This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Spyware Remover 2009

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok the first thing i did is click restore MS hosts file because MVP hosts file was not available. Now I found MVP hosts file because it was under download. When I click on MVPs hosts and replace it says "Your DNS Client Service is running and should be disabled before utilizing a large Hosts file. See help file for more information. Press OK to proceed anyway" What should I do. Should I: 1.) Disable DNS Client Service 2.) Press OK to proceed without disabling DNS
Hi Jackie

we seem to have gotton off track here and haven't yet dealt with the malware that may remain on your system.

Please do the following:


>>>FIRST<<<



Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.

>>>NEXT<<<

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder. Click Next.
  • Hit OK at the prompt for scanning in Safe Mode.
  • It will then open a box. There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the top right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then choose the delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file, name it Kas.
  • Save it to your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.





>>>FINALLY<<<



  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.


So in your next reply I need


  • Rooter Log
  • AVP log
  • OTListIt2 Log
Here is the Rooter Log, AVP log, and otlist2 log

Scan
—-
Scanned: 914902
Detected: 1
Untreated: 0
Start time: 4/20/2009 11:14:48 AM
Duration: 07:01:28
Finish time: 4/20/2009 6:16:16 PM


Detected
——–
Status Object
—— ——
deleted: Trojan program Trojan.WinREG.RunKeys.e File: C:\_OTMoveIt\MovedFiles\04152009_093239\WINDOWS\system32\drivers\nVIDIA\DLL\regedit


Events
——
Time Name Status Reason
—- —- —— ——
4/20/2009 11:14:58 AM Running module: smss.exe\smss.exe ok scanned


Statistics
———-
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
—— ——- ——– ——— ——- ——————- ——– ———— —————— ———


Settings
——–
Parameter Value
——— —–
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes


Quarantine
———-
Status Object Size Added
—— —— —- —–


Backup
——
Status Object Size
—— —— —-

Microsoft Windows XP Professional (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:39997 Mo/Free:1116 Mo)
D:\ [Fixed] - NTFS - (Total:198474 Mo/Free:697 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
G:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
H:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
I:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
J:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
K:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

Mon 04/20/2009| 9:25

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\Ati2evxx.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Windows Defender\MsMpEng.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\LEXBCES.EXE
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\WINDOWS\system32\LEXPPS.EXE
———- C:\WINDOWS\Explorer.EXE
———- C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
———- C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
———- C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
———- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
———- C:\Program Files\QuickTime\QTTask.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\Java\jre6\bin\jusched.exe
———- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
———- C:\WINDOWS\SOUNDMAN.EXE
———- C:\Program Files\Geelix.4.0.6.0\GeelixHUDDesktop.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\Program Files\FinePixViewer\QuickDCF2.exe
———- C:\Program Files\Logitech\SetPoint\SetPoint.exe
———- C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
———- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
———- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
———- C:\WINDOWS\system32\bgsvcgen.exe
———- C:\Program Files\Bonjour\mDNSResponder.exe
———- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
———- C:\Program Files\Java\jre6\bin\jqs.exe
———- C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
———- c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
———- c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
———- C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
———- C:\Program Files\McAfee\MPF\MPFSrv.exe
———- C:\WINDOWS\system32\PnkBstrA.exe
———- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
———- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
———- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
———- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
———- C:\Program Files\Mozilla Firefox\firefox.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Mon 04/20/2009| 9:25

———————-\\ Scan completed at 9:25

OTListIt logfile created on: 4/20/2009 7:00:01 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Online College class\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.48 Mb Total Physical Memory | 461.64 Mb Available Physical Memory | 45.15% Memory free
2.40 Gb Paging File | 1.88 Gb Available in Paging File | 78.36% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 4.97 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive D: | 193.82 Gb Total Space | 40.68 Gb Free Space | 20.99% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEIGER-908F50B
Current User Name: Online College class
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Lexmark X5100 Series\lxbabmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Geelix.4.0.6.0\GeelixHUDDesktop.exe (Gridmedia Technologies AS)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Logitech, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Online College class\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (bgsvcgen [Auto | Running]) – C:\WINDOWS\system32\bgsvcgen.exe (B.H.A Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (Capture Device Service [Auto | Running]) – C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (fsssvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – File not found
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LBTServ [On_Demand | Stopped]) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (LWWLicenseService [On_Demand | Stopped]) – C:\Program Files\Common Files\WoltersKluwerLWW Shared\Service\LWWLicenseService.exe (WoltersKluwerLWW)
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PnkBstrA [Auto | Running]) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (sprtsvc_ddoctorv2 [Auto | Running]) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (UleadBurningHelper [Auto | Running]) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (YahooAUService [Auto | Running]) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)

