 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 40 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1216677254796 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WBSrv: DllName - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll (Stardock Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\explorer.exe: Debugger - C:\Program Files\Microsoft Common\svchost.exe ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\Explore\command - "" = I:\system.exe – File not found
O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\Open\command - "" = I:\system.exe – File not found
O33 - MountPoints2\{e589a2f6-7a89-11dd-b5a8-001d92b405b9}\Shell - "" = AutoRun
O33 - MountPoints2\{e589a2f6-7a89-11dd-b5a8-001d92b405b9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e589a2f6-7a89-11dd-b5a8-001d92b405b9}\Shell\AutoRun\command - "" = I:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/03/16 13:26:05 | 00,499,712 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/03/16 08:29:48 | 00,000,316 | —- | C] () – C:\WINDOWS\tasks\HP WEP.job
[2009/03/16 08:02:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\OTScanIt2
[2009/03/16 08:02:19 | 00,661,370 | —- | C] () – C:\Documents and Settings\Owner\Desktop\OTScanIt2.exe
[2009/03/16 07:59:40 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/03/16 07:57:46 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/03/11 10:03:46 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/10 13:36:46 | 00,000,868 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk
[2009/03/10 13:36:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\FrostWire
[2009/03/10 13:36:20 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2009/03/10 13:35:46 | 00,000,000 | —D | C] – C:\Program Files\FrostWire
[2009/03/10 13:29:14 | 00,000,000 | —D | C] – C:\unblock websites proxy tool
[2009/03/05 16:41:40 | 00,450,560 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioTransform2.dll
[2009/03/05 16:41:40 | 00,335,872 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioVisualization2.dll
[2009/03/05 16:41:40 | 00,196,608 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTWMAFile2.dll
[2009/03/05 16:41:39 | 01,843,200 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioFile2.dll
[2009/03/05 16:41:39 | 01,040,384 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioInformation2.dll
[2009/03/05 16:41:39 | 00,835,584 | —- | C] (NCT) – C:\WINDOWS\System32\NCTAudioCDGrabber2.dll
[2009/03/05 16:41:39 | 00,344,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msvcr70.dll
[2009/03/05 16:41:39 | 00,315,392 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioPlayer2.dll
[2009/03/05 16:41:39 | 00,311,296 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioRecord2.dll
[2009/03/05 16:41:39 | 00,270,336 | —- | C] (NCT Company Ltd.) – C:\WINDOWS\System32\NCTAudioDisplay2.dll
[2009/03/05 16:41:39 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2009/03/05 16:41:38 | 04,057,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wmfdist.exe
[2009/03/05 16:41:38 | 00,000,000 | —D | C] – C:\Program Files\FreeCDRipper
[2009/03/05 16:38:42 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\{E1DB40F6-4763-4285-BD9B-18A3C599D561}
[2009/03/05 16:25:59 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Common
[2009/03/03 15:31:11 | 00,000,000 | —D | C] – C:\Program Files\Bonjour
[2009/03/03 14:33:39 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/03/03 14:33:37 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/03/03 14:33:37 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/03/03 14:11:37 | 00,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/03 14:11:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Apple
[2009/03/03 14:11:35 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2009/03/03 14:11:14 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2009/03/03 14:11:14 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/03/02 16:54:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Google
[2009/03/02 16:54:06 | 00,029,697 | —- | C] () – C:\Documents and Settings\Owner\Application Data\upd.exe
[2009/03/02 11:31:35 | 00,000,000 | —D | C] – C:\Program Files\DVD Ripper Suite
[2009/03/02 11:31:24 | 00,000,000 | —D | C] – C:\Program Files\SearchIn1Step
[2009/03/02 11:31:24 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2009/02/20 19:10:04 | 00,000,000 | —- | C] () – C:\WINDOWS\WB.ini
[2009/02/20 16:14:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2009/02/20 16:11:49 | 00,000,000 | —D | C] – C:\Program Files\GIMP-2.0
[2009/02/19 18:44:39 | 00,903,168 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Ice Crystal.scr
[2009/02/19 18:44:39 | 00,495,104 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Ice Crystal.exe
[2009/02/19 18:44:39 | 00,023,558 | —- | C] () – C:\WINDOWS\Ice Crystal.ico
[2009/02/19 18:44:39 | 00,002,551 | —- | C] () – C:\WINDOWS\Ice Crystal.c2
[2009/02/19 18:44:39 | 00,001,712 | —- | C] () – C:\WINDOWS\Ice Crystal.swf
[2009/02/19 18:44:39 | 00,000,676 | —- | C] () – C:\WINDOWS\Ice Crystal.c3
[2009/02/19 18:44:39 | 00,000,676 | —- | C] () – C:\WINDOWS\Ice Crystal.c1
[2009/02/19 18:44:39 | 00,000,639 | —- | C] () – C:\WINDOWS\Ice Crystal.c4
[2009/02/19 18:44:39 | 00,000,000 | —D | C] – C:\WINDOWS\Ice Crystal Uninstaller
[2009/02/19 18:44:39 | 00,000,000 | —- | C] () – C:\WINDOWS\Ice Crystal.ini
[2009/02/19 17:59:44 | 00,042,672 | —- | C] (Stardock.Net, Inc) – C:\WINDOWS\System32\wbsys.dll
[2009/02/19 16:09:36 | 01,280,512 | —- | C] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\TheMatrixTrilogy.scr
[2009/02/19 14:48:05 | 00,001,727 | —- | C] () – C:\WINDOWS\unins000.dat
[2009/02/19 14:24:54 | 01,008,128 | —- | C] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\The Matrix Trilogy.scr
[2009/02/19 14:24:54 | 00,161,280 | —- | C] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2009/02/18 15:59:46 | 00,000,000 | —D | C] – C:\Program Files\PhotoScape
[2009/02/17 19:35:33 | 00,495,104 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Pulsing Orb.exe
[2009/02/17 19:35:33 | 00,270,398 | —- | C] () – C:\WINDOWS\Pulsing Orb.ico
[2009/02/17 19:35:33 | 00,161,078 | —- | C] () – C:\WINDOWS\Pulsing Orb.bmp
[2009/02/17 19:35:33 | 00,000,676 | —- | C] () – C:\WINDOWS\Pulsing Orb.c3
[2009/02/17 19:35:33 | 00,000,676 | —- | C] () – C:\WINDOWS\Pulsing Orb.c1
[2009/02/17 19:35:33 | 00,000,639 | —- | C] () – C:\WINDOWS\Pulsing Orb.c4
[2009/02/17 19:35:33 | 00,000,000 | —- | C] () – C:\WINDOWS\Pulsing Orb.ini
[2009/02/17 19:35:32 | 00,903,680 | —- | C] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Pulsing Orb.scr
[2009/02/17 19:35:32 | 00,610,162 | —- | C] () – C:\WINDOWS\Pulsing Orb.swf
[2009/02/17 19:35:32 | 00,000,000 | —D | C] – C:\WINDOWS\Pulsing Orb Uninstaller
[2009/02/17 17:20:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Mat's Stuff
[2009/02/17 16:40:13 | 00,001,685 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
[2009/02/17 16:40:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Stardock
[2009/02/17 16:39:48 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Stardock
[2009/02/17 16:37:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Stardock
[2009/02/17 16:37:16 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\{DE032019-B933-4DF4-9174-48C52613DA13}
[2009/02/17 16:37:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Stardock
[2009/02/17 16:37:14 | 00,000,000 | —D | C] – C:\Program Files\Stardock

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/03/16 13:26:06 | 00,499,712 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/03/16 12:03:33 | 00,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{33E247AF-18E5-4228-8CB2-028C36BDBD3B}.job
[2009/03/16 11:30:03 | 00,000,316 | —- | M] () – C:\WINDOWS\tasks\HP WEP.job
[2009/03/16 08:18:06 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/16 08:06:39 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/16 08:06:38 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/16 08:02:23 | 00,661,370 | —- | M] () – C:\Documents and Settings\Owner\Desktop\OTScanIt2.exe
[2009/03/16 07:57:46 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/03/11 08:42:56 | 00,475,154 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/11 08:42:56 | 00,404,630 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/11 08:42:56 | 00,063,740 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/11 03:07:32 | 00,146,016 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 03:01:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/10 14:19:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/10 13:36:46 | 00,000,868 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk
[2009/03/09 16:31:18 | 00,010,988 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Building 2.xlsx
[2009/03/03 14:11:58 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/03/02 16:54:06 | 00,029,697 | —- | M] () – C:\Documents and Settings\Owner\Application Data\upd.exe
[2009/02/27 16:11:57 | 00,000,650 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/25 12:55:00 | 24,768,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/02/20 19:10:04 | 00,000,000 | —- | M] () – C:\WINDOWS\WB.ini
[2009/02/19 16:09:36 | 01,280,512 | —- | M] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\TheMatrixTrilogy.scr
[2009/02/19 16:09:36 | 00,161,280 | —- | M] (Firelight Technologies Pty, Ltd) – C:\WINDOWS\System32\fmod.dll
[2009/02/19 15:57:24 | 01,008,128 | —- | M] (The Matrix Trilogy Screensaver Development Team) – C:\WINDOWS\System32\The Matrix Trilogy.scr
[2009/02/19 14:48:05 | 00,001,727 | —- | M] () – C:\WINDOWS\unins000.dat
[2009/02/17 16:40:13 | 00,001,685 | —- | M] () – C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk

========== LOP Check ==========

[2009/03/16 07:59:40 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/03 14:33:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/11/17 14:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/03/03 14:11:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/03/03 14:33:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/11/06 08:46:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg8
[2008/09/29 15:05:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/11/06 11:35:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2008/09/23 07:49:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2008/09/03 14:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2008/11/04 16:35:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2009/01/08 15:20:24 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/03/11 03:01:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/07/21 13:51:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2008/09/18 14:45:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pianosoft
[2008/07/21 13:46:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/02/27 09:11:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/07/21 15:54:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/04 10:13:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2008/07/21 21:23:57 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Default User\Application Data
[2008/07/22 03:33:23 | 00,000,000 | –SD | M] – C:\Documents and Settings\Default User\Application Data\Microsoft
[2008/07/22 03:35:55 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data
[2008/11/06 08:45:37 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/03/02 11:31:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Mozilla
[2008/07/22 03:35:34 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data
[2008/11/06 08:45:37 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/03/10 13:36:20 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data
[2008/09/23 09:00:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2009/03/04 15:02:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2008/09/23 07:50:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2008/09/29 15:05:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2009/03/10 15:19:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2008/12/11 20:09:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2009/03/02 16:54:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Google
[2009/02/20 16:21:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gtk-2.0
[2008/09/23 07:49:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HotSync
[2008/07/22 03:37:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2008/07/22 03:43:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2008/11/04 14:20:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Internet Antivirus Pro
[2009/03/03 18:33:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/01/22 15:41:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2008/12/11 18:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2009/03/12 00:00:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spyware Terminator
[2008/07/21 13:47:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2008/09/04 09:57:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Tibia
[2009/01/05 19:05:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2009/03/10 14:19:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/04/14 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/16 11:30:03 | 00,000,316 | —- | M] () – C:\WINDOWS\Tasks\HP WEP.job
[2009/03/16 08:06:39 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/03/16 12:03:33 | 00,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{33E247AF-18E5-4228-8CB2-028C36BDBD3B}.job

========== Purity Check ==========

< End of report >
Could you let me know how your computer is running on completion of this

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    SRV - (SearchIn1Step Service [Disabled | Stopped]) – File not found
    O4 - HKLM..\Run: [Gjuvoxoyiviyifan] rundll32.exe "C:\WINDOWS\Ipisuru.dll",e File not found
    O4 - HKLM..\Run: [Rxibaxuwibiqor] rundll32.exe "C:\WINDOWS\onixoxiw.dll",e File not found
    O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\Explore\command - "" = I:\system.exe – File not found
    O33 - MountPoints2\{a8f4208c-082f-11de-b5cf-001d92b405b9}\Shell\Open\command - "" = I:\system.exe – File not found
    
    :Files
    C:\Program Files\SearchIn1Step
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
In that case and subject to no further problems

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI