Here is the 1st post.
OTListIt logfile created on: 5/14/2009 3:13:45 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.7 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
447.48 Mb Total Physical Memory | 120.90 Mb Available Physical Memory | 27.02% Memory free
1.03 Gb Paging File | 0.63 Gb Available in Paging File | 61.35% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.10 Gb Total Space | 124.43 Gb Free Space | 86.96% Space Free | Partition Type: NTFS
Drive D: | 5.94 Gb Total Space | 2.12 Gb Free Space | 35.64% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-AT5QGAAC3Z
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2007/10/18 10:24:46 | 00,801,296 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
PRC - [2007/10/18 10:24:44 | 00,145,936 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
PRC - [2008/06/24 19:10:30 | 00,281,104 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
PRC - [2007/10/18 10:24:46 | 01,010,192 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
PRC - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2007/08/20 13:27:26 | 00,144,960 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
PRC - [2008/10/10 05:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2007/01/04 12:10:22 | 00,280,080 | —- | M] (CA, Inc.) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
PRC - [2007/08/20 13:36:42 | 00,242,952 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
PRC - [2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2008/04/13 19:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/04/10 17:41:20 | 00,181,488 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
PRC - [2002/10/16 18:57:10 | 00,081,920 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\system32\ps2.exe
PRC - [2005/06/07 00:46:24 | 00,057,344 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
PRC - [2007/08/31 14:01:21 | 01,037,736 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2009/03/12 20:56:58 | 00,342,312 | —- | M] (Apple Inc.) – C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/04/10 17:41:19 | 00,177,392 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
PRC - [2009/04/10 17:36:41 | 00,014,088 | —- | M] (CA) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
PRC - [2007/08/20 13:36:38 | 00,230,664 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
PRC - [2009/04/10 17:41:20 | 00,173,296 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
PRC - [2005/11/10 14:03:52 | 00,036,975 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
PRC - [2007/08/31 13:58:50 | 00,357,800 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
PRC - [2009/04/10 17:41:19 | 00,214,256 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
PRC - [2007/08/16 21:10:14 | 00,218,376 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
PRC - [2009/03/12 20:56:52 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe
PRC - [2007/08/16 21:10:16 | 00,189,704 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
PRC - [2007/01/19 13:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe
PRC - [2009/05/14 15:12:20 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2009/03/06 00:04:30 | 00,132,424 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/04/10 17:41:19 | 00,214,256 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe – (CaCCProvSP [On_Demand | Running])
SRV - [2007/08/20 13:27:26 | 00,144,960 | —- | M] (Computer Associates International, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe – (CAISafe [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/04/13 19:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/04/04 01:41:10 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [Disabled | Stopped])
SRV - [2008/10/10 05:45:26 | 00,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService [Auto | Running])
SRV - [2009/03/12 20:56:52 | 00,656,168 | —- | M] (Apple Inc.) – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service [On_Demand | Running])
SRV - [2007/01/04 12:10:22 | 00,280,080 | —- | M] (CA, Inc.) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe – (ITMRTSVC [Auto | Running])
SRV - [2001/08/06 07:41:48 | 00,028,672 | —- | M] () – C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe – (nhksrv [Disabled | Stopped])
SRV - [2003/07/28 22:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2004/09/29 12:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\System32\HPZipm12.exe – (Pml Driver HPZ12 [Disabled | Stopped])
SRV - [2007/08/16 21:10:16 | 00,189,704 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe – (PPCtlPriv [On_Demand | Running])
SRV - [2007/10/18 10:24:46 | 01,010,192 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe – (UmxAgent [Auto | Running])
SRV - [2007/10/18 10:24:46 | 00,801,296 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe – (UmxCfg [Auto | Running])
SRV - [2007/10/18 10:24:44 | 00,145,936 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe – (UmxFwHlp [Auto | Running])
SRV - [2008/06/24 19:10:30 | 00,281,104 | —- | M] (CA) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe – (UmxPol [Auto | Running])
SRV - [2007/01/19 13:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc [On_Demand | Running])
SRV - [2007/08/20 13:36:42 | 00,242,952 | —- | M] (CA, Inc.) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe – (VETMSGNT [Auto | Running])
SRV - [2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])
SRV - [2006/11/03 19:19:58 | 00,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend [Auto | Running])
SRV - [2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2004/10/07 20:16:04 | 00,035,840 | —- | M] (Oak Technology Inc.) – C:\WINDOWS\System32\drivers\AFS2K.SYS – (AFS2K [System | Running])
DRV - [2005/03/04 12:02:20 | 01,066,278 | —- | M] (Agere Systems) – C:\WINDOWS\System32\DRIVERS\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
DRV - [2003/12/12 09:54:14 | 00,391,424 | —- | M] (Sensaura Ltd) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS [On_Demand | Stopped])
DRV - [2004/10/01 10:24:02 | 02,279,424 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2003/12/02 21:23:20 | 00,142,336 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys – (fasttx2k [Boot | Running])
DRV - [2004/12/16 14:36:30 | 00,042,496 | —- | M] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\DRIVERS\fetnd5bv.sys – (FETND5BV [On_Demand | Running])
DRV - [2003/01/16 02:05:54 | 00,041,984 | —- | M] (VIA Technologies, Inc. ) – C:\WINDOWS\System32\DRIVERS\fetnd5b.sys – (FETNDISB [On_Demand | Stopped])
DRV - [2009/01/15 12:19:36 | 00,023,848 | —- | M] (GEAR Software Inc.) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys – (GEARAspiWDM [On_Demand | Running])
DRV - [1998/07/01 01:55:56 | 00,052,800 | —- | M] () – C:\WINDOWS\System32\drivers\HPFECP16.SYS – (HPFECP16 [Auto | Stopped])
DRV - [2004/12/14 11:07:44 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Running])
DRV - [2004/12/14 11:07:44 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
DRV - [2004/12/14 11:07:44 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Running])
DRV - [2003/11/20 19:25:14 | 00,095,579 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Stopped])
DRV - [2008/06/24 19:08:36 | 00,063,504 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxagent.sys – (KmxAgent [System | Running])
DRV - [2008/06/24 19:08:42 | 00,134,648 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxCF.sys – (KmxCF [Auto | Running])
DRV - [2008/06/24 19:08:42 | 00,088,816 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxcfg.sys – (KmxCfg [On_Demand | Running])
DRV - [2008/06/24 19:08:46 | 00,045,584 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxFile.sys – (KmxFile [System | Running])
DRV - [2008/06/24 19:08:52 | 00,115,216 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxfw.sys – (KmxFw [System | Running])
DRV - [2008/06/24 19:08:56 | 00,066,576 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\KmxSbx.sys – (KmxSbx [Auto | Running])
DRV - [2008/06/24 19:08:58 | 00,093,712 | —- | M] (CA) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys – (KmxStart [Boot | Running])
DRV - [2007/04/11 15:32:30 | 00,020,496 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys – (L8042Kbd [On_Demand | Running])
DRV - [2007/01/23 16:44:00 | 00,062,992 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\DRIVERS\L8042mou.Sys – (L8042mou [On_Demand | Stopped])
DRV - [2007/04/11 15:32:52 | 00,034,832 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys – (LHidFilt [On_Demand | Running])
DRV - [2006/03/28 18:56:06 | 00,027,008 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\DRIVERS\LHidKE.Sys – (LHidKe [On_Demand | Stopped])
DRV - [2006/03/28 18:55:20 | 00,036,736 | —- | M] (Logitech, Inc.) – C:\WINDOWS\System32\Drivers\LHidUsbK.Sys – (LHidUsbK [On_Demand | Running])
DRV - [2007/04/11 15:32:58 | 00,036,112 | —- | M] (Logitech, Inc.) – C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys – (LMouFilt [On_Demand | Running])
DRV - [2007/01/23 16:45:00 | 00,078,864 | —- | M] (Logitech Inc.) – C:\WINDOWS\system32\DRIVERS\LMouKE.Sys – (LMouKE [On_Demand | Stopped])
DRV - [2007/01/23 16:45:00 | 00,028,176 | —- | M] (Logitech, Inc.) – C:\WINDOWS\System32\Drivers\LUsbFilt.Sys – (LUsbFilt [On_Demand | Stopped])
DRV - [2001/12/20 10:02:12 | 00,006,656 | —- | M] (Netropa Corporation) – C:\WINDOWS\System32\DRIVERS\msikbd2k.sys – (msikbd2k [System | Running])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2003/09/03 02:51:00 | 00,021,120 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp [Boot | Running])
DRV - [2003/09/19 01:47:00 | 00,010,368 | —- | M] (Padus, Inc.) – C:\WINDOWS\system32\drivers\pfc.sys – (Pfc [On_Demand | Running])
DRV - [2007/08/21 03:12:59 | 00,021,760 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\point32.sys – (Point32 [On_Demand | Running])