========== Driver Services (SafeList) ==========

DRV - (a347bus [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi [Boot | Running]) – C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (FETNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (fssfltr [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (L8042Kbd [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech Inc.)
DRV - (L8042mou [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\L8042mou.Sys (Logitech Inc.)
DRV - (LHidFilt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\LMouKE.Sys (Logitech Inc.)
DRV - (LUsbFilt [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\LUsbFilt.Sys (Logitech, Inc.)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (SCREAMINGBDRIVER [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ScreamingBAudio.sys (Screaming Bee LLC)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (videX32 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (xfilt [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value Default_Secondary_Page_URL = 0 bytes
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value Secondary Start Pages = 0 bytes
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://downloads.yahoo.com/internetexplorer/welcome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8


FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\GOOGLE\TOOLBAR FOR FIREFOX\{3112CA9C-DE6D-4884-A869-9855DE68056C} [2008/11/25 08:35:27 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/08 11:19:02 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/17 15:14:55 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/10 14:45:33 | 00,000,000 | —D | M]

[2009/02/24 15:39:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\mozilla\Extensions
[2009/02/24 15:39:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/19 22:16:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\mozilla\Firefox\Profiles\8w94w70x.default\extensions
[2009/04/09 10:47:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\mozilla\Firefox\Profiles\8w94w70x.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/04/17 08:45:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\mozilla\Firefox\Profiles\8w94w70x.default\extensions\[removed]
[2009/04/19 22:16:57 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/05/11 10:10:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/04/10 14:45:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/04/10 14:45:33 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/11/24 18:27:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/04/08 11:19:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2007/08/24 07:53:45 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2008/05/11 10:10:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2009/03/26 15:11:21 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/26 15:11:22 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/26 14:56:22 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/03/26 14:56:22 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/03/26 14:56:22 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/03/26 14:56:22 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/03/26 14:56:22 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/03/26 14:56:22 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/03/26 14:56:22 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2 (SupportSoft, Inc.)
O4 - HKLM..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe File not found
O4 - HKLM..\Run: [GeelixHUDDesktop] C:\Program Files\Geelix.4.0.6.0\GeelixHUDDesktop.exe -startup (Gridmedia Technologies AS)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech, Inc.)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" (Adobe Systems Incorporated)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe (TLC Productivity Properties LLC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jackie\Start Menu\Programs\IMVU\Run IMVU.lnk File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.srtest.com/srl_bin/sysreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx (get_atlcom Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase9563.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1165543934470 (WUWebControl Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemrequirementslab.com/sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1183046861468 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin_0.5.1.cab (Imikimi_activex_plugin Control)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…436/mcfscan.cab (McFreeScan Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O32 - Autorun File - C:\autoexec27901.txt () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[2009/04/20 18:55:35 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Online College class\Desktop\OTListIt2.exe
[2009/04/20 09:26:01 | 38,024,528 | —- | C] ( ) – C:\Documents and Settings\Online College class\Desktop\setup_7.0.0.290_20.04.2009_13-12.exe
[2009/04/20 09:25:08 | 00,000,000 | —D | C] – C:\Rooter$
[2009/04/20 09:24:57 | 00,267,612 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\Rooter.exe
[2009/04/17 08:46:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Application Data\Move Networks
[2009/04/16 14:17:37 | 02,534,400 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\Rental Unit Information.doc
[2009/04/16 14:13:23 | 02,502,959 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\Rental Unit Information.docx
[2009/04/16 13:14:58 | 00,012,547 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\To whom it may concern lease letter.docx
[2009/04/16 10:03:54 | 00,081,607 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\Receipt for Carpeting.jpg
[2009/04/16 03:01:11 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/04/15 12:51:30 | 00,029,696 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\ADMN_197_Outline_Spring_2009.xls
[2009/04/15 10:10:03 | 00,013,722 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\Jacqueline Derrick Resume.docx
[2009/04/15 09:32:39 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/04/15 09:31:34 | 00,389,632 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Online College class\Desktop\OTMoveIt3.exe
[2009/04/15 09:28:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Desktop\EVERYTHING
[2009/04/14 19:52:12 | 00,000,055 | —- | C] () – C:\xcrashdump.dat
[2009/04/14 19:50:02 | 00,000,000 | —D | C] – C:\ComboFix
[2009/04/14 19:48:59 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF25062.exe
[2009/04/14 19:48:52 | 00,073,728 | —- | C] () – C:\pv.exe
[2009/04/14 14:36:38 | 00,009,216 | -HS- | C] () – C:\Documents and Settings\Online College class\Desktop\Thumbs.db
