hi oldman
all tools remain on desktop. here is the OTLIST2 log
OTListIt logfile created on: 2009-04-11 23:16:22 - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\al\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd
254.98 Mb Total Physical Memory | 84.38 Mb Available Physical Memory | 33.09% Memory free
626.95 Mb Paging File | 281.05 Mb Available in Paging File | 44.83% Paging File free
Paging file location(s): C:\pagefile.sys 385 1000;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.22 Gb Total Space | 18.30 Gb Free Space | 49.17% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MIULING
Current User Name: al
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
PRC - C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe (America Online Inc)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\mcafee.com\antivirus\McShield.exe (McAfee Inc.)
PRC - C:\Program Files\mcafee.com\personal firewall\MPFService.exe (McAfee Corporation)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\mcafee.com\personal firewall\MPFTray.exe (McAfee Security)
PRC - C:\Documents and Settings\al\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AOL TopSpeedMonitor [Auto | Running]) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (America Online, Inc)
SRV - (aolavupd [Auto | Running]) – C:\Program Files\Common Files\AOL\1159552586\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe (AOL LLC)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (McShield [Auto | Running]) – C:\Program Files\mcafee.com\antivirus\McShield.exe (McAfee Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\mcafee.com\personal firewall\MPFService.exe (McAfee Corporation)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WANMiniportService [Auto | Running]) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ac97intc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (aliidex [Boot | Running]) – C:\WINDOWS\System32\drivers\aliidex.sys (Windows ® 2000 DDK provider)
DRV - (aliperf [Boot | Running]) – C:\WINDOWS\system32\drivers\aliperf.sys (Windows ® 2000 DDK provider)
DRV - (AN983 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\AN983.sys (ADMtek Incorporated.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (basic2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\basic2.sys (Conexant Systems)
DRV - (brfilt [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Brfilt.sys (Brother Industries Ltd.)
DRV - (BrSerWDM [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbScn [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\BrUsbScn.sys (Brother Industries Ltd.)
DRV - (CamDrL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (Cnxtdiag [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\cnxtdiag.sys (Conexant Systems)
DRV - (epstw2k [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\epstw2k.sys (Microsoft Corporation)
DRV - (Fallback [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\fallback.sys (Conexant Systems)
DRV - (Fsks [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\fsksnt.sys (Conexant Systems)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (hidgame [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\hidgame.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (hsf_msft [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys (Conexant)
DRV - (ICAM3NT5 [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\Icam3.sys (Microsoft Corporation)
DRV - (K56 [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\k56nt.sys (Conexant Systems)
DRV - (LVUSBSta [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (mf [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\mf.sys (Microsoft Corporation)
DRV - (MPFIREWL [System | Running]) – C:\WINDOWS\System32\Drivers\MpFirewall.sys (McAfee)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (NaiAvFilter1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\naiavf5x.sys (McAfee Inc.)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RimUsb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\RimUsb.sys (Research In Motion Limited)
DRV - (RimVSerPort [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RimSerial.sys (Research in Motion Ltd)
DRV - (Rksample [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\rksample.sys (Conexant Systems)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (scsiscan [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\scsiscan.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ser2pl [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (SoftFax [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\faxnt.sys (Conexant Systems)
DRV - (Tones [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\tonesnt.sys (Conexant Systems)
DRV - (usbaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (V124 [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\v124nt.sys (Conexant Systems)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {C156E417-9A64-4EAC-A086-55F394343BB5}:1.0
FF - prefs.js..extensions.enabledItems: {C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\Extensions\\{C156E417-9A64-4EAC-A086-55F394343BB5}: C:\DOCUMENTS AND SETTINGS\AL\LOCAL SETTINGS\APPLICATION DATA\{C156E417-9A64-4EAC-A086-55F394343BB5} [2008-12-17 13:24:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}: C:\DOCUMENTS AND SETTINGS\MARIAN\LOCAL SETTINGS\APPLICATION DATA\{C23BDED9-5414-4EFD-ACC9-64BFDCB0023C}\ [2009-03-02 10:06:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-04-02 20:53:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-03-28 20:12:37 | 00,000,000 | —D | M]
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Extensions
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008-12-16 21:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\al\Application Data\mozilla\Firefox\Profiles\0fe092zp.default\extensions
[2008-12-16 21:14:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009-03-28 20:12:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-03-28 20:12:25 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-03-28 20:12:25 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-03-13 09:46:19 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009-03-13 09:46:19 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009-03-13 09:46:19 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009-03-13 09:46:19 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009-03-13 09:46:19 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-03-13 09:46:19 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009-03-13 09:46:19 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (BellSouth Toolbar) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (ST) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (MSNToolBandBHO) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - File not found
O3 - HKLM\..\Toolbar: (BellSouth Toolbar) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (MSN) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\Program Files\blstoolbar\blstoolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MPFEXE] "C:\Program Files\mcafee.com\personal firewall\MPFTray.exe" (McAfee Security)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://by7fd.bay7.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4}
http://catalog.update.microsoft.com/v7/sit…b?1199841972187 (MUCatalogWebControl Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1199841588625 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…7387.6772222222 (Reg Error: Key error.)
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D}
http://www.ravantivirus.com/scan/ravonline.cab (CRAVOnline Object)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} http://messenger.msn.com/download/MsnMesse…pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6}
http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[5 C:\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009-04-11 23:08:32 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTListIt2.exe
[2009-04-11 23:04:53 | 00,180,736 | —- | C] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTCleanIt.exe
[2009-04-11 17:39:48 | 00,360,002 | —- | C] () – C:\Documents and Settings\al\Desktop\dds.scr
[2009-04-11 17:20:42 | 00,000,000 | —D | C] – C:\WINDOWS\Temp
[2009-04-11 17:18:06 | 00,455,680 | —- | C] () – C:\Documents and Settings\al\Desktop\ToolsCleaner2.exe
[2009-04-11 17:06:23 | 00,000,000 | —D | C] – C:\worksnow
[2009-04-11 13:35:10 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009-04-11 13:30:08 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009-04-11 13:27:41 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2009-04-11 13:25:21 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009-04-11 13:24:36 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009-04-11 13:18:13 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009-04-11 13:17:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009-04-11 13:17:40 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009-04-11 13:16:20 | 00,000,000 | —D | C] – C:\Program Files\Windows Live
[2009-04-11 12:55:36 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009-04-11 12:53:19 | 01,143,656 | —- | C] (Microsoft Corporation) – C:\Program Files\wlsetup-web.exe
[2009-04-10 15:33:30 | 26,744,0128 | -HS- | C] () – C:\hiberfil.sys
[2009-04-10 15:30:21 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\almar
[2009-04-10 15:19:28 | 00,000,256 | —- | C] () – C:\Documents and Settings\al\Desktop\almar.zip
[2009-04-09 21:38:52 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009-04-09 21:38:52 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009-04-09 12:01:11 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Application Data\Malwarebytes
[2009-04-09 12:01:04 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009-04-09 12:01:03 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009-04-09 12:01:01 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-04-09 12:00:58 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009-04-09 12:00:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009-04-09 11:48:05 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\al\Desktop\mbam-setup.exe
[2009-04-08 13:49:22 | 00,059,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009-04-08 13:49:22 | 00,059,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2009-04-08 13:47:57 | 00,000,000 | —D | C] – C:\Program Files\Common Files\logishrd
[2009-04-08 01:07:31 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF12995.exe
[2009-04-08 00:49:24 | 03,307,596 | R— | C] () – C:\Documents and Settings\al\Desktop\worksnow.exe
[2009-04-07 16:50:12 | 03,063,218 | —- | C] (Symantec Corporation) – C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
[2009-04-07 09:37:45 | 00,091,648 | —- | C] () – C:\Documents and Settings\al\Desktop\SystemLook.exe
[2009-04-06 08:29:41 | 16,021,536 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-06 08:29:41 | 00,188,828 | -HS- | C] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-05 10:35:38 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\Virus Removal Tool
[2009-04-05 10:23:49 | 37,352,800 | —- | C] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:27 | 00,097,759 | —- | C] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 16:18:09 | 00,000,000 | —- | C] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 16:18:00 | 01,516,400 | —- | C] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 14:20:44 | 00,360,002 | —- | C] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:09:13 | 00,000,000 | —D | C] – C:\Documents and Settings\al\Desktop\RootRepeal
[2009-04-02 17:01:26 | 00,440,104 | —- | C] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip
[2009-04-02 11:08:02 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009-04-02 11:02:00 | 00,000,592 | —- | C] () – C:\Documents and Settings\al\Desktop\ERUNT.lnk
[2009-04-02 11:01:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009-04-02 10:55:57 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\al\Desktop\erunt-setup.exe
[2009-03-31 19:13:43 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009-03-31 14:03:14 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009-03-31 12:39:59 | 00,115,671 | —- | C] () – C:\Documents and Settings\al\My Documents\duaa.jpg
[2009-03-27 18:50:56 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
[2008-01-03 18:27:54 | 00,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2007-06-04 23:21:04 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2007-06-04 23:20:25 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2007-02-03 08:59:04 | 00,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007-01-14 19:28:13 | 00,002,324 | —- | C] () – C:\WINDOWS\BRMFBIDI.INI
[2006-10-22 13:22:00 | 00,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006-05-23 14:28:44 | 00,000,208 | —- | C] () – C:\WINDOWS\Dit.INI
[2006-05-23 14:28:43 | 00,139,264 | —- | C] () – C:\WINDOWS\Dit.DLL
[2006-05-12 15:49:42 | 00,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006-05-12 15:43:15 | 00,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006-03-18 04:11:02 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005-11-22 18:37:26 | 00,000,073 | —- | C] () – C:\WINDOWS\upst.ini
[2005-08-20 15:18:31 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2005-07-18 17:26:05 | 00,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2005-06-09 16:46:15 | 00,000,062 | —- | C] () – C:\WINDOWS\draw.ini
[2005-06-09 16:41:53 | 00,000,158 | —- | C] () – C:\WINDOWS\estud.ini
[2005-04-27 14:38:00 | 00,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2005-04-27 14:37:49 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2005-04-01 17:16:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005-04-01 17:16:00 | 01,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005-04-01 17:16:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005-04-01 17:16:00 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005-04-01 17:16:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005-04-01 17:16:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2004-11-28 21:33:16 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2004-10-16 00:11:19 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004-10-16 00:11:19 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2004-10-15 23:48:16 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004-09-28 13:10:22 | 00,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004-06-24 19:02:30 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2004-06-24 12:17:19 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2004-06-24 12:13:51 | 00,000,028 | —- | C] () – C:\WINDOWS\ICOA.INI
[2004-06-24 12:10:22 | 00,000,650 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004-06-24 12:10:21 | 00,001,687 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004-06-24 12:10:17 | 00,000,252 | —- | C] () – C:\WINDOWS\ADDRBOOK.INI
[2004-06-24 12:10:14 | 00,207,872 | —- | C] () – C:\WINDOWS\System32\RDMWIN32.DLL
[2004-06-24 12:09:54 | 00,000,054 | —- | C] () – C:\WINDOWS\QFP.INI
[2004-06-24 12:09:54 | 00,000,054 | —- | C] () – C:\WINDOWS\MFF.INI
[2004-06-01 17:47:14 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004-05-31 00:32:50 | 00,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004-05-31 00:32:49 | 00,000,027 | —- | C] () – C:\WINDOWS\upth.ini
[2004-03-19 16:05:29 | 00,002,415 | —- | C] () – C:\WINDOWS\TRA.INI
[2004-01-22 12:00:28 | 00,012,635 | —- | C] () – C:\WINDOWS\System32\DAntivirus.ini
[2003-12-04 12:59:49 | 00,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2003-10-09 08:18:08 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\missouri.dll
[2003-07-19 14:25:06 | 00,000,087 | —- | C] () – C:\WINDOWS\WALLSTRT.INI
[2003-03-27 15:28:44 | 00,004,955 | —- | C] () – C:\WINDOWS\System32\DProg.ini
[2003-02-08 18:35:07 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2003-02-08 18:34:37 | 00,000,056 | —- | C] () – C:\WINDOWS\winhelp.ini
[2003-02-08 18:34:24 | 00,795,548 | —- | C] () – C:\WINDOWS\System32\ica2.dll
[2003-02-08 18:33:33 | 01,523,712 | —- | C] () – C:\WINDOWS\System32\VARIETYPACKLOCALIZATION.DLL
[2003-02-08 18:33:32 | 01,830,912 | —- | C] () – C:\WINDOWS\System32\RFVPB.dll
[2003-02-08 18:33:32 | 01,699,840 | —- | C] () – C:\WINDOWS\System32\RFVPS.dll
[2003-02-08 18:33:32 | 00,401,408 | —- | C] () – C:\WINDOWS\System32\rfutils.dll
[2003-02-08 18:33:32 | 00,335,872 | —- | C] () – C:\WINDOWS\System32\RFVPPTB.dll
[2003-02-08 18:33:32 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\GenericVFW.dll
[2003-02-08 18:33:32 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\rfnullvideo.dll
[2003-02-08 18:33:32 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\RFInstallRoutines.dll
[2003-02-08 18:32:58 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2002-11-01 16:17:50 | 00,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2002-09-14 15:39:29 | 00,000,069 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2002-08-05 20:40:52 | 00,002,586 | —- | C] () – C:\WINDOWS\Xtreme.ini
[2002-07-04 15:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2002-06-12 17:50:29 | 00,000,074 | —- | C] () – C:\WINDOWS\eFaxView.ini
[2002-05-22 10:53:49 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2002-05-01 17:35:17 | 00,000,355 | —- | C] () – C:\WINDOWS\EXLAW.INI
[2002-05-01 17:35:17 | 00,000,103 | —- | C] () – C:\WINDOWS\HIGHEDIT.INI
[2002-02-20 21:19:51 | 00,000,304 | —- | C] () – C:\WINDOWS\hpccopy.INI
[2002-02-19 19:53:46 | 00,000,928 | —- | C] () – C:\WINDOWS\System32\hpsj1695.dll
[2002-02-19 19:53:44 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2002-02-19 19:53:43 | 00,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2002-02-19 18:09:02 | 00,000,074 | —- | C] () – C:\WINDOWS\hpsjbmgr.ini
[2002-02-18 20:08:57 | 00,000,029 | —- | C] () – C:\WINDOWS\qbwcd.ini
[2002-02-18 20:07:15 | 00,003,275 | —- | C] () – C:\WINDOWS\WININIT.INI
[2002-02-18 20:06:18 | 00,001,385 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2002-02-18 20:06:08 | 00,000,362 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2002-02-18 20:06:08 | 00,000,038 | —- | C] () – C:\WINDOWS\ACCWIZ.INI
[2002-02-18 20:06:08 | 00,000,021 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2002-02-17 21:20:27 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2002-01-05 12:53:40 | 00,000,482 | —- | C] () – C:\WINDOWS\ODBC.INI
[2001-12-21 15:19:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2001-12-21 15:02:52 | 00,000,884 | —- | C] () – C:\WINDOWS\orun32.ini
[2001-12-21 15:00:48 | 00,000,777 | —- | C] () – C:\WINDOWS\lrun32.ini
[2001-12-21 13:38:43 | 00,001,012 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001-12-21 13:38:43 | 00,000,433 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2001-12-21 13:38:09 | 00,001,899 | —- | C] () – C:\WINDOWS\win.ini
[2001-12-21 13:38:02 | 00,000,491 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2001-12-21 13:37:33 | 00,000,325 | —- | C] () – C:\WINDOWS\System32\ntnet.drv
[2001-12-14 13:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[1999-07-23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999-07-23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999-01-22 14:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998-01-12 04:00:00 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
[1997-10-24 15:56:36 | 00,000,643 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
========== Files - Modified Within 30 Days ==========
[5 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009-04-11 23:08:33 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTListIt2.exe
[2009-04-11 23:04:58 | 00,180,736 | —- | M] (OldTimer Tools) – C:\Documents and Settings\al\Desktop\OTCleanIt.exe
[2009-04-11 23:01:15 | 00,075,680 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009-04-11 23:00:21 | 00,088,224 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009-04-11 23:00:18 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009-04-11 22:57:21 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009-04-11 22:56:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009-04-11 22:56:39 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009-04-11 22:56:30 | 26,744,0128 | -HS- | M] () – C:\hiberfil.sys
[2009-04-11 22:56:30 | 00,274,168 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009-04-11 17:39:51 | 00,360,002 | —- | M] () – C:\Documents and Settings\al\Desktop\dds.scr
[2009-04-11 17:18:24 | 00,455,680 | —- | M] () – C:\Documents and Settings\al\Desktop\ToolsCleaner2.exe
[2009-04-11 13:48:25 | 00,077,576 | —- | M] () – C:\Documents and Settings\al\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009-04-11 13:43:31 | 00,407,210 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009-04-11 13:43:31 | 00,393,968 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009-04-11 13:43:31 | 00,059,472 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009-04-11 13:21:31 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009-04-11 12:34:07 | 00,000,888 | —- | M] () – C:\Documents and Settings\al\My Documents\My Sharing Folders.lnk
[2009-04-11 11:50:32 | 16,021,536 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.dat
[2009-04-11 11:50:32 | 00,188,828 | -HS- | M] () – C:\WINDOWS\System32\drivers\fidbox.idx
[2009-04-10 17:55:27 | 00,001,899 | —- | M] () – C:\WINDOWS\win.ini
[2009-04-10 15:19:41 | 00,000,256 | —- | M] () – C:\Documents and Settings\al\Desktop\almar.zip
[2009-04-09 21:49:06 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009-04-09 21:38:52 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009-04-09 21:38:52 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009-04-09 12:01:04 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009-04-09 11:48:23 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\al\Desktop\mbam-setup.exe
[2009-04-08 23:09:16 | 00,002,497 | —- | M] () – C:\Documents and Settings\al\Desktop\Microsoft Outlook (2).lnk
[2009-04-08 01:07:24 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF12995.exe
[2009-04-08 01:03:21 | 03,307,596 | R— | M] () – C:\Documents and Settings\al\Desktop\worksnow.exe
[2009-04-07 16:52:13 | 03,063,218 | —- | M] (Symantec Corporation) – C:\Documents and Settings\al\Desktop\Norton_Removal_Tool.exe
[2009-04-07 09:37:48 | 00,091,648 | —- | M] () – C:\Documents and Settings\al\Desktop\SystemLook.exe
[2009-04-06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-04-06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009-04-05 10:31:33 | 37,352,800 | —- | M] ( ) – C:\Documents and Settings\al\Desktop\setup_7.0.0.290_05.04.2009_16-12.exe
[2009-04-04 17:56:35 | 00,097,759 | —- | M] () – C:\Documents and Settings\al\Desktop\user.zip
[2009-04-03 17:50:11 | 01,516,400 | —- | M] (Doctor Web, Ltd.) – C:\Documents and Settings\al\Desktop\drweb-cureit.exe.part
[2009-04-03 16:18:09 | 00,000,000 | —- | M] () – C:\Documents and Settings\al\Desktop\drweb-cureit.exe
[2009-04-03 14:20:46 | 00,360,002 | —- | M] () – C:\Documents and Settings\al\Desktop\dds.pif
[2009-04-02 17:01:38 | 00,440,104 | —- | M] () – C:\Documents and Settings\al\Desktop\RootRepeal.zip
[2009-04-02 11:02:00 | 00,000,592 | —- | M] () – C:\Documents and Settings\al\Desktop\ERUNT.lnk
[2009-04-02 10:55:59 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\al\Desktop\erunt-setup.exe
[2009-03-31 12:40:00 | 00,115,671 | —- | M] () – C:\Documents and Settings\al\My Documents\duaa.jpg
[2009-03-30 19:50:40 | 02,624,744 | -H– | M] () – C:\Documents and Settings\al\Local Settings\Application Data\IconCache.db
[2009-03-28 14:42:08 | 00,000,029 | —- | M] () – C:\WINDOWS\qbwcd.ini
[2009-03-28 14:35:44 | 00,001,687 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009-03-28 11:47:17 | 00,110,060 | —- | M] () – C:\WINDOWS\hpoins11.dat
[2009-03-28 09:30:15 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009-03-18 20:09:53 | 00,002,180 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009-03-17 21:20:06 | 00,001,751 | —- | M] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
========== Alternate Data Streams ==========
@Alternate Data Stream - 2972 bytes -> C:\WINDOWS\System32\OEMLOGO.BMP:Q30lsldxJoudresxAaaqpcawXc
< End of report >
I ran OTCleanIt, there was no log produced.