DRV - [1997/04/09 16:08:24 | 00,085,868 | —- | M] (Silitek Corporation.) – C:\WINDOWS\System32\drivers\ppclass.sys – (PPCLASS [Auto | Running])
DRV - [1998/02/20 14:37:10 | 00,115,136 | —- | M] (Shuttle Technology.) – C:\WINDOWS\System32\drivers\ppscan.sys – (PPSCAN [Auto | Stopped])
DRV - [2001/06/04 16:00:00 | 00,014,112 | —- | M] (Hewlett-Packard Company) – C:\WINDOWS\System32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Stopped])
DRV - [2003/03/31 14:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2005/08/30 19:45:08 | 00,020,576 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2002/10/04 20:04:10 | 00,046,976 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS – (rtl8139 [On_Demand | Stopped])
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/12/06 05:13:42 | 00,429,440 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys – (SiS315 [On_Demand | Stopped])
DRV - [2003/07/18 19:58:20 | 00,036,992 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys – (SISAGP [Boot | Running])
DRV - [2003/12/05 19:25:54 | 00,011,392 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\System32\DRIVERS\srvkp.sys – (SiSkp [System | Running])
DRV - [2003/11/10 11:24:24 | 00,039,532 | —- | M] (Alcor Micro Corp.) – C:\WINDOWS\System32\Drivers\sunkfilt.sys – (SunkFilt [On_Demand | Stopped])
DRV - [2006/12/15 21:09:16 | 00,010,344 | —- | M] (Symantec Corporation) – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd [Auto | Running])
DRV - [2009/03/05 23:59:00 | 00,036,864 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\Drivers\usbaapl.sys – (USBAAPL [On_Demand | Stopped])
DRV - [2007/08/20 13:38:16 | 00,026,376 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys – (VET-FILT [System | Running])
DRV - [2007/08/20 13:38:16 | 00,021,128 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys – (VET-REC [System | Running])
DRV - [2009/04/10 17:41:19 | 00,108,368 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys – (VETEBOOT [On_Demand | Running])
DRV - [2009/04/10 17:41:19 | 00,880,560 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys – (VETEFILE [System | Running])
DRV - [2007/08/20 13:38:20 | 00,021,512 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys – (VETFDDNT [System | Running])
DRV - [2007/08/20 13:38:22 | 00,032,264 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys – (VETMONNT [System | Running])
DRV - [2003/07/02 14:42:00 | 00,027,904 | —- | M] (VIA Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys – (viaagp1 [Boot | Running])
DRV - [2004/12/07 21:08:58 | 00,172,672 | —- | M] (Copyright © VIA/S3 Graphics Co, Ltd.) – C:\WINDOWS\System32\DRIVERS\vtmini.sys – (viagfx [On_Demand | Running])
DRV - [2003/01/10 17:13:04 | 00,033,588 | —- | M] (America Online, Inc.) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys – (wanatw [On_Demand | Stopped])
DRV - [2003/11/20 19:26:20 | 00,122,110 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmsbw.sys – ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped])
DRV - [2003/11/20 19:26:12 | 00,099,002 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\ialmkchw.sys – ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/06 20:09:41 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/06 20:09:41 | 00,000,000 | —D | M]
[2008/08/26 22:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/08/26 22:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/13 19:58:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\emd7utl7.default\extensions
[2008/09/23 19:23:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\emd7utl7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/04/25 10:58:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\emd7utl7.default\extensions\[removed]
[2008/08/26 22:17:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/29 23:56:01 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/29 23:55:49 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/29 23:55:49 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/08/26 22:16:45 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/08/26 22:16:45 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/08/26 22:16:45 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/13 01:10:20 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/08/26 22:16:45 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/07/30 09:02:12 | 00,000,897 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\livecom.png
[2008/07/30 09:02:12 | 00,001,015 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\livecom.src
[2008/08/26 22:16:45 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/08/26 22:16:45 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: () - - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl (CA, Inc.)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" (CA, Inc.)
O4 - HKLM..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" (CA, Inc.)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE (Logitech Inc.)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" (CA)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - Reg Error: Key error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\system32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 82 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3}
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/3/9…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9}
http://download.microsoft.com/download/0/5…b?1090196253562 (MSSecurityAdvisor Class)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3}
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0}
http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab (CBankshotZoneCtrl Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444223240000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B}
http://ndormail01.dor.state.ne.us/dwa7W.cab (Domino Web Access 7 Control)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\system32\UmxWnp.Dll (CA)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/20 20:16:37 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 03:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{2cee5c98-fca8-11da-8471-000ea6959c2c}\Shell\AutoRun\command - "" = L:\
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/05/14 15:09:21 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/05/12 16:50:27 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/05/12 16:46:31 | 00,389,632 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/05/12 16:11:04 | 76,658,072 | —- | C] () – C:\Documents and Settings\Owner\Desktop\jdk-6u13-windows-i586-p.1.2D0D17.efw
[2009/05/06 20:09:44 | 00,202,072 | R— | C] (Coupons, Inc.) – C:\WINDOWS\cpnprt2.cid
[2009/05/06 20:09:43 | 00,202,072 | —- | C] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2009/05/03 23:58:06 | 00,001,745 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/05/03 23:58:06 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/03 21:45:29 | 00,000,000 | -HSD | C] – C:\WINDOWS\ftpcache
[2009/05/03 21:25:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/05/03 21:25:38 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/03 21:25:38 | 00,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/03 21:25:36 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/03 21:25:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/03 21:25:34 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/03 21:11:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/05/03 21:01:32 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/24 19:42:49 | 00,001,533 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Freecell.lnk
[2009/04/24 16:36:27 | 00,000,859 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Monte Carlo Patience.lnk
[2009/04/24 16:36:13 | 00,001,502 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Solitaire.lnk
[2009/04/16 18:13:11 | 00,075,954 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/04/16 18:13:11 | 00,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/04/15 00:35:32 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 00:35:32 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 00:35:31 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 00:35:31 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 00:35:30 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 00:35:29 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 00:35:28 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/15 00:35:28 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 00:35:27 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 00:34:20 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/15 00:34:19 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/15 00:34:18 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2008/11/12 18:18:58 | 00,223,232 | —- | C] () – C:\WINDOWS\System32\sqlite3.dll
[2007/10/02 17:36:33 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/06/12 20:11:42 | 00,000,010 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/03/22 10:24:11 | 00,000,000 | —- | C] () – C:\WINDOWS\EAREMOVE.INI
[2006/01/12 20:03:00 | 00,000,000 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/01/12 20:02:55 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\msiosd32.dll
[2006/01/12 20:02:55 | 00,000,245 | —- | C] () – C:\WINDOWS\Msiosd.ini
[2005/10/14 18:06:05 | 00,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2005/03/12 10:21:24 | 00,001,175 | —- | C] () – C:\WINDOWS\System32\imbrmute.ini
[2005/02/13 21:24:52 | 00,000,144 | —- | C] () – C:\WINDOWS\MVPHEART.INI
[2005/02/13 00:27:46 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/01/20 17:17:43 | 00,000,123 | —- | C] () – C:\WINDOWS\MVPEUCHR.INI
[2005/01/14 18:16:05 | 00,000,048 | —- | C] () – C:\WINDOWS\PerWin.ini
[2005/01/11 21:34:12 | 00,000,271 | —- | C] () – C:\WINDOWS\MVPBR.INI
[2005/01/02 15:46:56 | 00,000,176 | —- | C] () – C:\WINDOWS\MVPSPADE.INI
[2005/01/01 00:50:16 | 00,000,596 | —- | C] () – C:\WINDOWS\MVPCRIB.INI
[2004/12/27 18:30:37 | 00,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/12/12 21:50:41 | 00,000,050 | —- | C] () – C:\WINDOWS\upst.ini
[2004/11/19 19:13:17 | 00,000,078 | —- | C] () – C:\WINDOWS\qwimp.ini
[2004/11/19 19:13:16 | 00,000,509 | —- | C] () – C:\WINDOWS\intuprof.ini
[2004/10/08 20:47:12 | 00,000,061 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/17 18:37:42 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2004/08/29 16:18:34 | 00,000,190 | —- | C] () – C:\WINDOWS\er2.ini
[2004/07/31 20:31:24 | 00,004,224 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/07/30 16:04:13 | 00,000,049 | —- | C] () – C:\WINDOWS\upth.ini
[2004/07/30 16:04:13 | 00,000,030 | —- | C] () – C:\WINDOWS\atid.ini
[2004/06/15 16:26:59 | 00,000,068 | —- | C] () – C:\WINDOWS\Prestopm.INI
[2004/06/07 18:07:25 | 00,002,334 | —- | C] () – C:\WINDOWS\vista32d.ini
[2004/06/07 17:53:47 | 00,000,231 | —- | C] () – C:\WINDOWS\ppdrv.ini
[2004/05/23 20:07:07 | 00,000,103 | —- | C] () – C:\WINDOWS\pmw.INI
[2004/05/23 10:23:55 | 00,000,138 | —- | C] () – C:\WINDOWS\HPFTBX16.INI
[2004/05/23 10:09:53 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/05/23 10:09:53 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/05/23 10:09:53 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/05/23 10:09:53 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/05/23 10:09:53 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/05/23 10:09:53 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/05/22 18:19:06 | 00,036,352 | —- | C] () – C:\WINDOWS\UTHUNK32.DLL
[2004/05/22 18:05:04 | 00,000,775 | —- | C] () – C:\WINDOWS\OPLIMIT.INI
[2004/05/22 18:04:29 | 00,000,602 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2004/05/22 17:48:54 | 00,000,189 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2004/05/22 17:47:44 | 00,000,512 | —- | C] () – C:\WINDOWS\ALBUM.INI
[2004/05/22 17:47:44 | 00,000,103 | —- | C] () – C:\WINDOWS\PAEDIT.INI
[2004/01/22 12:00:28 | 00,012,635 | —- | C] () – C:\WINDOWS\System32\DAntivirus.ini
[2004/01/22 04:26:02 | 00,000,451 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2004/01/21 05:04:38 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/01/21 04:52:52 | 00,002,142 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2004/01/20 23:08:05 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/01/20 23:07:21 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/01/20 23:07:21 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/01/20 23:02:24 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/01/20 22:56:41 | 00,030,197 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/01/20 22:56:16 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2004/01/20 22:55:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/01/20 22:42:36 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/01/20 22:34:02 | 00,000,994 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/01/20 21:21:37 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/01/20 20:47:52 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/01/20 20:38:07 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/01/20 20:38:07 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/01/20 20:37:39 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/01/20 20:20:37 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/01/20 19:05:12 | 00,000,466 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/01/20 19:04:50 | 00,000,733 | —- | C] () – C:\WINDOWS\win.ini
[2004/01/20 19:04:46 | 00,000,262 | —- | C] () – C:\WINDOWS\system.ini
[2003/03/07 01:53:16 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\hpnvr82.dll
[2003/01/08 01:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1998/07/01 02:40:30 | 00,003,782 | —- | C] () – C:\WINDOWS\System32\HPFlnk16.ini
[1998/07/01 02:23:58 | 00,007,680 | —- | C] () – C:\WINDOWS\System32\HPFhrl16.dll
[1998/07/01 02:23:56 | 00,249,856 | —- | C] () – C:\WINDOWS\System32\HPFsrl16.dll
[1998/07/01 02:23:50 | 00,260,096 | —- | C] () – C:\WINDOWS\System32\HPFmrl16.dll
[1998/07/01 02:23:46 | 01,113,088 | —- | C] () – C:\WINDOWS\System32\HPFtrl16.dll
[1998/07/01 02:20:56 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\HPFstb16.dll
[1998/07/01 02:20:48 | 00,193,536 | —- | C] () – C:\WINDOWS\System32\HPFcps16.dll
[1998/07/01 02:20:20 | 00,076,800 | —- | C] () – C:\WINDOWS\System32\HPF24r16.dll
[1998/07/01 02:19:08 | 00,044,544 | —- | C] () – C:\WINDOWS\System32\HPFtst16.dll
[1998/07/01 02:17:26 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\HPFpcl16.dll
[1998/07/01 02:15:18 | 00,163,328 | —- | C] () – C:\WINDOWS\System32\HPFntu16.dll
[1998/07/01 02:10:40 | 00,395,264 | —- | C] () – C:\WINDOWS\System32\HPFui16.dll
[1998/07/01 02:04:14 | 00,266,752 | —- | C] () – C:\WINDOWS\System32\HPFwin16.dll
[1998/07/01 02:00:18 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\HPFmon16.dll
[1998/07/01 01:59:40 | 00,033,280 | —- | C] () – C:\WINDOWS\System32\HPFcbl16.dll
[1998/07/01 01:57:42 | 00,022,528 | —- | C] () – C:\WINDOWS\System32\HPFnet16.dll
[1998/07/01 01:57:28 | 00,033,384 | —- | C] () – C:\WINDOWS\System32\HPFiop16.dll
[1998/07/01 01:57:16 | 00,069,284 | —- | C] () – C:\WINDOWS\System32\HPFpml16.dll
[1998/07/01 01:57:12 | 00,137,232 | —- | C] () – C:\WINDOWS\System32\HPFmlc16.dll
[1998/07/01 01:57:06 | 00,057,240 | —- | C] () – C:\WINDOWS\System32\HPFmem16.dll
[1998/07/01 01:57:00 | 00,048,292 | —- | C] () – C:\WINDOWS\System32\HPFlpm16.dll
[1998/07/01 01:56:48 | 00,072,368 | —- | C] () – C:\WINDOWS\System32\HPFcom16.dll
[1998/07/01 01:55:56 | 00,052,800 | —- | C] () – C:\WINDOWS\System32\drivers\HPFecp16.sys
[1998/07/01 01:55:08 | 00,029,184 | —- | C] () – C:\WINDOWS\System32\HPFrsu16.dll
[1998/07/01 01:54:38 | 00,117,760 | —- | C] () – C:\WINDOWS\System32\HPFrsa16.dll
[1998/07/01 01:50:12 | 01,777,664 | —- | C] () – C:\WINDOWS\System32\HPFimg16.dll
[1998/07/01 01:46:52 | 00,124,928 | —- | C] () – C:\WINDOWS\System32\HPFcnt16.dll
========== Files - Modified Within 30 Days ==========
[2009/05/14 15:12:20 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/05/14 02:19:25 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/13 23:03:57 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/13 23:03:21 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/13 23:03:19 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\desktop.ini
[2009/05/13 23:03:15 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/13 23:03:14 | 46,929,1008 | -HS- | M] () – C:\hiberfil.sys
[2009/05/13 23:02:37 | 00,075,954 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2009/05/13 23:02:37 | 00,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2009/05/13 18:44:15 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/12 17:00:55 | 00,000,591 | —- | M] () – C:\Documents and Settings\Owner\My Documents\My Sharing Folders.lnk
[2009/05/12 16:46:33 | 00,389,632 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTMoveIt3.exe
[2009/05/12 16:11:16 | 76,658,072 | —- | M] () – C:\Documents and Settings\Owner\Desktop\jdk-6u13-windows-i586-p.1.2D0D17.efw
[2009/05/10 18:53:48 | 00,000,514 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Owner at 5 36 PM.job
[2009/05/07 02:16:29 | 24,699,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/05/06 20:09:44 | 00,202,072 | R— | M] (Coupons, Inc.) – C:\WINDOWS\cpnprt2.cid
[2009/05/06 20:09:43 | 00,202,072 | —- | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2009/05/03 23:58:07 | 00,001,745 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/05/03 21:25:38 | 00,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/03 21:00:22 | 00,485,396 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/03 21:00:22 | 00,412,008 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/03 21:00:22 | 00,065,884 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/03 14:34:38 | 00,002,497 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2003.lnk
[2009/04/22 17:26:53 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/15 03:08:57 | 00,000,733 | —- | M] () – C:\WINDOWS\win.ini
========== LOP Check ==========
[2009/05/13 23:05:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/01 19:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008/07/21 19:42:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/23 00:39:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/03/20 13:56:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2008/01/23 00:42:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/12/05 22:47:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/12/29 02:16:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/18 14:19:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ascentive
[2004/05/22 17:34:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2004/05/22 17:34:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2009/04/10 17:56:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2009/02/11 22:31:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/09/27 11:41:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/07/14 00:00:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Gtek
[2004/01/20 21:41:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2005/08/27 20:05:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2009/03/08 13:54:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2008/07/07 16:42:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/07/25 20:15:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2009/05/03 21:25:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2006/06/12 13:51:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/06/12 13:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/06/14 20:36:59 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/01/20 23:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2004/05/14 18:16:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 5.0.0544
[2004/05/14 18:17:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/05/03 21:11:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/03/01 14:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2006/06/17 23:13:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pixelStorm
[2006/06/18 02:13:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2004/07/31 00:05:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2004/05/14 18:05:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/01/20 20:21:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/05/13 22:37:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/05/03 21:15:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/05/03 20:58:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/10/23 12:18:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/03/20 14:04:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/05/05 13:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/09/10 11:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2007/06/18 18:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/12/27 21:54:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/05/03 21:25:40 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Owner\Application Data
[2008/07/06 10:26:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2006/03/08 00:19:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeAUM
[2008/07/21 19:39:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2006/06/09 17:06:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AOL
[2005/11/03 19:08:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2009/03/25 00:33:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ascentive
[2008/01/10 22:56:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2008/08/26 13:36:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Google
[2006/09/05 17:56:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2005/04/14 12:52:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HP
[2008/01/07 18:40:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2007/03/12 12:55:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2006/06/12 22:43:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2004/05/15 14:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/30 12:30:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2005/10/04 13:52:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lavasoft
[2004/10/07 22:21:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2008/05/28 22:48:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LimeWire
[2007/01/13 16:07:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/05/03 21:25:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2004/12/27 21:06:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
[2008/07/30 09:02:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2004/05/24 08:52:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2008/05/08 17:14:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/08/26 22:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2007/03/01 15:50:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2005/12/24 21:11:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Musicmatch
[2007/04/22 16:08:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MySpace
[2006/05/20 20:34:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Raptisoft
[2006/03/23 11:02:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Real
[2004/01/20 23:29:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2004/10/07 22:22:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sonic
[2004/01/20 20:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2008/01/09 17:17:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SuperNZB
[2008/08/02 11:56:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2008/01/25 01:30:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2007/06/18 18:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Yahoo!
[2004/07/31 00:04:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\You've Got Pictures Screensaver
[2009/05/13 18:44:15 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/05/10 18:53:48 | 00,000,514 | —- | M] () – C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Owner at 5 36 PM.job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/01 15:49:12 | 00,000,290 | -H– | M] () – C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[2009/05/14 02:19:25 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/05/13 23:03:21 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 894 bytes -> C:\Documents and Settings\Owner\Desktop\Road Runner.url:favicon
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >