OTListIt logfile created on: 27/04/2009 7:00:04 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Brian\Local Settings\Temporary Internet Files\Content.IE5\F3T19LC4
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1022.98 Mb Total Physical Memory | 614.45 Mb Available Physical Memory | 60.06% Memory free
2.40 Gb Paging File | 2.09 Gb Available in Paging File | 87.08% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 65.98 Gb Free Space | 88.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ROBINSON
Current User Name: Brian
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008/04/14 04:42:20 | 01,033,728 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\Explorer.EXE
PRC - [2008/10/17 14:52:10 | 00,149,352 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/08/24 06:35:30 | 00,243,064 | โ- | M] (Symantec Corporation) โ C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2004/04/11 10:43:44 | 00,053,248 | โ- | M] (CyberLink Corp.) โ C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
PRC - [2008/05/07 11:41:56 | 02,162,688 | โ- | M] (Telstra) โ C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe
PRC - [2008/10/17 14:52:10 | 00,149,352 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2009/04/20 09:18:48 | 00,148,888 | โ- | M] (Sun Microsystems, Inc.) โ C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/04/14 04:42:30 | 01,695,232 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Messenger\msmsgs.exe
PRC - [2007/12/08 10:42:02 | 00,376,832 | โ- | M] (The Eraser Project) โ C:\Program Files\Eraser\Eraser.exe
PRC - [2009/01/14 11:00:00 | 00,525,664 | Rโ | M] (WinZip Computing, S.L.) โ C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2009/04/20 09:18:48 | 00,152,984 | โ- | M] (Sun Microsystems, Inc.) โ C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2003/06/19 22:25:00 | 00,322,120 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/05/16 13:01:00 | 00,159,812 | โ- | M] (NVIDIA Corporation) โ C:\WINDOWS\system32\nvsvc32.exe
PRC - [2009/04/27 18:59:24 | 00,501,248 | โ- | M] (OldTimer Tools) โ C:\Documents and Settings\Brian\Local Settings\Temporary Internet Files\Content.IE5\F3T19LC4\OTListIt2[1].exe
PRC - [2009/01/17 13:00:26 | 01,251,720 | โ- | M] () โ C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2009/02/06 20:10:02 | 00,227,840 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\system32\wbem\wmiprvse.exe
========== Win32 Services (SafeList) ==========
SRV - [2007/10/24 00:47:22 | 00,033,800 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe โ (aspnet_state [On_Demand | Stopped])
SRV - [2007/08/24 06:35:30 | 00,243,064 | โ- | M] (Symantec Corporation) โ C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe โ (Automatic LiveUpdate Scheduler [Auto | Running])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ (ccEvtMgr [Auto | Running])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ (ccSetMgr [Auto | Running])
SRV - [2007/10/24 00:47:40 | 00,070,144 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe โ (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ (CLTNetCnService [Auto | Running])
SRV - [2008/04/14 04:42:04 | 00,038,400 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll โ (helpsvc [Auto | Running])
SRV - [2009/04/20 09:18:48 | 00,152,984 | โ- | M] (Sun Microsystems, Inc.) โ C:\Program Files\Java\jre6\bin\jqs.exe โ (JavaQuickStarterService [Auto | Running])
SRV - [2007/08/24 06:35:22 | 03,192,184 | โ- | M] (Symantec Corporation) โ C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE โ (LiveUpdate [On_Demand | Stopped])
SRV - [2008/10/17 14:52:10 | 00,149,352 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe โ (LiveUpdate Notice [Auto | Running])
SRV - [2003/06/19 22:25:00 | 00,322,120 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE โ (MDM [Auto | Running])
SRV - File not found โ โ (Nero BackItUp Scheduler 4.0 [Auto | Stopped])
SRV - [2008/05/16 13:01:00 | 00,159,812 | โ- | M] (NVIDIA Corporation) โ C:\WINDOWS\system32\nvsvc32.exe โ (NVSvc [Auto | Running])
SRV - [2003/07/28 11:28:22 | 00,089,136 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE โ (ose [On_Demand | Stopped])
SRV - [2009/01/17 13:00:26 | 01,251,720 | โ- | M] () โ C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe โ (Symantec Core LC [On_Demand | Running])
SRV - [2006/10/18 19:05:24 | 00,913,408 | โ- | M] (Microsoft Corporation) โ C:\Program Files\Windows Media Player\WMPNetwk.exe โ (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2008/04/13 23:16:22 | 00,048,128 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\system32\DRIVERS\61883.sys โ (61883 [On_Demand | Stopped])
DRV - [2002/04/01 13:15:00 | 00,004,816 | โ- | M] (Andrea Electronics Corporation) โ C:\WINDOWS\system32\drivers\aeaudio.sys โ (aeaudio [On_Demand | Running])
DRV - [2008/04/13 23:16:22 | 00,038,912 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\system32\DRIVERS\avc.sys โ (Avc [On_Demand | Stopped])
DRV - [2004/03/23 03:24:00 | 00,004,272 | Rโ | M] () โ C:\WINDOWS\System32\drivers\bvrp_pci.sys โ (bvrp_pci [On_Demand | Stopped])
DRV - [2007/06/22 08:54:32 | 00,087,424 | โ- | M] (Cmotech Co., Ltd) โ C:\WINDOWS\system32\DRIVERS\cmusbnet.sys โ (cmusbnet [On_Demand | Running])
DRV - [2006/12/13 17:31:56 | 00,087,040 | โ- | M] (Cmotech Co.,Ltd) โ C:\WINDOWS\system32\DRIVERS\cmusbser.sys โ (cmusbser [On_Demand | Running])
DRV - [2008/07/30 16:42:12 | 00,023,888 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\system32\Drivers\COH_Mon.sys โ (COH_Mon [On_Demand | Stopped])
DRV - [2005/06/13 11:58:04 | 00,162,816 | โ- | M] (Intel Corporation) โ C:\WINDOWS\system32\DRIVERS\e100b325.sys โ (E100B [On_Demand | Running])
DRV - [2009/02/28 19:00:00 | 00,371,248 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys โ (eeCtrl [System | Running])
DRV - [2009/02/28 19:00:00 | 00,101,936 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys โ (EraserUtilRebootDrv [On_Demand | Running])
DRV - [2008/04/13 23:16:10 | 00,051,200 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\system32\DRIVERS\msdv.sys โ (MSDV [On_Demand | Stopped])
DRV - [2009/03/16 18:00:00 | 00,089,104 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090421.006\NAVENG.SYS โ (NAVENG [On_Demand | Running])
DRV - [2009/03/16 18:00:00 | 00,876,144 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090421.006\NAVEX15.SYS โ (NAVEX15 [On_Demand | Running])
DRV - [2008/05/16 13:01:00 | 06,557,408 | โ- | M] (NVIDIA Corporation) โ C:\WINDOWS\System32\DRIVERS\nv4_mini.sys โ (nv [On_Demand | Running])
DRV - [2001/08/22 07:42:58 | 00,013,632 | โ- | M] (Dell Computer Corporation) โ C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS โ (OMCI [System | Running])
DRV - [2007/07/13 15:25:22 | 00,027,072 | โ- | M] (Printing Communications Assoc., Inc. (PCAUSA)) โ C:\WINDOWS\System32\Drivers\PCASp50.sys โ (PCASp50 [On_Demand | Stopped])
DRV - [2003/07/17 06:42:18 | 00,017,792 | โ- | M] (Parallel Technologies, Inc.) โ C:\WINDOWS\System32\DRIVERS\ptilink.sys โ (Ptilink [On_Demand | Running])
DRV - [2008/04/13 21:09:16 | 00,020,480 | โ- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) โ C:\WINDOWS\System32\DRIVERS\secdrv.sys โ (Secdrv [On_Demand | Stopped])
DRV - [2003/05/06 08:14:34 | 00,580,992 | โ- | M] (Analog Devices, Inc.) โ C:\WINDOWS\system32\drivers\smwdm.sys โ (smwdm [On_Demand | Running])
DRV - [2008/09/05 13:31:42 | 00,447,024 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys โ (SPBBCDrv [System | Running])
DRV - [2007/11/30 22:57:12 | 00,279,088 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SRTSP.SYS โ (SRTSP [On_Demand | Running])
DRV - [2007/11/30 22:57:12 | 00,317,616 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SRTSPL.SYS โ (SRTSPL [On_Demand | Stopped])
DRV - [2007/11/30 22:57:12 | 00,043,696 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SRTSPX.SYS โ (SRTSPX [System | Running])
DRV - [2009/02/19 10:31:16 | 00,013,616 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SYMDNS.SYS โ (SYMDNS [On_Demand | Running])
DRV - [2009/01/17 13:05:09 | 00,124,464 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\system32\Drivers\SYMEVENT.SYS โ (SymEvent [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,096,560 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SYMFW.SYS โ (SYMFW [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,038,576 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SYMIDS.SYS โ (SYMIDS [On_Demand | Running])
DRV - [2009/02/10 08:59:18 | 00,251,768 | โ- | M] (Symantec Corporation) โ C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090414.001\SymIDSCo.sys โ (SYMIDSCO [On_Demand | Running])
DRV - [2009/02/19 10:31:42 | 00,031,280 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\system32\DRIVERS\SymIM.sys โ (SymIM [On_Demand | Stopped])
DRV - [2009/02/19 10:31:42 | 00,031,280 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\system32\DRIVERS\SymIM.sys โ (SymIMMP [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,037,424 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SYMNDIS.SYS โ (SYMNDIS [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,022,320 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SYMREDRV.SYS โ (SYMREDRV [On_Demand | Running])
DRV - [2009/02/19 10:31:16 | 00,184,496 | โ- | M] (Symantec Corporation) โ C:\WINDOWS\System32\Drivers\SYMTDI.SYS โ (SYMTDI [System | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.telstra.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/20 09:18:49 | 00,000,000 | โD | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (BigPond Wireless Broadband 2.0 Auto Dial) - {DB92EC3F-697D-4C3B-9A3B-3ABBD23D4A85} - C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\bpwbb2ad.dll (Telstra)
O2 - BHO: (Javaโข Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BigPondWirelessBroadbandCM] "C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" -tsr (Telstra)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide (The Eraser Project)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdatโฆb?1232003071343 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โฆindows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/15 15:53:38 | 00,000,000 | โ- | M] () - C:\AUTOEXEC.BAT โ [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/04/22 06:25:47 | 00,000,000 | โD | C] โ C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/04/22 06:25:45 | 00,000,000 | โD | C] โ C:\Program Files\WinZip Self-Extractor
[2009/04/20 09:19:37 | 00,000,000 | โD | C] โ C:\WINDOWS\Sun
[2009/04/20 09:18:43 | 00,000,000 | โD | C] โ C:\Program Files\Java
[2009/04/20 09:11:19 | 00,000,000 | โD | C] โ C:\Documents and Settings\Brian\Application Data\Sun
[2009/04/18 10:16:32 | 01,203,922 | โ- | C] () โ C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/18 10:16:32 | 00,002,560 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\xpsp4res.dll
[2009/04/18 10:16:31 | 00,215,552 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/18 10:11:23 | 00,473,600 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/18 10:11:23 | 00,401,408 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/18 10:11:23 | 00,284,160 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/18 10:11:23 | 00,110,592 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\services.exe
[2009/04/18 10:11:22 | 00,729,088 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/18 10:11:22 | 00,714,752 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/18 10:11:22 | 00,617,472 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/18 10:11:22 | 00,453,120 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/18 10:11:22 | 00,227,840 | โ- | C] (Microsoft Corporation) โ C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:35:54 | 00,000,000 | โD | C] โ C:\Documents and Settings\Brian\My Documents\My Received Files
[2009/04/15 18:55:42 | 00,000,000 | โD | C] โ C:\Documents and Settings\Brian\Local Settings\Application Data\Newsman Pro
[2009/04/15 07:53:10 | 00,000,000 | โD | C] โ C:\Program Files\NewsMan Pro
[2009/04/13 11:24:33 | 00,000,000 | โD | C] โ C:\Program Files\Trend Micro
[2009/04/07 18:54:29 | 00,000,000 | โD | C] โ C:\WINDOWS\pss
[2009/04/07 18:52:29 | 00,000,000 | โD | C] โ C:\Program Files\CleanUp2
[2009/04/07 06:35:32 | 00,000,000 | โD | C] โ C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/04/06 06:20:53 | 00,000,712 | โ- | C] () โ C:\Documents and Settings\Brian\Desktop\Outlook Express.lnk
[2009/04/06 06:19:37 | 00,000,654 | โ- | C] () โ C:\Documents and Settings\Brian\Desktop\WinRAR.lnk
[2009/04/06 05:50:26 | 00,000,000 | โD | C] โ C:\Program Files\RAR Password Cracker
[2009/04/06 05:50:05 | 00,210,109 | โ- | C] () โ C:\Program Files\rpc412_setup.exe
[2009/04/04 11:59:47 | 00,000,000 | โD | C] โ C:\Documents and Settings\Brian\My Documents\Cyberlink
[2009/04/04 11:59:47 | 00,000,000 | โD | C] โ C:\Documents and Settings\Brian\Application Data\CyberLink
[2009/04/04 11:59:46 | 00,000,000 | โD | C] โ C:\Documents and Settings\Brian\Local Settings\Application Data\PowerDVD
[2009/02/13 05:28:25 | 00,000,000 | โ- | C] () โ C:\WINDOWS\OpPrintServer.INI
[2009/02/13 04:46:50 | 00,000,116 | โ- | C] () โ C:\WINDOWS\NeroDigital.ini
[2009/01/17 11:42:06 | 00,000,410 | โ- | C] () โ C:\WINDOWS\BRWMARK.INI
[2009/01/16 07:40:09 | 00,000,376 | โ- | C] () โ C:\WINDOWS\ODBC.INI
[2009/01/15 16:14:39 | 00,004,272 | Rโ | C] () โ C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2008/12/31 16:04:42 | 00,691,560 | โ- | C] () โ C:\WINDOWS\System32\OGACheckControl.dll
[2008/05/16 13:01:00 | 01,703,936 | โ- | C] () โ C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/16 13:01:00 | 01,019,904 | โ- | C] () โ C:\WINDOWS\System32\nvwimg.dll
[2008/05/16 13:01:00 | 00,286,720 | โ- | C] () โ C:\WINDOWS\System32\nvnt4cpl.dll
[2003/07/28 14:19:00 | 01,486,848 | โ- | C] () โ C:\WINDOWS\System32\nview.dll
[2003/07/28 14:19:00 | 00,466,944 | โ- | C] () โ C:\WINDOWS\System32\nvshell.dll
[2003/07/17 06:51:23 | 00,000,576 | โ- | C] () โ C:\WINDOWS\win.ini
[2003/07/17 06:47:28 | 00,000,227 | โ- | C] () โ C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[2009/04/27 18:54:38 | 00,186,097 | โ- | M] () โ C:\WINDOWS\System32\nvapps.xml
[2009/04/27 18:54:38 | 00,000,438 | โ- | M] () โ C:\WINDOWS\tasks\RegCure Program Check.job
[2009/04/27 18:54:32 | 00,000,006 | -Hโ | M] () โ C:\WINDOWS\tasks\SA.DAT
[2009/04/27 18:54:27 | 00,002,048 | โS- | M] () โ C:\WINDOWS\bootstat.dat
[2009/04/27 05:58:32 | 00,029,696 | โ- | M] () โ C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/27 05:56:57 | 00,000,116 | โ- | M] () โ C:\WINDOWS\NeroDigital.ini
[2009/04/27 05:25:02 | 00,002,206 | โ- | M] () โ C:\WINDOWS\System32\wpa.dbl
[2009/04/25 09:43:27 | 00,000,576 | โ- | M] () โ C:\WINDOWS\win.ini
[2009/04/20 20:00:03 | 00,000,556 | โ- | M] () โ C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Brian.job
[2009/04/19 05:38:24 | 00,477,846 | โ- | M] () โ C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/19 05:38:24 | 00,406,636 | โ- | M] () โ C:\WINDOWS\System32\perfh009.dat
[2009/04/19 05:38:24 | 00,063,644 | โ- | M] () โ C:\WINDOWS\System32\perfc009.dat
[2009/04/18 22:26:29 | 00,001,374 | โ- | M] () โ C:\WINDOWS\imsins.BAK
[2009/04/18 18:57:48 | 00,000,442 | โ- | M] () โ C:\WINDOWS\tasks\ParetoLogic Registration.job
[2009/04/11 09:37:47 | 00,021,504 | โ- | M] () โ C:\Documents and Settings\Brian\My Documents\Geelong.xls
[2009/04/07 18:55:51 | 00,000,227 | โ- | M] () โ C:\WINDOWS\system.ini
[2009/04/07 18:55:51 | 00,000,211 | RHS- | M] () โ C:\boot.ini
[2009/04/07 00:57:24 | 24,921,544 | โ- | M] (Microsoft Corporation) โ C:\WINDOWS\System32\MRT.exe
[2009/04/06 06:20:53 | 00,000,712 | โ- | M] () โ C:\Documents and Settings\Brian\Desktop\Outlook Express.lnk
[2009/04/06 06:19:37 | 00,000,654 | โ- | M] () โ C:\Documents and Settings\Brian\Desktop\WinRAR.lnk
========== LOP Check ==========
[2009/04/22 06:25:47 | 00,000,000 | RH-D | M] โ C:\Documents and Settings\All Users\Application Data
[2009/01/16 07:47:35 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Adobe
[2009/02/12 18:28:29 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Ahead
[2009/02/07 05:47:38 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Cached Installations
[2009/03/02 18:00:33 | 00,000,000 | โSD | M] โ C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/02/12 04:51:38 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Nero
[2009/04/07 06:35:32 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/02/15 05:16:09 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/01/17 13:01:31 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Symantec
[2009/01/15 17:07:41 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/27 18:32:45 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/22 06:25:47 | 00,000,000 | โD | M] โ C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/04/20 09:11:19 | 00,000,000 | RH-D | M] โ C:\Documents and Settings\Brian\Application Data
[2009/01/16 13:40:32 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Adobe
[2009/02/13 04:47:05 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Ahead
[2009/01/18 14:14:53 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\ASCOMP Software
[2009/01/18 11:37:13 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\CoSoSys
[2009/04/04 11:59:47 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\CyberLink
[2009/01/27 18:29:44 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Help
[2009/01/15 16:11:50 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Identities
[2009/02/12 18:42:51 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\JPEGsnoop
[2009/01/16 06:50:57 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Macromedia
[2009/04/11 09:05:33 | 00,000,000 | โSD | M] โ C:\Documents and Settings\Brian\Application Data\Microsoft
[2009/01/16 12:27:42 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Nero
[2009/04/20 09:11:19 | 00,000,000 | โD | M] โ C:\Documents and Settings\Brian\Application Data\Sun
[2003/07/17 06:36:49 | 00,000,065 | RHโ | M] () โ C:\WINDOWS\Tasks\desktop.ini
[2009/04/20 20:00:03 | 00,000,556 | โ- | M] () โ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Brian.job
[2009/04/18 18:57:48 | 00,000,442 | โ- | M] () โ C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2009/04/27 18:54:38 | 00,000,438 | โ- | M] () โ C:\WINDOWS\Tasks\RegCure Program Check.job
[2009/01/16 08:22:54 | 00,000,372 | โ- | M] () โ C:\WINDOWS\Tasks\RegCure.job
[2009/04/27 18:54:32 | 00,000,006 | -Hโ | M] () โ C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >