This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cannot Access McAfee Website

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I believe that my PC has been infected with malware. My main problem, that I cannot work around, is that when I attempt to access the McAfee website, using IE - the loading of the page stops; using Netscape - a message apprears to state that the "document has no contents" or something to that effect. Secondly, my internet browsing started acting strange a few weeks ago when I was getting redirected to a different website when I tried to connect to the site I wanted. I was able to work around that. I ran HijackThis and my log follows. I apprecieate any help you can give:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:36 AM, on 4/4/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Radmin\r_server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Dell\Media Experience\PCM2.exe
C:\WINDOWS\System32\hpbpro.exe
C:\WINDOWS\System32\hpboid.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://netscape.aol.com/"); (C:\Documents and

Settings\TIM\Application Data\Mozilla\Profiles\default\bl0vpmod.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",

"engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and

Settings\TIM\Application Data\Mozilla\Profiles\default\bl0vpmod.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program

Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program

Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program

Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} -

c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding

-boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKUS\S-1-5-19\..\Run: [zulefejume] Rundll32.exe "C:\WINDOWS\System32\batimalu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [zulefejume] Rundll32.exe "C:\WINDOWS\System32\batimalu.dll",s (User 'NETWORK SERVICE')
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -

http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -

http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.5.cab
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) -

http://i.dell.com/images/global/js/scanner/SysProExe.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/2405419e1e5e12…ip/RdxIE601.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) -

http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/…b?1122130191891
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) -

http://h30155.www3.hp.com/ediags/dd/instal…edsolutions.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -

https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -

http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common

Files\Seagate\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN

Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\System32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\System32\hpboid.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application

Accelerator\iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program

Files\Java\jre6\bin\jqs.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\Program Files\Radmin\r_server.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 16386 bytes
Hi there when you post logs can you ensure that wordwrap is not checked in notepad as it makes them difficult to read

Lets see what you have first

Download Rooter.exe to your desktop
  • Doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%(usually C:)\Rooter.txt. Copy and paste it with your OTLI log.

THEN

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Hi EssexBoy, Sorry about the word wrap.

Rooter.exe log:

Microsoft Windows XP Professional (5.1.2600) Service Pack 1

C:\ [Fixed] - NTFS - (Total:149495 Mo/Free:1324 Mo)
D:\ [Fixed] - NTFS - (Total:305242 Mo/Free:3631 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)

Sat 04/04/2009|10:15

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\System32\Ati2evxx.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
———- C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
———- C:\Program Files\Dell\Media Experience\PCMService.exe
———- C:\WINDOWS\system32\dla\tfswctrl.exe
———- C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
———- C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
———- C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
———- C:\WINDOWS\System32\CTHELPER.EXE
———- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
———- C:\PROGRA~1\Yahoo!\browser\ycommon.exe
———- C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb11.exe
———- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
———- C:\WINDOWS\system32\hphmon06.exe
———- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
———- C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
———- C:\PROGRA~1\Yahoo!\YOP\yop.exe
———- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
———- C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
———- C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
———- C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
———- C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
———- C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
———- C:\Program Files\Java\jre6\bin\jusched.exe
———- C:\Program Files\Microsoft Money\System\mnyexpr.exe
———- C:\WINDOWS\System32\ctfmon.exe
———- C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
———- C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
———- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
———- C:\WINDOWS\System32\CTsvcCDA.exe
———- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
———- C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
———- C:\Program Files\Java\jre6\bin\jqs.exe
———- C:\Program Files\TrueAssistant\TrueAssistant.exe
———- C:\WINDOWS\system32\LxrJD31s.exe
———- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
———- C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
———- c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
———- c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
———- C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
———- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
———- C:\Program Files\McAfee\MPF\MPFSrv.exe
———- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
———- C:\Program Files\Radmin\r_server.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\wdfmgr.exe
———- C:\WINDOWS\System32\MsPMSPSv.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\fxssvc.exe
———- C:\WINDOWS\System32\wuauclt.exe
———- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
———- C:\WINDOWS\System32\HPZipm12.exe
———- C:\Program Files\Dell\Media Experience\PCM2.exe
———- C:\WINDOWS\System32\hpbpro.exe
———- C:\WINDOWS\System32\hpboid.exe
———- C:\Program Files\Netscape\Netscape\Netscp.exe
———- C:\Documents and Settings\Tim\My Documents\My Downloads\Rooter.exe
———- C:\WINDOWS\System32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!


———————-\\ Cracks & Keygens..

C:\DOCUME~1\Tim\Cookies\tim@crackle[2].txt
C:\DOCUME~1\Tim\Cookies\[removed][1].txt
C:\DOCUME~1\Tim\Local Settings\Temporary Internet Files\Content.IE5\AYEHXXG2\Q109_KMCCrackers_300x250[1].swf


1 - "C:\Rooter$\Rooter_1.txt" - Sat 04/04/2009|10:16

———————-\\ Scan completed at 10:16


OTListIt.Txt:

OTListIt logfile created on: 4/4/2009 10:20:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.10.0 Folder = C:\Documents and Settings\Tim\My Documents\My Downloads
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.90 Gb Available in Paging File | 97.47% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.99 Gb Total Space | 37.29 Gb Free Space | 25.54% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 67.55 Gb Free Space | 22.66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDWVCF51
Current User Name: Tim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
PRC - C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE (Creative Technology Ltd)
PRC - C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb11.exe (HP)
PRC - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\system32\hphmon06.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Yahoo!\YOP\yop.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
PRC - C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
PRC - C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft Money\System\mnyexpr.exe (Microsoft Corp.)
PRC - C:\Program Files\Ahead\Nero PhotoShow\data\Xtras\mssysmgr.exe (Ahead Software)
PRC - C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
PRC - C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
PRC - C:\WINDOWS\system32\LxrJD31s.exe ()
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Radmin\r_server.exe ()
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\WINDOWS\System32\HPZipm12.exe (HP)
PRC - C:\Program Files\Dell\Media Experience\PCM2.exe (CyberLink Corp.)
PRC - C:\WINDOWS\System32\hpbpro.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\hpboid.exe (Hewlett-Packard Company)
PRC - C:\Documents and Settings\Tim\My Documents\My Downloads\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AcrSch2Svc [Auto | Running]) – C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Acronis)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe ()
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\System32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (CVPND [Auto | Running]) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HP Port Resolver [On_Demand | Running]) – C:\WINDOWS\System32\hpbpro.exe (Hewlett-Packard Company)
SRV - (HP Status Server [On_Demand | Running]) – C:\WINDOWS\System32\hpboid.exe (Hewlett-Packard Company)
SRV - (IAANTMon [Auto | Running]) – C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe (Intel Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LxrJD31s [Auto | Running]) – C:\WINDOWS\system32\LxrJD31s.exe ()
SRV - (McAfee SiteAdvisor Service [Auto | Running]) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSSQL$MICROSOFTBCM [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Unknown | Running]) – C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (r_server [Auto | Running]) – C:\Program Files\Radmin\r_server.exe ()
SRV - (SQLAgent$MICROSOFTBCM [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
SRV - (uploadmgr [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINDOWS\System32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (YPCService [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\YPcservice.exe (Yahoo! Inc.)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (ASAPIW2K [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\ASAPIW2K.sys (VOB Computersysteme GmbH)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (b57w2k [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (bvrp_pci [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (COMMONFX.DLL [On_Demand | Running]) – C:\WINDOWS\system32\COMMONFX.DLL (Creative Technology Ltd)
DRV - (CT20XUT.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CT20XUT.DLL (Creative Technology Ltd.)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (CTAUDFX.DLL [On_Demand | Running]) – C:\WINDOWS\system32\CTAUDFX.DLL (Creative Technology Ltd)
DRV - (ctdvda2k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (CTEAPSFX.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTEAPSFX.DLL (Creative Technology Ltd)
DRV - (CTEDSPFX.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTEDSPFX.DLL (Creative Technology Ltd)
DRV - (CTEDSPIO.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTEDSPIO.DLL (Creative Technology Ltd)
DRV - (CTEDSPSY.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTEDSPSY.DLL (Creative Technology Ltd)
DRV - (CTERFXFX.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTERFXFX.DLL (Creative Technology Ltd)
DRV - (CTEXFIFX.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTEXFIFX.DLL (Creative Technology Ltd.)
DRV - (CTHWIUT.DLL [On_Demand | Stopped]) – C:\WINDOWS\system32\CTHWIUT.DLL (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (CTSBLFX.DLL [On_Demand | Running]) – C:\WINDOWS\system32\CTSBLFX.DLL (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINDOWS\System32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (hap17v2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\hap17v2k.sys (Creative Technology Ltd)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (IntelC51 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (IntelC52 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC53 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (Iviaspi [On_Demand | Running]) – C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (LxrJD31d [Auto | Running]) – C:\WINDOWS\System32\Drivers\LxrJD31d.sys ()
DRV - (MarvinBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (MCSTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mohfilt [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MxlW2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PCLEPCI [System | Running]) – C:\WINDOWS\System32\drivers\pclepci.sys (Pinnacle Systems GmbH)
DRV - (PfModNT [Auto | Running]) – C:\WINDOWS\System32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys ()
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (snapman [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\snapman.sys (Acronis)
DRV - (sonyhcb [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\sonyhcb.sys (Sony Corporation)
DRV - (sonyhcs [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sonyhcs.sys (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (StkMini [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\StkMini.sys (Syntek America Inc.)
DRV - (StkScan [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\StkScan.sys (Syntek America Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tifsfilter [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\tifsfilt.sys (Acronis)
DRV - (timounter [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\timntr.sys (Acronis)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINDOWS\System32\vsdatant.sys (Zone Labs LLC)
DRV - (iaStor [Boot | Running]) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\PROGRAM FILES\MCAFEE\SITEADVISOR [2009/03/31 17:45:28 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/02 05:50:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape 7.2\Extensions\\Components: C:\PROGRAM FILES\NETSCAPE\NETSCAPE\COMPONENTS [2008/09/02 16:16:23 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape 7.2\Extensions\\Plugins: C:\PROGRAM FILES\NETSCAPE\NETSCAPE\PLUGINS [2009/03/27 12:15:51 | 00,000,000 | —D | M]


O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon (CANON INC.)
O4 - HKLM..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb11.exe (HP)
O4 - HKLM..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe (TODO: )
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" (ScanSoft, Inc.)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot (Scansoft, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKLM..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart (Yahoo! Inc.)
O4 - HKCU..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" (Microsoft Corp.)
O4 - HKCU..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe" (Ahead Software AG)
O4 - HKCU..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe (Ahead Software)
O4 - HKCU..\Run: [SB Audigy 2 Startup Menu] /L:ENG File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Tim\Start Menu\Programs\Startup\TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe (Esaya, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html ()
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html ()
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html ()
O9 - Extra Button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm ()
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (Microsoft Corporation)
O15 - HKCU\..Trusted Sites: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Sites: mcafee.com ([]https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.5.cab (DownloadManager Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (Reg Error: Key error.)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} http://software-dl.real.com/2405419e1e5e12…ip/RdxIE601.cab (Reg Error: Key error.)
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} http://www.amiuptodate.com/vsc/bin/1,0,0,9…pdatePortal.cab (McUpdatePortalFactory Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1122130191891 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} http://h30155.www3.hp.com/ediags/dd/instal…edsolutions.cab (HPObjectInstaller Class)
O16 - DPF: {9CF28A69-7659-4C51-BFD5-9ADE19E19EC3} http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab (RegConfig Class)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} http://download.yahoo.com/dl/installs/ymail/ymmapi.dll (YahooYMailTo Class)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (YAddBook Class)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab (PhotosCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} http://www.trueswitch.com/sbc/TrueInstallSBC.exe (Reg Error: Key error.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\System32\msdxm.ocx ()
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {08223B03-1B38-4A33-A83A-A4D3CC1D6E4E} - File not found
O28 - HKLM ShellExecuteHooks: {3474A8C2-BEF9-46C8-983A-A26A0030EC30} - File not found
O28 - HKLM ShellExecuteHooks: {369774CA-7CB4-4A3F-A9A9-77D6BC53CB3B} - File not found
O28 - HKLM ShellExecuteHooks: {4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F} - File not found
O28 - HKLM ShellExecuteHooks: {5184B75C-E5FF-48A3-83FE-44336678D83E} - File not found
O28 - HKLM ShellExecuteHooks: {7ADC2AB1-5C6A-4178-82DA-94863354AF7C} - File not found
O28 - HKLM ShellExecuteHooks: {9CA963CA-107C-4089-B0AB-31380F90D7E3} - File not found
O28 - HKLM ShellExecuteHooks: {C5350C93-DD58-4039-A467-D3C62A810689} - File not found
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.PXW () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\Documents and Settings\Tim\My Documents\*.tmp files]
[2009/04/04 10:15:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Tim\My Documents\PC Problem
[2009/04/04 10:15:06 | 00,000,000 | —D | C] – C:\Rooter$
[2009/04/03 17:05:09 | 00,423,727 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Registry Optimizer 040309 AROscanlog.xml
[2009/04/03 16:49:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Tim\Application Data\Sammsoft
[2009/04/03 16:49:53 | 00,001,728 | —- | C] () – C:\Documents and Settings\Tim\Desktop\Registry Optimizer.lnk
[2009/04/03 16:49:43 | 00,000,000 | —D | C] – C:\Program Files\Advanced Registry Optimizer
[2009/03/27 11:26:54 | 00,009,139 | —- | C] () – C:\WINDOWS\System32\Config.MPF
[2009/03/27 11:26:37 | 00,000,681 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\McAfee Security Center.lnk
[2009/03/27 11:25:17 | 00,079,304 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2009/03/27 11:25:17 | 00,040,552 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfesmfk.sys
[2009/03/27 11:25:17 | 00,035,272 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2009/03/27 11:25:15 | 00,120,136 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\Mpfp.sys
[2009/03/27 11:25:07 | 00,000,336 | —- | C] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/03/27 11:25:07 | 00,000,328 | —- | C] () – C:\WINDOWS\tasks\McQcTask.job
[2009/03/27 11:25:00 | 00,000,000 | —D | C] – C:\Program Files\McAfee.com
[2009/03/27 11:25:00 | 00,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2009/03/27 11:24:56 | 00,000,000 | —D | C] – C:\Program Files\McAfee
[2009/03/27 11:22:52 | 00,034,216 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdk.sys
[2009/03/27 09:50:37 | 00,001,744 | —- | C] () – C:\Documents and Settings\Tim\Desktop\HijackThis.lnk
[2009/03/27 09:50:37 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/25 16:00:41 | 00,136,192 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Saturday Night Live Seasons 1-4 episode details.xls
[2009/03/25 06:08:01 | 00,015,872 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Midnight Special DVDs.xls
[2009/03/21 12:39:17 | 00,140,288 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Saturday Night Live Seasons 1-4.xls
[2009/03/17 14:13:16 | 00,034,816 | —- | C] () – C:\Documents and Settings\Tim\My Documents\British Hit Parade Volume 5.xls
[2009/03/16 13:25:00 | 00,126,464 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Mike Dole Updates.xls
[2009/03/16 08:03:10 | 00,038,400 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Mike Dole Ordering Info.doc
[2009/03/13 13:24:13 | 00,049,152 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Videos from camcorder.xls
[2009/03/12 08:02:03 | 00,024,576 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Mike_Dole_New_titles_for_March_2009.doc
[2009/03/11 13:34:35 | 00,036,352 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Backup of Resume (outside) rev 03112009.wbk
[2009/03/11 13:34:35 | 00,035,840 | —- | C] () – C:\Documents and Settings\Tim\My Documents\Resume (outside) rev 03112009.doc
[2008/03/03 16:25:38 | 00,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2007/04/12 08:10:28 | 00,105,728 | —- | C] () – C:\WINDOWS\System32\APOMgrH.dll
[2007/04/09 12:55:14 | 00,097,785 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2007/04/09 12:55:14 | 00,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/04/09 12:33:50 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2007/04/09 12:32:58 | 00,034,816 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2006/11/27 19:04:46 | 00,000,017 | —- | C] () – C:\WINDOWS\MovingPicture.ini
[2006/11/27 18:02:45 | 00,194,248 | —- | C] () – C:\WINDOWS\System32\LTRFD13n.DLL
[2006/11/27 17:35:14 | 00,001,289 | —- | C] () – C:\WINDOWS\VFO.INI
[2006/11/27 17:35:13 | 00,196,096 | —- | C] () – C:\WINDOWS\System32\macd32.dll
[2006/11/27 17:35:13 | 00,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2006/11/27 17:35:13 | 00,136,192 | —- | C] () – C:\WINDOWS\System32\mamc32.dll
[2006/11/27 17:35:13 | 00,057,856 | —- | C] () – C:\WINDOWS\System32\masd32.dll
[2006/11/27 17:35:13 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2006/11/25 21:44:49 | 00,000,419 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2006/11/25 13:44:02 | 00,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/11/25 13:44:00 | 00,470,528 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2006/11/25 13:44:00 | 00,316,928 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2006/11/23 22:11:54 | 00,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/10/02 09:25:18 | 00,000,307 | —- | C] () – C:\WINDOWS\System32\kill.ini
[2006/07/25 18:00:41 | 00,029,752 | —- | C] () – C:\WINDOWS\System32\InstHelper.dll
[2006/07/25 17:59:46 | 00,197,680 | —- | C] () – C:\WINDOWS\System32\vpnapi.dll
[2006/04/28 04:05:18 | 00,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/01/05 18:48:03 | 00,000,000 | —- | C] () – C:\WINDOWS\JDSecure31.INI
[2006/01/05 18:47:59 | 00,249,856 | —- | C] () – C:\WINDOWS\System32\LxrJD31.dll
[2006/01/05 18:47:59 | 00,069,824 | —- | C] () – C:\WINDOWS\System32\drivers\LxrJD31d.sys
[2006/01/05 18:47:59 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\LxrJD20Sat.dll
[2005/12/28 08:41:55 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/12/12 21:18:42 | 00,000,635 | —- | C] () – C:\WINDOWS\Dc.INI
[2005/11/18 19:54:48 | 00,193,584 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2005/08/30 09:14:00 | 01,227,776 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2005/06/16 10:17:16 | 00,071,680 | —- | C] () – C:\WINDOWS\System32\ctmmactl.dll
[2005/04/29 17:39:25 | 00,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2005/04/06 17:47:32 | 00,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/02/13 12:31:01 | 00,338,944 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL
[2005/02/13 12:31:01 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2005/02/05 12:50:17 | 00,000,023 | —- | C] () – C:\WINDOWS\MixBUda.INI
[2004/12/20 18:24:03 | 01,663,068 | —- | C] () – C:\WINDOWS\System32\libmmd.dll
[2004/10/17 18:56:41 | 00,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/10/10 10:41:11 | 00,047,895 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/09/18 17:48:56 | 00,000,208 | —- | C] () – C:\WINDOWS\PDOXWIN.INI
[2004/09/18 17:48:56 | 00,000,034 | —- | C] () – C:\WINDOWS\WINHELP.INI
[2004/09/05 17:41:00 | 00,043,513 | —- | C] () – C:\WINDOWS\System32\e10kxwdm.ini
[2004/09/05 12:27:54 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/09/05 12:27:27 | 00,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2004/09/05 12:27:18 | 00,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2004/08/30 17:22:30 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/08/27 21:45:06 | 00,000,290 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/08/20 21:56:25 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2004/08/07 16:38:59 | 00,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2004/08/03 00:46:27 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/08/03 00:36:03 | 00,000,453 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/08/03 00:31:05 | 00,000,678 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/08/03 00:27:03 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/08/03 00:15:32 | 00,471,868 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2004/08/02 23:58:06 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/03/26 16:59:22 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/03/20 13:21:34 | 00,000,791 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/03/20 12:58:32 | 00,000,830 | —- | C] () – C:\WINDOWS\WIN.INI
[2004/03/20 12:58:32 | 00,000,000 | —- | C] () – C:\WINDOWS\CONTROL.INI
[2004/03/20 12:58:20 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/03/20 12:55:34 | 00,000,037 | —- | C] () – C:\WINDOWS\VBADDIN.INI
[2004/03/20 12:55:34 | 00,000,036 | —- | C] () – C:\WINDOWS\VB.INI
[2004/03/20 12:50:44 | 00,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2004/03/19 17:44:34 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\WIN87EM.DLL
[2004/03/19 17:43:52 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\TSD32.DLL
[2004/03/19 17:43:52 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\TSLABELS.INI
[2004/03/19 17:43:36 | 00,045,672 | —- | C] () – C:\WINDOWS\System32\TCPMON.INI
[2004/03/19 17:42:50 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\DESKTOP.INI
[2004/03/19 17:42:50 | 00,000,002 | —- | C] () – C:\WINDOWS\DESKTOP.INI
[2004/03/19 17:42:28 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\SECDRV.SYS
[2004/03/19 17:42:26 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\SCRIPTPW.DLL
[2004/03/19 17:42:22 | 00,218,112 | —- | C] () – C:\WINDOWS\System32\SBE.DLL
[2004/03/19 17:42:14 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\RSVP.INI
[2004/03/19 17:42:02 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\RASCTRS.INI
[2004/03/19 17:41:54 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\PSCHDPRF.INI
[2004/03/19 17:41:38 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\PRODSPEC.INI
[2004/03/19 17:41:30 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\PERFCI.INI
[2004/03/19 17:41:30 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\PERFWCI.INI
[2004/03/19 17:41:30 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\PERFFILT.INI
[2004/03/19 17:40:50 | 00,035,632 | —- | C] () – C:\WINDOWS\System32\NTIO411.SYS
[2004/03/19 17:40:50 | 00,035,392 | —- | C] () – C:\WINDOWS\System32\NTIO412.SYS
[2004/03/19 17:40:50 | 00,034,528 | —- | C] () – C:\WINDOWS\System32\NTIO804.SYS
[2004/03/19 17:40:50 | 00,034,528 | —- | C] () – C:\WINDOWS\System32\NTIO404.SYS
[2004/03/19 17:40:50 | 00,033,808 | —- | C] () – C:\WINDOWS\System32\NTIO.SYS
[2004/03/19 17:40:48 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\NTDOS411.SYS
[2004/03/19 17:40:48 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\NTDOS412.SYS
[2004/03/19 17:40:48 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\NTDOS804.SYS
[2004/03/19 17:40:48 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\NTDOS404.SYS
[2004/03/19 17:40:48 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\NTDOS.SYS
[2004/03/19 17:40:34 | 00,002,656 | —- | C] () – C:\WINDOWS\System32\NETWARE.DRV
[2004/03/19 17:39:36 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\MSENCODE.DLL
[2004/03/19 17:39:36 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\MSDXMLC.DLL
[2004/03/19 17:39:34 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\MSDTCPRF.INI
[2004/03/19 17:39:34 | 00,001,405 | —- | C] () – C:\WINDOWS\MSDFMAP.INI
[2004/03/19 17:39:18 | 00,010,110 | —- | C] () – C:\WINDOWS\System32\MQPERF.INI
[2004/03/19 17:38:32 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\KEY01.SYS
[2004/03/19 17:38:32 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\KEYBOARD.SYS
[2004/03/19 17:38:20 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\IR32_32.DLL
[2004/03/19 17:37:46 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\HIMEM.SYS
[2004/03/19 17:37:28 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[2004/03/19 17:37:08 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\ESENTPRF.INI
[2004/03/19 17:37:04 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\ENCDEC.DLL
[2004/03/19 17:37:00 | 00,498,205 | —- | C] () – C:\WINDOWS\System32\DXMASF.DLL
[2004/03/19 17:36:52 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\PAQSP.DLL
[2004/03/19 17:34:46 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\COUNTRY.SYS
[2004/03/19 17:34:38 | 00,238,592 | —- | C] () – C:\WINDOWS\System32\compatUI.dll
[2004/03/19 17:33:38 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ANSI.SYS
[2003/07/14 14:30:28 | 00,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2003/05/30 09:00:02 | 00,132,608 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/12 00:14:32 | 01,798,144 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2002/12/12 00:14:32 | 00,733,184 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2002/12/12 00:14:32 | 00,257,024 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2002/12/12 00:14:32 | 00,064,512 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2002/12/12 00:14:32 | 00,034,304 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2002/12/12 00:14:32 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2000/07/10 09:06:14 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\admdll.dll
[1980/01/01 00:00:00 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[1900/01/01 12:00:00 | 00,005,120 | -HS- | C] () – C:\WINDOWS\System32\zusenene.dll
[1900/01/01 12:00:00 | 00,005,120 | -HS- | C] () – C:\WINDOWS\System32\nobuyeli.dll

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Tim\My Documents\*.tmp files]
[2009/04/03 20:11:53 | 00,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/04/03 20:09:59 | 00,001,125 | —- | M] () – C:\WINDOWS\winamp.ini
[2009/04/03 20:09:49 | 04,932,148 | —- | M] () – C:\WINDOWS\{00000004-00000000-00000002-00001102-00000004-10031102}.CDF
[2009/04/03 18:49:32 | 00,009,139 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2009/04/03 18:47:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/03 18:47:09 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/04/03 18:47:07 | 32,192,96256 | -HS- | M] () – C:\hiberfil.sys
[2009/04/03 18:47:07 | 00,298,848 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/03 18:46:31 | 00,030,912 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/03 18:46:31 | 00,030,912 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/03 18:46:31 | 00,030,120 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/03 18:46:31 | 00,030,120 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/03 18:46:31 | 00,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000004-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/03 18:45:27 | 04,932,148 | —- | M] () – C:\WINDOWS\{00000004-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/04/03 17:05:09 | 00,423,727 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Registry Optimizer 040309 AROscanlog.xml
[2009/04/03 16:49:53 | 00,001,728 | —- | M] () – C:\Documents and Settings\Tim\Desktop\Registry Optimizer.lnk
[2009/04/03 06:16:15 | 00,015,872 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Midnight Special DVDs.xls
[2009/04/01 01:01:53 | 00,000,328 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2009/03/30 16:21:54 | 00,140,288 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Saturday Night Live Seasons 1-4.xls
[2009/03/30 11:27:40 | 00,043,008 | —- | M] () – C:\Documents and Settings\Tim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/29 20:14:22 | 00,136,192 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Saturday Night Live Seasons 1-4 episode details.xls
[2009/03/27 11:26:37 | 00,000,681 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\McAfee Security Center.lnk
[2009/03/27 11:25:08 | 00,000,336 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/03/27 09:50:37 | 00,001,744 | —- | M] () – C:\Documents and Settings\Tim\Desktop\HijackThis.lnk
[2009/03/26 09:13:44 | 00,019,968 | —- | M] () – C:\Documents and Settings\Tim\My Documents\James Bond Movies.xls
[2009/03/25 22:19:28 | 03,284,992 | —- | M] () – C:\Documents and Settings\Tim\My Documents\My Money.mny
[2009/03/25 22:19:19 | 04,507,079 | R— | M] () – C:\Documents and Settings\Tim\My Documents\My Money Backup.mbf
[2009/03/18 17:50:27 | 00,034,816 | —- | M] () – C:\Documents and Settings\Tim\My Documents\British Hit Parade Volume 5.xls
[2009/03/17 19:00:39 | 00,001,558 | —- | M] () – C:\Documents and Settings\Tim\Desktop\Audacity.lnk
[2009/03/17 19:00:18 | 00,000,977 | —- | M] () – C:\Documents and Settings\Tim\Desktop\VPN Client.lnk
[2009/03/17 08:17:16 | 00,126,464 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Mike Dole Updates.xls
[2009/03/16 08:03:11 | 00,038,400 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Mike Dole Ordering Info.doc
[2009/03/14 21:08:05 | 00,000,136 | —- | M] () – C:\WINDOWS\SBWIN.INI
[2009/03/13 17:42:28 | 00,049,152 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Videos from camcorder.xls
[2009/03/12 08:02:04 | 00,024,576 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Mike_Dole_New_titles_for_March_2009.doc
[2009/03/11 15:07:09 | 00,035,840 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Resume (outside) rev 03112009.doc
[2009/03/11 13:50:08 | 00,036,352 | —- | M] () – C:\Documents and Settings\Tim\My Documents\Backup of Resume (outside) rev 03112009.wbk

========== LOP Check ==========

[2009/02/27 13:43:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/31 12:55:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2008/09/12 18:09:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2005/03/26 13:42:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2004/08/30 17:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/07/03 19:21:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2004/08/03 00:26:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2006/11/25 21:38:33 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2007/11/10 07:54:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2004/08/03 00:30:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2005/06/14 19:33:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2009/04/03 20:12:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2005/06/12 07:57:09 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2005/11/25 18:14:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2006/11/24 21:33:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/02/25 14:10:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/03/27 11:26:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2005/11/09 18:00:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/10/13 22:01:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2006/11/27 18:40:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2006/11/27 17:33:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2004/08/03 00:31:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/08/02 23:56:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2006/11/25 21:44:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/08/18 14:27:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2008/10/01 04:34:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2006/11/29 20:01:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/02/27 14:20:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2004/09/05 14:52:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/03/09 20:31:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/12/16 17:48:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/18 16:51:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/11/12 12:24:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/04/03 16:49:54 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Tim\Application Data
[2008/07/27 20:44:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Adobe
[2009/03/27 11:41:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\AdobeUM
[2005/11/05 15:17:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Ahead
[2006/11/03 17:58:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Apple Computer
[2006/12/16 11:57:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Canon
[2004/08/07 18:23:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Creative
[2004/08/06 20:03:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\CyberLink
[2006/11/27 19:00:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Download Manager
[2007/04/12 08:58:32 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Tim\Application Data\GTek
[2004/09/18 17:12:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Help
[2004/08/02 23:56:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Identities
[2006/11/27 19:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\InstallShield
[2004/08/03 00:34:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Jasc Software Inc
[2004/08/06 20:35:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Leadertech
[2004/08/22 18:14:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Macromedia
[2008/03/22 10:49:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\McAfee
[2007/01/27 12:25:31 | 00,000,000 | –SD | M] – C:\Documents and Settings\Tim\Application Data\Microsoft
[2009/02/24 06:15:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Move Networks
[2004/12/26 10:48:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Mozilla
[2007/11/23 19:51:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Real
[2009/04/03 16:49:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Sammsoft
[2006/11/25 21:44:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\ScanSoft
[2005/03/26 22:22:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Simple Star
[2005/03/27 16:34:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Snapfish
[2004/08/06 20:36:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Sonic
[2004/08/03 00:23:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Sun
[2004/08/03 00:41:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Symantec
[2004/09/10 04:19:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\TextPad
[2005/12/28 09:29:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\ThumbsPlus
[2009/02/09 19:54:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\U3
[2007/03/09 20:31:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Viewpoint
[2009/04/01 13:57:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Tim\Application Data\Yahoo!
[2004/03/19 17:40:06 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2007/11/12 18:01:48 | 00,000,720 | —- | M] () – C:\WINDOWS\Tasks\McAfee Cleanup.job
[2009/03/27 11:25:08 | 00,000,336 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/04/01 01:01:53 | 00,000,328 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/04/03 18:47:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

Extras.Txt:

OTListIt Extras logfile created on: 4/4/2009 10:20:32 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.10.0 Folder = C:\Documents and Settings\Tim\My Documents\My Downloads
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.90 Gb Available in Paging File | 97.47% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.99 Gb Total Space | 37.29 Gb Free Space | 25.54% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 67.55 Gb Free Space | 22.66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDWVCF51
Current User Name: Tim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = YBrowser.HTML] – C:\Program Files\Yahoo!\browser\ybrowser.exe (Yahoo!, Inc.)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Yahoo!\Messenger\YPAGER.EXE:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\yserver.exe:*:Enabled:Yahoo! FT Server File not found

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0609D0AF-1382-42BE-81DB-CF30F8B0F6E2}" = Serif PhotoPlus 6.0
"{08094E03-AFE4-4853-9D31-6D0743DF5328}" = QuickTime
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP160" = Canon MP160
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{18061680-E63E-11D4-89EB-0000865451E1}" = KeyStone Learning Systems CBT V4
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 13
"{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2C0A655C-61E7-428A-8ED2-23A3D20E7DD2}" = Data Lifeguard Tools
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66563AD8-637B-407F-BCA7-0233A16891AB}" = Business Contact Manager for Outlook 2003
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6A012D9C-2E2E-405A-B87C-E909F5297C3F}" = Studio 10 Bonus DVD
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7D9B77E1-0078-0001-4447-ADD4C0A93D1D}" = Sansa Media Converter
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{81A60A13-224D-4637-8203-3EAC03B121A4}" = Seagate DiscWizard
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Application Accelerator
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A260B422-70E1-41E2-957D-F76FA21266D5}" = Apple Software Update
"{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}" = DiscAPI (Studio 10)
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B510A987-487E-4C66-9F4F-D386AC275715}" = TextPad 4.7
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CEF294F4-6A80-463E-8F68-E4D3A80147A4}" = PS8400
"{D568AF3D-A5A8-4E72-A0C0-3E781E15131D}" = VPN-RA Combo 3.0
"{DC1D7AD2-583A-4024-9041-387E8FFA5D8C}" = MediaFACE II
"{E1208658-C2EE-4A34-9FB1-040943DA3084}" = VideoAdvantage USB
"{E2EFF20D-30BF-4907-B1FD-B7EBCED798D6}" = HPHDiscovery
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E662A98E-8A02-4158-9047-4EBFA4F9F2ED}" = VideoAdvantage USB Driver
"{E82BF103-904F-49C0-B77F-6EC110B71E87}" = Sound Blaster Audigy 2
"{E8B4F9A7-4A62-4521-A94C-EBCC577AB24C}" = Remote Administrator 2.1y
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{EEECE229-49F6-4851-A73A-99B058221F8C}" = RAPID (Studio 10)
"{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}" = Pinnacle Instant DVD Recorder
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FC053571-8507-44E4-8B6D-AACEAB8CA57C}" = Sansa Media Converter
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Advanced Registry Optimizer_is1" = Advanced Registry Optimizer
"ATI Display Driver" = ATI Display Driver
"Best Buy Digital Music Store" = Best Buy Digital Music Store
"Best Buy Rhapsody" = Best Buy Rhapsody
"Canon MP160 User Registration" = Canon MP160 User Registration
"CanonMyPrinter" = Canon My Printer
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"Excel XP Essentials Beginning" = KeyStone CBT-Excel XP Essentials Beginning
"HijackThis" = HijackThis 2.0.2
"Hollywood FX for Studio" = Pinnacle Hollywood FX for Studio
"HP Photo & Imaging" = HP Image Zone 4.0
"InstallShield_{2E086814-7392-4E0F-ADB8-54A81E47406C}" = Broadcom Advanced Control Suite 2
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"Intel® 537EP V9x DFV PCI Modem" = Intel® 537EP V9x DFV PCI Modem
"InterActual Player" = InterActual Player
"JDSecure" = JD Secure 3.1
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MP Navigator 3.0" = Canon MP Navigator 3.0
"MSC" = McAfee SecurityCenter
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"Nero PhotoShow Express" = Nero PhotoShow Express
"NeroVision!UninstallKey" = Nero Digital
"Netscape (7.2)" = Netscape (7.2)
"NMIX!UninstallKey" = NeroMIX
"NMPUninstallKey" = Nero Media Player
"proDAD-Heroglyph-2.0" = proDAD Heroglyph 2.0
"Q327979" = Windows XP Hotfix (SP2) Q327979
"Q329112" = Windows XP Hotfix (SP2) Q329112
"q329623" = Windows XP Hotfix (SP2) q329623
"Q329909" = Windows XP Hotfix (SP2) Q329909
"Q331060" = Windows XP Hotfix (SP2) [See Q331060 for more information]
"Q811789" = Windows XP Hotfix (SP2) Q811789
"Q813862" = Windows XP Hotfix (SP2) Q813862
"Q816981" = Windows XP Hotfix (SP2) Q816981
"Q819696" = Windows XP Hotfix (SP2) Q819696
"Q828026" = Windows Media Player Hotfix [See wm828026 for more information]
"RealPlayer 6.0" = RealPlayer
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TrueSwitch Wizard SBC" = TrueSwitch Wizard SBC
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Yahoo! Applications" = AT&T Yahoo! Applications
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/3/2009 9:07:30 PM | Computer Name = DDWVCF51 | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 10.0.0.3646, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/3/2009 9:13:34 PM | Computer Name = DDWVCF51 | Source = Perflib | ID = 1015
Description = The timeout waiting for the performance data collection function "PerfOS"
in
the "C:\WINDOWS\system32\perfos.dll" Library to finish has expired. There may be
a problem with this extensible counter or the service it is collecting data from
or the system may have been very busy when this call was attempted.

Error - 4/3/2009 10:24:25 PM | Computer Name = DDWVCF51 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2800.1106, faulting
module unknown, version 0.0.0.0, fault address 0x10011e39.

Error - 4/4/2009 9:31:59 AM | Computer Name = DDWVCF51 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2800.1106, faulting
module unknown, version 0.0.0.0, fault address 0x10011e39.

Error - 4/4/2009 10:08:04 AM | Computer Name = DDWVCF51 | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application winword.exe, version 11.0.5604.0, stamp 3f314a2f,
faulting module unknown, version 0.0.0.0, stamp 00000000, debug? 0, fault address
0x10011e39.

Error - 4/4/2009 10:08:37 AM | Computer Name = DDWVCF51 | Source = Microsoft Office 11 | ID = 1000
Description = Faulting application winword.exe, version 11.0.5604.0, stamp 3f314a2f,
faulting module unknown, version 0.0.0.0, stamp 00000000, debug? 0, fault address
0x10011e39.

Error - 4/4/2009 10:55:20 AM | Computer Name = DDWVCF51 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2800.1106, faulting
module unknown, version 0.0.0.0, fault address 0x10011e39.

Error - 4/4/2009 10:57:53 AM | Computer Name = DDWVCF51 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2800.1106, faulting
module unknown, version 0.0.0.0, fault address 0x10011e39.

Error - 4/4/2009 10:58:10 AM | Computer Name = DDWVCF51 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2800.1106, faulting
module unknown, version 0.0.0.0, fault address 0x10011e39.

Error - 4/4/2009 11:19:40 AM | Computer Name = DDWVCF51 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt2.exe, version 2.0.10.0, hang module OTListIt2.exe,
version 2.0.10.0, hang address 0x00002862.

[ System Events ]
Error - 4/4/2009 11:15:33 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:16:14 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:16:54 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:17:34 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:18:15 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:18:55 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:19:35 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:20:16 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:20:56 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/4/2009 11:21:36 AM | Computer Name = DDWVCF51 | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.


< End of report >
OK it is playing hide and seek - normally I win this game :P

We will now do a deep search of your processes and files

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Investigation" check box.
  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.

When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Investigation" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach both zip files to your next post

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Hi, It's just my luck that this won't be easy. I encountered a problem. I received the attached error message while running AVZ. If this is what you were referring to in your instructions, can you clarify what "chose a different source" means? Well, the "upload" process is in a loop apparently, so I couldn't upload the error. THe verbiage is as follows: Access violation at address 00401F2F in module 'avz.exe'. Read of address 069B36B3. I will attempt again to upload. and advise you of the status.
Nope - it won't complete the upload, unless it takes more than 5 minutes. Its a screen print of the error embedded in a word doc. 55 kb. Suggestions?????
OK never give up is my motto so,,,,,,,,,,

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
  • Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
  • During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
    • Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
  • Once the scan is complete, on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply
What do I do with the "active" AVZ panel? Task Manager says it is running, and I am unable to clik on anything in the window. Secondly, should I restart my PC PRIOR to running Dr. Web Cure It? I REALLY appreciate your help with this.
Of course, another glitch - A file was found during the complete scan. It is not asking to "cure", but to "move". Should I restart or reload Dr. Web Cure It??? If I answer "No" to the "move", will it then ask to "cure" it?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI