OTViewIt logfile created on: 4/16/2009 12:12:31 AM - Run 2
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.25 Gb Total Physical Memory | 0.77 Gb Available Physical Memory | 61.97% Memory free
2.98 Gb Paging File | 2.33 Gb Available in Paging File | 78.28% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 113.17 Gb Free Space | 75.93% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465.76 Gb Total Space | 390.74 Gb Free Space | 83.89% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2009/03/25 23:18:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2009/03/25 23:18:56 | 01,356,616 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgfws8.exe
[1999/12/13 02:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE
[2009/01/17 15:10:29 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
[2004/02/04 11:37:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
[2004/09/29 13:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
[2009/03/19 23:35:15 | 00,066,872 | —- | M] () – C:\WINDOWS\system32\PnkBstrA.exe
[2006/04/21 22:06:14 | 00,069,632 | —- | M] () – G:\Dad\PrfldSvc.exe
[2009/03/25 23:19:10 | 00,832,792 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgam.exe
[2009/03/25 23:19:16 | 00,485,144 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
[2009/01/07 13:40:56 | 00,348,752 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe
[2009/03/25 23:18:58 | 00,593,176 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
[2009/01/21 14:08:06 | 01,095,560 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe
[2009/03/25 23:18:59 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
[2009/03/25 23:19:16 | 00,691,992 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
[2009/03/25 23:19:06 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
[2008/12/08 14:33:48 | 01,173,384 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsTray.exe
[2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
[2009/04/16 00:10:18 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008/12/27 01:29:04 | 00,072,704 | —- | M] (Adobe Systems) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [On_Demand | Stopped])
[2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
[2009/03/25 23:18:59 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
[2009/03/25 23:18:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
[2009/03/25 23:18:56 | 01,356,616 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgfws8.exe – (avgfws8 [Auto | Running])
[2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[1999/12/13 02:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE – (Creative Service for CDROM Access [Auto | Running])
[2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
[2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
[2009/01/17 15:10:29 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
[2003/03/03 14:33:40 | 00,143,360 | —- | M] (Intel® Corporation) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc [On_Demand | Stopped])
[2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
[2004/02/04 11:37:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
[2004/09/29 13:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12 [Auto | Running])
[2009/03/19 23:35:15 | 00,066,872 | —- | M] () – C:\WINDOWS\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
[2006/04/21 22:06:14 | 00,069,632 | —- | M] () – G:\Dad\PrfldSvc.exe – (prfldsvc [Auto | Running])
[2009/01/07 13:40:56 | 00,348,752 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService [Auto | Running])
[2009/01/21 14:08:06 | 01,095,560 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService [Auto | Running])
[2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services ==========
[2008/12/26 22:29:51 | 00,029,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgfwdx.sys – (Avgfwdx [On_Demand | Running])
[2008/12/26 22:29:51 | 00,029,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgfwdx.sys – (Avgfwfd [On_Demand | Stopped])
[2009/03/25 23:19:16 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys – (AvgLdx86 [System | Running])
[2009/01/08 15:17:04 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
[2009/01/08 15:17:01 | 00,012,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgrkx86.sys – (AvgRkx86 [Boot | Running])
[2009/03/25 23:19:04 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys – (AvgTdiX [System | Running])
[2003/02/20 18:22:38 | 00,135,040 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctac32k.sys – (ctac32k [On_Demand | Running])
[2003/03/26 17:33:58 | 00,498,688 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctaud2k.sys – (ctaud2k [On_Demand | Running])
[2003/03/27 12:58:56 | 00,287,920 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctdvda2k.sys – (ctdvda2k [On_Demand | Stopped])
[2003/02/20 18:24:18 | 00,006,144 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctprxy2k.sys – (ctprxy2k [On_Demand | Running])
[2003/02/20 18:24:34 | 00,135,248 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k [On_Demand | Running])
[2003/03/04 12:56:26 | 00,145,408 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\e100b325.sys – (E100B [On_Demand | Running])
[2003/02/20 18:24:46 | 00,116,000 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\emupia2k.sys – (emupia [On_Demand | Running])
[2003/03/26 17:31:40 | 00,823,616 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ha10kx2k.sys – (ha10kx2k [On_Demand | Running])
[2003/03/26 17:32:02 | 00,141,536 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\hap16v2k.sys – (hap16v2k [On_Demand | Running])
[2005/03/08 00:52:26 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412 [On_Demand | Stopped])
[2005/03/08 00:52:27 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12 [On_Demand | Stopped])
[2005/03/08 00:52:28 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12 [On_Demand | Stopped])
[2004/02/04 11:37:00 | 01,878,432 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv [On_Demand | Running])
[2001/08/22 09:42:58 | 00,013,632 | —- | M] (Dell Computer Corporation) – C:\WINDOWS\system32\drivers\omci.sys – (OMCI [System | Running])
[2003/03/26 17:32:32 | 00,189,504 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv [On_Demand | Running])
[2009/03/06 16:45:06 | 00,130,424 | —- | M] (PC Tools) – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore [Boot | Running])
[2003/03/06 11:10:34 | 00,015,840 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\pfmodnt.sys – (PfModNT [Auto | Running])
[2006/04/21 09:22:24 | 00,070,912 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\drivers\prvflder.sys – (Prvflder [Auto | Running])
[2003/07/16 16:42:18 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink [On_Demand | Running])
[2008/11/06 12:37:28 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20 [Boot | Running])
