OTListIt logfile created on: 5/2/2009 12:34:56 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.48 Mb Total Physical Memory | 89.60 Mb Available Physical Memory | 20.02% Memory free
1.03 Gb Paging File | 0.76 Gb Available in Paging File | 74.01% Paging File free
Paging file location(s): C:\pagefile.sys 1344 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.22 Gb Total Space | 13.72 Gb Free Space | 7.53% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.69 Gb Free Space | 17.06% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 993.21 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KILLA_CHUBS
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2008/10/28 16:42:30 | 00,156,968 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
PRC - [2006/10/30 10:36:36 | 00,256,576 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/02/10 14:21:40 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/10/28 16:42:12 | 00,181,544 | —- | M] (Seagate LLC) – C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
PRC - [2007/08/03 12:51:06 | 00,202,024 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
PRC - [2007/08/08 09:25:08 | 00,836,904 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
PRC - [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004/11/02 17:59:50 | 00,316,544 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PRC - [2006/10/30 10:36:32 | 00,492,608 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2007/08/03 12:51:18 | 00,382,248 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
PRC - [2007/08/03 12:51:18 | 01,422,632 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2004/11/04 19:36:46 | 00,425,984 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
PRC - [2009/05/02 00:39:29 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2005/11/01 23:26:44 | 00,068,096 | —- | M] () – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [Disabled | Stopped])
SRV - [2005/09/23 07:28:32 | 00,029,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [Disabled | Stopped])
SRV - [2008/04/04 01:52:29 | 00,418,816 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgamsvr.exe – (Avg7Alrt [Disabled | Stopped])
SRV - [2008/04/04 01:52:54 | 00,049,664 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgupsvc.exe – (Avg7UpdSvc [Disabled | Stopped])
SRV - [2008/04/04 01:52:36 | 00,406,528 | —- | M] (GRISOFT, s.r.o.) – C:\Program Files\Grisoft\AVG7\avgemc.exe – (AVGEMS [Disabled | Stopped])
SRV - [2004/12/22 18:45:22 | 00,255,600 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr [Disabled | Stopped])
SRV - [2004/12/22 18:45:30 | 00,087,664 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe – (ccPwdSvc [Disabled | Stopped])
SRV - [2004/12/22 18:45:42 | 00,235,120 | —- | M] (Symantec Corporation) – c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr [Disabled | Stopped])
SRV - [2005/09/23 07:28:56 | 00,066,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2006/10/20 21:21:24 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/10/28 16:42:30 | 00,156,968 | —- | M] (Seagate Technology LLC) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe – (FreeAgentGoNext Service [Auto | Running])
SRV - [2004/08/04 03:56:44 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2006/10/30 03:33:58 | 00,741,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2006/10/30 10:36:32 | 00,492,608 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2009/02/10 14:21:40 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2004/08/06 04:50:00 | 00,102,463 | —- | M] (Network Associates, Inc.) – C:\Program Files\Network Associates\Common Framework\FrameworkService.exe – (McAfeeFramework [Disabled | Stopped])
SRV - [2004/09/22 21:00:00 | 00,221,191 | —- | M] (Network Associates, Inc.) – C:\Program Files\Network Associates\VirusScan\mcshield.exe – (McShield [Disabled | Stopped])
SRV - [2004/09/22 21:00:00 | 00,028,672 | —- | M] (Network Associates, Inc.) – C:\Program Files\Network Associates\VirusScan\vstskmgr.exe – (McTaskManager [Disabled | Stopped])
SRV - [2002/12/17 17:26:22 | 07,520,337 | —- | M] (Microsoft Corporation) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR [On_Demand | Stopped])
SRV - [2002/12/17 17:23:30 | 00,066,112 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2004/04/23 11:04:18 | 00,158,848 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\navapsvc.exe – (navapsvc [Disabled | Stopped])
SRV - [2007/08/08 09:25:08 | 00,836,904 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe – (Nero BackItUp Scheduler 3 [Auto | Running])
SRV - File not found – – (Nero BackItUp Scheduler 4.0 [Auto | Stopped])
SRV - [2006/10/30 03:34:02 | 00,122,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/08/03 12:51:18 | 00,382,248 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe – (NMIndexingService [On_Demand | Running])
SRV - [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12 [Auto | Running])
SRV - [2003/04/04 15:54:50 | 00,077,824 | —- | M] () – C:\Program Files\WinPcap\rpcapd.exe – (rpcapd [Disabled | Stopped])
SRV - [2003/12/04 18:22:30 | 00,193,816 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\SAVScan.exe – (SAVScan [Disabled | Stopped])
SRV - [2005/01/21 23:32:12 | 00,206,552 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc [Disabled | Stopped])
SRV - [2002/12/17 17:23:30 | 00,311,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR [On_Demand | Stopped])
SRV - [2004/11/02 17:59:50 | 00,316,544 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe – (SymWSC [Auto | Running])
SRV - [2005/12/05 00:24:24 | 00,126,976 | —- | M] () – C:\WINDOWS\System32\UAService7.exe – (UserAccess7 [Disabled | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [Disabled | Stopped])
SRV - [2007/03/14 17:03:40 | 00,975,400 | —- | M] (Microsoft Corporation) – C:\Program Files\Zune\ZuneNss.exe – (ZuneNetworkSvc [Disabled | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2004/08/04 02:10:10 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\61883.sys – (61883 [On_Demand | Stopped])
DRV - [2004/06/29 10:07:18 | 01,268,204 | —- | M] (Agere Systems) – C:\WINDOWS\System32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2003/12/12 10:54:14 | 00,391,424 | —- | M] (Sensaura Ltd) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS [On_Demand | Stopped])
DRV - [2004/10/01 11:24:02 | 02,279,424 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2009/03/18 13:08:10 | 00,103,744 | —- | M] (SlySoft, Inc.) – C:\WINDOWS\System32\Drivers\AnyDVD.sys – (AnyDVD [On_Demand | Running])
DRV - [2004/08/04 02:10:10 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\avc.sys – (Avc [On_Demand | Stopped])
DRV - [2008/04/04 01:53:06 | 00,821,856 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avg7core.sys – (Avg7Core [System | Running])
DRV - [2008/04/04 01:53:24 | 00,004,224 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avg7rsw.sys – (Avg7RsW [System | Running])
DRV - [2008/04/04 01:53:27 | 00,027,776 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avg7rsxp.sys – (Avg7RsXP [System | Running])
DRV - [2008/04/04 01:53:33 | 00,010,760 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avgclean.sys – (AvgClean [System | Running])
DRV - [2008/04/04 01:53:31 | 00,004,960 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdi.sys – (AvgTdi [Auto | Running])
DRV - [2005/11/10 14:54:56 | 00,402,944 | R— | M] (Belkin Corporation) – C:\WINDOWS\System32\DRIVERS\BLKWGU.sys – (BLKWGU(Belkin) [On_Demand | Stopped])
DRV - [2003/02/28 17:13:58 | 00,042,624 | —- | M] (Accapella Ltd.) – C:\WINDOWS\System32\DRIVERS\CoachUsb.sys – (CoachUsb [On_Demand | Stopped])
DRV - [2003/01/25 00:12:20 | 00,046,048 | —- | M] (Accapella Ltd.) – C:\WINDOWS\System32\DRIVERS\CoachVc.sys – (CoachVc [On_Demand | Stopped])
DRV - [2003/05/01 13:26:34 | 00,005,220 | —- | M] (Cisco Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\CVirtA.sys – (CVirtA [On_Demand | Stopped])
DRV - [2004/08/22 16:31:10 | 00,155,136 | —- | M] ( ) – C:\WINDOWS\System32\DRIVERS\d347bus.sys – (d347bus [Boot | Running])
DRV - [2004/08/22 16:31:48 | 00,005,248 | —- | M] ( ) – C:\WINDOWS\System32\Drivers\d347prt.sys – (d347prt [Boot | Running])
DRV - [2009/02/17 13:11:30 | 00,024,232 | —- | M] (Elaborate Bytes AG) – C:\WINDOWS\System32\Drivers\ElbyCDIO.sys – (ElbyCDIO [System | Running])
DRV - [2004/09/22 21:00:00 | 00,008,320 | —- | M] (Network Associates, Inc) – C:\WINDOWS\system32\drivers\EntDrv51.sys – (EntDrv51 [On_Demand | Stopped])
DRV - [2009/02/25 20:22:12 | 00,008,704 | —- | M] () – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv [On_Demand | Stopped])
DRV - [2009/02/25 20:22:12 | 00,003,072 | —- | M] () – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv [On_Demand | Stopped])
DRV - [2003/12/02 22:23:20 | 00,142,336 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys – (fasttx2k [Boot | Running])
DRV - [2003/11/12 05:41:00 | 00,041,984 | —- | M] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\DRIVERS\fetnd5b.sys – (FETNDISB [On_Demand | Running])
DRV - [2006/09/19 16:44:04 | 00,015,664 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [2004/12/14 12:07:44 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Running])
DRV - [2004/12/14 12:07:44 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
DRV - [2004/12/14 12:07:44 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Running])
DRV - [2004/02/10 22:17:06 | 00,681,469 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Stopped])
DRV - [2004/08/04 02:09:58 | 00,051,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\msdv.sys – (MSDV [On_Demand | Stopped])
DRV - [2004/09/22 21:00:00 | 00,108,256 | —- | M] (Network Associates, Inc.) – C:\WINDOWS\system32\drivers\naiavf5x.sys – (NaiAvFilter1 [On_Demand | Stopped])
DRV - [2004/09/22 21:00:00 | 00,058,048 | —- | M] (Network Associates, Inc.) – C:\WINDOWS\system32\drivers\mvstdi5x.sys – (NaiAvTdi1 [System | Running])
DRV - [2004/11/19 05:00:00 | 00,072,712 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041119.003\NAVENG.SYS – (NAVENG [On_Demand | Running])
DRV - [2004/11/19 05:00:00 | 00,629,544 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041119.003\NAVEX15.SYS – (NAVEX15 [On_Demand | Running])
DRV - [2003/04/04 16:07:20 | 00,030,336 | —- | M] (Politecnico di Torino) – C:\WINDOWS\system32\drivers\npf.sys – (NPF [On_Demand | Stopped])
DRV - [2005/01/04 05:43:08 | 00,004,682 | —- | M] (INCA Internet Co., Ltd.) – C:\WINDOWS\System32\npptNT2.sys – (NPPTNT2 [System | Running])
DRV - [2004/08/04 01:29:54 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2009/03/23 17:15:25 | 00,047,360 | —- | M] (VSO Software) – C:\WINDOWS\System32\Drivers\Pcouffin.sys – (Pcouffin [On_Demand | Running])
DRV - [2003/09/19 04:47:00 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc [On_Demand | Running])
DRV - [2002/07/30 01:43:50 | 00,023,808 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\System32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Running])
DRV - [2003/08/15 22:10:32 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/07 19:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2002/10/04 21:04:10 | 00,046,976 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2003/12/04 18:22:30 | 00,308,416 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\SAVRT.SYS – (SAVRT [System | Running])
DRV - [2003/12/04 18:22:30 | 00,037,056 | —- | M] (Symantec Corporation) – c:\Program Files\Norton AntiVirus\SAVRTPEL.SYS – (SAVRTPEL [System | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [Auto | Running])
DRV - [2004/01/02 23:20:40 | 00,432,000 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys – (SiS315 [On_Demand | Stopped])
DRV - [2003/07/18 20:58:20 | 00,036,992 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys – (SISAGP [Boot | Running])
DRV - [2004/01/03 00:05:48 | 00,011,520 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\srvkp.sys – (SiSkp [System | Running])
DRV - [2004/12/20 19:58:18 | 00,110,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\SYMEVENT.SYS – (SymEvent [On_Demand | Running])
DRV - [2005/01/21 23:31:48 | 00,026,424 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV [On_Demand | Stopped])
DRV - [2005/01/21 23:31:50 | 00,267,384 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI [System | Running])
DRV - [2008/06/03 15:35:32 | 00,102,664 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
DRV - [2004/08/04 02:04:32 | 00,012,672 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\usb8023.sys – (USB_RNDIS_XP [On_Demand | Running])
DRV - [2003/07/02 15:42:00 | 00,027,904 | —- | M] (VIA Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys – (viaagp1 [Boot | Running])
DRV - [2004/12/07 20:08:58 | 00,172,672 | —- | M] (Copyright © VIA/S3 Graphics Co, Ltd.) – C:\WINDOWS\System32\DRIVERS\vtmini.sys – (viagfx [On_Demand | Running])
DRV - [2004/10/25 13:40:58 | 00,017,664 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\WINDOWS\System32\Drivers\ZDPSp50.sys – (ZDPSp50 [On_Demand | Stopped])
DRV - [2008/04/04 01:53:31 | 00,004,960 | —- | M] (GRISOFT, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdi.sys – ({8applayrver [Disabled | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://broadband.zoomtown.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://broadband.zoomtown.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/10 14:21:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 21:56:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 21:56:43 | 00,000,000 | —D | M]
[2009/01/18 11:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/01/18 11:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/27 22:29:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\0wqhwt4c.a\extensions
[2008/09/18 14:20:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\0wqhwt4c.a\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2008/09/03 13:30:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\0wqhwt4c.a\extensions\[removed]
[2008/09/01 22:30:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions
[2006/01/24 19:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\{7E77F5DF-8022-40e3-9122-F03DEBEFC43B}
[2007/04/15 21:09:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\{9d1f059c-cada-4111-9696-41a62d64e3ba}
[2007/03/03 03:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\{fd048119-78ee-487f-8fb1-1668d3a6859b}
[2008/05/18 23:33:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\[removed]
[2008/05/28 14:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\6trvxeg1.default\extensions\[removed]
[2008/08/28 08:15:28 | 00,001,412 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\6trvxeg1.default\searchplugins\bittorrent.xml
[2009/04/27 22:29:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/28 21:56:43 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/02/23 01:35:29 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2008/04/05 15:01:42 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/02/10 14:23:03 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/28 21:56:06 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 21:56:06 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/01/18 11:43:01 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/18 11:43:02 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/01/18 11:43:02 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/18 11:43:02 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/18 11:43:02 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/18 11:43:02 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/18 11:43:02 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)
O4 - HKLM..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc.)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KBD.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" (Seagate LLC)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" (Nero AG)
O4 - HKCU..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" (www.BitComet.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://activation.rr.com/install/downloads/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02}
http://housecall-beta.trendmicro.com/housecall/xscan60.cab (HouseCall Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} http://www.webshots.com/samplers/WSDownloader.ocx (WSDownloader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1184020652671 (MUWebControl Class)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab (HouseCall Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} http://community.webshots.com/html/WSPhotoUploader.CAB (Webshots Photo Uploader)
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab (HGPlugin7USA Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6}
http://chat.msn.com/controls/msnchat45.cab (MSN Chat Control 4.5)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/02 15:55:20 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 14:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/10 11:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2007/08/09 11:10:22 | 00,001,868 | R— | M] () - G:\Autorun.inf – [ CDFS ]
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Info.exe – [2002/09/10 05:54:58 | 00,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/05/02 00:39:26 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/22 23:50:47 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/04/22 23:43:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\DVDFab
[2009/04/22 23:43:07 | 00,000,000 | —D | C] – C:\Program Files\DVDFab 5
[2009/04/22 14:44:15 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts
[2009/04/22 14:42:01 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Performance
[2009/04/22 14:38:20 | 00,000,000 | —D | C] – C:\Program Files\Defraggler
[2009/04/22 12:12:24 | 00,257,865 | —- | C] () – C:\Documents and Settings\Owner\Desktop\cc_20090422_1212.reg
[2009/04/21 16:50:13 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/04/20 19:03:47 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/20 19:03:13 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/04/20 16:55:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\AnyDVDHD
[2009/04/20 13:55:01 | 00,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/04/20 13:55:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2009/04/20 13:54:25 | 00,000,000 | —D | C] – C:\Program Files\SlySoft
[2009/04/19 20:33:25 | 01,228,854 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OrbError.bmp
[2009/04/19 19:48:39 | 00,001,132 | RH– | C] () – C:\WINDOWS\EPMBatch.ept
[2009/04/19 19:42:24 | 01,907,712 | —- | C] () – C:\WINDOWS\System32\BootMan.exe
[2009/04/19 19:42:24 | 00,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2009/04/19 19:42:23 | 00,086,408 | —- | C] () – C:\WINDOWS\System32\setupempdrv03.exe
[2009/04/19 19:42:23 | 00,008,704 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2009/04/19 19:42:23 | 00,003,072 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/04/19 19:41:58 | 00,000,000 | —D | C] – C:\Program Files\EASEUS
[2009/04/19 17:23:33 | 00,088,064 | -HS- | C] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2009/04/19 13:09:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\External
[2009/04/15 21:06:00 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 21:05:59 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/15 21:05:56 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 21:05:55 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 21:05:53 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 21:05:52 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:05:49 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 21:05:43 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 21:05:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 20:58:48 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/03/23 16:09:03 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/03/22 23:43:47 | 00,000,014 | —- | C] () – C:\WINDOWS\System32\systeminfo3.dll
[2009/03/10 01:24:03 | 00,000,039 | —- | C] () – C:\WINDOWS\Irremote.ini
[2006/05/01 19:40:14 | 00,000,026 | —- | C] () – C:\WINDOWS\dvdSanta.INI
[2005/12/05 00:24:24 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\CmdLineExt.dll
[2005/12/05 00:16:12 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/10/06 16:42:14 | 00,000,071 | —- | C] () – C:\WINDOWS\pex.INI
[2005/09/20 00:39:01 | 00,000,125 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2005/09/13 20:18:09 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/07/12 14:44:42 | 00,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2005/03/27 18:16:16 | 00,001,009 | R-S- | C] () – C:\WINDOWS\System32\TBPS.ini
[2005/03/26 23:23:13 | 00,000,070 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/02/17 04:12:54 | 00,025,157 | —- | C] () – C:\WINDOWS\RMAgentOutput.dll
[2005/02/17 04:12:00 | 00,126,976 | —- | C] () – C:\WINDOWS\dllTSCLIBMT.dll
[2005/02/16 18:55:49 | 00,001,597 | —- | C] () – C:\WINDOWS\HattrickPoli.INI
[2005/02/02 19:40:51 | 00,001,271 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/01/27 22:59:48 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2005/01/27 22:56:37 | 00,000,306 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/12/04 01:19:33 | 00,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2004/10/01 18:33:46 | 00,000,809 | —- | C] () – C:\WINDOWS\TSC.ini
[2004/09/21 10:19:04 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2004/09/21 10:18:46 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/09/09 20:32:19 | 00,155,136 | —- | C] ( ) – C:\WINDOWS\System32\drivers\d347bus.sys
[2004/09/09 20:32:19 | 00,005,248 | —- | C] ( ) – C:\WINDOWS\System32\drivers\d347prt.sys
[2004/09/06 16:04:52 | 00,000,069 | —- | C] () – C:\WINDOWS\DVDXCopy.INI
[2004/09/02 13:23:06 | 00,001,110 | —- | C] () – C:\WINDOWS\winamp.ini
[2004/08/31 10:38:37 | 00,010,646 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2004/08/25 12:29:48 | 00,000,045 | —- | C] () – C:\WINDOWS\FEGHMMN.ini
[2004/08/22 20:23:06 | 00,053,760 | —- | C] () – C:\WINDOWS\System32\ZLIB.DLL
[2004/08/22 17:10:47 | 00,139,104 | —- | C] () – C:\WINDOWS\System32\CSGina.dll
[2004/08/22 17:04:56 | 00,069,120 | —- | C] () – C:\WINDOWS\daemon.dll
[2004/07/12 17:07:21 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/06/12 15:43:39 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/06/12 15:43:39 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/06/12 15:43:39 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/06/12 15:43:39 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/06/12 15:43:39 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/06/12 15:43:39 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/06/06 12:53:42 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/06/05 12:56:16 | 00,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/04/03 02:35:49 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2004/04/03 02:35:48 | 00,000,451 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2004/04/02 22:57:39 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/04/02 19:08:49 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/04/02 19:08:20 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/04/02 19:08:20 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/04/02 19:03:06 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/04/02 18:47:59 | 00,027,754 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/04/02 18:47:19 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/04/02 18:31:02 | 00,000,453 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/04/02 18:22:10 | 00,000,907 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/04/02 17:40:20 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/04/02 16:54:44 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/04/02 16:54:44 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/04/02 16:54:16 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/04/02 15:59:40 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/04/02 14:42:06 | 00,000,553 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/04/02 14:41:43 | 00,000,792 | —- | C] () – C:\WINDOWS\win.ini
[2004/04/02 14:41:40 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2004/03/23 16:38:00 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2004/01/24 03:33:14 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/11/01 16:17:50 | 00,000,256 | —- | C] () – C:\WINDOWS\aucfg.ini
[2002/07/04 15:05:34 | 00,000,269 | —- | C] () – C:\WINDOWS\tmupdate.ini
[2002/03/02 05:10:02 | 00,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2001/12/14 14:34:46 | 00,164,864 | —- | C] () – C:\WINDOWS\patchw32.dll
[1999/07/23 14:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
========== Files - Modified Within 30 Days ==========
[6 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/05/02 12:34:19 | 00,000,186 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2009/05/02 12:18:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/02 12:18:26 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\desktop.ini
[2009/05/02 12:18:16 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/02 12:17:32 | 46,929,1008 | -HS- | M] () – C:\hiberfil.sys
[2009/05/02 00:39:29 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/05/01 23:58:16 | 00,000,530 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
[2009/04/30 14:23:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/28 21:51:17 | 00,000,559 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Shortcut to Downloads.lnk
[2009/04/24 01:03:48 | 00,000,040 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2009/04/22 14:48:10 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/22 14:21:53 | 00,000,792 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/22 14:21:53 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/04/22 14:21:53 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/22 12:12:46 | 00,257,865 | —- | M] () – C:\Documents and Settings\Owner\Desktop\cc_20090422_1212.reg
[2009/04/20 17:25:51 | 00,000,039 | —- | M] () – C:\WINDOWS\Irremote.ini
[2009/04/20 12:23:27 | 00,549,846 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/20 12:23:27 | 00,459,360 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/20 12:23:27 | 00,079,672 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/20 02:05:49 | 00,010,646 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/04/19 21:30:02 | 01,228,854 | —- | M] () – C:\Documents and Settings\All Users\Application Data\OrbError.bmp
[2009/04/19 20:13:31 | 00,001,132 | RH– | M] () – C:\WINDOWS\EPMBatch.ept
[2009/04/19 17:24:03 | 00,088,064 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 10:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
========== LOP Check ==========
[2009/04/22 23:50:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/03 16:56:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2006/09/21 15:05:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/04/04 02:01:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg7
[2009/03/10 13:26:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/03/22 23:42:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVDXStudio
[2008/04/04 01:52:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2005/10/02 03:26:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2004/09/21 23:38:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macrovision
[2008/07/17 21:45:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/15 14:34:43 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/04/02 19:06:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2009/04/21 16:56:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2005/02/25 11:37:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Network Associates
[2008/12/02 16:09:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2008/08/08 13:16:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Outspark
[2006/05/09 14:06:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2005/10/10 15:44:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/04/02 16:00:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/03/29 15:07:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/04/20 13:55:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2005/10/11 16:37:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/04/22 14:26:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/03/07 21:37:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2004/04/02 22:43:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/05/25 21:59:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/24 12:57:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2005/09/20 14:46:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2004/09/26 16:57:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/22 23:50:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2007/07/09 18:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/03/23 17:16:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data
[2008/09/15 22:09:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2008/09/04 14:24:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2006/04/10 00:31:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/02/18 05:17:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2009/04/22 10:55:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG7
[2005/03/08 00:21:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\drms
[2004/09/26 20:22:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2004/04/02 15:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2004/09/06 16:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2004/09/12 17:39:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Jasc
[2004/09/27 02:18:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lavasoft
[2004/08/21 19:11:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2009/03/24 16:19:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\log
[2004/09/08 20:22:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2008/07/17 21:46:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2008/09/04 14:44:08 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2005/03/27 17:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2008/05/22 14:01:03 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2009/01/18 11:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2009/04/21 17:11:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nero
[2005/10/12 00:26:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NetMedia Providers
[2006/07/26 00:28:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\NHN Corporation
[2006/05/09 14:19:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Propellerhead Software
[2004/08/28 00:59:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Publish Providers
[2008/04/04 15:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Real
[2004/04/02 19:24:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2005/12/05 00:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SecuROM
[2004/08/21 19:11:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sonic
[2005/10/12 00:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony
[2004/04/02 17:11:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2004/04/02 22:42:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Symantec
[2005/04/08 21:47:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Talkback
[2005/10/06 16:41:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ulead Systems
[2009/04/29 02:40:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso
[2005/02/17 00:00:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/11/14 23:36:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Webshots
[2009/04/30 14:23:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2003/08/16 12:14:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/01 23:58:16 | 00,000,530 | —- | M] () – C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job
[2009/05/02 12:18:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2005/02/23 01:40:31 | 00,000,364 | —- | M] () – C:\WINDOWS\Tasks\Symantec NetDetect.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:9F128BAA51D65A77
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:02C77207
< End of report >