thanks for help on my new pc. I checked security and it said auto update was on, as well as window firewall. I created new restore point on that one.
Here is pc scans info. from my old pc. thanks much. I am using avast virus protection windows firewall and ad-aware from lavasoft on this pc as well. System restore is also running.
OTListIt Extras logfile created on: 4/27/2009 6:46:08 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Andrew & Connor\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.07 Mb Total Physical Memory | 30.21 Mb Available Physical Memory | 11.84% Memory free
619.60 Mb Paging File | 269.28 Mb Available in Paging File | 43.46% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 29.77 Gb Free Space | 79.90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 629.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KRISTIN
Current User Name: Andrew & Connor
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36373CE1-6999-11D5-96DC-98302790D441}" = Bob the Builder
"{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111940693}" = Bookworm Adventures
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-1143087}" = Garden Defense
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115495490}" = 10 Days Under the Sea
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FAB1F336-1B7C-4057-A7BC-2922CD82A781}" = Ralink Wireless LAN
"102 Dalmatians Activity Center" = 102 Dalmatians Activity Center
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AT&T WorldNet Software" = AT&T WorldNet Setup
"avast!" = avast! Antivirus
"Azkend" = Azkend
"Bubblefish Bob" = Bubblefish Bob (remove only)
"ElmosArtWorkshop" = Sesame Street Elmo's Art Workshop
"ffdshow" = ffdshow (remove only)
"Garden Defense" = Garden Defense
"Google Desktop" = Google Desktop
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"InterVideo WinDVD" = InterVideo WinDVD
"Leap Ahead Kindergarten" = Leap Ahead Kindergarten
"Little Bear™ Rainy Day Activities" = Little Bear™ Rainy Day Activities
"Mr. Potato Head's Activity Pack" = Mr. Potato Head Uninstaller
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"My.Freeze.com NetAssistant" = My.Freeze.com NetAssistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PRC" = JumpStart Parent Resource Center
"PRSCHL99" = JumpStart Preschool
"QuickTime" = QuickTime
"Rescue Heroes Meteor Madness" = Rescue Heroes Meteor Madness
"SearchLearnAdventures" = Sesame Street Search & Learn Adventures
"Seekeen" = Seekeen 1.0 build 132
"Stunt Track Driver" = Stunt Track Driver
"Thomas & Friends - Railway Adventures" = Thomas & Friends - Railway Adventures
"Tonka Raceway" = Tonka Raceway
"UnityWebPlayer" = Unity Web Player
"VLC media player" = VLC media player 0.9.2
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 11/30/2008 2:46:41 PM | Computer Name = KRISTIN | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://msnprod.oberon-media.com/game-detai…in=zone.msn.com
failed, 0000A413.
[ Application Events ]
Error - 1/24/2009 8:31:02 PM | Computer Name = KRISTIN | Source = Application Hang | ID = 1002
Description = Hanging application msn6.exe, version 7.2.11.2700, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/24/2009 8:31:26 PM | Computer Name = KRISTIN | Source = Application Hang | ID = 1001
Description = Fault bucket 31136365.
Error - 2/4/2009 12:53:22 PM | Computer Name = KRISTIN | Source = Application Error | ID = 1000
Description = Faulting application ad-aware.exe, version 7.1.0.12, faulting module
ad-aware.exe, version 7.1.0.12, fault address 0x0015566e.
Error - 2/4/2009 12:53:44 PM | Computer Name = KRISTIN | Source = Application Error | ID = 1001
Description = Fault bucket 1101135296.
Error - 2/21/2009 11:38:31 AM | Computer Name = KRISTIN | Source = Application Error | ID = 1005
Description = Windows cannot access the file E:\Bob the Builder.exe for one of the
following reasons: there is a problem with the network connection, the disk that
the file is stored on, or the storage drivers installed on this computer; or the
disk is missing. Windows closed the program Bob the Builder.exe because of this
error. Program: Bob the Builder.exe File: E:\Bob the Builder.exe The error value is
listed in the Additional Data section. User Action 1. Open the file again. This situation
might be a temporary problem that corrects itself when the program runs again. 2.
If the file still cannot be accessed and - It is on the network, your network administrator
should verify that there is not a problem with the network and that the server
can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM,
verify that the disk is fully inserted into the computer. 3. Check and repair the
file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD,
and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4.
If the problem persists, restore the file from a backup copy. 5. Determine whether
other files on the same disk can be opened. If not, the disk might be damaged.
If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance. Additional Data Error value: C0000240 Disk type: 5
Error - 2/21/2009 11:38:31 AM | Computer Name = KRISTIN | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.
Error - 2/21/2009 11:48:16 AM | Computer Name = KRISTIN | Source = Application Hang | ID = 1002
Description = Hanging application taskmgr.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/21/2009 11:48:16 AM | Computer Name = KRISTIN | Source = Application Hang | ID = 1002
Description = Hanging application taskmgr.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/27/2009 10:02:18 AM | Computer Name = KRISTIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2/27/2009 10:02:21 AM | Computer Name = KRISTIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 4/18/2009 4:34:05 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327684
Description = AMLI: ACPI BIOS is attempting to read from an illegal IO port address
(0x71), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/21/2009 8:50:01 AM | Computer Name = KRISTIN | Source = ACPI | ID = 327685
Description = AMLI: ACPI BIOS is attempting to write to an illegal IO port address
(0x70), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/21/2009 8:50:01 AM | Computer Name = KRISTIN | Source = ACPI | ID = 327684
Description = AMLI: ACPI BIOS is attempting to read from an illegal IO port address
(0x71), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/21/2009 8:53:21 AM | Computer Name = KRISTIN | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.
Error - 4/26/2009 2:52:06 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327685
Description = AMLI: ACPI BIOS is attempting to write to an illegal IO port address
(0x70), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/26/2009 2:52:06 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327684
Description = AMLI: ACPI BIOS is attempting to read from an illegal IO port address
(0x71), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/26/2009 4:09:53 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327685
Description = AMLI: ACPI BIOS is attempting to write to an illegal IO port address
(0x70), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/26/2009 4:09:53 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327684
Description = AMLI: ACPI BIOS is attempting to read from an illegal IO port address
(0x71), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/27/2009 7:34:06 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327685
Description = AMLI: ACPI BIOS is attempting to write to an illegal IO port address
(0x70), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
Error - 4/27/2009 7:34:06 PM | Computer Name = KRISTIN | Source = ACPI | ID = 327684
Description = AMLI: ACPI BIOS is attempting to read from an illegal IO port address
(0x71), which lies in the 0x70 - 0x71 protected address range. This could lead to
system instability. Please contact your system vendor for technical assistance.
< End of report >
———————————————————————–
OTListIt logfile created on: 4/27/2009 6:46:08 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Andrew & Connor\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.07 Mb Total Physical Memory | 30.21 Mb Available Physical Memory | 11.84% Memory free
619.60 Mb Paging File | 269.28 Mb Available in Paging File | 43.46% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 29.77 Gb Free Space | 79.90% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 629.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KRISTIN
Current User Name: Andrew & Connor
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\MSN\MSNCoreFiles\msn6.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Documents and Settings\Andrew & Connor\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\Google\Update\Download\{C70F50CB-74D9-4B2F-8FA0-C3B3F0CC67E3}\chrome_updater.exe (Google Inc.)
PRC - C:\Documents and Settings\Andrew & Connor\Local Settings\Temp\CR_58.tmp\setup.exe (Google Inc.)
========== Win32 Services (SafeList) ==========
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (Aspi32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ctljystk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (EL90X [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\el90xnd5.sys (3Com Corporation)
DRV - (emu10k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (HCF_MSFT [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HCF_MSFT.sys (Conexant)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RT61.sys (Ralink Technology, Corp.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (NetAssistantBHO Class) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files\My.Freeze.com NetAssistant\NetAssistant.dll (W3i, LLC)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - Reg Error: Key error. File not found
O9 - Extra Button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://zone.msn.com/BINGAME/POPCAPLOADER_V10.CAB (PopCapLoader Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - E:\AUTORUN.INF () - [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2009/04/27 18:45:20 | 00,267,612 | —- | C] () – C:\Documents and Settings\Andrew & Connor\Desktop\Rooter.exe
[2009/04/27 18:41:02 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Andrew & Connor\Desktop\OTListIt2.exe
[2009/04/26 13:59:12 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/26 13:59:12 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/26 13:59:12 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/26 13:59:11 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/26 13:59:11 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/26 13:59:10 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/26 13:59:10 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/26 13:59:10 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/26 13:59:09 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/18 16:18:59 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\FlyWheelGames
[2009/04/18 16:18:15 | 00,001,807 | —- | C] () – C:\Documents and Settings\Andrew & Connor\Desktop\10 Days Under the Sea.lnk
[2009/04/18 15:25:21 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/18 15:25:16 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/18 15:25:13 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/06 17:44:28 | 00,105,393 | —- | C] () – C:\Documents and Settings\Andrew & Connor\Desktop\oiio__puuy.jpg
[2009/04/06 17:07:31 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/04/06 17:07:31 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/06 15:03:48 | 00,268,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2009/04/06 15:03:48 | 00,208,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\muweb.dll
[2009/04/06 15:03:48 | 00,027,496 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2009/04/05 08:33:24 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/04/05 08:32:02 | 04,909,440 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Andrew & Connor\Desktop\Silverlight.2.0.exe
[2008/12/15 09:31:54 | 00,000,658 | —- | C] () – C:\WINDOWS\KA.INI
[2008/12/10 11:26:15 | 00,001,009 | —- | C] () – C:\WINDOWS\hegames.ini
[2008/12/03 11:26:32 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2008/11/27 08:44:37 | 00,000,058 | —- | C] () – C:\WINDOWS\Tonka_Raceway.INI
[2008/11/26 13:39:13 | 00,001,421 | —- | C] () – C:\WINDOWS\disney.ini
[2008/11/23 14:20:15 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\regobj.dll
[2008/11/23 14:03:59 | 00,000,162 | —- | C] () – C:\WINDOWS\mrpotato.ini
[2008/11/23 13:28:45 | 00,000,051 | —- | C] () – C:\WINDOWS\SSAW.INI
[2004/08/04 07:00:00 | 00,000,554 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 07:00:00 | 00,000,247 | —- | C] () – C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/04/27 18:45:22 | 00,267,612 | —- | M] () – C:\Documents and Settings\Andrew & Connor\Desktop\Rooter.exe
[2009/04/27 18:41:03 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Andrew & Connor\Desktop\OTListIt2.exe
[2009/04/27 18:34:15 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/27 18:34:07 | 00,013,728 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/27 18:34:00 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/27 18:33:58 | 26,753,4336 | -HS- | M] () – C:\hiberfil.sys
[2009/04/26 15:20:07 | 00,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-492894223-1060284298-1004.job
[2009/04/26 15:14:58 | 00,311,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/26 15:14:58 | 00,039,992 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/26 15:14:56 | 00,356,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/21 09:01:07 | 03,209,026 | -H– | M] () – C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\IconCache.db
[2009/04/18 17:14:57 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/18 16:18:16 | 00,001,807 | —- | M] () – C:\Documents and Settings\Andrew & Connor\Desktop\10 Days Under the Sea.lnk
[2009/04/18 16:18:16 | 00,001,444 | —- | M] () – C:\Documents and Settings\Andrew & Connor\Desktop\MSN Games.lnk
[2009/04/09 08:14:16 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/06 17:44:28 | 00,105,393 | —- | M] () – C:\Documents and Settings\Andrew & Connor\Desktop\oiio__puuy.jpg
[2009/04/06 17:07:41 | 00,000,310 | —- | M] () – C:\WINDOWS\EReg515.dat
[2009/04/06 17:07:35 | 00,001,421 | —- | M] () – C:\WINDOWS\disney.ini
[2009/04/06 17:07:31 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/04/06 09:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/05 08:32:02 | 04,909,440 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Andrew & Connor\Desktop\Silverlight.2.0.exe
========== LOP Check ==========
[2009/04/18 16:18:59 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/27 10:43:49 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2008/11/26 18:28:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/11/28 17:00:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2008/11/27 09:18:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2009/03/07 18:23:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy-PizzaParty
[2009/04/18 16:18:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FlyWheelGames
[2009/04/05 08:04:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/01/09 18:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GrimmsHatchery
[2008/12/20 10:38:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InterAction studios
[2009/02/27 10:43:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/11/27 08:43:25 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/11/21 22:45:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/01 10:16:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/11/28 13:23:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mushroom Age
[2009/01/07 17:54:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MythPeople
[2008/12/31 13:47:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2009/01/04 10:26:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2008/11/29 09:05:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2009/01/07 18:44:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/02/25 17:17:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Raptisoft
[2008/12/24 14:46:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/04/18 16:53:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/21 10:19:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/11/26 19:24:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/11/28 15:04:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/01/18 15:45:25 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Andrew & Connor\Application Data
[2008/11/27 08:02:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Adobe
[2008/11/26 18:30:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\AdobeUM
[2008/11/28 16:15:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\dvdcss
[2008/12/31 13:47:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\GameHouse
[2009/04/05 08:04:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Google
[2008/12/15 09:34:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Help
[2008/11/21 18:57:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Identities
[2008/11/26 18:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\InstallShield
[2008/12/02 19:19:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\iWin
[2008/11/21 20:00:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Macromedia
[2008/11/21 22:51:07 | 00,000,000 | –SD | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Microsoft
[2008/11/26 19:13:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\MSN6
[2008/11/21 19:22:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\MSNInstaller
[2009/01/18 15:45:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Oberonv1001
[2008/11/30 13:50:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\PlayFirst
[2008/12/02 18:54:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Pogo Games
[2008/11/28 17:00:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Uniblue
[2008/12/17 12:01:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Unity
[2008/11/28 16:15:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\vlc
[2008/11/28 15:04:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\WeatherBug
[2009/01/09 17:29:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Wildfire
[2008/11/28 15:04:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Andrew & Connor\Application Data\Yahoo!
[2009/03/27 09:55:04 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/26 15:20:07 | 00,000,966 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-492894223-1060284298-1004.job
[2009/04/27 18:34:15 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6468C896
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F880DE59
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:58EB307C
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3C9CF9A7
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9F683177
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:92D18A5E
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F5BB3657
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA45F5FF
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0104E054
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:82C50600
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:193426B4
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6EAE3ABC
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3C75E5BE
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1247C505
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4D066AD2
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F4921BC9
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8173A019
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4E1E5A60
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3447AB86
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3AED98EA
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2FAFBD6A
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8A7CF18
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1F04E8D
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AB689DEA
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:588B60C7
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:370EF5E8
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CC832A16
< End of report >
—————————————————-
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:38154 Mo/Free:1816 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Mon 04/27/2009|18:54
———————-\\ Processes..
–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
———- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
———- C:\Program Files\Alwil Software\Avast4\ashServ.exe
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
———- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
———- C:\WINDOWS\system32\wbem\unsecapp.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\WINDOWS\system32\wbem\wmiprvse.exe
———- C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
———- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
———- C:\WINDOWS\system32\devldr32.exe
———- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Documents and Settings\Andrew & Connor\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
———- C:\Program Files\RALINK\Common\RaUI.exe
———- C:\Program Files\MSN\MSNCoreFiles\msn6.exe
———- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
———- C:\Documents and Settings\Andrew & Connor\Desktop\OTListIt2.exe
———- C:\WINDOWS\notepad.exe
———- C:\WINDOWS\notepad.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe
———————-\\ Search..
———————-\\ ROOTKIT !!
———————-\\ Cracks & Keygens..
C:\DOCUME~1\ANDREW~1\Local Settings\Temporary Internet Files\Content.IE5\8ARLLHWF\small-cyberchase-crackcode[1].gif
C:\DOCUME~1\ANDREW~1\Local Settings\Temporary Internet Files\Content.IE5\L63XXYV4\crack_code[1].jpg
C:\DOCUME~1\ANDREW~1\Local Settings\Temporary Internet Files\Content.IE5\L63XXYV4\small-cyberchase-cracksafe[1].gif
C:\DOCUME~1\ANDREW~1\Local Settings\Temporary Internet Files\Content.IE5\QY91OWWY\crack_hackers_safe[1].jpg
C:\DOCUME~1\ANDREW~1\Local Settings\Temporary Internet Files\Content.IE5\QY91OWWY\small-animalia-codecracker[1].jpg
1 - "C:\Rooter$\Rooter_1.txt" - Mon 04/27/2009|18:55
———————-\\ Scan completed at 18:55