[2008/04/13 12:39:15 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv [On_Demand | Stopped])
[2008/04/13 14:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Running])
[2008/04/13 14:46:20 | 00,121,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbvideo.sys – (usbvideo [On_Demand | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (HKLM) – C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (HKLM) – C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{AE7CD045-E861-484f-8273-0445EE161910} (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} (HKLM) – C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) – C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) – C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414}" (HKLM) – C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsioReg"=REGSVR32.EXE /S CTASIO.DLL (Microsoft Corporation)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" (PC Tools)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"UpdReg"=C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
"UserFaultCheck"=%systemroot%\system32\dumprep 0 -u File not found
========== (O4) Startup Folders ==========
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&D&ownload &with BitComet: C:\Program Files\BitComet\BitComet.exe [2008/12/03 06:11:42 | 02,514,744 | —- | M] (www.BitComet.com)
&D&ownload all video with BitComet: C:\Program Files\BitComet\BitComet.exe [2008/12/03 06:11:42 | 02,514,744 | —- | M] (www.BitComet.com)
&D&ownload all with BitComet: C:\Program Files\BitComet\BitComet.exe [2008/12/03 06:11:42 | 02,514,744 | —- | M] (www.BitComet.com)
Convert link target to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert link target to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selected links to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selected links to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selection to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selection to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2001/02/16 02:05:38 | 09,164,192 | R— | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}: Button: BitComet – %ProgramFiles%\BitComet\tools\BitCometBHO_1.2.8.7.dll [2008/08/11 04:12:14 | 00,656,696 | —- | M] (BitComet)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 – %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find…=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
: msn in My Computer
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{6414512B-B978-451D-A0D8-FCFDF33E833C}:
http://www.update.microsoft.com/windowsupd…b?1229815666593 – WUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com – Java Plug-in 1.6.0_11
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}:
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab – Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab – Shockwave Flash Object
========== (O17) DNS Name Servers ==========
{5F626E98-A6DD-4AD8-A787-5EC00921F05D} (Servers: | Description: Intel® PRO/100 VE Network Connection)
{D40E7502-BF13-485A-A048-A9B562C71BA4} (Servers: | Description: )
{E11F8FCE-2960-4377-9ABA-69323650A802} (Servers: | Description: 1394 Net Adapter)
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
avgrsstarter: "DllName" = avgrsstx.dll – C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2008/12/20 18:12:44 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT – [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/16 00:10:14 | 00,422,912 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTViewIt.exe
[2009/04/14 22:44:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\My Albums
[2009/04/14 00:16:48 | 00,007,168 | -HS- | C] () – C:\WINDOWS\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
[2009/04/13 02:03:17 | 00,000,317 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url
@Alternate Data Stream - 3638 bytes -> C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url:favicon
[2009/04/13 01:51:34 | 00,001,740 | —- | C] () – C:\Documents and Settings\Dad\Desktop\HijackThis.lnk
[2009/04/13 01:51:33 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/11 23:24:01 | 00,000,166 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Auto-mo-brella by GTM Products, LLC,.url
[2009/04/11 23:17:19 | 00,000,322 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url
@Alternate Data Stream - 6598 bytes -> C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url:favicon
[2009/04/08 18:36:53 | 00,024,576 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Tail light.doc
[2009/04/07 19:33:27 | 00,000,358 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url
@Alternate Data Stream - 4286 bytes -> C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url:favicon
[2009/04/06 20:21:21 | 00,048,064 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Email-Sms.mp3
[2009/04/03 18:58:04 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/04/02 23:15:25 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2009/04/02 23:13:27 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/04/02 23:13:23 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/04/02 23:13:15 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/04/02 23:12:13 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/04/02 23:12:13 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/04/02 23:12:13 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/04/02 23:12:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/04/02 23:12:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/04/02 23:12:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/04/02 23:12:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/04/02 23:05:53 | 00,000,000 | RH-D | C] – C:\AHCache
[2009/04/02 22:59:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2009/04/02 22:55:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\Uniblue 2009 (SpeedUpMyPC + RegistryBooster + DriverScanner){H33T}{JOHNCANADUDE}
[2009/04/02 22:48:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Uniblue
[2009/03/31 23:45:13 | 00,332,276 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Nitro_Circus.mp3
[2009/03/31 23:40:53 | 00,104,906 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Cool_One.mp3
[2009/03/31 23:39:15 | 00,046,854 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Soft_Alert.mp3
[2009/03/31 23:38:20 | 00,034,316 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Nova.mp3
[2009/03/31 22:31:36 | 00,159,600 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009/03/31 22:31:20 | 00,130,424 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/03/31 22:31:20 | 00,073,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009/03/31 22:31:09 | 00,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/03/31 22:31:07 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/03/31 22:31:06 | 00,064,392 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2009/03/31 22:31:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/03/29 17:02:12 | 00,395,264 | —- | C] () – C:\Documents and Settings\All Users\Documents\Wenonah 1.doc
[2009/03/29 14:28:18 | 00,395,264 | —- | C] () – C:\Documents and Settings\All Users\Documents\Wenonah.doc
[2009/03/29 14:28:04 | 00,395,264 | —- | C] () – C:\Documents and Settings\All Users\Documents\Wenonah 2.doc
[2009/03/28 15:00:03 | 00,024,064 | —- | C] () – C:\Documents and Settings\All Users\Documents\Canoe For Sale.doc
[2009/03/28 12:51:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\iWin
[2009/03/28 00:24:20 | 00,022,952 | —- | C] () – C:\Documents and Settings\Dad\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/27 23:46:41 | 00,352,256 | —- | C] () – C:\Documents and Settings\Dad\My Documents\SWINGARM Parts.doc
[2009/03/27 22:33:35 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/03/27 22:33:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Mozilla
[2009/03/27 22:33:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Mozilla
[2009/03/27 22:33:12 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/03/26 13:03:16 | 00,278,528 | —- | C] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Program Files\Real Alternative
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Real
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Real
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2009/03/25 23:16:45 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/03/19 23:37:12 | 00,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/19 23:37:06 | 00,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/19 23:35:15 | 00,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
========== Files - Modified Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/16 00:10:18 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTViewIt.exe
[2009/04/16 00:05:39 | 00,003,733 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/04/15 19:33:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/15 19:33:42 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/15 00:02:34 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/04/15 00:02:34 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/04/15 00:02:34 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2009/04/15 00:02:33 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2009/04/14 23:39:02 | 00,028,160 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/14 00:21:04 | 00,000,322 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url
@Alternate Data Stream - 6598 bytes -> C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url:favicon
[2009/04/14 00:16:48 | 00,007,168 | -HS- | M] () – C:\WINDOWS\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
[2009/04/14 00:15:56 | 00,013,312 | -HS- | M] () – C:\Documents and Settings\Dad\Desktop\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dad\Desktop\Thumbs.db:encryptable
[2009/04/14 00:15:02 | 00,000,474 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Shared Documents.lnk
[2009/04/14 00:13:22 | 00,000,358 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url
@Alternate Data Stream - 4286 bytes -> C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url:favicon
[2009/04/14 00:10:18 | 00,000,166 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Auto-mo-brella by GTM Products, LLC,.url
[2009/04/13 23:27:45 | 00,000,317 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url
@Alternate Data Stream - 3638 bytes -> C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url:favicon
[2009/04/13 16:52:33 | 00,521,942 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/13 16:52:33 | 00,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/13 16:52:33 | 00,071,060 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/13 01:51:34 | 00,001,740 | —- | M] () – C:\Documents and Settings\Dad\Desktop\HijackThis.lnk
[2009/04/12 06:52:55 | 00,000,010 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2009/04/11 09:40:24 | 35,043,589 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/04/11 09:40:24 | 00,093,132 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/04/08 20:30:00 | 00,000,601 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/08 20:30:00 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/08 20:30:00 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/04/08 18:36:54 | 00,024,576 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Tail light.doc
[2009/04/07 18:23:54 | 00,024,576 | —- | M] () – C:\Documents and Settings\Dad\My Documents\You are bidding on a like new 2006 Bob Long Alias.doc
[2009/04/06 20:21:22 | 00,048,064 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Email-Sms.mp3
[2009/04/02 23:18:50 | 00,022,952 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/02 23:16:52 | 00,126,112 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/01 00:39:50 | 00,046,854 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Soft_Alert.mp3
[2009/04/01 00:13:24 | 00,034,316 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Nova.mp3
[2009/03/31 23:45:13 | 00,332,276 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Nitro_Circus.mp3
[2009/03/31 23:40:53 | 00,104,906 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Cool_One.mp3
[2009/03/31 22:35:16 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/31 22:31:09 | 00,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/03/29 17:02:12 | 00,395,264 | —- | M] () – C:\Documents and Settings\All Users\Documents\Wenonah 1.doc
[2009/03/29 14:28:19 | 00,395,264 | —- | M] () – C:\Documents and Settings\All Users\Documents\Wenonah.doc
[2009/03/29 14:28:04 | 00,395,264 | —- | M] () – C:\Documents and Settings\All Users\Documents\Wenonah 2.doc
[2009/03/28 15:00:04 | 00,024,064 | —- | M] () – C:\Documents and Settings\All Users\Documents\Canoe For Sale.doc
[2009/03/28 00:24:20 | 00,022,952 | —- | M] () – C:\Documents and Settings\Dad\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/27 23:46:41 | 00,352,256 | —- | M] () – C:\Documents and Settings\Dad\My Documents\SWINGARM Parts.doc
[2009/03/27 22:33:35 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/03/25 23:19:17 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/25 23:19:16 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/25 23:19:04 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/22 11:28:42 | 00,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/03/20 22:15:58 | 00,022,328 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/20 22:15:51 | 00,103,736 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/19 23:35:15 | 00,066,872 | —- | M] () – C:\WINDOWS\System32\PnkBstrA.exe
< End of report >