This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TR/Crypt.FKM.gen

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having problems with removing the trojan TR/Crypt.fkm.gen. I have Avira free antivirus and it finds it every single morning and says it is removing it but it doesn't. When I restart my computer I get the same alert from Avira. I did have AVG free antivirus on my machine and it did the same thing - kept finding it but couldn't remove it.

My computer runs SUPER slow. Sometimes while on the net (using Firefox) the tower will beep and Firefox will shut down - don't know if this is related or not.


Here is my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:14:40 PM, on 4/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
C:\Program Files\Sharp\Sharpdesk\IndexTray.exe
C:\Program Files\Sharp\Sharpdesk\Indexer.exe
C:\Program Files\Sharp\Sharpdesk\SharpTray.exe
C:\Program Files\SHARP\Button Manager G\btnman.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE
C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe
C:\Program Files\EMBARQ Online Security\Common\FSMB32.EXE
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\EMBARQ Online Security\Common\FCH32.EXE
C:\Program Files\EMBARQ Online Security\Common\FAMEH32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {7846CD13-76D6-4C18-89AD-369ED4935B53} - C:\WINDOWS\system32\comdlg32n.dll
O2 - BHO: (no name) - {79997E2D-2255-4D36-9AFA-1564A8CEB07A} - c:\windows\system32\cmdial32f.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
O4 - HKLM\..\Run: [IndexTray] "C:\Program Files\Sharp\Sharpdesk\IndexTray.exe"
O4 - HKLM\..\Run: [Indexer] "C:\Program Files\Sharp\Sharpdesk\Indexer.exe"
O4 - HKLM\..\Run: [SharpTray] "C:\Program Files\Sharp\Sharpdesk\SharpTray.exe"
O4 - HKLM\..\Run: [TypeRegChecker] "C:\Program Files\Sharp\Sharpdesk\TypeRegChecker.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'Default user')
O4 - Global Startup: Button Manager G.lnk = C:\Program Files\SHARP\Button Manager G\btnman.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145365066093
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://support.ohiobwc.com/webline/applets/msie40x.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O20 - Winlogon Notify: rsgdatkh - C:\WINDOWS\SYSTEM32\cmdial32f.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 7855 bytes


Here is my Malwarebytes log:
Malwarebytes' Anti-Malware 1.36
Database version: 1951
Windows 5.1.2600 Service Pack 2

4/20/2009 1:14:09 PM
mbam-log-2009-04-20 (13-14-09).txt

Scan type: Quick Scan
Objects scanned: 72646
Time elapsed: 9 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7846cd13-76d6-4c18-89ad-369ed4935b53} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{7846cd13-76d6-4c18-89ad-369ed4935b53} (Trojan.BHO.H) -> Delete on reboot.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Delete on reboot.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\SYSTEM32\comdlg32n.dll (Trojan.BHO.H) -> Delete on reboot.


****Any help will be sincerely appreciated!!!!!!****
Hi there to enable me to kill as much as possible in one go I would like you to run a different scanner for me

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
OTListIt Extras logfile created on: 4/20/2009 4:15:13 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Stacy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 188.94 Mb Available Physical Memory | 37.05% Memory free
1.21 Gb Paging File | 0.87 Gb Available in Paging File | 71.73% Paging File free
Paging file location(s): C:\pagefile.sys 765 765;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 63.74 Gb Free Space | 85.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.86 Gb Total Space | 1.86 Gb Free Space | 99.92% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D673T931
Current User Name: Stacy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"80:TCP" = 80:TCP:*:Enabled:@xpsp2res.dll,-22009
"3711:TCP" = 3711:TCP:*:Enabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AMERIC~2.0 (America Online, Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AMERIC~2.0 (America Online, Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0AEF384B-610F-4309-8DA3-91834FE4E80E}" = Sharpdesk
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F8EB641-6AD2-45DE-A8DD-91D7BDD39CDE}" = Microsoft USB Flash Drive Manager
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{4E7E8E6A-15F1-4E26-9352-26AD235131E9}" = Documents To Go
"{590D4F8F-98FE-47FA-AC2B-3F22FDCF7C09}" = ShareIns
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{796ADAFF-7C5B-4CED-BA11-55A3644F1E0D}" = HP Photo and Imaging 2.2 - Scanjet 3970 Series
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9EF64DD1-6249-414E-AD80-7AE5E6BE9475}" = WROCSG4
"{A2A227E0-8DEC-11D2-A564-B2890D000000}" = Jaws PDF Creator
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D2007C5F-FE8C-4E1B-AA9E-DBC5FF4F45CE}" = Jaws PDF Editor 2.1
"{DD9AF2B0-F3F3-4BCE-82CC-C0E4C6FE3E3A}" = Brother HL-2140
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E123986D-B310-4B47-8C92-0AFA6D1B0682}" = WROCSG6
"{E629851A-1B1A-4671-961A-A9AF549E03A2}" = ArcSoft PhotoImpression 5
"{EB7A2041-6A16-4BAC-8079-43B985673C2C}" = Avery Wizard 3.1
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"America Online us" = America Online (Choose which version to remove)
"AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus
"Avery Wizard 2.1 MSW10" = Avery Wizard 2.1 for Microsoft® Word 2002
"Bankruptcy2009" = Bankruptcy2009
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BDE32" = BDE32
"CCleaner" = CCleaner (remove only)
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Form Pilot Home (full)_is1" = Form Pilot Home version 1.92.1
"HijackThis" = HijackThis 2.0.2
"hp instant support" = hp instant support
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{0AEF384B-610F-4309-8DA3-91834FE4E80E}" = Sharpdesk
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"InstallShield_{EB7A2041-6A16-4BAC-8079-43B985673C2C}" = Avery Wizard 3.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"Mozilla Firefox (2.0.0.20)" = Mozilla Firefox (2.0.0.20)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OPD 1026R v2.08" = OPD 1026R v2.08
"PDF-XChange 2.5 Driver Install" = PDF-XChange 2.5 Driver Install
"Quicken 2001 Deluxe" = Quicken 2001 Deluxe
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"SHARP AR-M160/M200 Series Type B MFP Driver" = SHARP AR-M160/M200 Series Type B MFP Driver
"Sharp Button Manager G" = Sharp Button Manager G
"Spyware Terminator_is1" = Spyware Terminator
"StumbleUponIEToolbar" = StumbleUpon IE Toolbar
"SyncBack_is1" = SyncBack
"ViewpointMediaPlayer" = Viewpoint Media Player
"WGA" = Windows Genuine Advantage Validation Tool
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinZip" = WinZip
"WROCSG4" = WROCSG4

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{D2007C5F-FE8C-4E1B-AA9E-DBC5FF4F45CE}" = Jaws PDF Editor 2.1
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/8/2009 10:09:29 AM | Computer Name = D673T931 | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 4/8/2009 10:09:29 AM | Computer Name = D673T931 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 4/9/2009 8:31:52 AM | Computer Name = D673T931 | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 4/9/2009 8:31:52 AM | Computer Name = D673T931 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 4/15/2009 9:52:40 AM | Computer Name = D673T931 | Source = Application Error | ID = 1004
Description = Faulting application CIDAEMON.EXE, version 5.1.2600.0, faulting module
unknown, version 0.0.0.0, fault address 0x1000b9c0.

Error - 4/15/2009 9:53:44 AM | Computer Name = D673T931 | Source = Application Error | ID = 1004
Description = Faulting application winlogon.exe, version 0.0.0.0, faulting module
ntdll.dll, version 5.1.2600.2180, fault address 0x000105f8.

Error - 4/20/2009 9:08:18 AM | Computer Name = D673T931 | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 4/20/2009 9:08:18 AM | Computer Name = D673T931 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 4/20/2009 12:44:28 PM | Computer Name = D673T931 | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 4/20/2009 1:30:01 PM | Computer Name = D673T931 | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 10.0.6775.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 4/20/2009 8:09:50 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:11:52 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:13:54 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:15:56 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:17:58 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:20:00 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:22:02 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:24:04 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 8:26:06 AM | Computer Name = D673T931 | Source = DCOM | ID = 10010
Description = The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register
with DCOM within the required timeout.

Error - 4/20/2009 1:30:02 PM | Computer Name = D673T931 | Source = Print | ID = 6161
Description =


< End of report >


OTListIt logfile created on: 4/20/2009 4:15:13 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Stacy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 188.94 Mb Available Physical Memory | 37.05% Memory free
1.21 Gb Paging File | 0.87 Gb Available in Paging File | 71.73% Paging File free
Paging file location(s): C:\pagefile.sys 765 765;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 63.74 Gb Free Space | 85.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 1.86 Gb Total Space | 1.86 Gb Free Space | 99.92% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D673T931
Current User Name: Stacy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\System32\brss01a.exe (brother Industries Ltd)
PRC - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe (Global Graphics Software Ltd)
PRC - C:\Program Files\EMBARQ Online Security\Common\FSMB32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\EMBARQ Online Security\Common\FCH32.EXE (F-Secure Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
PRC - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe (Global Graphics Software Ltd.)
PRC - C:\Program Files\EMBARQ Online Security\Common\FAMEH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Sharp\Sharpdesk\IndexTray.exe (SHARP CORPORATION)
PRC - C:\Program Files\Sharp\Sharpdesk\Indexer.exe (SHARP CORPORATION)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\Program Files\Sharp\Sharpdesk\SharpTray.exe (SHARP CORPORATION)
PRC - C:\Program Files\SHARP\Sharpdesk\Indexer.exe (SHARP CORPORATION)
PRC - C:\Program Files\SHARP\Button Manager G\btnman.exe (SHARP CORPORATION)
PRC - C:\WINDOWS\system32\cidaemon.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe ()
PRC - c:\program files\common files\mozilla shared\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (AntiVirScheduler [Auto | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH)
SRV - (AntiVirService [Auto | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH)
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Brother XP spl Service [Auto | Running]) – C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (FSMA [Auto | Running]) – C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PDFCreatorMessages [Auto | Running]) – C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe (Global Graphics Software Ltd)
SRV - (sp_rssrv [Auto | Running]) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (tmfnasbx [Auto | Running]) – C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
SRV - (WANMiniportService [Auto | Running]) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (AFS2K [System | Running]) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (avgio [System | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys (Avira GmbH)
DRV - (avgntflt [On_Demand | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys (Avira GmbH)
DRV - (avipbb [System | Running]) – C:\WINDOWS\system32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (BrPar [Auto | Running]) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (bvrp_pci [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (eskddiwc [Boot | Running]) – C:\WINDOWS\system32\drivers\eskddiwc.sys (Andrea Electronics Corporation)
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (MODEMCSA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sp_rsdrv2 [System | Running]) – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (ssmdrv [System | Running]) – C:\WINDOWS\system32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/en-us/srchasst/srchasst.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2008/12/22 09:28:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/08 08:40:39 | 00,000,000 | —D | M]

[2008/04/17 12:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Extensions
[2009/01/28 10:07:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Firefox\Profiles\aa4zo93q.default\extensions
[2008/08/12 11:58:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Firefox\Profiles\aa4zo93q.default\extensions\[removed]
[2008/03/12 12:37:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/12/22 09:28:10 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/26 10:50:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2008/12/22 09:28:05 | 00,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jar50.dll
[2008/12/22 09:28:05 | 00,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jsd3250.dll
[2008/12/22 09:28:06 | 00,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\myspell.dll
[2008/12/22 09:28:06 | 00,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\spellchk.dll
[2008/12/22 09:28:06 | 00,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\xpinstal.dll
[2008/03/13 11:31:25 | 00,001,514 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/03/13 11:31:25 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/03/13 11:31:25 | 00,001,038 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/03/13 11:31:25 | 00,001,046 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/03/13 11:31:25 | 00,002,351 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/13 11:31:26 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (753 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 AdNuker
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {7846CD13-76D6-4C18-89AD-369ED4935B53} - C:\WINDOWS\system32\comdlg32n.dll ()
O2 - BHO: () - {79997E2D-2255-4D36-9AFA-1564A8CEB07A} - c:\windows\system32\cmdial32f.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {459CAF0F-CA9F-4D69-A1A9-B0699D07AB8A} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Indexer] "C:\Program Files\Sharp\Sharpdesk\Indexer.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [IndexTray] "C:\Program Files\Sharp\Sharpdesk\IndexTray.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe (Global Graphics Software Ltd.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SharpTray] "C:\Program Files\Sharp\Sharpdesk\SharpTray.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [TypeRegChecker] "C:\Program Files\Sharp\Sharpdesk\TypeRegChecker.exe" (SHARP CORPORATION)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk = C:\Program Files\SHARP\Button Manager G\btnman.exe (SHARP CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1145365066093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} http://support.ohiobwc.com/webline/applets/msie40x.cab (WebLine Browser Integration Classes)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sds {79E0F14C-9C52-4218-89A7-7C4B0563D121} - C:\Program Files\Sharp\Sharpdesk\ExplorerExtensions.dll (SHARP CORPORATION)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\rsgdatkh: DllName - cmdial32f.dll - C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.001 () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2009/04/20 16:13:32 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe
[2009/04/20 13:35:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Local Settings\Application Data\urdidseb
[2009/04/20 13:35:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\urdidseb
[2009/04/20 13:29:47 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Stacy\Desktop\~$count of Time.doc
[2009/04/20 13:14:29 | 00,001,734 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\HijackThis.lnk
[2009/04/20 13:14:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/20 12:37:10 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/20 12:37:09 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/04/16 16:25:16 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/04/16 09:02:27 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/16 09:02:27 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/16 09:02:27 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/16 09:02:26 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/16 09:02:26 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/16 09:02:26 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/16 09:02:26 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/16 09:02:26 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/16 09:02:25 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/16 09:02:24 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/16 09:00:07 | 01,193,414 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/16 09:00:06 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/15 09:58:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\Sharpdesk
[2009/04/15 09:58:18 | 00,510,758 | —- | C] () – C:\Documents and Settings\Stacy\Application Data\fontlst2.opf
[2009/04/15 09:53:37 | 00,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/04/15 09:53:37 | 00,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2009/04/15 09:51:30 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2009/04/15 09:46:25 | 00,000,000 | —D | C] – C:\Sharpdesk Desktop
[2009/04/15 09:45:49 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Sharp Shared
[2009/04/15 09:45:15 | 00,001,924 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Sharpdesk.lnk
[2009/04/15 09:42:10 | 00,005,450 | —- | C] () – C:\WINDOWS\bmgsetG.inc
[2009/04/15 09:42:10 | 00,000,822 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk
[2009/04/15 09:42:10 | 00,000,000 | —D | C] – C:\Button Manager Image
[2009/04/15 09:41:56 | 00,000,000 | —D | C] – C:\Program Files\SHARP
[2009/04/15 09:41:54 | 00,002,589 | —- | C] () – C:\WINDOWS\se4.isu
[2009/04/15 09:41:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\Sharp
[2009/04/15 09:41:49 | 00,143,360 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CGCP.DLL
[2009/04/15 09:41:49 | 00,135,168 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CLMON.DLL
[2009/04/15 09:41:49 | 00,054,488 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CLPT.SYS
[2009/04/15 09:41:49 | 00,049,152 | —- | C] (SHARP) – C:\WINDOWS\System32\SE4CMTNT.DLL
[2009/04/15 09:41:49 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\SE4CUD.MCF
[2009/04/15 09:41:49 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\SE4CLMON.DAT
[2009/04/15 09:41:49 | 00,000,074 | —- | C] () – C:\WINDOWS\System32\SE4CLMON.MTX
[2009/04/15 09:41:48 | 00,057,344 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CGC.DLL
[2009/04/15 09:41:41 | 00,054,488 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BLPT.SYS
[2009/04/15 09:41:41 | 00,049,152 | —- | C] (SHARP) – C:\WINDOWS\System32\SE4BMTNT.DLL
[2009/04/15 09:41:41 | 00,015,427 | —- | C] () – C:\WINDOWS\System32\SE4BUD.MCF
[2009/04/15 09:41:41 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\SE4BLMON.DAT
[2009/04/15 09:41:41 | 00,000,074 | —- | C] () – C:\WINDOWS\System32\SE4BLMON.MTX
[2009/04/15 09:41:40 | 00,143,360 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BGCP.DLL
[2009/04/15 09:41:40 | 00,135,168 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BLMON.DLL
[2009/04/15 09:41:40 | 00,057,344 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BGC.DLL
[2009/04/15 09:41:33 | 00,159,744 | —- | C] () – C:\WINDOWS\_isusr32.dll
[2009/04/15 09:41:22 | 00,004,737 | —- | C] () – C:\WINDOWS\se4cins.sii
[2009/04/15 09:41:15 | 00,122,880 | —- | C] () – C:\WINDOWS\System32\use4b.dll
[2009/04/15 09:41:15 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\_isusr2k.dll
[2009/04/15 09:41:15 | 00,005,281 | —- | C] () – C:\WINDOWS\se4bins.sii
[2009/04/15 09:41:15 | 00,000,142 | —- | C] () – C:\WINDOWS\System32\Use4bMsg.dat
[2009/04/15 09:41:14 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SCDRV
[2008/12/03 09:18:52 | 00,561,688 | —- | C] () – C:\WINDOWS\System32\wuapi.dll.wusetup.1203093.new
[2008/10/13 09:27:17 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2008/10/13 09:26:53 | 00,009,853 | —- | C] () – C:\WINDOWS\HL-2140.INI
[2008/03/12 08:10:28 | 00,088,064 | —- | C] () – C:\WINDOWS\System32\comdlg32n.dll
[2007/09/10 09:36:17 | 00,000,004 | -H– | C] () – C:\WINDOWS\uccspecb.sys
[2007/06/22 11:00:30 | 00,138,752 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/02 15:10:12 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/10/02 15:10:12 | 00,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2005/04/13 14:16:25 | 00,000,032 | —- | C] () – C:\WINDOWS\brqikmon.ini
[2004/08/05 12:27:40 | 00,000,034 | —- | C] () – C:\WINDOWS\AuthMgr.INI
[2004/04/20 14:32:51 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2004/01/20 13:32:31 | 00,290,816 | —- | C] () – C:\WINDOWS\System32\niknakXML.dll
[2004/01/20 13:32:31 | 00,135,168 | —- | C] () – C:\WINDOWS\System32\expat.dll
[2004/01/20 13:32:31 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\EventConsumer.dll
[2004/01/20 13:32:31 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\PDFMacroUtils.dll
[2003/12/15 14:20:01 | 00,009,216 | —- | C] () – C:\WINDOWS\System32\pdfxcds.dll
[2003/12/08 16:53:08 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2003/12/08 16:36:33 | 00,000,035 | —- | C] () – C:\WINDOWS\A6W.INI
[2003/12/05 15:10:22 | 00,000,278 | —- | C] () – C:\WINDOWS\hpqcopy.INI
[2003/11/19 17:44:30 | 00,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2003/10/31 15:36:37 | 00,000,006 | —- | C] () – C:\WINDOWS\ep213.ini
[2003/10/09 16:05:29 | 00,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2003/09/16 14:03:30 | 00,000,058 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2003/09/16 14:03:30 | 00,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2003/09/16 14:03:30 | 00,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2003/09/16 14:03:26 | 00,000,468 | —- | C] () – C:\WINDOWS\Brownie.ini
[2003/09/16 14:03:26 | 00,000,296 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2003/09/16 14:03:26 | 00,000,167 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2003/09/16 14:03:11 | 00,000,500 | —- | C] () – C:\WINDOWS\brwmark.ini
[2003/09/16 14:03:09 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2003/09/16 14:03:08 | 00,000,038 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2003/09/10 15:45:24 | 00,000,601 | —- | C] () – C:\WINDOWS\bk2001.INI
[2003/08/25 09:31:08 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/08/25 09:31:06 | 00,001,218 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/08/22 11:43:37 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.dll
[2003/08/22 11:40:48 | 00,000,028 | —- | C] () – C:\WINDOWS\qbwcd.ini
[2003/08/22 11:31:02 | 00,001,130 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/08/22 11:30:51 | 00,001,412 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2003/08/22 11:29:32 | 00,000,362 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2003/08/22 11:29:32 | 00,000,028 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2003/08/22 11:29:29 | 00,000,038 | —- | C] () – C:\WINDOWS\ACCWIZ.INI
[2003/08/19 11:24:58 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/19 11:20:23 | 00,000,893 | —- | C] () – C:\WINDOWS\lrun32.ini
[2003/08/19 11:19:04 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/08/19 11:13:22 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/19 10:59:30 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/19 10:59:14 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/08/19 10:47:50 | 00,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/09/03 09:59:58 | 00,001,271 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 09:50:58 | 00,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2002/08/29 06:00:00 | 00,105,472 | —- | C] () – C:\WINDOWS\System32\cmdial32f.dll.bak
[2002/03/13 16:46:46 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\zlib.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/04/20 16:14:11 | 00,002,483 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Microsoft Word.lnk
[2009/04/20 16:13:17 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe
[2009/04/20 16:11:28 | 00,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2009/04/20 13:46:21 | 00,023,552 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\WNG-Designation.doc
[2009/04/20 13:29:47 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Stacy\Desktop\~$count of Time.doc
[2009/04/20 13:22:48 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/04/20 13:21:30 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/20 13:20:48 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/20 13:20:19 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/04/20 13:20:12 | 53,484,3392 | -HS- | M] () – C:\hiberfil.sys
[2009/04/20 13:14:29 | 00,001,734 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\HijackThis.lnk
[2009/04/20 12:37:10 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/04/20 10:03:42 | 00,072,320 | —- | M] () – C:\Documents and Settings\Stacy\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/20 09:15:08 | 00,000,028 | —- | M] () – C:\WINDOWS\qbwcd.ini
[2009/04/20 09:13:01 | 00,001,271 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/04/20 08:32:10 | 00,445,536 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 08:32:10 | 00,384,308 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/04/20 08:32:10 | 00,054,650 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/04/16 16:32:01 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/15 15:51:30 | 00,068,096 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\LETTERHEAD.doc
[2009/04/15 14:32:40 | 00,001,218 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/04/15 10:41:44 | 00,008,628 | -H– | M] () – C:\WINDOWS\System32\SE42TWN.GID
[2009/04/15 09:58:19 | 00,510,758 | —- | M] () – C:\Documents and Settings\Stacy\Application Data\fontlst2.opf
[2009/04/15 09:45:15 | 00,001,924 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Sharpdesk.lnk
[2009/04/15 09:42:10 | 00,000,822 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk
[2009/04/15 09:42:02 | 00,002,589 | —- | M] () – C:\WINDOWS\se4.isu
[2009/04/08 10:08:26 | 00,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2009/04/08 10:07:30 | 00,001,730 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/04/08 09:05:35 | 00,415,766 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\cc_20090408_090508.reg
[2009/04/07 13:10:14 | 00,082,993 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Hardin County Driving.pdf
[2009/04/07 11:59:40 | 00,032,768 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Innocent Owner, releasing vehicle to.doc
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/02 13:55:08 | 00,072,320 | —- | M] () – C:\Documents and Settings\Stacy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/27 03:09:32 | 01,193,414 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/22 12:33:59 | 00,023,040 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\GEM.doc

========== LOP Check ==========

[2009/04/15 09:51:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/07/10 09:37:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/08/09 14:50:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/01/29 10:47:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/01/29 10:59:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avira
[2005/05/26 09:30:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2008/12/04 12:59:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2008/01/16 14:11:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2005/05/25 14:43:34 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/12/08 10:51:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/12/04 13:38:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2004/02/09 11:09:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2005/10/21 12:39:48 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/16 13:21:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2005/07/01 12:58:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2003/11/14 14:13:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2003/08/19 11:14:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/04/15 09:51:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2009/04/08 08:41:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/12/01 12:08:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/12/22 12:20:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2008/12/04 16:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sunbelt
[2008/12/11 11:44:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/03/27 10:43:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sync App Settings
[2003/11/14 14:13:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/07/29 13:32:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/20 13:35:22 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Stacy\Application Data
[2008/06/16 11:16:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Adobe
[2007/07/10 09:17:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\AdobeUM
[2009/01/14 15:29:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Arcsoft
[2006/07/05 08:12:34 | 00,000,000 | R–D | M] – C:\Documents and Settings\Stacy\Application Data\Brother
[2008/02/27 11:49:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\F-Secure
[2008/12/11 11:34:38 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Stacy\Application Data\GTek
[2005/07/22 15:44:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Help
[2003/09/17 11:03:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Hewlett-Packard
[2003/08/19 10:46:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Identities
[2003/11/19 17:22:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Leadertech
[2004/01/05 13:03:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Macromedia
[2008/12/04 13:38:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Malwarebytes
[2005/10/21 12:47:54 | 00,000,000 | –SD | M] – C:\Documents and Settings\Stacy\Application Data\Microsoft
[2008/04/17 12:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Mozilla
[2003/11/10 11:10:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Share-to-Web Upload Folder
[2009/04/15 09:41:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Sharp
[2009/04/15 09:58:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Sharpdesk
[2009/04/08 09:07:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Spyware Terminator
[2008/09/11 09:25:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\StumbleUpon
[2004/01/23 12:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Sun
[2009/04/08 08:42:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\SUPERAntiSpyware.com
[2008/06/11 15:41:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\SystemRequirementsLab
[2009/02/09 12:00:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\U3
[2009/04/20 13:35:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\urdidseb
[2008/02/21 15:41:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Viewpoint
[2005/08/24 12:59:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Yahoo! Messenger
[2002/08/29 06:00:00 | 00,000,065 | —- | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/04/20 13:20:48 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2003/10/17 11:02:11 | 00,000,338 | —- | M] () – C:\WINDOWS\Tasks\WebReg 20031017110211.job

========== Purity Check ==========

< End of report >
I have just modified your post to remove some none essential data in your documents and settings folder

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O2 - BHO: (no name) - {7846CD13-76D6-4C18-89AD-369ED4935B53} - C:\WINDOWS\system32\comdlg32n.dll ()
    O2 - BHO: () - {79997E2D-2255-4D36-9AFA-1564A8CEB07A} - c:\windows\system32\cmdial32f.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {459CAF0F-CA9F-4D69-A1A9-B0699D07AB8A} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O20 - Winlogon\Notify\rsgdatkh: DllName - cmdial32f.dll - C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
    
    :Files
    C:\WINDOWS\System32\comdlg32n.dll
    C:\WINDOWS\System32\cmdial32f.dll.bak
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

THEN

Please download DirLook by jpshortstuff from here.
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the textfield labeled "Directory:":

    C:\Documents and Settings\Stacy\Local Settings\Application Data\urdidseb
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\dl_log.txt)

Note: Scanning may take longer for large folders.
OTListIt logfile created on: 4/21/2009 8:24:18 AM - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Stacy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 265.46 Mb Available Physical Memory | 52.05% Memory free
1.21 Gb Paging File | 1.01 Gb Available in Paging File | 82.89% Paging File free
Paging file location(s): C:\pagefile.sys 765 765;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 63.74 Gb Free Space | 85.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D673T931
Current User Name: Stacy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\System32\brss01a.exe (brother Industries Ltd)
PRC - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe (Global Graphics Software Ltd)
PRC - C:\Program Files\EMBARQ Online Security\Common\FSMB32.EXE (F-Secure Corporation)
PRC - C:\Program Files\EMBARQ Online Security\Common\FCH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\EMBARQ Online Security\Common\FAMEH32.EXE (F-Secure Corporation)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (AntiVirScheduler [Auto | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH)
SRV - (AntiVirService [Auto | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH)
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Brother XP spl Service [Auto | Running]) – C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (FSMA [Auto | Running]) – C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PDFCreatorMessages [Auto | Running]) – C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe (Global Graphics Software Ltd)
SRV - (sp_rssrv [Auto | Running]) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (tmfnasbx [Auto | Running]) – C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
SRV - (WANMiniportService [Auto | Running]) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (AFS2K [System | Running]) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (avgio [System | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys (Avira GmbH)
DRV - (avgntflt [On_Demand | Running]) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys (Avira GmbH)
DRV - (avipbb [System | Running]) – C:\WINDOWS\system32\DRIVERS\avipbb.sys (Avira GmbH)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (BrPar [Auto | Running]) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (bvrp_pci [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (eskddiwc [Boot | Running]) – C:\WINDOWS\system32\drivers\eskddiwc.sys (Andrea Electronics Corporation)
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (MODEMCSA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sp_rsdrv2 [System | Running]) – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (ssmdrv [System | Running]) – C:\WINDOWS\system32\DRIVERS\ssmdrv.sys (Avira GmbH)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/en-us/srchasst/srchasst.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2008/12/22 09:28:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/08 08:40:39 | 00,000,000 | —D | M]

[2008/04/17 12:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Extensions
[2009/01/28 10:07:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Firefox\Profiles\aa4zo93q.default\extensions
[2008/08/12 11:58:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Firefox\Profiles\aa4zo93q.default\extensions\[removed]
[2008/03/12 12:37:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/12/22 09:28:10 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/26 10:50:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2008/12/22 09:28:05 | 00,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jar50.dll
[2008/12/22 09:28:05 | 00,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jsd3250.dll
[2008/12/22 09:28:06 | 00,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\myspell.dll
[2008/12/22 09:28:06 | 00,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\spellchk.dll
[2008/12/22 09:28:06 | 00,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\xpinstal.dll
[2008/03/13 11:31:25 | 00,001,514 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/03/13 11:31:25 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/03/13 11:31:25 | 00,001,038 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/03/13 11:31:25 | 00,001,046 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/03/13 11:31:25 | 00,002,351 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/13 11:31:26 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (753 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 AdNuker
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {7846CD13-76D6-4C18-89AD-369ED4935B53} - C:\WINDOWS\system32\comdlg32n.dll ()
O2 - BHO: () - {79997E2D-2255-4D36-9AFA-1564A8CEB07A} - c:\windows\system32\cmdial32f.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Indexer] "C:\Program Files\Sharp\Sharpdesk\Indexer.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [IndexTray] "C:\Program Files\Sharp\Sharpdesk\IndexTray.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe (Global Graphics Software Ltd.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SharpTray] "C:\Program Files\Sharp\Sharpdesk\SharpTray.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [TypeRegChecker] "C:\Program Files\Sharp\Sharpdesk\TypeRegChecker.exe" (SHARP CORPORATION)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
O4 - HKLM..\RunOnce: [OTListIt] C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe (OldTimer Tools)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk = C:\Program Files\SHARP\Button Manager G\btnman.exe (SHARP CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1145365066093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} http://support.ohiobwc.com/webline/applets/msie40x.cab (WebLine Browser Integration Classes)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sds {79E0F14C-9C52-4218-89A7-7C4B0563D121} - C:\Program Files\Sharp\Sharpdesk\ExplorerExtensions.dll (SHARP CORPORATION)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\rsgdatkh: DllName - cmdial32f.dll - C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.001 () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2009/04/21 08:12:25 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/21 07:54:27 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Local Settings\Application Data\urdidseb
[2009/04/21 07:54:27 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\urdidseb
[2009/04/20 16:13:32 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe
[2009/04/20 13:29:47 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Stacy\Desktop\~$count of Time.doc
[2009/04/20 13:14:29 | 00,001,734 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\HijackThis.lnk
[2009/04/20 13:14:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/20 12:37:10 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/20 12:37:09 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/04/16 16:25:16 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/04/16 09:02:27 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/16 09:02:27 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/16 09:02:27 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/16 09:02:26 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/16 09:02:26 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/16 09:02:26 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/16 09:02:26 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/16 09:02:26 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/16 09:02:25 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/16 09:02:24 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/16 09:00:07 | 01,193,414 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/16 09:00:06 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/15 09:58:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\Sharpdesk
[2009/04/15 09:58:18 | 00,510,758 | —- | C] () – C:\Documents and Settings\Stacy\Application Data\fontlst2.opf
[2009/04/15 09:53:37 | 00,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/04/15 09:53:37 | 00,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2009/04/15 09:51:30 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2009/04/15 09:46:25 | 00,000,000 | —D | C] – C:\Sharpdesk Desktop
[2009/04/15 09:45:49 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Sharp Shared
[2009/04/15 09:45:15 | 00,001,924 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Sharpdesk.lnk
[2009/04/15 09:42:10 | 00,005,450 | —- | C] () – C:\WINDOWS\bmgsetG.inc
[2009/04/15 09:42:10 | 00,000,822 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk
[2009/04/15 09:42:10 | 00,000,000 | —D | C] – C:\Button Manager Image
[2009/04/15 09:41:56 | 00,000,000 | —D | C] – C:\Program Files\SHARP
[2009/04/15 09:41:54 | 00,002,589 | —- | C] () – C:\WINDOWS\se4.isu
[2009/04/15 09:41:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\Sharp
[2009/04/15 09:41:49 | 00,143,360 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CGCP.DLL
[2009/04/15 09:41:49 | 00,135,168 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CLMON.DLL
[2009/04/15 09:41:49 | 00,054,488 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CLPT.SYS
[2009/04/15 09:41:49 | 00,049,152 | —- | C] (SHARP) – C:\WINDOWS\System32\SE4CMTNT.DLL
[2009/04/15 09:41:49 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\SE4CUD.MCF
[2009/04/15 09:41:49 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\SE4CLMON.DAT
[2009/04/15 09:41:49 | 00,000,074 | —- | C] () – C:\WINDOWS\System32\SE4CLMON.MTX
[2009/04/15 09:41:48 | 00,057,344 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CGC.DLL
[2009/04/15 09:41:41 | 00,054,488 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BLPT.SYS
[2009/04/15 09:41:41 | 00,049,152 | —- | C] (SHARP) – C:\WINDOWS\System32\SE4BMTNT.DLL
[2009/04/15 09:41:41 | 00,015,427 | —- | C] () – C:\WINDOWS\System32\SE4BUD.MCF
[2009/04/15 09:41:41 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\SE4BLMON.DAT
[2009/04/15 09:41:41 | 00,000,074 | —- | C] () – C:\WINDOWS\System32\SE4BLMON.MTX
[2009/04/15 09:41:40 | 00,143,360 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BGCP.DLL
[2009/04/15 09:41:40 | 00,135,168 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BLMON.DLL
[2009/04/15 09:41:40 | 00,057,344 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BGC.DLL
[2009/04/15 09:41:33 | 00,159,744 | —- | C] () – C:\WINDOWS\_isusr32.dll
[2009/04/15 09:41:22 | 00,004,737 | —- | C] () – C:\WINDOWS\se4cins.sii
[2009/04/15 09:41:15 | 00,122,880 | —- | C] () – C:\WINDOWS\System32\use4b.dll
[2009/04/15 09:41:15 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\_isusr2k.dll
[2009/04/15 09:41:15 | 00,005,281 | —- | C] () – C:\WINDOWS\se4bins.sii
[2009/04/15 09:41:15 | 00,000,142 | —- | C] () – C:\WINDOWS\System32\Use4bMsg.dat
[2009/04/15 09:41:14 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SCDRV
[2009/04/08 14:34:19 | 00,000,497 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Shortcut to Bankruptcy2009.LNK
[2009/04/08 09:05:13 | 00,415,766 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\cc_20090408_090508.reg
[2009/04/07 13:10:14 | 00,082,993 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Hardin County Driving.pdf
[2009/04/06 15:48:15 | 00,027,648 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\Notice Leave Premises pg 1-2aa.doc
[2009/04/02 09:48:07 | 00,064,879 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Snake.jpg
[2009/04/02 09:47:29 | 00,061,352 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Snake and Dale.jpg
[2009/03/30 14:00:34 | 00,032,256 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\Forcible Entry & Detention12.doc
[2009/03/25 09:00:40 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Stacy\My Documents\~$thdraw as Counsel.doc
[2008/12/03 09:18:52 | 00,561,688 | —- | C] () – C:\WINDOWS\System32\wuapi.dll.wusetup.1203093.new
[2008/10/13 09:27:17 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2008/10/13 09:26:53 | 00,009,853 | —- | C] () – C:\WINDOWS\HL-2140.INI
[2008/03/12 08:10:28 | 00,088,064 | —- | C] () – C:\WINDOWS\System32\comdlg32n.dll
[2007/09/10 09:36:17 | 00,000,004 | -H– | C] () – C:\WINDOWS\uccspecb.sys
[2007/06/22 11:00:30 | 00,138,752 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/02 15:10:12 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/10/02 15:10:12 | 00,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2005/04/13 14:16:25 | 00,000,032 | —- | C] () – C:\WINDOWS\brqikmon.ini
[2004/08/05 12:27:40 | 00,000,034 | —- | C] () – C:\WINDOWS\AuthMgr.INI
[2004/04/20 14:32:51 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2004/01/20 13:32:31 | 00,290,816 | —- | C] () – C:\WINDOWS\System32\niknakXML.dll
[2004/01/20 13:32:31 | 00,135,168 | —- | C] () – C:\WINDOWS\System32\expat.dll
[2004/01/20 13:32:31 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\EventConsumer.dll
[2004/01/20 13:32:31 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\PDFMacroUtils.dll
[2003/12/15 14:20:01 | 00,009,216 | —- | C] () – C:\WINDOWS\System32\pdfxcds.dll
[2003/12/08 16:53:08 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2003/12/08 16:36:33 | 00,000,035 | —- | C] () – C:\WINDOWS\A6W.INI
[2003/12/05 15:10:22 | 00,000,278 | —- | C] () – C:\WINDOWS\hpqcopy.INI
[2003/11/19 17:44:30 | 00,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2003/10/31 15:36:37 | 00,000,006 | —- | C] () – C:\WINDOWS\ep213.ini
[2003/10/09 16:05:29 | 00,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2003/09/16 14:03:30 | 00,000,058 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2003/09/16 14:03:30 | 00,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2003/09/16 14:03:30 | 00,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2003/09/16 14:03:26 | 00,000,468 | —- | C] () – C:\WINDOWS\Brownie.ini
[2003/09/16 14:03:26 | 00,000,296 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2003/09/16 14:03:26 | 00,000,167 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2003/09/16 14:03:11 | 00,000,500 | —- | C] () – C:\WINDOWS\brwmark.ini
[2003/09/16 14:03:09 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2003/09/16 14:03:08 | 00,000,038 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2003/09/10 15:45:24 | 00,000,601 | —- | C] () – C:\WINDOWS\bk2001.INI
[2003/08/25 09:31:08 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/08/25 09:31:06 | 00,001,218 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/08/22 11:43:37 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.dll
[2003/08/22 11:40:48 | 00,000,028 | —- | C] () – C:\WINDOWS\qbwcd.ini
[2003/08/22 11:31:02 | 00,001,130 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/08/22 11:30:51 | 00,001,412 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2003/08/22 11:29:32 | 00,000,362 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2003/08/22 11:29:32 | 00,000,028 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2003/08/22 11:29:29 | 00,000,038 | —- | C] () – C:\WINDOWS\ACCWIZ.INI
[2003/08/19 11:24:58 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/19 11:20:23 | 00,000,893 | —- | C] () – C:\WINDOWS\lrun32.ini
[2003/08/19 11:19:04 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/08/19 11:13:22 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/19 10:59:30 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/19 10:59:14 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/08/19 10:47:50 | 00,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/09/03 09:59:58 | 00,001,271 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 09:50:58 | 00,000,227 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2002/08/29 06:00:00 | 00,105,472 | —- | C] () – C:\WINDOWS\System32\cmdial32f.dll.bak
[2002/03/13 16:46:46 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\zlib.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/04/21 08:25:55 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/04/21 08:23:57 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/21 08:23:37 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/04/21 08:23:35 | 53,484,3392 | -HS- | M] () – C:\hiberfil.sys
[2009/04/21 08:10:58 | 00,002,483 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Microsoft Word.lnk
[2009/04/21 07:51:24 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/20 16:13:17 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe
[2009/04/20 16:11:28 | 00,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2009/04/20 13:46:21 | 00,023,552 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\WNG-Designation.doc
[2009/04/20 13:29:47 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Stacy\Desktop\~$count of Time.doc
[2009/04/20 13:14:29 | 00,001,734 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\HijackThis.lnk
[2009/04/20 12:37:10 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/04/20 11:54:48 | 00,034,816 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\COURT LETTER.doc
[2009/04/20 10:13:49 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\AA MIKE LABELS.doc
[2009/04/20 10:03:42 | 00,072,320 | —- | M] () – C:\Documents and Settings\Stacy\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/20 09:15:08 | 00,000,028 | —- | M] () – C:\WINDOWS\qbwcd.ini
[2009/04/20 09:13:01 | 00,001,271 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/04/20 08:32:10 | 00,445,536 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 08:32:10 | 00,384,308 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/04/20 08:32:10 | 00,054,650 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/04/16 16:32:01 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/16 13:17:56 | 00,033,280 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Interrog-Notice of Service.doc
[2009/04/15 15:51:30 | 00,068,096 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\LETTERHEAD.doc
[2009/04/15 14:32:40 | 00,001,218 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/04/15 10:41:44 | 00,008,628 | -H– | M] () – C:\WINDOWS\System32\SE42TWN.GID
[2009/04/15 09:58:19 | 00,510,758 | —- | M] () – C:\Documents and Settings\Stacy\Application Data\fontlst2.opf
[2009/04/15 09:45:15 | 00,001,924 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Sharpdesk.lnk
[2009/04/15 09:42:10 | 00,000,822 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk
[2009/04/15 09:42:02 | 00,002,589 | —- | M] () – C:\WINDOWS\se4.isu
[2009/04/14 15:48:46 | 00,032,768 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Continuance-CPC Dom..doc
[2009/04/14 14:27:47 | 00,034,304 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Form Letter.doc
[2009/04/14 13:44:46 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Notice Leave Premises pg 1-2aa.doc
[2009/04/13 09:59:21 | 00,251,215 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Real Estate Tax Transfer.fdc
[2009/04/09 11:41:44 | 00,028,672 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Dismiss lack of probable cause2.doc
[2009/04/09 11:15:29 | 00,033,280 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Judicial Release-2.doc
[2009/04/09 10:32:07 | 00,036,352 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\JC1.doc
[2009/04/08 14:34:19 | 00,000,497 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Shortcut to Bankruptcy2009.LNK
[2009/04/08 13:56:39 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation-Juvenile.doc
[2009/04/08 12:34:22 | 00,000,191 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\DPE.DUS
[2009/04/08 10:08:26 | 00,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2009/04/08 10:07:30 | 00,001,730 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/04/08 09:05:35 | 00,415,766 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\cc_20090408_090508.reg
[2009/04/07 13:10:14 | 00,082,993 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Hardin County Driving.pdf
[2009/04/07 11:59:40 | 00,032,768 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Innocent Owner, releasing vehicle to.doc
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 14:39:17 | 00,030,208 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation of Counsel.doc
[2009/04/06 14:32:25 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Request for Pretrial.doc
[2009/04/06 12:01:52 | 00,211,968 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Warranty Deed.doc
[2009/04/06 11:27:07 | 00,011,173 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Caretaker Affidavit page 2.fdc
[2009/04/06 11:27:05 | 00,022,714 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Caretaker Affidavit page 1.fdc
[2009/04/06 11:26:43 | 00,067,072 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Power of Attorney-Grandparents NEW House Bill2.doc
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/02 13:55:08 | 00,072,320 | —- | M] () – C:\Documents and Settings\Stacy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/02 09:48:09 | 00,064,879 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Snake.jpg
[2009/04/02 09:47:29 | 00,061,352 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Snake and Dale.jpg
[2009/04/01 14:41:21 | 00,029,696 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Notice to Clerk.doc
[2009/03/31 11:18:04 | 00,028,672 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Subpoena-Juvenile-page 1.doc
[2009/03/30 14:38:06 | 00,032,256 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Forcible Entry & Detention12.doc
[2009/03/30 14:38:02 | 00,029,696 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Notice to Clerk-stumbaugh.doc
[2009/03/30 13:28:03 | 00,029,184 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation of Counsel-aug. co..doc
[2009/03/30 13:19:02 | 00,024,064 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation-CPC Dom.doc
[2009/03/29 13:48:01 | 00,023,040 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\First Federal Invoice.doc
[2009/03/27 03:09:32 | 01,193,414 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/26 14:00:47 | 00,029,184 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Default-Motion-Brower Commons.doc
[2009/03/26 13:20:44 | 00,020,992 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Default Judgment-brower.doc
[2009/03/26 12:51:37 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Subpoena-Juvenile-page 2.doc
[2009/03/25 09:00:40 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Stacy\My Documents\~$thdraw as Counsel.doc
[2009/03/24 16:03:11 | 00,033,280 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Withdraw as Counsel.doc
[2009/03/22 12:33:59 | 00,023,040 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\GEM.doc
< End of report >
DirLook.exe v2.0 by jpshortstuff
Log created at 08:34 on 21/04/2009
==================================
Contents of "C:\Documents and Settings\Stacy\Local Settings\Application Data\urdidseb"

—FOLDERS—

Profiles (Created on 21/04/2009 at 11:54) d—–

—FILES—

(none found)

==================================
=EOF=
Thought I should also let you know that now when I start up my pc it goes through a series of error messages that I have to click "ok" to bypass…then the OTListit2 program opens but nothing else….in order to close the OTListit2 program I have to click "fix it"….and it then will let me shut down OTListit2 and go to my normal desktop. Then Avira antivirus finds the same old virus again and my tower beeps. I feel like the pc is even more messed up. This is a work PC so I cannot be losing the information on it. Any help will be sincerely appreciated.
I will need a stronger hammer to kill this one as OTListit was not strong enough

We will now do a deep search of your processes and files

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Investigation" check box.
  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.

When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Investigation" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach both zip files to your next post

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
My pc still starts up the same way…with the error messages and the OTListit still coming up. By the way thanks for taking the time to try and help me. I appreciate it.
It seems as though the run once key is stuck and not self deleting like it should I will fix that this time

AVZ FIX

  • Double click on AVZ.exe
  • Click File > Custom scripts
  • Copy & paste the contents of the following codebox in the box in the program (start with begin and end with end )
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     DelBHO('{79997E2D-2255-4D36-9AFA-1564A8CEB07A}');
     DelBHO('{7846CD13-76D6-4C18-89AD-369ED4935B53}');
     DelBHO('{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}');
     DeleteService('eskddiwc');
     StopService('eskddiwc');
     SetServiceStart('eskddiwc', 4);
     DeleteFile('C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe');
     BC_DeleteFile('C:\WINDOWS\winstart.bat');
     DeleteFile('C:\WINDOWS\winstart.bat');
     BC_DeleteFile('C:\WINDOWS\system32\comdlg32n.dll');
     DeleteFile('C:\WINDOWS\system32\comdlg32n.dll');
     BC_DeleteFile('c:\windows\system32\cmdial32f.dll');
     DeleteFile('c:\windows\system32\cmdial32f.dll');
    BC_ImportDeletedList;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.
  • Note: When you run the script, your PC will be restarted
  • Click Run
  • Restart your PC if it doesn't do it automatically.

ON COMPLETION

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Investigation" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach the zip file to your next post


THEN

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a OTListit log so we can continue cleaning the system.
ComboFix 09-04-23.A1 - Stacy 04/23/2009 8:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.121 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-4-23 )))))))))))))))))))))))))))))))
.

2009-04-23 11:59 . 2009-04-23 11:59 ——– d—–w c:\documents and settings\Stacy\Application Data\urdidseb
2009-04-23 11:59 . 2009-04-23 11:59 ——– d—–w c:\documents and settings\Stacy\Local Settings\Application Data\urdidseb
2009-04-22 16:09 . 2004-12-07 10:11 258352 —-a-w c:\windows\system32\unicows.dll
2009-04-21 20:14 . 2004-09-02 20:39 28236 —-a-w c:\windows\system32\drivers\SGuard.sys
2009-04-21 20:14 . 2004-05-29 10:15 9728 —-a-w c:\windows\system32\drivers\filedisk.sys
2009-04-21 20:14 . 2004-09-20 15:17 567808 —-a-w c:\windows\system32\Incinerator.dll
2009-04-21 20:14 . 2004-09-16 21:07 31454 —-a-w c:\windows\system32\iolobtdfg.exe
2009-04-21 20:14 . 2004-08-28 19:18 25264 —-a-w c:\windows\system32\smrgdf.exe
2009-04-21 20:07 . 2009-04-22 16:28 ——– d—–w c:\windows\CAVTemp
2009-04-21 19:43 . 2009-04-21 19:42 880560 —-a-w c:\windows\system32\drivers\vetefile.sys
2009-04-21 19:43 . 2009-04-21 19:42 108368 —-a-w c:\windows\system32\drivers\veteboot.sys
2009-04-21 19:36 . 2007-08-20 17:38 32264 —-a-w c:\windows\system32\drivers\vetmonnt.sys
2009-04-21 19:36 . 2007-08-20 17:38 21512 —-a-w c:\windows\system32\drivers\vetfddnt.sys
2009-04-21 19:36 . 2007-08-20 17:38 26376 —-a-w c:\windows\system32\drivers\vet-filt.sys
2009-04-21 19:36 . 2007-08-20 17:38 21128 —-a-w c:\windows\system32\drivers\vet-rec.sys
2009-04-21 19:36 . 2007-08-20 17:37 75016 —-a-w c:\windows\system32\isafprod.dll
2009-04-21 19:36 . 2007-08-20 17:37 99592 —-a-w c:\windows\system32\isafeif.dll
2009-04-21 19:36 . 2007-08-20 17:26 79424 —-a-w c:\windows\system32\vetredir.dll
2009-04-21 19:35 . 2009-04-21 19:47 ——– d—–w c:\documents and settings\All Users\Application Data\CA
2009-04-21 12:12 . 2009-04-21 12:12 ——– d—–w C:\_OTListIt
2009-04-20 16:37 . 2009-04-21 19:36 1409 —-a-w c:\windows\QTFont.for
2009-04-20 16:37 . 2009-04-23 12:16 54156 —ha-w c:\windows\QTFont.qfn
2009-04-16 20:25 . 2009-04-16 20:32 1374 —-a-w c:\windows\imsins.BAK
2009-04-16 13:02 . 2009-03-06 14:44 283648 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-16 13:02 . 2009-02-06 16:54 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-04-16 13:02 . 2005-07-26 04:39 60416 ——w c:\windows\system32\dllcache\colbact.dll
2009-04-16 13:02 . 2009-02-09 10:20 399360 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 13:02 . 2009-02-09 10:20 473088 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 13:02 . 2009-02-09 10:20 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 13:02 . 2009-02-06 17:14 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-16 13:02 . 2009-02-06 16:39 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 13:02 . 2009-02-09 10:20 616960 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 13:02 . 2009-02-09 10:20 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 13:00 . 2009-03-27 07:09 1193414 ——w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 13:00 . 2008-04-21 10:02 215552 ——w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 13:58 . 2009-04-15 13:58 ——– d—–w c:\documents and settings\Stacy\Application Data\Sharpdesk
2009-04-15 13:53 . 2004-08-04 06:08 31616 —-a-w c:\windows\system32\drivers\usbccgp.sys
2009-04-15 13:53 . 2004-08-04 06:08 31616 —-a-w c:\windows\system32\dllcache\usbccgp.sys
2009-04-15 13:51 . 2009-04-15 13:51 ——– d—–w c:\documents and settings\All Users\Application Data\Sharpdesk
2009-04-15 13:46 . 2009-04-22 15:09 ——– d—–w C:\Sharpdesk Desktop
2009-04-15 13:42 . 2009-04-15 13:42 ——– d—–w C:\Button Manager Image
2009-04-15 13:42 . 2004-09-24 07:44 5450 —-a-w c:\windows\bmgsetG.inc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 16:25 . 2003-09-10 19:45 ——– d—–w c:\program files\New Hope
2009-04-22 16:09 . 2009-04-22 16:09 ——– d—–w c:\program files\Tracker Software
2009-04-21 20:58 . 2009-04-21 20:27 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-21 20:58 . 2008-12-11 16:42 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-21 20:14 . 2009-04-21 20:14 ——– d—–w c:\program files\iolo
2009-04-21 19:46 . 2009-04-21 19:34 16664 —-a-w C:\caisslog.txt
2009-04-21 19:36 . 2009-04-21 19:36 34639 —-a-w C:\caavsetupLog.txt
2009-04-21 19:35 . 2009-04-21 19:35 ——– d—–w c:\program files\Common Files\Scanner
2009-04-21 19:35 . 2009-04-21 19:35 ——– d—–w c:\program files\CA
2009-04-21 14:28 . 2003-10-31 20:05 13030 —-a-w C:\PDOXUSRS.NET
2009-04-21 12:34 . 2009-04-21 12:34 864 —-a-w C:\DirLook.txt
2009-04-20 17:14 . 2009-04-20 17:14 ——– d—–w c:\program files\Trend Micro
2009-04-20 14:03 . 2003-10-20 20:44 72320 —-a-w c:\documents and settings\Stacy\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 13:47 . 2009-04-15 13:45 ——– d—–w c:\program files\Common Files\Sharp Shared
2009-04-15 13:43 . 2009-04-15 13:41 ——– d—–w c:\program files\SHARP
2009-04-15 13:41 . 2009-04-15 13:41 ——– d—–w c:\documents and settings\Stacy\Application Data\Sharp
2009-04-13 13:51 . 2004-01-22 14:52 ——– d—–w c:\program files\Form Pilot Home
2009-04-08 12:42 . 2008-12-08 14:49 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-08 12:42 . 2008-12-11 15:44 ——– d—–w c:\documents and settings\Stacy\Application Data\SUPERAntiSpyware.com
2009-04-08 12:40 . 2003-08-19 15:15 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-02 17:55 . 2003-08-22 14:40 72320 —-a-w c:\documents and settings\Stacy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-24 19:14 . 2003-08-25 13:30 ——– d—–w c:\program files\QUICKENW
2009-03-21 14:18 . 2006-07-05 10:55 986112 ——w c:\windows\SYSTEM32\DLLCACHE\kernel32.dll
2009-03-06 14:44 . 2002-08-29 10:00 283648 ——w c:\windows\SYSTEM32\pdh.dll
2009-03-02 23:27 . 2006-05-29 15:30 1499136 ——w c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
2009-02-20 21:44 . 2006-05-19 15:08 3067904 ——w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2009-02-19 09:50 . 2006-05-09 11:00 18432 ——w c:\windows\SYSTEM32\DLLCACHE\iedw.exe
2009-02-09 10:20 . 2006-08-17 12:28 723456 ——w c:\windows\SYSTEM32\DLLCACHE\lsasrv.dll
2009-02-09 10:20 . 2004-04-14 14:57 399360 —-a-w c:\windows\SYSTEM32\rpcss.dll
2009-02-09 10:20 . 2002-08-29 10:00 723456 ——w c:\windows\SYSTEM32\lsasrv.dll
2009-02-09 10:20 . 2002-08-29 10:00 714752 ——w c:\windows\SYSTEM32\ntdll.dll
2009-02-09 10:20 . 2002-08-29 10:00 616960 ——w c:\windows\SYSTEM32\advapi32.dll
2009-02-09 10:19 . 2007-03-08 13:47 1846272 ——w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2009-02-09 10:19 . 2002-08-29 10:00 1846272 ——w c:\windows\SYSTEM32\win32k.sys
2009-02-06 17:24 . 2006-12-19 14:17 2180480 ——w c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2009-02-06 17:24 . 1980-01-01 05:00 2180480 ——w c:\windows\SYSTEM32\ntoskrnl.exe
2009-02-06 17:22 . 2006-12-19 14:15 2136064 ——w c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2009-02-06 17:14 . 2002-08-29 10:00 110592 ——w c:\windows\SYSTEM32\services.exe
2009-02-06 16:54 . 2002-08-29 10:00 35328 ——w c:\windows\SYSTEM32\sc.exe
2009-02-06 16:49 . 2006-12-19 12:55 2015744 ——w c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2009-02-06 16:49 . 2006-12-19 12:55 2057728 ——w c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2009-02-06 16:49 . 1980-01-01 05:00 2057728 ——w c:\windows\SYSTEM32\ntkrnlpa.exe
2009-02-03 20:08 . 2009-02-03 20:08 55808 ——w c:\windows\SYSTEM32\DLLCACHE\secur32.dll
2009-02-03 20:08 . 2002-08-29 10:00 55808 —-a-w c:\windows\SYSTEM32\secur32.dll
2008-01-23 16:50 . 2008-01-23 16:50 128 —-a-w c:\documents and settings\Stacy\Local Settings\Application Data\fusioncache.dat
2007-04-09 13:17 . 2007-04-09 13:17 8 —-a-w c:\documents and settings\Stacy\Application Data\usb.dat.bin
2005-07-25 15:02 . 2004-04-08 14:54 0 —ha-w c:\documents and settings\Stacy\hpothb07.dat
2005-07-20 13:29 . 2004-04-08 14:54 164 —ha-w c:\documents and settings\All Users\hpothb07.dat
2003-08-19 15:17 . 2008-12-08 14:08 12328 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-12-22 13:2007-08-08 19:18 28:05 . c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 13:2007-08-08 19:18 28:05 . c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 13:2007-08-08 19:18 28:06 . c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 13:2007-08-08 19:18 28:06 . c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 13:2007-08-08 19:18 28:06 . c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7846CD13-76D6-4C18-89AD-369ED4935B53}]
2004-08-04 07:56 88064 —-a-w c:\windows\system32\comdlg32n.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79997E2D-2255-4D36-9AFA-1564A8CEB07A}]
2002-08-29 10:00 105472 —-a-w c:\windows\system32\cmdial32f.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2003-11-14 77824]
"PDFCreatorClient"="c:\program files\JawsSystems\Jaws PDF Creator\PDFClient.exe" [2003-12-09 315392]
"IndexTray"="c:\program files\Sharp\Sharpdesk\IndexTray.exe" [2005-11-16 106496]
"Indexer"="c:\program files\Sharp\Sharpdesk\Indexer.exe" [2005-11-16 184320]
"SharpTray"="c:\program files\Sharp\Sharpdesk\SharpTray.exe" [2005-11-16 32768]
"TypeRegChecker"="c:\program files\Sharp\Sharpdesk\TypeRegChecker.exe" [2005-11-16 57344]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-04-21 177392]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2009-04-21 14088]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-08-20 230664]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2008-03-25 218496]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Button Manager G.lnk - c:\program files\SHARP\Button Manager G\btnman.exe [2009-4-15 176128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rsgdatkh]
2002-08-29 10:00 105472 —-a-w c:\windows\SYSTEM32\cmdial32f.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=c:\windows\pss\AOL Companion.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=c:\windows\pss\Billminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Dataviz Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Dataviz Messenger.lnk
backup=c:\windows\pss\Dataviz Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PDF-Capture.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PDF-Capture.lnk
backup=c:\windows\pss\PDF-Capture.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=c:\windows\pss\Quicken Startup.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\Ad-Aware.exe"=
"c:\\Program Files\\Puritas\\WROCSG6\\wrocsg6.exe"=
"c:\\Program Files\\WROCSG4\\wrocsg4.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Album\\hpqaprnt.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3711:TCP"= 3711:TCP:@xpsp2res.dll,-22009

R3 F-Secure Gatekeeper;F-Secure Gatekeeper; [x]
R3 SBRE;SBRE; [x]
R4 F-Secure Filter;F-Secure File System Filter; [x]
R4 F-Secure Recognizer;F-Secure File System Recognizer; [x]
S0 eskddiwc;eskddiwc;c:\windows\system32\drivers\eskddiwc.sys [2002-08-29 23424]
S2 tmfnasbx;Intel PentiumIII Processor Monitor;c:\windows\System32\svchost.exe [2004-08-04 14336]
S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2007-08-17 189704]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
tmfnasbx
.
Contents of the 'Scheduled Tasks' folder

2009-04-21 c:\windows\Tasks\CAAntiSpywareScan_Daily as Stacy at 3 35 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 01:10]

2003-10-17 c:\windows\Tasks\WebReg 20031017110211.job
- c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe [2002-10-16 19:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dellnet.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\windows\system32\VetRedir.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Stacy\Application Data\Mozilla\Firefox\Profiles\aa4zo93q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-23 08:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1184)
c:\windows\system32\cmdial32f.dll
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

- - - - - - - > 'lsass.exe'(1372)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll

- - - - - - - > 'explorer.exe'(220)
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\windows\system32\cmdial32f.dll
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Completion time: 2009-04-23 8:51
ComboFix-quarantined-files.txt 2009-04-23 12:50

Pre-Run: 68,356,964,352 bytes free
Post-Run: 68,412,960,768 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

248 — E O F — 2009-04-16 20:32
OTListIt logfile created on: 4/23/2009 9:01:51 AM - Run 4
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Stacy\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 128.41 Mb Available Physical Memory | 25.18% Memory free
1.21 Gb Paging File | 0.88 Gb Available in Paging File | 72.03% Paging File free
Paging file location(s): C:\pagefile.sys 765 765;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.47 Gb Total Space | 63.75 Gb Free Space | 85.61% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D673T931
Current User Name: Stacy
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\WINDOWS\System32\brss01a.exe (brother Industries Ltd)
PRC - C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\EMBARQ Online Security\Common\FSMB32.EXE (F-Secure Corporation)
PRC - C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe (Global Graphics Software Ltd)
PRC - C:\Program Files\EMBARQ Online Security\Common\FCH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\EMBARQ Online Security\Common\FAMEH32.EXE (F-Secure Corporation)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
PRC - C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Sharp\Sharpdesk\IndexTray.exe (SHARP CORPORATION)
PRC - C:\Program Files\Sharp\Sharpdesk\Indexer.exe (SHARP CORPORATION)
PRC - C:\Program Files\Sharp\Sharpdesk\SharpTray.exe (SHARP CORPORATION)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
PRC - C:\Program Files\SHARP\Button Manager G\btnman.exe (SHARP CORPORATION)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\WINDOWS\system32\cidaemon.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\acsd.exe (America Online, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Brother XP spl Service [Auto | Stopped]) – C:\WINDOWS\System32\brsvc01a.exe (brother Industries Ltd)
SRV - (CaCCProvSP [On_Demand | Running]) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe [Auto | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (FSMA [Auto | Running]) – C:\Program Files\EMBARQ Online Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (ITMRTSVC [Auto | Running]) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (PDFCreatorMessages [Auto | Running]) – C:\WINDOWS\SYSTEM32\PDFCreatorMessages.exe (Global Graphics Software Ltd)
SRV - (PPCtlPriv [On_Demand | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (tmfnasbx [Auto | Running]) – C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
SRV - (VETMSGNT [Auto | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
SRV - (WANMiniportService [Auto | Running]) – C:\WINDOWS\wanmpsvc.exe (America Online, Inc.)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (AFS2K [System | Running]) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (BrPar [Auto | Running]) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)
DRV - (bvrp_pci [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\el90xbc5.sys (3Com Corporation)
DRV - (eskddiwc [Boot | Running]) – C:\WINDOWS\system32\drivers\eskddiwc.sys (Andrea Electronics Corporation)
DRV - (FileDisk [System | Running]) – C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wADV05NT.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (MODEMCSA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (VET-FILT [System | Running]) – C:\WINDOWS\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VET-REC [System | Running]) – C:\WINDOWS\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT [On_Demand | Running]) – C:\WINDOWS\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETEFILE [System | Running]) – C:\WINDOWS\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT [System | Running]) – C:\WINDOWS\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VETMONNT [System | Running]) – C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"

FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2008/12/22 09:28:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/08 08:40:39 | 00,000,000 | —D | M]

[2008/04/17 12:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Extensions
[2009/01/28 10:07:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Firefox\Profiles\aa4zo93q.default\extensions
[2008/08/12 11:58:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\mozilla\Firefox\Profiles\aa4zo93q.default\extensions\[removed]
[2008/03/12 12:37:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/12/22 09:28:10 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/26 10:50:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\[removed]
[2008/12/22 09:28:05 | 00,067,688 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jar50.dll
[2008/12/22 09:28:05 | 00,054,368 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\jsd3250.dll
[2008/12/22 09:28:06 | 00,034,944 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\myspell.dll
[2008/12/22 09:28:06 | 00,046,712 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\spellchk.dll
[2008/12/22 09:28:06 | 00,172,136 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\xpinstal.dll
[2008/03/13 11:31:25 | 00,001,514 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/03/13 11:31:25 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/03/13 11:31:25 | 00,001,038 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/03/13 11:31:25 | 00,001,046 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/03/13 11:31:25 | 00,002,351 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/13 11:31:26 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (753 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 AdNuker
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {7846CD13-76D6-4C18-89AD-369ED4935B53} - C:\WINDOWS\system32\comdlg32n.dll ()
O2 - BHO: () - {79997E2D-2255-4D36-9AFA-1564A8CEB07A} - c:\windows\system32\cmdial32f.dll (Microsoft Corporation)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" (CA, Inc.)
O4 - HKLM..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" (CA, Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Indexer] "C:\Program Files\Sharp\Sharpdesk\Indexer.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [IndexTray] "C:\Program Files\Sharp\Sharpdesk\IndexTray.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe (Global Graphics Software Ltd.)
O4 - HKLM..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" (CA)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SharpTray] "C:\Program Files\Sharp\Sharpdesk\SharpTray.exe" (SHARP CORPORATION)
O4 - HKLM..\Run: [TypeRegChecker] "C:\Program Files\Sharp\Sharpdesk\TypeRegChecker.exe" (SHARP CORPORATION)
O4 - HKCU..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe (Adobe Systems Incorporated)
O4 - HKLM..\RunOnce: [OTListIt] C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe (OldTimer Tools)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk = C:\Program Files\SHARP\Button Manager G\btnman.exe (SHARP CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…72/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1145365066093 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} http://support.ohiobwc.com/webline/applets/msie40x.cab (WebLine Browser Integration Classes)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sds {79E0F14C-9C52-4218-89A7-7C4B0563D121} - C:\Program Files\Sharp\Sharpdesk\ExplorerExtensions.dll (SHARP CORPORATION)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\rsgdatkh: DllName - cmdial32f.dll - C:\WINDOWS\system32\cmdial32f.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.001 () - [ NTFS ]
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/04/23 09:00:35 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe
[2009/04/23 08:58:51 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2009/04/23 08:51:12 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/04/23 08:38:42 | 00,000,211 | —- | C] () – C:\Boot.bak
[2009/04/23 08:38:37 | 00,260,272 | —- | C] () – C:\cmldr
[2009/04/23 08:38:34 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/04/23 08:35:58 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/04/23 08:35:58 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/04/23 08:35:58 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/04/23 08:35:58 | 00,109,568 | —- | C] () – C:\WINDOWS\vFind.exe
[2009/04/23 08:35:58 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/04/23 08:35:58 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/04/23 08:35:58 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/04/23 08:35:58 | 00,029,696 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/04/23 08:35:44 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/23 08:35:38 | 00,000,000 | —D | C] – C:\Qoobox
[2009/04/23 08:33:53 | 02,999,160 | R— | C] () – C:\Documents and Settings\Stacy\Desktop\Combo.exe
[2009/04/23 07:59:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\urdidseb
[2009/04/23 07:59:06 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Local Settings\Application Data\urdidseb
[2009/04/22 12:09:15 | 00,258,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\unicows.dll
[2009/04/22 12:09:11 | 00,000,000 | —D | C] – C:\Program Files\Tracker Software
[2009/04/22 11:50:28 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Desktop\avz4
[2009/04/22 09:25:24 | 08,433,664 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\B2K733.exe
[2009/04/21 16:28:26 | 00,000,933 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Spybot - Search & Destroy.lnk
[2009/04/21 16:27:55 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/04/21 16:14:31 | 00,000,807 | —- | C] () – C:\Documents and Settings\All Users\Desktop\System Mechanic 5 Professional.lnk
[2009/04/21 16:14:19 | 00,028,236 | —- | C] (iolo technologies, LLC) – C:\WINDOWS\System32\drivers\SGuard.sys
[2009/04/21 16:14:19 | 00,009,728 | —- | C] (iolo technologies, LLC (based on original work by Bo Brantén)) – C:\WINDOWS\System32\drivers\filedisk.sys
[2009/04/21 16:14:15 | 00,567,808 | —- | C] (iolo technologies, LLC) – C:\WINDOWS\System32\Incinerator.dll
[2009/04/21 16:14:14 | 00,031,454 | —- | C] () – C:\WINDOWS\System32\iolobtdfg.exe
[2009/04/21 16:14:14 | 00,025,264 | —- | C] () – C:\WINDOWS\System32\smrgdf.exe
[2009/04/21 16:14:14 | 00,000,000 | —D | C] – C:\Program Files\iolo
[2009/04/21 16:07:36 | 00,000,000 | —D | C] – C:\WINDOWS\CAVTemp
[2009/04/21 15:43:10 | 00,880,560 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2009/04/21 15:43:10 | 00,108,368 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2009/04/21 15:36:04 | 00,099,592 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\isafeif.dll
[2009/04/21 15:36:04 | 00,079,424 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\vetredir.dll
[2009/04/21 15:36:04 | 00,075,016 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\isafprod.dll
[2009/04/21 15:36:04 | 00,032,264 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2009/04/21 15:36:04 | 00,026,376 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2009/04/21 15:36:04 | 00,021,512 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2009/04/21 15:36:04 | 00,021,128 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2009/04/21 15:35:43 | 00,000,514 | —- | C] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Stacy at 3 35 PM.job
[2009/04/21 15:35:35 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Scanner
[2009/04/21 15:35:11 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2009/04/21 15:35:09 | 00,000,000 | —D | C] – C:\Program Files\CA
[2009/04/21 14:15:07 | 04,626,422 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\avz4.zip
[2009/04/21 11:59:58 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Stacy\My Documents\~$smiss lack of probable cause2.doc
[2009/04/21 11:11:57 | 00,036,352 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\FAX101.doc
[2009/04/21 08:33:45 | 00,199,680 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\DirLook.exe
[2009/04/21 08:12:25 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/20 13:14:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/20 12:37:10 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/20 12:37:09 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/04/16 16:25:16 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/04/16 09:02:27 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/16 09:02:27 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/16 09:02:27 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/16 09:02:26 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/16 09:02:26 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/16 09:02:26 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/16 09:02:26 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/16 09:02:26 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/16 09:02:25 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/16 09:02:24 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/16 09:00:07 | 01,193,414 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/16 09:00:06 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/15 09:58:23 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\Sharpdesk
[2009/04/15 09:58:18 | 00,510,758 | —- | C] () – C:\Documents and Settings\Stacy\Application Data\fontlst2.opf
[2009/04/15 09:53:37 | 00,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/04/15 09:53:37 | 00,031,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2009/04/15 09:51:30 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2009/04/15 09:46:25 | 00,000,000 | —D | C] – C:\Sharpdesk Desktop
[2009/04/15 09:45:49 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Sharp Shared
[2009/04/15 09:45:15 | 00,001,924 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Sharpdesk.lnk
[2009/04/15 09:42:10 | 00,005,450 | —- | C] () – C:\WINDOWS\bmgsetG.inc
[2009/04/15 09:42:10 | 00,000,822 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk
[2009/04/15 09:42:10 | 00,000,000 | —D | C] – C:\Button Manager Image
[2009/04/15 09:41:56 | 00,000,000 | —D | C] – C:\Program Files\SHARP
[2009/04/15 09:41:54 | 00,002,589 | —- | C] () – C:\WINDOWS\se4.isu
[2009/04/15 09:41:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Stacy\Application Data\Sharp
[2009/04/15 09:41:49 | 00,143,360 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CGCP.DLL
[2009/04/15 09:41:49 | 00,135,168 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CLMON.DLL
[2009/04/15 09:41:49 | 00,054,488 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CLPT.SYS
[2009/04/15 09:41:49 | 00,049,152 | —- | C] (SHARP) – C:\WINDOWS\System32\SE4CMTNT.DLL
[2009/04/15 09:41:49 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\SE4CUD.MCF
[2009/04/15 09:41:49 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\SE4CLMON.DAT
[2009/04/15 09:41:49 | 00,000,074 | —- | C] () – C:\WINDOWS\System32\SE4CLMON.MTX
[2009/04/15 09:41:48 | 00,057,344 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4CGC.DLL
[2009/04/15 09:41:41 | 00,054,488 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BLPT.SYS
[2009/04/15 09:41:41 | 00,049,152 | —- | C] (SHARP) – C:\WINDOWS\System32\SE4BMTNT.DLL
[2009/04/15 09:41:41 | 00,015,427 | —- | C] () – C:\WINDOWS\System32\SE4BUD.MCF
[2009/04/15 09:41:41 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\SE4BLMON.DAT
[2009/04/15 09:41:41 | 00,000,074 | —- | C] () – C:\WINDOWS\System32\SE4BLMON.MTX
[2009/04/15 09:41:40 | 00,143,360 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BGCP.DLL
[2009/04/15 09:41:40 | 00,135,168 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BLMON.DLL
[2009/04/15 09:41:40 | 00,057,344 | —- | C] (Sharp Corporation) – C:\WINDOWS\System32\SE4BGC.DLL
[2009/04/15 09:41:33 | 00,159,744 | —- | C] () – C:\WINDOWS\_isusr32.dll
[2009/04/15 09:41:22 | 00,004,737 | —- | C] () – C:\WINDOWS\se4cins.sii
[2009/04/15 09:41:15 | 00,122,880 | —- | C] () – C:\WINDOWS\System32\use4b.dll
[2009/04/15 09:41:15 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\_isusr2k.dll
[2009/04/15 09:41:15 | 00,005,281 | —- | C] () – C:\WINDOWS\se4bins.sii
[2009/04/15 09:41:15 | 00,000,142 | —- | C] () – C:\WINDOWS\System32\Use4bMsg.dat
[2009/04/15 09:41:14 | 00,000,000 | —D | C] – C:\WINDOWS\System32\SCDRV
[2009/04/08 14:34:19 | 00,000,672 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Shortcut to Bankruptcy2009.LNK
[2009/04/08 09:05:13 | 00,415,766 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\cc_20090408_090508.reg
[2009/04/07 13:10:14 | 00,082,993 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Hardin County Driving.pdf
[2009/04/06 15:48:15 | 00,027,648 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\Notice Leave Premises pg 1-2aa.doc
[2009/04/02 09:48:07 | 00,064,879 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Snake.jpg
[2009/04/02 09:47:29 | 00,061,352 | —- | C] () – C:\Documents and Settings\Stacy\Desktop\Snake and Dale.jpg
[2009/03/30 14:00:34 | 00,032,256 | —- | C] () – C:\Documents and Settings\Stacy\My Documents\Forcible Entry & Detention12.doc
[2009/03/25 09:00:40 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Stacy\My Documents\~$thdraw as Counsel.doc
[2008/12/03 09:18:52 | 00,561,688 | —- | C] () – C:\WINDOWS\System32\wuapi.dll.wusetup.1203093.new
[2008/10/13 09:27:17 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2008/10/13 09:26:53 | 00,009,853 | —- | C] () – C:\WINDOWS\HL-2140.INI
[2008/03/12 08:10:28 | 00,088,064 | —- | C] () – C:\WINDOWS\System32\comdlg32n.dll
[2007/09/10 09:36:17 | 00,000,004 | -H– | C] () – C:\WINDOWS\uccspecb.sys
[2007/03/05 13:34:28 | 00,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/10/02 15:10:12 | 00,026,624 | —- | C] () – C:\WINDOWS\System32\BRGSRC32.DLL
[2006/10/02 15:10:12 | 00,004,608 | —- | C] () – C:\WINDOWS\System32\BRGSRC16.DLL
[2005/04/13 14:16:25 | 00,000,032 | —- | C] () – C:\WINDOWS\brqikmon.ini
[2004/08/05 12:27:40 | 00,000,034 | —- | C] () – C:\WINDOWS\AuthMgr.INI
[2004/04/20 14:32:51 | 00,000,043 | —- | C] () – C:\WINDOWS\INTUIT.INI
[2004/01/20 13:32:31 | 00,290,816 | —- | C] () – C:\WINDOWS\System32\niknakXML.dll
[2004/01/20 13:32:31 | 00,135,168 | —- | C] () – C:\WINDOWS\System32\expat.dll
[2004/01/20 13:32:31 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\EventConsumer.dll
[2004/01/20 13:32:31 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\PDFMacroUtils.dll
[2003/12/15 14:20:01 | 00,009,216 | —- | C] () – C:\WINDOWS\System32\pdfxcds.dll
[2003/12/08 16:53:08 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2003/12/08 16:36:33 | 00,000,035 | —- | C] () – C:\WINDOWS\A6W.INI
[2003/12/05 15:10:22 | 00,000,278 | —- | C] () – C:\WINDOWS\hpqcopy.INI
[2003/11/19 17:44:30 | 00,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2003/10/31 15:36:37 | 00,000,006 | —- | C] () – C:\WINDOWS\ep213.ini
[2003/10/09 16:05:29 | 00,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2003/09/16 14:03:30 | 00,000,058 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2003/09/16 14:03:30 | 00,000,040 | —- | C] () – C:\WINDOWS\opt_1440.ini
[2003/09/16 14:03:30 | 00,000,000 | —- | C] () – C:\WINDOWS\Brohl144.ini
[2003/09/16 14:03:26 | 00,000,468 | —- | C] () – C:\WINDOWS\Brownie.ini
[2003/09/16 14:03:26 | 00,000,296 | —- | C] () – C:\WINDOWS\BRDIAG.INI
[2003/09/16 14:03:26 | 00,000,167 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2003/09/16 14:03:11 | 00,000,500 | —- | C] () – C:\WINDOWS\brwmark.ini
[2003/09/16 14:03:09 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2003/09/16 14:03:08 | 00,000,038 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2003/09/10 15:45:24 | 00,000,601 | —- | C] () – C:\WINDOWS\bk2001.INI
[2003/08/25 09:31:08 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/08/25 09:31:06 | 00,001,218 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/08/22 11:43:37 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.dll
[2003/08/22 11:40:48 | 00,000,028 | —- | C] () – C:\WINDOWS\qbwcd.ini
[2003/08/22 11:31:02 | 00,001,130 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/08/22 11:30:51 | 00,001,412 | —- | C] () – C:\WINDOWS\QfnOnl.ini
[2003/08/22 11:29:32 | 00,000,362 | —- | C] () – C:\WINDOWS\QDQICK.INI
[2003/08/22 11:29:32 | 00,000,028 | —- | C] () – C:\WINDOWS\QFNOA.INI
[2003/08/22 11:29:29 | 00,000,038 | —- | C] () – C:\WINDOWS\ACCWIZ.INI
[2003/08/19 11:24:58 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/19 11:20:23 | 00,000,893 | —- | C] () – C:\WINDOWS\lrun32.ini
[2003/08/19 11:19:04 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/08/19 11:13:22 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/19 10:59:30 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/19 10:59:14 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/08/19 10:47:50 | 00,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/09/03 09:59:58 | 00,001,271 | —- | C] () – C:\WINDOWS\WIN.INI
[2002/09/03 09:50:58 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2002/08/29 06:00:00 | 00,105,472 | —- | C] () – C:\WINDOWS\System32\cmdial32f.dll.bak
[2002/03/13 16:46:46 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\zlib.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/04/23 08:59:51 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Stacy\Desktop\OTListIt2.exe
[2009/04/23 08:57:35 | 00,002,483 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Microsoft Word.lnk
[2009/04/23 08:51:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/23 08:45:38 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/23 08:38:42 | 00,000,281 | RHS- | M] () – C:\BOOT.INI
[2009/04/23 08:33:53 | 02,999,160 | R— | M] () – C:\Documents and Settings\Stacy\Desktop\Combo.exe
[2009/04/23 08:16:29 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2009/04/23 08:16:24 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/23 08:14:07 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/04/23 08:14:04 | 53,484,3392 | -HS- | M] () – C:\hiberfil.sys
[2009/04/22 11:20:52 | 00,000,672 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Shortcut to Bankruptcy2009.LNK
[2009/04/22 09:26:49 | 08,433,664 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\B2K733.exe
[2009/04/21 16:41:29 | 00,000,514 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Stacy at 3 35 PM.job
[2009/04/21 16:28:26 | 00,000,933 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Spybot - Search & Destroy.lnk
[2009/04/21 16:14:31 | 00,000,807 | —- | M] () – C:\Documents and Settings\All Users\Desktop\System Mechanic 5 Professional.lnk
[2009/04/21 15:42:50 | 00,880,560 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2009/04/21 15:42:50 | 00,108,368 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2009/04/21 15:36:06 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/04/21 14:14:57 | 04,626,422 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\avz4.zip
[2009/04/21 14:00:15 | 00,036,352 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\FAX101.doc
[2009/04/21 11:59:58 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Stacy\My Documents\~$smiss lack of probable cause2.doc
[2009/04/21 10:28:27 | 00,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2009/04/21 09:58:08 | 00,109,568 | —- | M] () – C:\WINDOWS\vFind.exe
[2009/04/21 08:33:41 | 00,199,680 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\DirLook.exe
[2009/04/20 13:46:21 | 00,023,552 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\WNG-Designation.doc
[2009/04/20 11:54:48 | 00,034,816 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\COURT LETTER.doc
[2009/04/20 10:13:49 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\AA MIKE LABELS.doc
[2009/04/20 10:03:42 | 00,072,320 | —- | M] () – C:\Documents and Settings\Stacy\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/20 09:15:08 | 00,000,028 | —- | M] () – C:\WINDOWS\qbwcd.ini
[2009/04/20 09:13:01 | 00,001,271 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/04/20 08:32:10 | 00,445,536 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 08:32:10 | 00,384,308 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/04/20 08:32:10 | 00,054,650 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/04/16 16:32:01 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/16 13:17:56 | 00,033,280 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Interrog-Notice of Service.doc
[2009/04/15 15:51:30 | 00,068,096 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\LETTERHEAD.doc
[2009/04/15 14:32:40 | 00,001,218 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/04/15 10:41:44 | 00,008,628 | -H– | M] () – C:\WINDOWS\System32\SE42TWN.GID
[2009/04/15 09:58:19 | 00,510,758 | —- | M] () – C:\Documents and Settings\Stacy\Application Data\fontlst2.opf
[2009/04/15 09:45:15 | 00,001,924 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Sharpdesk.lnk
[2009/04/15 09:42:10 | 00,000,822 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Button Manager G.lnk
[2009/04/15 09:42:02 | 00,002,589 | —- | M] () – C:\WINDOWS\se4.isu
[2009/04/14 15:48:46 | 00,032,768 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Continuance-CPC Dom..doc
[2009/04/14 14:27:47 | 00,034,304 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Form Letter.doc
[2009/04/14 13:44:46 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Notice Leave Premises pg 1-2aa.doc
[2009/04/13 09:59:21 | 00,251,215 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Real Estate Tax Transfer.fdc
[2009/04/09 11:41:44 | 00,028,672 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Dismiss lack of probable cause2.doc
[2009/04/09 11:15:29 | 00,033,280 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Judicial Release-2.doc
[2009/04/09 10:32:07 | 00,036,352 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\JC1.doc
[2009/04/08 13:56:39 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation-Juvenile.doc
[2009/04/08 12:34:22 | 00,000,191 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\DPE.DUS
[2009/04/08 10:08:26 | 00,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2009/04/08 10:07:30 | 00,001,730 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/04/08 09:05:35 | 00,415,766 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\cc_20090408_090508.reg
[2009/04/07 13:10:14 | 00,082,993 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Hardin County Driving.pdf
[2009/04/07 11:59:40 | 00,032,768 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Innocent Owner, releasing vehicle to.doc
[2009/04/06 14:39:17 | 00,030,208 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation of Counsel.doc
[2009/04/06 14:32:25 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Request for Pretrial.doc
[2009/04/06 12:01:52 | 00,211,968 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Warranty Deed.doc
[2009/04/06 11:27:07 | 00,011,173 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Caretaker Affidavit page 2.fdc
[2009/04/06 11:27:05 | 00,022,714 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Caretaker Affidavit page 1.fdc
[2009/04/06 11:26:43 | 00,067,072 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Power of Attorney-Grandparents NEW House Bill2.doc
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/02 13:55:08 | 00,072,320 | —- | M] () – C:\Documents and Settings\Stacy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/02 09:48:09 | 00,064,879 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Snake.jpg
[2009/04/02 09:47:29 | 00,061,352 | —- | M] () – C:\Documents and Settings\Stacy\Desktop\Snake and Dale.jpg
[2009/04/01 14:41:21 | 00,029,696 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Notice to Clerk.doc
[2009/03/31 11:18:04 | 00,028,672 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Subpoena-Juvenile-page 1.doc
[2009/03/30 14:38:06 | 00,032,256 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Forcible Entry & Detention12.doc
[2009/03/30 14:38:02 | 00,029,696 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Notice to Clerk-stumbaugh.doc
[2009/03/30 13:28:03 | 00,029,184 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation of Counsel-aug. co..doc
[2009/03/30 13:19:02 | 00,024,064 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Designation-CPC Dom.doc
[2009/03/29 13:48:01 | 00,023,040 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\First Federal Invoice.doc
[2009/03/27 03:09:32 | 01,193,414 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/26 14:00:47 | 00,029,184 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Default-Motion-Brower Commons.doc
[2009/03/26 13:20:44 | 00,020,992 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Default Judgment-brower.doc
[2009/03/26 12:51:37 | 00,027,648 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Subpoena-Juvenile-page 2.doc
[2009/03/25 09:00:40 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Stacy\My Documents\~$thdraw as Counsel.doc
[2009/03/24 16:03:11 | 00,033,280 | —- | M] () – C:\Documents and Settings\Stacy\My Documents\Withdraw as Counsel.doc

========== LOP Check ==========

[2009/04/23 08:32:23 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/07/10 09:37:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/08/09 14:50:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/01/29 10:47:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/04/21 15:47:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2005/05/26 09:30:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2008/12/04 12:59:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2008/01/16 14:11:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2005/05/25 14:43:34 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/12/08 10:51:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/12/04 13:38:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2004/02/09 11:09:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2005/10/21 12:39:48 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/16 13:21:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2005/07/01 12:58:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2003/11/14 14:13:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2003/08/19 11:14:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/04/15 09:51:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sharpdesk
[2009/04/21 16:58:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/12/22 12:20:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2008/12/04 16:07:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sunbelt
[2008/12/11 11:44:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/03/27 10:43:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sync App Settings
[2003/11/14 14:13:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/07/29 13:32:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/23 07:59:07 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Stacy\Application Data
[2008/06/16 11:16:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Adobe
[2007/07/10 09:17:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\AdobeUM
[2009/01/14 15:29:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Arcsoft
[2006/07/05 08:12:34 | 00,000,000 | R–D | M] – C:\Documents and Settings\Stacy\Application Data\Brother
[2008/02/27 11:49:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\F-Secure
[2008/12/11 11:34:38 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Stacy\Application Data\GTek
[2005/07/22 15:44:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Help
[2003/09/17 11:03:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Hewlett-Packard
[2003/08/19 10:46:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Identities
[2003/11/19 17:22:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Leadertech
[2004/01/05 13:03:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Macromedia
[2008/12/04 13:38:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Malwarebytes
[2005/10/21 12:47:54 | 00,000,000 | –SD | M] – C:\Documents and Settings\Stacy\Application Data\Microsoft
[2008/04/17 12:32:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Mozilla
[2003/11/10 11:10:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Share-to-Web Upload Folder
[2009/04/15 09:41:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Sharp
[2009/04/15 09:58:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Sharpdesk
[2008/09/11 09:25:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\StumbleUpon
[2004/01/23 12:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Sun
[2009/04/08 08:42:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\SUPERAntiSpyware.com
[2008/06/11 15:41:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\SystemRequirementsLab
[2009/02/09 12:00:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\U3
[2009/04/23 07:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\urdidseb
[2008/02/21 15:41:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Viewpoint
[2005/08/24 12:59:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Stacy\Application Data\Yahoo! Messenger
[2009/04/21 16:41:29 | 00,000,514 | —- | M] () – C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Stacy at 3 35 PM.job
[2002/08/29 06:00:00 | 00,000,065 | —- | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/04/23 08:51:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2003/10/17 11:02:11 | 00,000,338 | —- | M] () – C:\WINDOWS\Tasks\WebReg 20031017110211.job

========== Purity Check ==========

< End of report >
I ran the AVG fix that you posted yesterday and it totally got rid of the error messages I was getting on startup. It also deleted the OTListit program from my desktop. As you asked me to run another OTListit scan after I ran the ComboFix program I had to redownload OTListit….and I started getting the same error messages as I had been getting before I ran your AVG fix. In frustration I "deleted" the OTListit.exe program from my desktop. Now I am only getting one error message on startup. It says something like "Can't locate C:\Documents". I click "ok" and it proceeds with starting up. A little annoying….what do you suggest? Thanks as always!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI