Here's the info you requested.
Thanks much
Blind Lemon
OTL Extras logfile created on: 6/24/2009 8:37:28 AM - Run 1
OTL by OldTimer - Version 3.0.5.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 51.73% Memory free
3.85 Gb Paging File | 3.26 Gb Available in Paging File | 84.70% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072E:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.34 Gb Total Space | 25.71 Gb Free Space | 23.95% Space Free | Partition Type: NTFS
Drive D: | 4.43 Gb Total Space | 0.53 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
Drive E: | 149.05 Gb Total Space | 108.36 Gb Free Space | 72.70% Space Free | Partition Type: NTFS
Drive F: | 298.01 Gb Total Space | 232.36 Gb Free Space | 77.97% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 65.94 Gb Total Space | 29.75 Gb Free Space | 45.12% Space Free | Partition Type: NTFS
Drive M: | 111.81 Gb Total Space | 56.68 Gb Free Space | 50.69% Space Free | Partition Type: NTFS
Drive O: | 243.98 Mb Total Space | 243.37 Mb Free Space | 99.75% Space Free | Partition Type: FAT
Computer Name: TKPGOLD
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] –
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.scr [@ = AutoCADScriptFile] – C:\WINDOWS\notepad.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"9000:TCP" = 9000:TCP:*:Enabled:SqueezeCenter 9000 tcp
"3483:UDP" = 3483:UDP:*:Enabled:SqueezeCenter 3483 udp
"3483:TCP" = 3483:TCP:*:Enabled:SqueezeCenter 3483 tcp
"137:TCP" = 137:TCP:*:Enabled:MacMachine
"138:TCP" = 138:TCP:*:Enabled:MacMachine2
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 (Microsoft Corporation)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe:*:Disabled:BackWeb-137903 ()
C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe:*:Enabled:Microsoft Flight Simulator (Microsoft Corporation)
C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server (Microsoft Corporation)
C:\Program Files\NETGEAR\Media Server\MediaServer.exe:*:Enabled:Digital 5 Streaming Media Application File not found
C:\Program Files\NETGEAR\Media Server\immsService.exe:*:Enabled:D5 Integrated Multimedia Server Service File not found
G:\Program Files\NETGEAR\Media Server\immsService.exe:*:Enabled:D5 Integrated Multimedia Server Service File not found
G:\Program Files\NETGEAR\Media Server\MediaServer.exe:*:Enabled:Media Server Application File not found
C:\Program Files\Hewlett-Packard\HP DeskJet 1220C Toolbox\HPW8TBX.exe:*:Enabled:Toolbox for HP Printing System for Windows File not found
C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe:*:Enabled:Dreamweaver MX (Macromedia, Inc.)
E:\Program Files\NETGEAR\Media Server\MediaServer.exe:*:Enabled:Media Server File not found
E:\Program Files\NETGEAR\Media Server\immsService.exe:*:Enabled:D5 Integrated Multimedia Server Service File not found
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Computer, Inc.)
C:\Program Files\Macromedia\Flash MX\Flash.exe:*:Enabled:Flash 6.0 r25 (Macromedia, Inc.)
C:\Program Files\WS_FTP Pro\FTP95PRO.EXE:*:Enabled:FTP95PRO.EXE (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA)
C:\Program Files\Real\RealOne Player\realplay.exe:*:Enabled:RealOne Player (RealNetworks, Inc.)
C:\Program Files\Microsoft Games\Links 2003\LinksMMIII.exe:*:Enabled:Links 2003 (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player (Microsoft Corporation)
C:\Bentley\Program\MicroStation\ustation.exe:*:Enabled:MicroStation for Windows x86 (Bentley Systems, Inc.)
E:\Program Files\Bentley\Program\MicroStation\ustation.exe:*:Enabled:MicroStation for Windows x86 (Bentley Systems, Inc.)
C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit (Autodesk, Inc.)
C:\Program Files\DiskTrix\UltimateDefrag\UDefrag.exe:*:Enabled:UltimateDefrag V1.72 90 Day License File not found
C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup (Nero AG)
C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer (Microsoft Corporation)
C:\Program Files\DiskTrix\UltimateDefrag2008\UDefrag.exe:*:Enabled:UltimateDefrag 2008 (DiskTrix)
C:\Program Files\MediaMonkey\VisHelper.exe:*:Enabled:VisHelper ()
C:\Program Files\Microsoft ActiveSync\wcescomm.exe:*:Enabled:ActiveSync Connection Manager (Microsoft Corporation)
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:*:Enabled:ActiveSync Application (Microsoft Corporation)
C:\Program Files\CoffeeCup Software\CoffeeCup Website Access Manager\CCAccess.exe:*:Enabled:CoffeeCup Website Access Manager (CoffeeCup Software)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{0663708C-35D2-4A9B-AD98-2D49FB6729B6}" = LAGO Twin Otter Version 2.00
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0BD37B60-4FB2-48C9-B45F-39375611F899}" = LAGO Emma Field 2004
"{0F84C31B-D9D2-4FE2-935A-AF81A24DABB8}" = LAGO GeoRender3 version 2.00
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{16E217EA-C3E0-402D-8D4F-6189DB74497A}" = Studio 9.4 Patch
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{1CFF36CE-2A4C-4ABD-9251-284491A383D2}" = PTDD Partition Table Doctor 3.0
"{1D639238-EDDF-4A28-8AD7-82744AF5BC34}" = Saitek Drivers
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150080}" = J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E853C8-8E86-4259-B4D6-E2B5BEDDABCD}" = LAGO Male Scenery FS2004 2.00
"{35E90FA5-2CB4-4039-A8BB-BE1B9DB94E21}" = HP Memories Disc
"{362BFFCD-8274-11D8-97C8-000129760CBE}" = MediaLife
"{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
"{3A9E0E2F-B0D1-452B-B833-7A7300EA1231}" = Saitek SD02.5 NT Drivers
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{419CF344-3D94-4DAD-99C8-EA7B00E5EA8B}" = Acronis True Image Home
"{48EE6C79-1CE2-4CE8-B511-F2140B6781D6}" = Google Earth Pro
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4F45B603-8E1B-4E1F-8E5D-0ADDD1BF0621}_0" = Bentley MicroStation (V 08.01.01.09) - 1
"{4FCC384C-18EA-4E25-9281-A06AE006D219}" = Weblink
"{5094C629-274C-4631-84D7-960FEF6D13F7}" = LAGO Honolulu INTL Version 2.00
"{53480370-6CA2-47EC-BC05-02B4B9271C31}" = O&O; Defrag Professional Edition
"{5783F2D7-0201-0409-0000-0060B0CE6BBA}" = AutoCAD 2004
"{5B3FB6D4-1B88-413D-8DE7-A7E2D58DE5B2}" = TOPO! 4
"{5FAB6A66-2DAC-11D4-8524-00C04F602FD3}" = Adobe After Effects 5.0
"{5FAC5488-E7CF-43C5-AC88-B4514F31456D}" = aerosoft's - DHC2 Beaver
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{60E80B13-8649-4A69-85E2-1AE99E061F43}" = ShowBiz DVD
"{60E971B7-51A0-48CA-8687-C6B8F094A409}" = Simple Backup for My Pictures
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{666E0B91-3FD3-43B7-B6A2-EB9012758982}" = FSAutoStart
"{698BB337-5F2B-4944-90BB-180A16D37787}" = Weather Maker Pro 4.2 (Update)
"{6B36DEBF-27D0-4B1E-858D-D397091C6C7D}" = HP Precisionscan Pro 3.1
"{6C3F7A25-458D-4FBF-8C38-B29313CD99C7}" = Weather Maker Pro 4.0
"{6C57791A-4AA1-46A4-9879-2E9852A42D9C}" = LAGO GeoRender 6 Scenery FS2004 Version 1.00
"{73317C31-2B6E-4B88-9865-B97C1331A39D}" = PayPal Plug-In
"{7A5E68D5-DEA7-4067-B191-B4AE756C057B}" = STOPzilla
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7C5BCAA4-80F2-4092-BD22-F426453BCD17}" = gigabeat S Series Manual
"{8055A473-C0E0-4F14-8B07-A531C44E5DE4}" = American Data Roads Railroads and Streams
"{85D9D4FD-AD19-459E-A901-158AE62A3A7D}" = Patch
"{868D7896-99D4-4513-BC62-2B3AD3E24926}" = TuneUp Utilities 2006
"{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}" = iTunes
"{884705D8-575F-4F12-9FA6-E4558866A127}" = Spam Bully 2 for Outlook Express
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8BF6957D-9288-41A3-88B6-D5902FBC51EF}" = Uru - To D'ni Expansion Pack
"{8DFFE63E-A689-45C7-A309-E00E28ACDF07}" = Tongass Fjords
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90126B79-C0D2-41A5-86B2-2F6666C446B9}" = Saitek Configuration Software
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{97097F2D-CFBF-4DC9-A8AF-1C8EAC322275}" = Vocal Remover
"{97A908F8-F3B6-44ED-83BB-55E7BFE23F06}" = TOPO!
"{9E491AB7-4589-48CA-9CBB-874CB2788391}" = Studio 9
"{A1BC8E02-6B5B-4B4A-A75F-B27A16918C2B}" = DiscWizard for Windows
"{A351224F-533A-4EED-89F4-0BF3417FD31D}" = WD Backup
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe
"{A7BF5269-3E74-11D5-B00F-00104B398D77}" = QuarkXPress 5.0
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B1A9CD45-A702-4E3B-91ED-8CD562869901}" = DWG TrueView 2008
"{B28B351F-1232-46EA-85EF-B8EA91641033}" = Nero 7 Essentials
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B67624DE-75CE-4FAD-9F29-5C115773CE61}" = Studio 9 Content CD/DVD
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{C539AF6F-9DB3-458C-9274-1F3EE3291FB1}" = Abacus EZ-Libraries
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{C894366E-51C4-4162-BA82-ECBEFC1C2C61}" = PayPal Plug-In
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC016F21-3970-11DE-B878-005056806466}" = Google Earth
"{CE8472F3-6611-4F7A-B53E-A5E34103DD6B}" = LAGO FS Enhancer 2004
"{DA496AB5-DBFD-486F-8A37-D75FA179CAF3}" = CYPB - Port Alberni, British Columbia, Canada
"{DB1064C8-E623-441A-9036-FCDF0F2DE08C}" = NuRoads Configurator
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E55A7A90-184D-40A3-93AA-6F749B66C2F6}" = aerosoft's - Beech18 - FS2004
"{E7A6ED40-F230-11D4-BBC4-00104B991322}" = VBA (2720)
"{E96D4088-AAC5-437F-9E39-EC0E387897B4}" = Autodesk 3ds Max 9 32-bit
"{EA1F8E2F-9057-496A-BE1C-92CCA15479E3}" = H264 PRO IRS
"{EEF397AC-DAEF-4C04-90A9-5B2BD31875DC}" = Simple Installer - Multilanguage Version
"{F165A635-9DFF-4F34-A669-49493E0A5B38}" = M2PMCEncoderZX
"{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass
"{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FC053571-8507-44E4-8B6D-AACEAB8CA57C}" = Sansa Media Converter
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FD6C6B7F-5696-48C5-A601-2EE9E50C3D46}" = WD Firewire HID Driver
"{FDE97748-2050-47B1-9BDD-E049626FDE63}" = Smartparts Desktop
"3DSMAX25" = 3D Studio MAX R2.5
"AB 412 GUARDIA COSTIERA (Italia)" = AB 412 GUARDIA COSTIERA (Italia)
"ACDSee" = ACDSee
"ACID 2.0" = Sonic Foundry ACID 2.0d
"ACT! 4.0 for Windows" = ACT! 4.0 for Windows
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator 9.0" = Adobe Illustrator 9.0
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Advanced Encode Decode Tools v.1.062e" = Advanced Encode Decode Tools v.1.062e
"Advanced WMA Workshop_is1" = Advanced WMA Workshop version 2.09b
"allTunes" = allTunes
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"Antilles 2004" = Antilles 2004 v1.1 Int
"ArcherFS9" = Archer!
"ArcSoft Software Suite" = ArcSoft Picture Software
"ATI Display Driver" = ATI Display Driver (Omega 3.8.231)
"AutoCAD R14.0 Uninstall" = AutoCAD R14.0
"Autodesk Express Viewer" = Autodesk Express Viewer
"AutoGK" = Auto Gordian Knot 2.40
"AviSynth" = AviSynth 2.5
"BackWeb-137903 Uninstaller" = Updates from HP
"Belarc Advisor 2.0" = Belarc Advisor 7.1
"BirdsEyeView1.0" = BirdsEyeView
"BirdsEyeView1.1" = BirdsEyeView
"BrowserMaster_is1" = BrowserMaster v2.5
"Carenado Cessna U206G Stationair 6 II Full" = Carenado Cessna U206G Stationair 6 II Full
"CoffeeCup Web Form Builder - Registered" = CoffeeCup Web Form Builder - Registered
"CoffeeCup Web Form Builder - Trial" = CoffeeCup Web Form Builder - Trial
"CoffeeCup Website Access Manager" = CoffeeCup Website Access Manager
"Core FTP LE 1.3c" = Core FTP LE 1.3c
"DivX Content Uploader" = DivX Content Uploader
"DreamFleet A36 Bonanza 1.1" = DreamFleet A36 Bonanza 1.1
"DreamFleet A36 Bonanza Floatplane Update 1.1" = DreamFleet A36 Bonanza Floatplane Update 1.1
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVDx_is1" = DVDx
"DWG TrueView 2008" = DWG TrueView 2008
"EndItAll_is1" = EndItAll 2.0
"Flight Environment" = Flight Environment
"Flight Simulator 9.0" = Microsoft Flight Simulator 2004 A Century of Flight
"FlightZone 02: Portland" = FlightZone 02: Portland
"FSGenesis Appalachians & Northeast 38m Terrain" = FSGenesis Appalachians & Northeast 38m Terrain
"FSGenesis Cordillera Canada 38.2m Terrain" = FSGenesis Cordillera Canada 38.2m Terrain
"FSGenesis Cordillera Canada 38.2m Terrain – Yukon" = FSGenesis Cordillera Canada 38.2m Terrain – Yukon
"FSGenesis The Great Plains 38m Terrain" = FSGenesis The Great Plains 38m Terrain
"FSGenesis The West Coast 38m Terrain" = FSGenesis The West Coast 38m Terrain
"FSGenesis US National Landclass Project" = FSGenesis US National Landclass Project
"FZ02-CRGUT Compatibility Upgrade Kit" = FZ02-CRGUT Compatibility Upgrade Kit
"GAArcher" = Archer
"GARMIN 400 Series Trainer" = GARMIN 400 Series Trainer
"G-Force" = G-Force
"HijackThis" = HijackThis 2.0.2
"Hollywood FX 5" = Pinnacle Hollywood FX 5
"Hollywood FX 5.5 Additional Effects" = Hollywood FX 5.5 Additional Effects
"Hollywood FX for Studio" = Pinnacle Hollywood FX for Studio
"hp instant support" = HP Instant Support
"HPTOOLKIT" = toolkit
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ImgBurn" = ImgBurn (Remove Only)
"InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}" = QuickTime
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}" = iTunes
"InstallShield_{97A908F8-F3B6-44ED-83BB-55E7BFE23F06}" = TOPO!
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"InterActual Player" = InterActual Player
"Kai's Power Tools 5" = Kai's Power Tools 5
"LegalSounds Music Downloader_is1" = LegalSounds Music Downloader 1.4
"LifeGlobe Sharks, Terrors of the Deep 2_is1" = LifeGlobe Sharks, Terrors of the Deep 2
"Links 2003 1.0" = Microsoft Links 2003
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.0
"MegaCITY - Denver_is1" = Denver
"MegaCity Hawaii - Honolulu and the Island of Oahu_is1" = Hawaii Oahu
"MegaScenery - Pacific Northwest_is1" = Pacific Northwest Scenery
"MegaScenery - Southern California_is1" = Southern California
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"MovieConverter" = Movie Converter
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MultiRes (remove only)" = MultiRes (remove only)
"NetworkAddonMod" = NetworkAddonMod Beta Version 2006.12.24
"NFR" = Nasty File Remover v0.71 (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoTools 2.0" = Extensis PhotoTools 2.0
"Pinnacle Hollywood FX Pack - Extra FX" = Pinnacle Hollywood FX Pack - Extra FX
"Plugins Galaxy" = Plugins Galaxy
"PocketDVDStudio" = Pocket-DVD Studio(remove only)
"proDAD-Heroglyph-1.0" = proDAD Heroglyph 1.0
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"Python 2.2.1" = Python 2.2.1
"Radeon Omega Drivers for Windows 2k/XPv3.8.231" = Radeon Omega Drivers v3.8.231 Setup Files and Tools
"Real Terrain© Colorado Installation For FS 2004" = Real Terrain© Colorado Installation For FS 2004
"RealPlayer 6.0" = RealPlayer
"RER MOV Converter3.0.5" = RER MOV Converter
"S3Display" = S3Display
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"Save Flash" = Save Flash 4.1
"SimCity 4 Startup Manager" = SimCity 4 Startup Manager
"Sound Forge XP" = Sonic Foundry Sound Forge XP 4.5f
"Spam Bully for OE" = Spam Bully for OE [removed]
"SpeedFan" = SpeedFan (remove only)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"SqueezeCenter_is1" = SqueezeCenter 7.0.1
"Studio 9.0.4" = Studio 9.0.4
"SystemBooster V2.0" = SystemBooster V2.0
"TexoMatic_Unique" = Flight One Text-o-Matic
"The Weather Channel Desktop" = The Weather Channel Desktop
"Tools 1.0_is1" = Tools 1.0
"TOPO!" = TOPO!
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Ultimate Terrain - Canada & Alaska" = Ultimate Terrain - Canada & Alaska
"Ultimate Terrain - USA" = Ultimate Terrain - USA
"UltimateDefrag 2008" = UltimateDefrag 2008
"UniC310Ver10" = Seven Charlie Mike: The Cessna 310
"UniC310Ver11" = Seven Charlie Mike: The Cessna 310 - FS2004 Update
"Uninstaller_B4D28000_Schweizer 300CBi" = Schweizer 300CBi (Shared Components)
"USBTheater" = Sonica Theater [removed]
"VETWIN32Vp5" = CA Anti-Virus
"ViewBuild Professional" = ViewBuild Professional
"VobSub" = VobSub v2.23 (Remove Only)
"Vocal Remover" = Vocal Remover
"Weather Services" = Weather Services
"WhiteCap" = WhiteCap
"Winamp" = Winamp (remove only)
"Windows CE Services" = Microsoft ActiveSync 3.8
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/4/2009 11:08:30 AM | Computer Name = TKPGOLD | Source = | ID = 0
Description =
Error - 4/11/2009 12:06:38 AM | Computer Name = TKPGOLD | Source = Application Error | ID = 1000
Description = Faulting application mediamonkey.exe, version 3.0.4.1185, faulting
module kernel32.dll, version 5.1.2600.3119, fault address 0x00012a5b.
Error - 4/17/2009 10:17:49 AM | Computer Name = TKPGOLD | Source = Google Update | ID = 20
Description =
Error - 4/17/2009 1:07:06 PM | Computer Name = TKPGOLD | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office Standard Edition 2003 – Error 1706. Setup
cannot find the required files. Check your connection to the network, or CD-ROM
drive. For other potential solutions to this problem, see C:\Program Files\Microsoft
Office\OFFICE11\1033\SETUP.CHM.
Error - 4/27/2009 11:09:53 AM | Computer Name = TKPGOLD | Source = Application Hang | ID = 1002
Description = Hanging application Dreamweaver.exe, version 6.0.1714.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 6/3/2009 3:44:34 PM | Computer Name = TKPGOLD | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, faulting
module flash10b.ocx, version 10.0.22.87, fault address 0x002da8ba.
Error - 6/3/2009 3:46:29 PM | Computer Name = TKPGOLD | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, faulting
module flash10b.ocx, version 10.0.22.87, fault address 0x002da8ba.
Error - 6/3/2009 4:26:21 PM | Computer Name = TKPGOLD | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16827, faulting
module flash10b.ocx, version 10.0.22.87, fault address 0x002da926.
Error - 6/3/2009 4:26:41 PM | Computer Name = TKPGOLD | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 6/18/2009 4:33:30 PM | Computer Name = TKPGOLD | Source = Application Error | ID = 1000
Description = Faulting application vb3core.exe, version 0.0.0.0, faulting module
vb3core.exe, version 0.0.0.0, fault address 0x00064ad6.
[ System Events ]
Error - 6/23/2009 2:29:58 PM | Computer Name = TKPGOLD | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{29DC17E6-6DB8-4CB2-84A3-82E0F08B8D0D}. The
backup browser is stopping.
Error - 6/23/2009 4:15:31 PM | Computer Name = TKPGOLD | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 6/23/2009 4:15:32 PM | Computer Name = TKPGOLD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
agp440 fasttx2k SDManager SISAGP viaagp1
Error - 6/23/2009 4:16:06 PM | Computer Name = TKPGOLD | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 169.254.114.176,
since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.
Error - 6/23/2009 5:45:58 PM | Computer Name = TKPGOLD | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{29DC17E6-6DB8-4CB2-84A3-82E0F08B8D0D}. The
backup browser is stopping.
Error - 6/23/2009 8:36:14 PM | Computer Name = TKPGOLD | Source = Service Control Manager | ID = 7000
Description = The mrtRate service failed to start due to the following error: %%2
Error - 6/23/2009 8:36:15 PM | Computer Name = TKPGOLD | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
agp440 fasttx2k SDManager SISAGP viaagp1
Error - 6/23/2009 8:37:06 PM | Computer Name = TKPGOLD | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 169.254.114.176,
since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.
Error - 6/23/2009 10:03:38 PM | Computer Name = TKPGOLD | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{29DC17E6-6DB8-4CB2-84A3-82E0F08B8D0D}. The
backup browser is stopping.
Error - 6/24/2009 8:33:49 AM | Computer Name = TKPGOLD | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.101 for the Network Card with network
address 000C6E741192 has been denied by the DHCP server 192.168.0.254 (The DHCP
Server sent a DHCPNACK message).
< End of report >
OTL logfile created on: 6/24/2009 8:37:28 AM - Run 1
OTL by OldTimer - Version 3.0.5.2 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 51.73% Memory free
3.85 Gb Paging File | 3.26 Gb Available in Paging File | 84.70% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072E:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.34 Gb Total Space | 25.71 Gb Free Space | 23.95% Space Free | Partition Type: NTFS
Drive D: | 4.43 Gb Total Space | 0.53 Gb Free Space | 11.98% Space Free | Partition Type: FAT32
Drive E: | 149.05 Gb Total Space | 108.36 Gb Free Space | 72.70% Space Free | Partition Type: NTFS
Drive F: | 298.01 Gb Total Space | 232.36 Gb Free Space | 77.97% Space Free | Partition Type: FAT32
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 65.94 Gb Total Space | 29.75 Gb Free Space | 45.12% Space Free | Partition Type: NTFS
Drive M: | 111.81 Gb Total Space | 56.68 Gb Free Space | 50.69% Space Free | Partition Type: NTFS
Drive O: | 243.98 Mb Total Space | 243.37 Mb Free Space | 99.75% Space Free | Partition Type: FAT
Computer Name: TKPGOLD
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
PRC - C:\WINDOWS\System32\oodag.exe (O&O; Software GmbH)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Softex\OmniPass\Omniserv.exe ()
PRC - C:\Program Files\M-Audio Sonica Theater\Install\STinst.exe (Nemesis)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\SqueezeCenter\server\Bin\MSWin32-x86-multi-thread\mysqld.exe ()
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\WINDOWS\System32\ps2.exe (Hewlett-Packard Company)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
PRC - C:\Program Files\M-Audio Sonica Theater\STTask.exe (M-Audio)
PRC - C:\Program Files\SqueezeCenter\SqueezeTray.exe ()
PRC - C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE (Logitech Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aawservice [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe (Lavasoft)
SRV - (AcrSch2Svc [Auto | Running]) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (Autodesk Licensing Service [Auto | Running]) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (CaCCProvSP [On_Demand | Running]) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe [Auto | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
SRV - (clr_optimization_v2.0.50727_32 [Auto | Running]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gupdate1c99eaec907864 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPodService [Disabled | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
SRV - (Just Flight Limited License Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Just Flight Limited Shared\Service\JustFlightLimitedLicSvc.exe (Just Flight Limited)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (mi-raysat_3dsmax9_32 [Auto | Running]) – C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe ()
SRV - (NMIndexingService [On_Demand | Stopped]) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (O&O; Defrag [Auto | Running]) – C:\WINDOWS\System32\oodag.exe (O&O; Software GmbH)
SRV - (omniserv [Auto | Running]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (SonicaTheaterInstallerService [Auto | Running]) – C:\Program Files\M-Audio Sonica Theater\Install\STinst.exe (Nemesis)
SRV - (SqueezeMySQL [Auto | Running]) – C:\Program Files\SqueezeCenter\server\Bin\MSWin32-x86-multi-thread\mysqld.exe ()
SRV - (szserver [Auto | Running]) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (UxTuneUp [Auto | Running]) – C:\WINDOWS\System32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (VETMSGNT [Auto | Running]) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (WnsService [On_Demand | Stopped]) – File not found
SRV - (MBAMService [Auto | Running]) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
========== Driver Services (SafeList) ==========
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (ALCXSENS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (ALCXWDM [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ASAPIW2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ASAPIW2k.sys (Pinnacle Systems GmbH)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATIAVAIW [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\atinavt2.sys (ATI Technologies Inc.)
DRV - (atinevxx [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\atinevxx.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\atinrvxx.sys (ATI Technologies Inc.)
DRV - (atitray [System | Running]) – C:\Program Files\Radeon Omega Drivers\v3.8.231\ATI Tray Tools\atitray.sys ()
DRV - (BANTExt [System | Running]) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (BENDER [On_Demand | Running]) – C:\WINDOWS\System32\drivers\bender.sys (Pinnacle Systems GmbH)
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdrbsdrv [System | Running]) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (cdudf_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\drvmcdb.sys (VERITAS Software, Inc.)
DRV - (dvd_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (fasttx2k [Boot | Stopped]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (itchfltr [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\itchfltr.sys (Logitech, Inc.)
DRV - (Iviaspi [On_Demand | Running]) – C:\WINDOWS\System32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (L8042mou [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (ltmodem5 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (ma763007 [On_Demand | Running]) – C:\WINDOWS\System32\drivers\MA763007.sys (Nemesis)
DRV - (MarvinBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (MCSTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (mmc_2K [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (MPE [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\MPE.sys (Microsoft Corporation)
DRV - (MVDCODEC [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\atinmdxx.sys (ATI Technologies Inc.)
DRV - (NVENET [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\NVENET.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (PCLEPCI [System | Running]) – C:\WINDOWS\System32\drivers\pclepci.sys (Pinnacle Systems GmbH)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (Point32 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\point32.sys (Microsoft Corporation)
DRV - (Ps2 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2K [System | Running]) – C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (rxpvbus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\rxpvbus.sys (Reality XP)
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (SaiClass [On_Demand | Running]) – C:\WINDOWS\System32\drivers\SaiNtBus.sys (Saitek)
DRV - (SaiMini [On_Demand | Running]) – C:\WINDOWS\System32\drivers\SaiMini.sys (Saitek)
DRV - (SaiNtHid [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SaiNtHid.sys (Saitek)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Sentinel [Auto | Running]) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS ()
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Stopped]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (snapman [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (speedfan [Boot | Running]) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (SSHDRV64 [System | Running]) – C:\WINDOWS\System32\drivers\SSHDRV64.sys ()
DRV - (szkg5 [Boot | Running]) – C:\WINDOWS\system32\drivers\szkg.sys (iS3 Inc.)
DRV - (tifsfilter [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\tifsfilt.sys (Acronis)
DRV - (timounter [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (UdfReadr_xp [System | Running]) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (VET-FILT [System | Running]) – C:\WINDOWS\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VET-REC [System | Running]) – C:\WINDOWS\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT [On_Demand | Running]) – C:\WINDOWS\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETEFILE [System | Running]) – C:\WINDOWS\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT [System | Running]) – C:\WINDOWS\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VETMONNT [System | Running]) – C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (viaagp1 [Boot | Stopped]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (wceusbsh [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\wceusbsh.sys (Microsoft Corporation)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (MBAMProtector [On_Demand | Running]) – C:\WINDOWS\System32\drivers\mbam.sys (Malwarebytes Corporation)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\System32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://my.msn.com/"
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: paypalfirefoxplugin@orbiscom:[removed]
FF - prefs.js..extensions.enabledItems: {d494da20-8750-11db-b606-0800200c9a66}:3.0.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - HKLM\software\mozilla\Firefox\Extensions\\paypalfirefoxplugin@orbiscom: C:\Program Files\PayPal\PayPal Plug-In
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/16 10:53:02 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/16 10:53:02 | 00,000,000 | —D | M]
[2008/08/26 14:22:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/08/26 14:22:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/23 09:50:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions
[2009/01/07 10:30:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2007/12/04 17:12:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{526fd696-27a0-11dc-8314-0800200c9a66}
[2007/10/19 10:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{5c434b90-6318-11da-8cd6-0800200c9a69}
[2007/07/31 15:23:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2008/04/02 08:01:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{a45e6b3a-725d-4b20-afde-e7486bfe317c}
[2008/10/03 15:47:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{d494da20-8750-11db-b606-0800200c9a66}
[2006/04/27 16:05:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\{F2BF34A6-7865-4526-8FA1-F21C4E694AF3}
[2006/04/27 16:01:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\[removed]
[2009/01/22 20:23:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\p4y9thml.default\extensions\[removed]
[2008/06/18 15:21:34 | 00,001,712 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\p4y9thml.default\searchplugins\ask.xml
[2009/06/24 08:33:22 | 00,005,500 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\p4y9thml.default\searchplugins\foodtv.xml
[2008/06/18 15:21:36 | 00,000,908 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\p4y9thml.default\searchplugins\IMDB.xml
[2009/06/24 08:33:22 | 00,002,143 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\p4y9thml.default\searchplugins\marketwatch.xml
[2009/06/22 09:44:26 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2006/10/19 08:56:40 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/06/16 10:53:02 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/04/18 15:26:55 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2007/07/18 15:00:57 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2007/10/18 13:30:01 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/18 13:40:15 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/18 15:07:49 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/06/16 10:52:55 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/16 10:52:55 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/03/27 01:48:51 | 00,717,312 | —- | M] (DivX,Inc.) – C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2007/03/27 01:49:32 | 00,094,208 | —- | M] (DivX, Inc) – C:\Program Files\mozilla firefox\plugins\npDivxPlayerPlugin.dll
[2009/06/16 10:53:01 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2006/12/18 04:18:30 | 00,077,824 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2006/08/22 08:47:46 | 00,139,305 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2005/12/02 14:32:07 | 00,126,976 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2005/12/02 14:32:07 | 00,126,976 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2006/08/22 08:48:19 | 00,024,621 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2006/08/22 08:47:37 | 00,081,967 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2008/12/23 15:50:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/23 15:50:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/23 15:50:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/23 15:50:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/23 15:50:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/23 15:50:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/23 15:50:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (36936 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.whippet.bfast.com
O1 - Hosts: 127.0.0.1 www.qwest.bfast.com
O1 - Hosts: 127.0.0.1 www.qwest.bfast.com
O1 - Hosts: 127.0.0.1 www.reporting.net
O1 - Hosts: 127.0.0.1 www.whippet.bfast.com
O1 - Hosts: 127.0.0.1 www.wolfhound.bfast.com
O1 - Hosts: 127.0.0.1 www.ads09.bpath.com
O1 - Hosts: 127.0.0.1 www.ads51.bpath.com
O1 - Hosts: 127.0.0.1 www.ns2.acim.com
O1 - Hosts: 127.0.0.1 www1.track4.com
O1 - Hosts: 127.0.0.1 www.ad.se.doubleclick.net
O1 - Hosts: 127.0.0.1 www.gravitychannel.netgravity.com
O1 - Hosts: 127.0.0.1 www.network-199-95-208-4.doubleclick.net
O1 - Hosts: 127.0.0.1 www.ny.netgravity.com
O1 - Hosts: 127.0.0.1 www.phase2media.doubleclick.net
O1 - Hosts: 127.0.0.1 www.ads2.speedbit.com
O1 - Hosts: 127.0.0.1 www.ads3.speedbit.com
O1 - Hosts: 127.0.0.1 www.contenttest.conducent.com
O1 - Hosts: 127.0.0.1 www.ip134.timesink.com
O1 - Hosts: 127.0.0.1 www.ad2-1.aureate.com
O1 - Hosts: 127.0.0.1 www.ad2-4.aureate.com
O1 - Hosts: 127.0.0.1 www.aim3.aureate.com
O1 - Hosts: 127.0.0.1 www.aureatemedia.com
O1 - Hosts: 127.0.0.1 www.cyrus.aureate.com
O1 - Hosts: 896 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ZILLAbar Browser Helper Object) - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll (iS3, Inc)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O2 - BHO: (OToolbarHelper Class) - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll ()
O3 - HKLM\..\Toolbar: (&Save; Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll (TODO: )
O3 - HKLM\..\Toolbar: (STOPzilla) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll (iS3, Inc)
O3 - HKLM\..\Toolbar: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKLM\..\Toolbar: (PayPal Plug-In) - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (hp toolkit) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL (Hewlett-Packard Company)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Save; Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll (TODO: )
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [LtcyCfgApply] C:\Program Files\Ltcycfg2\LtcyCfg.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] File not found
O4 - HKLM..\Run: [PS2] C:\WINDOWS\System32\ps2.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\M-Audio Sonica Theater Control Panel Launcher.lnk = C:\Program Files\M-Audio Sonica Theater\STTask.exe (M-Audio)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SqueezeCenter Tray Tool.lnk = C:\Program Files\SqueezeCenter\SqueezeTray.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll (iS3 & AVG Exploit Prevention Labs, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 32 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BF30C8B-72D5-40FF-B169-BFE1D503E7E8}
http://plpadmin.tempdomainname.com/CabFile…gradeFinder.cab (NewUpgradeFinder Control)
O16 - DPF: {49232000-16E4-426C-A231-62846947304B}
http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab (SysData Class)
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2}
http://simcity.ea.com/update/EARTPX.cab (EARTPatchX Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1123110157281 (WUWebControl Class)
O16 - DPF: {6DD4EA80-8981-40FB-B2FC-06B8EDC632B8}
http://www.2for1.com/downloads/PrintControl.CAB (PrintControl.PrinterControl)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1213284287968 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…7869.3365972222 (Reg Error: Key error.)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09}
https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {BC18E6DF-BE57-4580-93E8-F228F9A133AA}
http://simcity.ea.com/exchange/lots/telepo…ty4LotTeleX.cab (MaxisSimCity4LotTeleX Control)
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD}
http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab (MaxisSimCity4PatcherX Control)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_08)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} http://fdl.msn.com/public/investor/v13/ticker.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.254
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mctp {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\System32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (C:\Documents) - File not found
O20 - HKLM Winlogon: UIHost - (and) - File not found
O20 - HKLM Winlogon: UIHost - (Settings\All) - File not found
O20 - HKLM Winlogon: UIHost - (Users\Application) - File not found
O20 - HKLM Winlogon: UIHost - (Data\TuneUp) - File not found
O20 - HKLM Winlogon: UIHost - (Software\TuneUp) - File not found
O20 - HKLM Winlogon: UIHost - (Utilities\WinStyler\tu_logonui.exe) - File not found
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\WlNotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\System32\SHELL32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\System32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\System32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\System32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\System32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/04/09 23:19:17 | 00,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 00,000,045 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2006/08/10 13:15:50 | 00,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O32 - AutoRun File - [2005/11/15 12:08:04 | 00,000,036 | -H– | M] () - F:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{92dda43e-adad-11dc-b9e4-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{92dda43e-adad-11dc-b9e4-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (SDEarlyDelete) - C:\WINDOWS\System32\SDEarlyDelete.exe ()
O34 - HKLM BootExecute: (SDEarlyDelete) - C:\WINDOWS\System32\SDEarlyDelete.exe ()
O34 - HKLM BootExecute: (\??\C:\Program) - File not found
O34 - HKLM BootExecute: (Files\SpywareDetector) - File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O; Software GmbH)
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2009/06/24 08:34:57 | 00,512,512 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/06/24 08:31:20 | 00,000,478 | —- | C] () – C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Owner.job
[2009/06/24 08:31:06 | 00,000,492 | —- | C] () – C:\WINDOWS\tasks\Malwarebytes' Scheduled Scan for Owner.job
[2009/06/23 18:34:24 | 00,000,920 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2009/06/23 13:44:44 | 00,026,624 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Please do the following.doc
[2009/06/23 13:42:57 | 00,278,221 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2009/06/23 13:42:02 | 00,359,893 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2009/06/23 09:42:06 | 18,071,615 | —- | C] () – C:\Fetch_5.5.dmg
[2009/06/23 09:39:00 | 00,000,791 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Shortcut to HijackThis.exe.lnk
[2009/06/22 14:31:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/06/22 14:31:06 | 00,000,739 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/22 14:31:04 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/22 14:31:02 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/22 14:31:02 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/22 14:31:02 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/22 14:27:42 | 03,561,744 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup.exe
[2009/06/10 15:40:27 | 00,095,676 | —- | C] () – C:\WINDOWS\System32\drivers\ac0a2fff5a08b1b35bb6f5c125c07e76.szcpf
[2009/06/10 15:34:52 | 00,144,648 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SupportBridge.remoteassist.ca.com.443.supportbridge.$.exe
[2009/06/10 15:07:19 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/06/09 17:16:40 | 00,095,676 | —- | C] () – C:\WINDOWS\System32\drivers\71f4af93.sys
[2009/06/08 10:07:55 | 06,768,808 | —- | C] () – C:\pccolorado.tif
[2009/05/28 14:16:24 | 00,017,408 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2009/05/28 14:15:22 | 00,294,912 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2009/05/28 14:14:56 | 00,540,672 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2009/01/13 17:49:48 | 00,000,101 | —- | C] () – C:\WINDOWS\VSWizard.ini
[2008/04/18 11:00:49 | 00,000,110 | —- | C] () – C:\WINDOWS\System32\SDEarlyDelete.ini
[2007/04/20 14:48:20 | 00,000,049 | —- | C] () – C:\WINDOWS\topo4.INI
[2007/04/13 09:47:09 | 00,000,000 | —- | C] () – C:\WINDOWS\MTSTACK.INI
[2007/04/02 16:11:44 | 00,000,110 | —- | C] () – C:\WINDOWS\TOPO.INI
[2007/03/27 01:55:48 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/12/12 10:24:42 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/12/08 06:50:14 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/12/08 06:47:54 | 01,159,168 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/05/04 16:03:52 | 00,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2006/05/04 16:03:52 | 00,023,552 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2006/04/17 16:13:01 | 00,009,392 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/03 14:55:27 | 00,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2006/01/26 06:51:56 | 00,110,080 | —- | C] () – C:\WINDOWS\System32\nlame.dll
[2006/01/03 10:15:34 | 00,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2006/01/03 10:15:28 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\adistres.dll
[2005/12/09 09:11:48 | 00,104,060 | —- | C] () – C:\WINDOWS\System32\ShellEx.dll
[2005/12/06 18:11:11 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/06 18:11:11 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/06 18:11:11 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/06 18:11:11 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/06 18:11:10 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/06 18:11:10 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/11/17 16:32:09 | 00,000,000 | —- | C] () – C:\WINDOWS\winpm.INI
[2005/11/17 16:28:38 | 03,592,192 | —- | C] () – C:\WINDOWS\System32\qt-mt323.dll
[2005/11/01 12:15:00 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/11/01 10:14:44 | 00,373,248 | —- | C] () – C:\WINDOWS\EyeCand3.INI
[2005/11/01 09:55:13 | 00,000,076 | —- | C] () – C:\WINDOWS\System32\PhotoRg2.ini
[2005/11/01 09:54:44 | 00,087,552 | —- | C] () – C:\WINDOWS\System32\ereglb32.dll
[2005/11/01 09:54:44 | 00,023,040 | —- | C] () – C:\WINDOWS\System32\ergint32.dll
[2005/10/30 15:51:27 | 00,000,000 | —- | C] () – C:\WINDOWS\ATIMMC.INI
[2005/10/29 14:11:26 | 00,094,720 | —- | C] () – C:\WINDOWS\System32\SH30W32.DLL
[2005/10/29 14:11:22 | 00,000,443 | —- | C] () – C:\WINDOWS\8272A4GS.INI
[2005/10/29 14:11:22 | 00,000,412 | —- | C] () – C:\WINDOWS\VIAPLAY.INI
[2005/10/29 14:11:22 | 00,000,000 | R— | C] () – C:\WINDOWS\VMARK.INI
[2005/10/13 16:53:43 | 00,003,120 | —- | C] () – C:\WINDOWS\System32\fd20925b-ce57-42b1-bf58-6eb6683232a2.dll
[2005/08/31 15:47:22 | 00,000,017 | —- | C] () – C:\WINDOWS\MovingPicture.ini
[2005/08/09 16:13:31 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 16:13:31 | 00,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/07/12 12:30:19 | 00,318,014 | —- | C] () – C:\WINDOWS\System32\flt1chk4.dll
[2005/05/11 10:40:26 | 00,000,032 | —- | C] () – C:\WINDOWS\CD-Start.INI
[2005/03/04 16:12:57 | 00,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2005/03/04 04:00:08 | 00,001,257 | —- | C] () – C:\WINDOWS\GARMINWT.INI
[2005/01/20 16:23:56 | 00,156,672 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2005/01/19 12:14:07 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\dfltchk2.dll
[2004/11/18 10:18:06 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\gpvbd.dll
[2004/11/18 10:18:06 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\AuthDVD.DLL
[2004/11/14 14:38:10 | 00,104,612 | —- | C] () – C:\WINDOWS\System32\TomcatShellEx.dll
[2004/11/14 14:38:09 | 00,107,520 | —- | C] () – C:\WINDOWS\System32\dvrms.dll
[2004/11/14 14:38:05 | 01,778,176 | —- | C] () – C:\WINDOWS\System32\avcodec.dll
[2004/11/14 14:38:05 | 00,182,272 | —- | C] () – C:\WINDOWS\System32\avformat.dll
[2004/11/14 14:38:03 | 00,916,480 | —- | C] () – C:\WINDOWS\System32\FFMpeg.dll
[2004/09/16 14:24:26 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/04/29 13:21:24 | 00,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\SENTINEL.SYS
[2004/04/29 13:21:24 | 00,038,400 | —- | C] () – C:\WINDOWS\System32\SNTI386.DLL
[2004/04/29 13:21:24 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\RNBOVDD.DLL
[2004/04/07 08:51:51 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2004/02/26 18:01:51 | 00,109,568 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV64.sys
[2003/12/22 15:40:06 | 01,663,068 | —- | C] () – C:\WINDOWS\System32\libmmd.dll
[2003/12/08 12:16:11 | 00,000,488 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/12/04 10:24:33 | 00,000,084 | —- | C] () – C:\WINDOWS\ALBUM.INI
[2003/11/19 19:41:42 | 00,037,954 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2003/11/08 23:31:34 | 00,544,768 | —- | C] () – C:\WINDOWS\System32\SZFrame.dll
[2003/10/24 17:18:21 | 00,000,053 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/10/07 13:17:24 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2003/09/23 16:38:03 | 00,004,005 | —- | C] () – C:\WINDOWS\FORGXP32.ini
[2003/09/23 16:28:56 | 00,061,952 | —- | C] () – C:\WINDOWS\System32\rmmerge2.DLL
[2003/09/23 16:28:56 | 00,009,728 | —- | C] () – C:\WINDOWS\System32\rmevents.DLL
[2003/09/12 11:01:05 | 00,000,386 | —- | C] () – C:\WINDOWS\I5E1000.INI
[2003/09/10 13:56:54 | 00,001,110 | —- | C] () – C:\WINDOWS\winamp.ini
[2003/09/06 08:43:49 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2003/09/05 10:05:14 | 00,000,219 | —- | C] () – C:\WINDOWS\hpbafd.ini
[2003/09/04 19:22:37 | 00,102,400 | —- | C] () – C:\WINDOWS\System32\SaiCfg.dll
[2003/09/04 17:20:57 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/07/08 08:33:00 | 00,031,744 | —- | C] () – C:\WINDOWS\System32\flt1chk2.dll
[2003/04/10 05:35:00 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 05:34:24 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\iAlmcoin.dll
[2003/04/10 05:21:36 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 02:51:07 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 02:51:07 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2003/04/10 01:32:34 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 01:32:34 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 01:06:10 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 01:03:38 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 01:03:38 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 00:57:15 | 00,000,052 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 00:57:04 | 00,000,626 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 00:16:44 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/09 23:44:58 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/09 23:44:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/09 23:44:29 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/09 23:23:21 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/09 23:05:45 | 00,000,659 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/09 23:05:33 | 00,000,935 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/09 23:05:31 | 00,000,290 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 16:54:04 | 00,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2002/02/27 18:50:00 | 00,197,120 | —- | C] () – C:\WINDOWS\System32\patchw32.dll
[2001/08/14 19:47:08 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\vxpsapi.dll
[2001/08/10 13:14:16 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\ImapiRoxPS.dll
[2000/04/14 17:50:02 | 00,343,040 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[1998/06/11 15:08:06 | 00,095,232 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/06/24 08:34:58 | 00,512,512 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/06/24 08:31:29 | 00,000,478 | —- | M] () – C:\WINDOWS\tasks\Malwarebytes' Scheduled Update for Owner.job
[2009/06/24 08:31:21 | 00,000,492 | —- | M] () – C:\WINDOWS\tasks\Malwarebytes' Scheduled Scan for Owner.job
[2009/06/24 08:09:25 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/06/24 04:04:47 | 00,000,920 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2009/06/23 18:36:52 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/06/23 18:36:45 | 00,000,189 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2009/06/23 18:35:11 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/06/23 18:34:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/06/23 18:33:34 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/06/23 18:33:22 | 21,468,81536 | -HS- | M] () – C:\hiberfil.sys
[2009/06/23 18:33:20 | 01,566,742 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2009/06/23 13:52:27 | 00,026,624 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Please do the following.doc
[2009/06/23 13:43:01 | 00,278,221 | —- | M] () – C:\Documents and Settings\Owner\Desktop\gmer.zip
[2009/06/23 13:42:02 | 00,359,893 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2009/06/23 09:43:31 | 18,071,615 | —- | M] () – C:\Fetch_5.5.dmg
[2009/06/23 09:39:00 | 00,000,791 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Shortcut to HijackThis.exe.lnk
[2009/06/23 09:24:08 | 00,001,777 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/06/22 14:31:06 | 00,000,739 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/22 14:27:54 | 03,561,744 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup.exe
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/15 08:11:42 | 00,037,954 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2009/06/11 18:10:50 | 00,555,160 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/11 18:02:25 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/06/10 19:59:48 | 00,000,935 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/10 15:40:27 | 00,095,676 | —- | M] () – C:\WINDOWS\System32\drivers\ac0a2fff5a08b1b35bb6f5c125c07e76.szcpf
[2009/06/10 15:39:03 | 00,095,676 | —- | M] () – C:\WINDOWS\System32\drivers\71f4af93.sys
[2009/06/10 15:34:53 | 00,144,648 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SupportBridge.remoteassist.ca.com.443.supportbridge.$.exe
[2009/06/10 15:23:35 | 00,161,920 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/06/08 10:15:03 | 06,768,808 | —- | M] () – C:\pccolorado.tif
[2009/06/04 15:37:04 | 86,751,7440 | —- | M] () – C:\Outlook backup.pst
[2009/06/01 10:51:12 | 23,635,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/05/28 14:16:24 | 00,017,408 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2009/05/28 14:15:22 | 00,294,912 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2009/05/28 14:14:56 | 00,540,672 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2009/05/26 08:10:20 | 00,004,005 | —- | M] () – C:\WINDOWS\FORGXP32.ini
========== LOP Check ==========
[2009/06/22 14:31:02 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/05/16 10:16:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{7DDD0C26-E7D0-4422-8616-030EE13368AF}
[2007/04/23 16:35:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2007/05/10 11:49:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\allTunes
[2003/10/23 18:53:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ArcSoft
[2005/10/31 15:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI MMC
[2008/02/11 14:59:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2006/10/08 12:14:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2007/02/02 13:44:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Just Flight Limited
[2007/12/18 16:38:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2003/09/12 18:10:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Links 2003
[2003/04/10 01:12:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2004/02/26 17:24:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2003/04/09 23:24:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/05/18 15:14:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SITEguard
[2006/04/17 12:26:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/06/26 16:34:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SqueezeCenter
[2009/06/24 08:39:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/06/25 13:46:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/27 13:45:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/06/22 21:02:21 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2005/03/04 16:13:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ACD Systems
[2007/04/26 14:18:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Acronis
[2007/12/18 16:38:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ahead
[2007/05/10 11:49:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\allTunes
[2008/06/10 21:08:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Amazon
[2006/11/24 16:16:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ArcSoft
[2006/04/20 14:14:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATI
[2005/08/08 19:00:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\atitray
[2007/04/13 10:58:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Autodesk
[2006/04/01 10:16:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Axaware
[2009/03/16 14:07:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CoffeeCup Software
[2009/06/17 11:08:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CoreFTP
[2005/11/11 10:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2005/09/23 11:21:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FSAutoStart
[2008/10/31 08:30:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2007/08/08 16:44:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ImgBurn
[2008/07/22 13:39:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/04/10 00:52:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterTrust
[2003/09/05 13:54:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2007/08/07 14:45:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LegalSounds
[2003/09/08 21:18:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2009/01/22 20:24:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2005/08/31 16:23:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OLYMPUS
[2009/02/23 18:10:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PluginLab
[2003/09/16 10:22:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 01:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2003/04/10 00:27:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Share-to-Web Upload Folder
[2009/04/10 16:59:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SoundSpectrum
[2004/05/27 11:53:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TuneUp Software
[2004/03/18 13:27:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2002/08/29 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2003/11/03 17:53:00 | 00,000,272 | —- | M] () – C:\WINDOWS\Tasks\easy Internet sign-up.job
[2009/06/23 18:35:11 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2009/06/24 08:31:21 | 00,000,492 | —- | M] () – C:\WINDOWS\Tasks\Malwarebytes' Scheduled Scan for Owner.job
[2009/06/24 08:31:29 | 00,000,478 | —- | M] () – C:\WINDOWS\Tasks\Malwarebytes' Scheduled Update for Owner.job
[2009/06/23 18:34:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 60 bytes -> C:\winzip.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\WINDOWS:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\sound32.dll:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile.rtf:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\signaturefile.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\mmcInst.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\megaScenery.ini:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\megaCITY.ini:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Log.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\GodWill.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\gateway.asp.htm:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\e_partitiontable.dat:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\devicetable.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\debug.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\CWSInstall.exe:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\CONFIG.SYS:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\caisslog.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\caavsetupLog.txt:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\caavsetup.log:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\AUTOEXEC.BAT:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Archifects:AFP_AfpInfo
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B7BEAFF
@Alternate Data Stream - 101 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F7B65412
< End of report >