[2009/04/14 14:17:32 | 00,041,808 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/04/14 12:27:42 | 00,425,984 | —- | C] () – C:\Documents and Settings\Online College class\My Documents\Repair Shop.accdb
[2009/04/12 12:32:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Application Data\Malwarebytes
[2009/04/10 14:19:44 | 00,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2009/04/10 13:33:06 | 00,259,072 | —- | C] () – C:\WINDOWS\VFIND.exe
[2009/04/10 13:33:06 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/04/10 13:33:06 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/04/10 13:33:06 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/04/10 13:33:06 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/04/10 13:33:06 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/04/10 13:33:06 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/04/10 13:32:41 | 00,000,000 | —D | C] – C:\Qoobox
[2009/04/10 13:31:56 | 03,009,757 | R— | C] () – C:\Documents and Settings\Online College class\Desktop\ComboFix.exe
[2009/04/09 10:58:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2009/04/09 10:57:49 | 00,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2009/04/09 10:57:48 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/04/09 10:45:45 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Application Data\FUJIFILM
[2009/04/08 11:37:11 | 00,001,548 | —- | C] () – C:\Documents and Settings\Online College class\Desktop\CCleaner.lnk
[2009/04/08 11:37:10 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/04/08 11:29:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Local Settings\Application Data\ATI
[2009/04/08 11:29:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Application Data\ATI
[2009/04/08 11:29:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Local Settings\Application Data\Geelix 4.0.6.0
[2009/04/08 11:26:27 | 00,001,612 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk
[2009/04/08 10:26:23 | 00,000,000 | —D | C] – C:\Program Files\Registry Mechanic
[2009/04/02 08:59:56 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\My Documents\Backup for JMS TechWizards
[2009/03/26 12:32:11 | 00,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/03/26 12:30:47 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/03/26 12:30:44 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/03/26 12:30:44 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/03/25 18:06:22 | 00,000,868 | —- | C] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/03/22 19:41:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Online College class\Local Settings\Application Data\PMB Files
[2009/03/22 19:40:48 | 00,000,000 | —D | C] – C:\Program Files\Pando Networks
[2009/01/25 21:07:44 | 00,000,247 | —- | C] () – C:\WINDOWS\game.ini
[2008/12/22 00:59:26 | 00,025,312 | —- | C] () – C:\WINDOWS\System32\DivXVfWCodec.dll
[2008/12/22 00:59:24 | 00,025,312 | —- | C] () – C:\WINDOWS\System32\SamsungVfWCodec.dll
[2008/12/22 00:59:08 | 00,447,200 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2008/12/22 00:52:02 | 00,066,272 | —- | C] () – C:\WINDOWS\System32\libfaac.dll
[2008/10/28 14:00:43 | 00,000,332 | —- | C] () – C:\WINDOWS\PRFA2K.INI
[2008/10/08 13:14:11 | 00,122,880 | —- | C] () – C:\WINDOWS\System32\adv6api.dll
[2008/04/21 10:25:45 | 00,000,192 | —- | C] () – C:\WINDOWS\ulead32.ini
[2008/04/21 09:39:47 | 00,210,456 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2008/04/21 09:39:47 | 00,206,360 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2008/04/21 09:39:47 | 00,198,168 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2008/04/21 09:39:47 | 00,198,168 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2008/04/21 09:39:47 | 00,194,072 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2008/04/21 09:39:47 | 00,026,136 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2008/03/31 17:25:46 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\divx_xx0a.dll
[2008/03/21 16:30:08 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/21 16:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/03/21 16:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/03/21 16:28:20 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/02/04 19:23:10 | 00,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/12/14 05:36:00 | 00,000,038 | —- | C] () – C:\WINDOWS\avisplitter.INI
[2007/12/09 16:41:18 | 00,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/12/09 16:41:18 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/01 16:11:22 | 00,000,000 | —- | C] () – C:\WINDOWS\MusicEditor.INI
[2007/12/01 16:03:23 | 00,000,000 | —- | C] () – C:\WINDOWS\CleaningLab.INI
[2007/12/01 16:02:44 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2007/12/01 16:01:56 | 00,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2007/12/01 16:01:33 | 00,005,937 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2007/11/25 06:06:19 | 00,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2007/11/25 05:58:35 | 00,000,035 | —- | C] () – C:\WINDOWS\WorldBuilder.INI
[2007/11/17 10:44:29 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2007/11/14 18:44:46 | 00,138,376 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/10/21 21:32:38 | 00,000,242 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2007/09/28 12:17:28 | 00,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2007/09/28 11:47:34 | 00,000,605 | —- | C] () – C:\WINDOWS\PCalcpro.ini
[2007/09/28 11:47:33 | 00,000,543 | —- | C] () – C:\WINDOWS\asc_sys.ini
[2007/09/28 11:47:33 | 00,000,182 | —- | C] () – C:\WINDOWS\medlrng.ini
[2007/09/28 11:47:22 | 00,018,432 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[2007/09/28 11:42:57 | 00,041,984 | —- | C] () – C:\WINDOWS\System32\iprocnt.dll
[2007/09/28 11:42:56 | 00,050,688 | —- | C] () – C:\WINDOWS\System32\iproc.dll
[2007/09/28 11:38:19 | 00,008,704 | —- | C] () – C:\WINDOWS\System32\twdll.dll
[2007/09/28 11:38:19 | 00,000,134 | —- | C] () – C:\WINDOWS\awshkwv.ini
[2007/09/21 09:20:47 | 00,000,074 | —- | C] () – C:\WINDOWS\ImportClient.INI
[2007/09/19 09:22:35 | 00,000,074 | —- | C] () – C:\WINDOWS\MPLAYER.INI
[2007/09/19 09:22:05 | 01,680,896 | —- | C] () – C:\WINDOWS\System32\LTCLR13n.dll
[2007/09/19 09:22:04 | 00,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2007/09/19 09:22:04 | 00,122,880 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[2007/08/07 15:39:00 | 00,000,061 | —- | C] () – C:\WINDOWS\wowCP.ini
[2007/08/02 23:13:20 | 00,000,000 | —- | C] () – C:\WINDOWS\PhotoNow.INI
[2007/07/06 20:41:50 | 00,000,031 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2007/06/22 19:09:15 | 00,000,106 | —- | C] () – C:\WINDOWS\MSREGUSR.INI
[2007/05/29 19:24:22 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\LXBALCNP.DLL
[2007/05/15 19:06:58 | 00,071,208 | —- | C] () – C:\WINDOWS\System32\PhysXLoader.dll
[2007/05/04 01:31:28 | 00,000,000 | —- | C] () – C:\WINDOWS\PCB123.INI
[2007/04/14 15:57:06 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/04/14 15:57:06 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/04/14 15:57:06 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/04/14 15:57:04 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/04/14 15:57:04 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/04/14 15:57:04 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2007/04/14 15:57:04 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/04/14 15:57:04 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2007/04/14 15:57:04 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/02/20 23:57:11 | 00,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/02/20 23:37:49 | 00,000,680 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2006/12/17 23:29:10 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/12/09 03:30:33 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/12/07 23:20:03 | 00,158,720 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347bus.sys
[2006/12/07 23:20:03 | 00,005,248 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347scsi.sys
[2006/12/07 22:29:10 | 00,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2006/12/07 22:29:02 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2005/10/14 05:56:50 | 00,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 05:56:48 | 03,223,552 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2005/10/14 05:56:48 | 00,540,672 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2005/10/14 05:56:48 | 00,266,240 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2005/10/14 05:56:48 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2005/10/14 05:56:48 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\MMSwitch.dll
[2004/09/01 11:49:17 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/08/04 08:00:00 | 00,000,256 | —- | C] () – C:\WINDOWS\system.ini
[2004/08/04 07:55:56 | 00,000,776 | —- | C] () – C:\WINDOWS\win.ini
[2003/12/09 14:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2002/10/06 14:42:56 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 19:04:24 | 00,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 19:04:24 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 19:04:16 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/08/21 09:55:26 | 00,000,188 | —- | C] () – C:\WINDOWS\System32\lxbacoin.ini
[2002/05/15 19:38:40 | 00,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/03/16 20:00:00 | 00,007,420 | —- | C] () – C:\WINDOWS\UA000079.DLL
[2000/01/28 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/20 18:55:36 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Online College class\Desktop\OTListIt2.exe
[2009/04/20 18:23:03 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/20 18:20:36 | 00,027,177 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2009/04/20 18:20:20 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/04/20 18:20:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/20 18:19:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/20 18:19:57 | 00,055,160 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2009/04/20 09:28:28 | 38,024,528 | —- | M] ( ) – C:\Documents and Settings\Online College class\Desktop\setup_7.0.0.290_20.04.2009_13-12.exe
[2009/04/20 09:27:28 | 00,000,680 | —- | M] () – C:\WINDOWS\LEXSTAT.INI
[2009/04/20 09:24:58 | 00,267,612 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\Rooter.exe
[2009/04/20 03:30:01 | 00,000,412 | —- | M] () – C:\WINDOWS\tasks\ErrorSmart Scheduled Scan.job
[2009/04/19 23:15:35 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/18 23:08:08 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/17 09:00:01 | 00,000,386 | —- | M] () – C:\WINDOWS\tasks\rpc.job
[2009/04/16 14:27:03 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/16 14:17:38 | 02,534,400 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\Rental Unit Information.doc
[2009/04/16 14:13:23 | 02,502,959 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\Rental Unit Information.docx
[2009/04/16 13:14:59 | 00,012,547 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\To whom it may concern lease letter.docx
[2009/04/16 10:26:34 | 00,009,216 | -HS- | M] () – C:\Documents and Settings\Online College class\Desktop\Thumbs.db
[2009/04/16 10:03:54 | 00,081,607 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\Receipt for Carpeting.jpg
[2009/04/16 03:16:46 | 00,526,648 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/16 03:16:46 | 00,444,728 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/16 03:16:46 | 00,072,558 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/16 03:12:37 | 01,687,704 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/16 03:05:47 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/15 12:51:30 | 00,029,696 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\ADMN_197_Outline_Spring_2009.xls
[2009/04/15 10:10:03 | 00,013,722 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\Jacqueline Derrick Resume.docx
[2009/04/15 09:38:44 | 00,130,104 | —- | M] () – C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT
[2009/04/15 09:31:34 | 00,389,632 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Online College class\Desktop\OTMoveIt3.exe
[2009/04/15 01:00:01 | 00,000,342 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/04/14 19:52:12 | 00,000,055 | —- | M] () – C:\xcrashdump.dat
[2009/04/14 19:49:40 | 03,009,757 | R— | M] () – C:\Documents and Settings\Online College class\Desktop\ComboFix.exe
[2009/04/14 19:48:49 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF25062.exe
[2009/04/14 14:17:32 | 00,041,808 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2009/04/14 14:17:25 | 00,425,984 | —- | M] () – C:\Documents and Settings\Online College class\My Documents\Repair Shop.accdb
[2009/04/10 14:45:37 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/04/10 13:39:32 | 00,000,256 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/09 10:42:39 | 00,000,776 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/09 10:42:39 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/04/09 10:33:07 | 03,197,712 | -H– | M] () – C:\Documents and Settings\Online College class\Local Settings\Application Data\IconCache.db
[2009/04/08 11:37:11 | 00,001,548 | —- | M] () – C:\Documents and Settings\Online College class\Desktop\CCleaner.lnk
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/01 01:00:01 | 00,000,334 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2009/03/27 03:09:32 | 01,193,414 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb

========== LOP Check ==========

[2009/04/09 10:58:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/26 12:31:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008/09/21 12:45:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro
[2008/09/07 19:15:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/13 19:27:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2007/02/20 23:59:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/02/20 23:58:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/02/20 23:59:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/11/06 23:58:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/11/09 12:43:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/31 15:24:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI
[2008/09/24 19:30:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI(2)
[2007/05/02 19:35:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/12/19 16:14:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Banner Maker Pro 7
[2007/02/20 23:38:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/07/09 00:24:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cabela's Big Game Hunter - Alaskan Adventure Saves
[2008/08/16 11:10:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2008/01/13 19:40:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/08/03 01:23:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/01/10 21:30:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2007/08/02 23:34:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\element5
[2008/05/13 11:15:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/02/14 05:44:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geelix 4.0.6.0
[2009/04/10 12:51:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/04/20 00:09:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/05/21 18:27:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/01/03 00:12:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HipSoft
[2008/04/21 09:39:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InterVideo
[2008/05/17 17:48:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2008/05/17 17:48:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logitech
[2007/12/01 16:03:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MAGIX
[2008/11/18 14:23:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/11/17 01:32:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2008/01/26 23:24:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MGS
[2009/02/05 21:02:12 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/04/16 03:01:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2008/01/13 19:33:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2008/09/02 22:31:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2008/03/04 11:36:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/12/27 20:03:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/03/23 00:52:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screaming Bee
[2009/04/10 10:28:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2008/08/26 13:56:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2008/03/22 19:22:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/04/10 10:29:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2007/05/19 17:57:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2007/08/31 10:07:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/04/14 19:37:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/04/21 12:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/04/08 11:04:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/10 21:29:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2006/12/07 22:35:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/11 17:30:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WoltersKluwerLWW
[2009/04/10 14:20:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/02/25 15:15:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/04/17 08:46:29 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Online College class\Application Data
[2009/01/28 17:54:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Adobe
[2009/03/07 16:45:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Apple Computer
[2009/04/08 11:29:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\ATI
[2009/01/10 21:26:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\CyberLink
[2009/01/10 21:26:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\DivX
[2009/01/10 21:30:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\eBay
[2009/04/09 10:46:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\FUJIFILM
[2009/02/19 11:06:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Google
[2009/02/05 10:47:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Help
[2009/01/10 21:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Identities
[2009/01/28 17:58:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Leadertech
[2009/01/10 21:25:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Logitech
[2009/02/19 16:27:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Macromedia
[2009/04/12 12:32:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Malwarebytes
[2009/04/07 11:34:09 | 00,000,000 | –SD | M] – C:\Documents and Settings\Online College class\Application Data\Microsoft
[2009/04/17 08:48:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Move Networks
[2009/02/24 15:39:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Mozilla
[2009/01/18 18:48:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Sun
[2009/04/18 23:16:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\teamspeak2
[2009/04/18 23:00:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Xfire
[2009/01/15 23:17:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Online College class\Application Data\Yahoo!
[2009/04/16 14:27:03 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/20 03:30:01 | 00,000,412 | —- | M] () – C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job
[2009/04/20 18:20:20 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/04/15 01:00:01 | 00,000,342 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/04/01 01:00:01 | 00,000,334 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/04/20 18:23:03 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/04/17 09:00:01 | 00,000,386 | —- | M] () – C:\WINDOWS\Tasks\rpc.job
[2009/04/20 18:20:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5635DE41
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >

OTListIt Extras logfile created on: 4/20/2009 7:00:01 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Online College class\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.48 Mb Total Physical Memory | 461.64 Mb Available Physical Memory | 45.15% Memory free
2.40 Gb Paging File | 1.88 Gb Available in Paging File | 78.36% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 4.97 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive D: | 193.82 Gb Total Space | 40.68 Gb Free Space | 20.99% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEIGER-908F50B
Current User Name: Online College class
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\DNA\btdna.exe:*:Enabled:DNA (BitTorrent, Inc.)
C:\Documents and Settings\Dallas.STEIGER-908F50B\Program Files\DNA\btdna.exe:*:Enabled:DNA ()
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire (Xfire Inc.)
C:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE (Lexmark International, Inc.)
D:\Azureus\Azureus\Azureus.exe:*:Enabled:Azureus (Vuze Inc.)
D:\cyberlink\PowerDirector\PDR.exe:*:Enabled:CyberLink PowerDirector (CyberLink Corp.)
D:\Ghost Recon\Ghost Recon Advanced Warfighter 2\graw2.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2 ()
D:\Ghost Recon\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:*:Enabled:Ghost Recon Advanced Warfighter® 2 Dedicated Server ()
D:\Program Files\Microsoft Games\Halo\halo.exe:*:Enabled:Halo (Microsoft Corporation)
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent ()
C:\Program Files\Tams11\Games\Farkle\farkle.exe:*:Enabled:farkle ()
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
D:\CoD2MP_s.exe:*:Enabled:CoD2MP_s ()
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0224CACC-994D-45F8-B973-D65056EA9C2F}" = Adobe XMP DVA Panels CS3
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{162B71B8-8464-4680-A086-601D555B331D}" = Apple Mobile Device Support
"{17D2AF72-1448-4C43-A1C4-842757E4DEB6}" = Cabela's Big Game Hunter - Alaskan Adventures
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1C8646E4-DC54-4E6D-95EA-C3524B09223E}" = Ready Reference Bookshelf
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{22F358CE-610B-A033-0D36-4FADA6E8F67A}" = Skins
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.3
"{255F566C-3F57-15AD-2CA5-E7EA41F9904F}" = Catalyst Control Center Graphics Full Existing
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{27DC856A-0916-4988-8198-8714DDD3183D}" = AGEIA PhysX v7.05.17
"{298FC7A4-44AF-411D-BB17-C8516C20849B}" = GSC
"{299CF645-48C7-4FA1-8BCD-5CE200CF180D}" = Microsoft Search Enhancement Pack
"{2A304FDE-F4E3-446D-AA0D-31425C897B71}" = PrintMaster
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2C294A0B-DF22-4023-B168-8C7645B10019}" = Adobe Setup
"{2F95F20C-658E-4758-B76C-111C0B3BF4B2}" = MorphVOX Pro
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = Logitech Registration
"{4287A29F-EA4C-24E4-4AAE-3E6CDC9C965A}" = CCC Help English
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4B215C29-1A3E-4736-92AA-10C83FA56EB9}" = Adobe After Effects CS3 Presets
"{4FEEDAA3-0D0C-7584-63F2-0F216D3426C9}" = ccc-core-preinstall
"{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService
"{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}" = Adobe Audition 3.0
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5490882C-6961-11D5-BAE5-00E0188E010B}" = FUJIFILM USB Driver
"{56918C0C-0D87-4CA6-92BF-4975A43AC719}" = KhalInstallWrapper
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75E607CF-7BAE-4B88-84B3-97F3DF44BA28}" = FEARCombat
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B4A5C13-069F-4AFE-AE57-C497B4E33C7E}" = Call of Duty® 2 Patch 1.3
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80AE66E6-E9FA-0CAC-C9F1-4E5A144886F0}" = Catalyst Control Center Graphics Full New
"{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}" = Adobe Video Profiles
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{88200B70-8473-11D6-A964-00B0D0119A5C}" = Family Tree Maker
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8AF3FB06-BDA3-42A3-995C-308812D2F094}" = Adobe After Effects CS3
"{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}" = CDDRV_Installer
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8D6EC7D6-E71D-8743-1396-591F4195F347}" = Catalyst Control Center Graphics Light
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8FD697DD-C94F-22BE-6EFD-AA4CA7CF2B33}" = ccc-core-static
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{924EB80F-C2BB-4B9F-8412-88BBA937393F}" = MobileMe Control Panel
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0120-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{962E05CF-3394-496D-0091-850CF1762F6B}" = The Battle for Middle-earth ™
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{AA7D532A-6C19-4168-A887-BF306A431B65}" = Game Cam Lite v1.4
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AFFA4BBF-051D-4926-A603-1F729240C7F7}" = COD2 RCON Commander
"{B093990A-AAF2-44AC-9216-14BB7A2189B6}" = ImageMixer VCD2 LE for FinePix
"{B38C3184-F573-CDC2-9452-FA9C576AB010}" = ccc-utility
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B44529FF-501E-47CD-A06D-223C161BE058}" = FinePixViewer Resource
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C26B06A9-27BB-45B0-9873-9C623EC2BA38}" = iTunes
"{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D45EC259-4A19-4656-B588-C2C360DD18EA}" = Half-Life® 2
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}" = Safari
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DB6901C6-E8B7-F5F0-F0C6-9028AFCD5A74}" = Catalyst Control Center Graphics Previews Common
"{DBAC1413-D5AE-4c89-AE9A-B330B02DBAB0}" = eVoice Player 1.0
"{DC509FE5-1445-46C9-827C-6120429CB942}" = Windows Live Family Safety
"{DD8408E9-9421-484F-979D-DB6361E3E828}" = Dawn Of War - Winter Assault
"{E068CD0F-E631-17E7-9A01-05C2B2B54C84}" = Catalyst Control Center Core Implementation
"{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}" = FinePix Studio
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" =
"{EE510252-96FC-49C1-AE63-36E1C49314CD}" = Moongamer's CoD2 Patch Switcher
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F78AC3C0-578C-49AB-BD4E-3107A6036A13}" = Tom Clancy's Ghost Recon Advanced Warfighter® 2
"{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = VideoStudio
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FE71D2C9-3512-4414-9489-EE74A8E42878}" = Stedman's Medical Dictionary for the Health Professions and Nursing, 6E
"{FF15EC4A-4BF5-4B86-9E09-1111BFC52B72}" = Radmin Viewer 3.0
"1Click DVD Copy Pro_is1" = 1Click DVD Copy Pro [removed]
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe AIR" = Adobe AIR
"Adobe Audition 3.0" = Adobe Audition 3.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"Adobe_b7dd24a87e82dcf8af8876fd727b7cf" = Adobe After Effects CS3
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AIM_6.0" = AIM 6.0
"All ATI Software" = ATI - Software Uninstall Utility
"ASIO4ALL" = ASIO4ALL
"ATI Display Driver" = ATI Display Driver
"AVI Codec Pack" = AVI Codec Pack
"AXIS Media Control Embedded" = AXIS Media Control Embedded
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"CopySafe Plugin" = CopySafe Plugin
"Cultures" = Cultures
"Diner Dash 2" = Diner Dash 2
"Ducky Screensaver" = Ducky Screensaver
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab Platinum_is1" = DVDFab Platinum 4.0.3.2 by Dr.Pc Putte - Team RES
"Farkle_is1" = Farkle [removed]
"FL Studio 7 public beta" = FL Studio 7 public beta
"FL Studio 8" = FL Studio 8
"Fraps" = Fraps
"Google Updater" = Google Updater
"Halo" = Microsoft Halo
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Imikimi Plugin" = Imikimi Plugin
"InstallShield_{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}" = Call of Duty® 4 - Modern Warfare™ 1.3 Patch
"InstallShield_{05B15E9F-4B26-4847-ACFB-943483873E3B}" = Stedman's Plus Spellchecker Standard 2007
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{298FC7A4-44AF-411D-BB17-C8516C20849B}" = GSC
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{8503C901-85D7-4262-88D2-8D8B2A7B08B8}" = Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}" = Call of Duty® 2
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.5.7 Full
"Lexmark X5100 Series" = Lexmark X5100 Series
"Little Shop of Treasures" = Little Shop of Treasures
"Magic ISO Maker v5.4 (build 0251)" = Magic ISO Maker v5.4 (build 0251)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MavisBeacon10_SE" = Mavis Beacon Teaches Typing 11
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"MONOPOLY HERE & NOW EDITION" = MONOPOLY HERE & NOW EDITION
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MS Access 97 SP2" = MS Access 97 SP2
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Network Play System (Patching)" = Network Play System (Patching)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"Professor Teaches Access 2000" = Professor Teaches Access 2000
"PROR" = Microsoft Office Professional 2007 Subscription
"RealArcade" = RealArcade
"Scrabble v2.0" = Scrabble v2.0
"Shockwave" = Shockwave
"Soulseek" = SoulSeek Client 156c
"SpywareBlaster_is1" = SpywareBlaster 4.1
"SpywareGuard_is1" = SpywareGuard v2.2
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tetris Game Gold" = Tetris Game Gold
"UFileDownloadD" = Versal FileDownload ActiveX Control Trial Version
"Uninstaller_B546F000_Stedmans HPND 6e" = Stedmans HPND 6e (Shared Components)
"Uninstaller_B546F000_Stedman's Medical Dictionary for the Health Professions, 6th Ed" = Stedman's Medical Dictionary for the Health Professions, 6th Ed (Shared Components)
"UT2004" = Unreal Tournament 2004
"Vodei Multimedia Processor" = Vodei Multimedia Processor 2.00
"Vuze" = Vuze
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
"Zoo Tycoon 1.0" = Microsoft Zoo Tycoon

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/10/2009 10:44:46 AM | Computer Name = STEIGER-908F50B | Source = Application Error | ID = 1000
Description = Faulting application setpoint.exe, version 4.60.122.0, faulting module
unknown, version 0.0.0.0, fault address 0x01a62f2d.

Error - 4/10/2009 11:03:46 AM | Computer Name = STEIGER-908F50B | Source = MsiInstaller | ID = 11706
Description = Product: Moongamer's CoD2 Patch Switcher – Error 1706. An installation
package for the product Moongamer's CoD2 Patch Switcher cannot be found. Try the
installation again using a valid copy of the installation package 'MGCOD2PatchSwitcher.msi'.

Error - 4/10/2009 1:21:48 PM | Computer Name = STEIGER-908F50B | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module unknown, version 0.0.0.0, fault address 0x02933f30.

Error - 4/10/2009 1:54:47 PM | Computer Name = STEIGER-908F50B | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module yietagbm.dll, version 2006.7.28.1, fault address 0x00001e14.

Error - 4/10/2009 1:55:45 PM | Computer Name = STEIGER-908F50B | Source = MsiInstaller | ID = 11719
Description = Product: Moongamer's CoD2 Patch Switcher – Error 1719. The Windows
Installer Service could not be accessed. This can occur if you are running Windows
in safe mode, or if the Windows Installer is not correctly installed. Contact your
support personnel for assistance.

Error - 4/10/2009 1:58:51 PM | Computer Name = STEIGER-908F50B | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module yietagbm.dll, version 2006.7.28.1, fault address 0x00001e14.

Error - 4/10/2009 2:19:56 PM | Computer Name = STEIGER-908F50B | Source = Internet Explorer 8 | ID = 921877
Description =

Error - 4/10/2009 2:48:04 PM | Computer Name = STEIGER-908F50B | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module unknown, version 0.0.0.0, fault address 0x0275b6f1.

Error - 4/14/2009 7:37:44 PM | Computer Name = STEIGER-908F50B | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: STEIGER-908F50B\Online College class Checkpoint ID: 23 Error
Code: 0x80070005 Error description: Access is denied.

Error - 4/16/2009 5:18:35 AM | Computer Name = STEIGER-908F50B | Source = McLogEvent | ID = 5019
Description = Exception in McShield.Exe! Exception details follow : VSCORE.14.0.0.349
Exception
Code : 0XC0000005 Exception Address : 0X7C918AF2 Exception Parameters :
2 Param 1 = 0X00000001 Param 2 = 0X01C9BE84 More information : ScanRequest : NTName
is \Device\HarddiskVolume1\Program Files\McAfee\MPS\IAEngine.dll.

[ OSession Events ]
Error - 2/26/2009 5:28:53 PM | Computer Name = STEIGER-908F50B | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 7509
seconds with 5880 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 4/20/2009 11:12:29 AM | Computer Name = STEIGER-908F50B | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 4/20/2009 11:12:29 AM | Computer Name = STEIGER-908F50B | Source = Service Control Manager | ID = 7001
Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 4/20/2009 11:12:29 AM | Computer Name = STEIGER-908F50B | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 4/20/2009 11:12:29 AM | Computer Name = STEIGER-908F50B | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 4/20/2009 11:12:29 AM | Computer Name = STEIGER-908F50B | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

Error - 4/20/2009 11:13:21 AM | Computer Name = STEIGER-908F50B | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2009 11:13:52 AM | Computer Name = STEIGER-908F50B | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 4/20/2009 11:13:53 AM | Computer Name = STEIGER-908F50B | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNASvc with
arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}

Error - 4/20/2009 6:17:12 PM | Computer Name = STEIGER-908F50B | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 4/20/2009 6:18:33 PM | Computer Name = STEIGER-908F50B | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}


< End of report >
Hi,

I don't see any obvious signs of malware remaining on your system.

Can you please describe in detail what issues you have remaining .

Thanks

CB
1.) When using Internet Explorer yahoo mail is blank when I go to check it. (the whole page is blank) 2.) When I open system restore the page is blank 3.) When I try and chat on yahoo messenger the chat box is blank 4.) I have no idea how many other things are affected by the same thing
Hi,

Please do this to restore your system restore

log in as administrator,

go to start, then run.

Type the following commands into the run box one after the other:

first type> regsvr32 jscript.dll > hit enter
now type> regsvr32 vbscript.dll > hit enter

your system restore should now be restored.


The other issues are broken services that occurred when the malware was removed….
for which there is likely a remedy.

I would like you to start a new topic in our Windows forum, linking back to this topic so our expert tech gurus can see what has occurred.

please post a new topic HERE
Nope! It is all taken care of …. that solved the problem! Thanks again! I donated 10.00 to the site, I know it is not much but my car is in the shop with transmission problems and I am moving in June, whew, when it rains it pours! Thanks for all your help
Hi,

I am so glad that resolved all your issues, (thanks to Abydos - a magical tech guru) and very kind of you to make a donation.

you are now clean of malware,

but there is a little clean up to do still, I don't want to leave all my tools lying around!!

Please do the following:

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK.
  • Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]


Next

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

Next


Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112on how to prevent malware and about safe computing here

Thank you for your patience, and performing all of the procedures requested.

NOTE: You have Spyware Blaster 4.1. installed. This program has been updated to version 4.2 … un-install your old program , re-install the new (LINK) and update the definitions. Be sure you click on "Protect All".
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI