OTL logfile created on: 10/4/2009 3:56:44 PM - Run 1
OTL by OldTimer - Version 3.0.18.3 Folder = C:\Documents and Settings\Friend\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
381.80 Mb Total Physical Memory | 116.32 Mb Available Physical Memory | 30.47% Memory free
1.46 Gb Paging File | 1.25 Gb Available in Paging File | 85.68% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.61 Gb Total Space | 9.42 Gb Free Space | 50.59% Space Free | Partition Type: NTFS
Drive D: | 27.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-2B69D4607
Current User Name: Friend
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
PRC - C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft ActiveSync\rapimgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Friend\My Documents\Downloads\OTL.exe (OldTimer Tools)
========== Win32 Services (All) ==========
SRV - (Alerter [Disabled | Stopped]) -- C:\WINDOWS\System32\alrsvc.dll (Microsoft Corporation)
SRV - (ALG [On_Demand | Running]) -- C:\WINDOWS\System32\alg.exe (Microsoft Corporation)
SRV - (AppMgmt [On_Demand | Stopped]) -- C:\WINDOWS\System32\appmgmts.dll (Microsoft Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (AudioSrv [Auto | Running]) -- C:\WINDOWS\System32\audiosrv.dll (Microsoft Corporation)
SRV - (BITS [Auto | Running]) -- C:\WINDOWS\System32\qmgr.dll (Microsoft Corporation)
SRV - (Browser [Auto | Stopped]) -- C:\WINDOWS\System32\browser.dll (Microsoft Corporation)
SRV - (CiSvc [On_Demand | Stopped]) -- C:\WINDOWS\System32\cisvc.exe (Microsoft Corporation)
SRV - (ClipSrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\clipsrv.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (COMSysApp [On_Demand | Stopped]) -- C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation)
SRV - (CryptSvc [Auto | Running]) -- C:\WINDOWS\System32\cryptsvc.dll (Microsoft Corporation)
SRV - (DcomLaunch [Auto | Running]) -- C:\WINDOWS\System32\rpcss.dll (Microsoft Corporation)
SRV - (Dhcp [Auto | Running]) -- C:\WINDOWS\System32\dhcpcsvc.dll (Microsoft Corporation)
SRV - (dmadmin [On_Demand | Stopped]) -- C:\WINDOWS\System32\dmadmin.exe (Microsoft Corp., Veritas Software)
SRV - (dmserver [Auto | Running]) -- C:\WINDOWS\System32\dmserver.dll (Microsoft Corp.)
SRV - (Dnscache [Auto | Running]) -- C:\WINDOWS\System32\dnsrslvr.dll (Microsoft Corporation)
SRV - (Dot3svc [On_Demand | Stopped]) -- C:\WINDOWS\System32\dot3svc.dll (Microsoft Corporation)
SRV - (EapHost [On_Demand | Stopped]) -- C:\WINDOWS\System32\eapsvc.dll (Microsoft Corporation)
SRV - (ERSvc [Auto | Running]) -- C:\WINDOWS\System32\ersvc.dll (Microsoft Corporation)
SRV - (Eventlog [Auto | Running]) -- C:\WINDOWS\System32\services.exe (Microsoft Corporation)
SRV - (EventSystem [On_Demand | Running]) -- C:\WINDOWS\System32\es.dll (Microsoft Corporation)
SRV - (FastUserSwitchingCompatibility [On_Demand | Running]) -- C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (HidServ [Disabled | Stopped]) -- C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
SRV - (hkmsvc [On_Demand | Stopped]) -- C:\WINDOWS\System32\kmsvc.dll (Microsoft Corporation)
SRV - (HTTPFilter [On_Demand | Stopped]) -- C:\WINDOWS\System32\w3ssl.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (ImapiService [On_Demand | Stopped]) -- C:\WINDOWS\System32\imapi.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (lanmanserver [Auto | Running]) -- C:\WINDOWS\System32\srvsvc.dll (Microsoft Corporation)
SRV - (lanmanworkstation [Auto | Running]) -- C:\WINDOWS\System32\wkssvc.dll (Microsoft Corporation)
SRV - (LmHosts [Auto | Running]) -- C:\WINDOWS\System32\lmhsvc.dll (Microsoft Corporation)
SRV - (Messenger [Disabled | Stopped]) -- C:\WINDOWS\System32\msgsvc.dll (Microsoft Corporation)
SRV - (mnmsrvc [On_Demand | Stopped]) -- C:\WINDOWS\System32\mnmsrvc.exe (Microsoft Corporation)
SRV - (MSDTC [On_Demand | Stopped]) -- C:\WINDOWS\System32\msdtc.exe (Microsoft Corporation)
SRV - (MSIServer [On_Demand | Stopped]) -- C:\WINDOWS\System32\msiexec.exe (Microsoft Corporation)
SRV - (napagent [On_Demand | Stopped]) -- C:\WINDOWS\System32\qagentrt.dll (Microsoft Corporation)
SRV - (NetDDE [Disabled | Stopped]) -- C:\WINDOWS\System32\netdde.exe (Microsoft Corporation)
SRV - (NetDDEdsdm [Disabled | Stopped]) -- C:\WINDOWS\System32\netdde.exe (Microsoft Corporation)
SRV - (Netlogon [On_Demand | Stopped]) -- C:\WINDOWS\System32\lsass.exe (Microsoft Corporation)
SRV - (Netman [On_Demand | Running]) -- C:\WINDOWS\System32\netman.dll (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (Nla [On_Demand | Running]) -- C:\WINDOWS\System32\mswsock.dll (Microsoft Corporation)
SRV - (NtLmSsp [On_Demand | Stopped]) -- C:\WINDOWS\System32\lsass.exe (Microsoft Corporation)
SRV - (NtmsSvc [On_Demand | Stopped]) -- C:\WINDOWS\System32\ntmssvc.dll (Microsoft Corporation)
SRV - (PlugPlay [Auto | Running]) -- C:\WINDOWS\System32\services.exe (Microsoft Corporation)
SRV - (PolicyAgent [Auto | Running]) -- C:\WINDOWS\System32\lsass.exe (Microsoft Corporation)
SRV - (ProtectedStorage [Auto | Running]) -- C:\WINDOWS\System32\lsass.exe (Microsoft Corporation)
SRV - (RasAuto [On_Demand | Stopped]) -- C:\WINDOWS\System32\rasauto.dll (Microsoft Corporation)
SRV - (RasMan [On_Demand | Running]) -- C:\WINDOWS\System32\rasmans.dll (Microsoft Corporation)
SRV - (RDSessMgr [On_Demand | Stopped]) -- C:\WINDOWS\System32\sessmgr.exe (Microsoft Corporation)
SRV - (RemoteAccess [Disabled | Stopped]) -- C:\WINDOWS\System32\mprdim.dll (Microsoft Corporation)
SRV - (RemoteRegistry [Auto | Running]) -- C:\WINDOWS\System32\regsvc.dll (Microsoft Corporation)
SRV - (RetroLauncher [Auto | Running]) -- C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (RpcLocator [On_Demand | Stopped]) -- C:\WINDOWS\System32\locator.exe (Microsoft Corporation)
SRV - (RpcSs [Auto | Running]) -- C:\WINDOWS\System32\rpcss.dll (Microsoft Corporation)
SRV - (RSVP [On_Demand | Stopped]) -- C:\WINDOWS\System32\rsvp.exe (Microsoft Corporation)
SRV - (SamSs [Auto | Running]) -- C:\WINDOWS\System32\lsass.exe (Microsoft Corporation)
SRV - (SBAMSvc [Auto | Running]) -- C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe (Sunbelt Software)
SRV - (SCardSvr [On_Demand | Stopped]) -- C:\WINDOWS\System32\SCardSvr.exe (Microsoft Corporation)
SRV - (Schedule [Auto | Running]) -- C:\WINDOWS\System32\schedsvc.dll (Microsoft Corporation)
SRV - (seclogon [Auto | Running]) -- C:\WINDOWS\System32\seclogon.dll (Microsoft Corporation)
SRV - (SENS [Auto | Running]) -- C:\WINDOWS\System32\sens.dll (Microsoft Corporation)
SRV - (SharedAccess [Auto | Running]) -- C:\WINDOWS\System32\ipnathlp.dll (Microsoft Corporation)
SRV - (ShellHWDetection [Auto | Running]) -- C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
SRV - (Spooler [Auto | Running]) -- C:\WINDOWS\System32\spoolsv.exe (Microsoft Corporation)
SRV - (sprtsvc_ddoctorv2 [Auto | Running]) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (srservice [Auto | Running]) -- C:\WINDOWS\System32\srsvc.dll (Microsoft Corporation)
SRV - (SSDPSRV [On_Demand | Running]) -- C:\WINDOWS\System32\ssdpsrv.dll (Microsoft Corporation)
SRV - (stisvc [On_Demand | Stopped]) -- C:\WINDOWS\System32\wiaservc.dll (Microsoft Corporation)
SRV - (SwPrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\dllhost.exe (Microsoft Corporation)
SRV - (SysmonLog [On_Demand | Stopped]) -- C:\WINDOWS\System32\smlogsvc.exe (Microsoft Corporation)
SRV - (TapiSrv [On_Demand | Running]) -- C:\WINDOWS\System32\tapisrv.dll (Microsoft Corporation)
SRV - (TermService [On_Demand | Running]) -- C:\WINDOWS\System32\termsrv.dll (Microsoft Corporation)
SRV - (Themes [Auto | Running]) -- C:\WINDOWS\System32\shsvcs.dll (Microsoft Corporation)
SRV - (TlntSvr [Disabled | Stopped]) -- C:\WINDOWS\System32\tlntsvr.exe (Microsoft Corporation)
SRV - (TrkWks [Auto | Running]) -- C:\WINDOWS\System32\trkwks.dll (Microsoft Corporation)
SRV - (upnphost [On_Demand | Stopped]) -- C:\WINDOWS\System32\upnphost.dll (Microsoft Corporation)
SRV - (UPS [On_Demand | Stopped]) -- C:\WINDOWS\System32\ups.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (VSS [On_Demand | Stopped]) -- C:\WINDOWS\System32\vssvc.exe (Microsoft Corporation)
SRV - (W32Time [Auto | Running]) -- C:\WINDOWS\System32\w32time.dll (Microsoft Corporation)
SRV - (WebClient [Auto | Running]) -- C:\WINDOWS\System32\webclnt.dll (Microsoft Corporation)
SRV - (winmgmt [Auto | Running]) -- C:\WINDOWS\System32\wbem\WMIsvc.dll (Microsoft Corporation)
SRV - (WmdmPmSN [On_Demand | Stopped]) -- C:\WINDOWS\System32\mspmsnsv.dll (Microsoft Corporation)
SRV - (Wmi [On_Demand | Stopped]) -- C:\WINDOWS\System32\advapi32.dll (Microsoft Corporation)
SRV - (WmiApSrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\wbem\wmiapsrv.exe (Microsoft Corporation)
SRV - (wscsvc [Auto | Running]) -- C:\WINDOWS\System32\wscsvc.dll (Microsoft Corporation)
SRV - (wuauserv [Auto | Running]) -- C:\WINDOWS\System32\wuauserv.dll (Microsoft Corporation)
SRV - (WZCSVC [Auto | Running]) -- C:\WINDOWS\System32\wzcsvc.dll (Microsoft Corporation)
SRV - (xmlprov [On_Demand | Stopped]) -- C:\WINDOWS\System32\xmlprov.dll (Microsoft Corporation)
SRV - (YahooAUService [Auto | Running]) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (Aspi32 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
DRV - (cercsr6 [Boot | Stopped]) -- C:\WINDOWS\System32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IdeBusDr [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\IdeBusDr.sys (Intel Corporation)
DRV - (IdeChnDr [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\IdeChnDr.sys (Intel Corporation)
DRV - (MXOFX [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\MXOFX.SYS (Cypress Semiconductor)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (sbaphd [System | Running]) -- C:\WINDOWS\System32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (sbapifs [Auto | Running]) -- C:\WINDOWS\System32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (SBRE [System | Running]) -- C:\WINDOWS\System32\drivers\SBREdrv.sys (Sunbelt Software)
DRV - (sbtis [System | Running]) -- C:\WINDOWS\System32\drivers\sbtis.sys (Sunbelt Software)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (STAC97 [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (usb_rndisx [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\usb8023x.sys (Microsoft Corporation)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [System | Running]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.bearshare.com/intl/
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - prefs.js..keyword.URL: "
http://slirsredirect...ir=2706&query="
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/03 03:00:31 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/09/06 12:46:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/09/14 21:25:27 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/09/14 21:25:27 | 00,000,000 | ---D | M]
[2009/09/06 13:10:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Extensions
[2008/10/25 00:27:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/06 13:10:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Extensions\mozswing@mozswing.org
[2009/10/03 21:57:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Firefox\Profiles\4lvnd4s1.default\extensions
[2009/09/05 21:15:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Firefox\Profiles\4lvnd4s1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/10/24 20:57:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Firefox\Profiles\4lvnd4s1.default\extensions\{2fbc1200-ad13-11db-abbd-0800200c9a66}
[2008/10/24 20:57:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Firefox\Profiles\4lvnd4s1.default\extensions\{47e5a66c-0e35-11dc-8314-0800200c9a66}
[2009/09/12 17:46:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Firefox\Profiles\4lvnd4s1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/03 12:29:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mozilla\Firefox\Profiles\4lvnd4s1.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2009/10/03 21:57:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/09/14 21:25:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/09/06 12:47:11 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
[2009/09/14 21:25:19 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/09/14 21:25:19 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/09/06 12:46:50 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/09/14 21:25:23 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2003/05/15 00:01:48 | 00,133,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/07/30 02:24:20 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/30 02:24:20 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/30 02:24:20 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/30 02:24:20 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/30 02:24:20 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/30 02:24:20 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/30 02:24:20 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor)
O4 - HKLM..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe (Sunbelt Software)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\Wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.68.166 68.87.74.166
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\28712617684: DllName - C:\WINDOWS\System32\dinput32.dll - C:\WINDOWS\System32\dinput32.dll File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/05/06 15:04:37 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/02/23 11:20:50 | 00,000,040 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ==========
[6 C:\WINDOWS\*.tmp files]
[2009/10/04 13:41:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/02 22:21:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sunbelt
[2009/09/12 14:21:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/09/12 14:22:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/09/06 12:47:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Application Data\LimeWire
[2009/10/04 13:41:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Application Data\Malwarebytes
[2009/10/02 22:21:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Application Data\Sunbelt
[2009/09/12 14:22:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Application Data\Yahoo!
[2009/09/12 14:23:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Local Settings\Application Data\Yahoo
[1 C:\Documents and Settings\Friend\My Documents\*.tmp files]
[2009/10/04 13:41:17 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/04 03:00:36 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2009/10/02 22:18:55 | 00,000,000 | ---D | C] -- C:\Program Files\Sunbelt Software
[2009/10/03 19:18:15 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/09/12 14:21:49 | 00,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2009/10/04 15:26:53 | 00,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2009/10/04 13:41:19 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/04 13:41:17 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/04 13:35:59 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/10/04 13:19:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Desktop\IE_pages_without_titles_keep_popping_up_randomly_I_think_I_m_inf_t107374.ht
ml&gopid=600667_files
[2009/10/04 10:44:58 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/10/04 10:43:34 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/10/04 10:43:34 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/10/04 10:43:34 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/10/04 10:43:34 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/10/04 10:43:21 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/10/04 10:40:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\Desktop\IE_pages_without_titles_keep_popping_up_randomly_I_think_I_m_inf_t107374.ht
ml_files
[2009/10/04 10:39:31 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/10/02 22:25:23 | 00,069,936 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\sbapifs.sys
[2009/10/02 22:25:23 | 00,013,360 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\sbaphd.sys
[2009/10/02 22:19:09 | 00,203,056 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\sbtis.sys
[2009/10/02 21:08:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8
[2009/10/02 21:03:48 | 00,000,000 | ---D | C] -- C:\ef28c563b48d5ea6fd0266d1c365fc83
[2009/09/19 15:47:45 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2009/09/07 14:02:46 | 00,027,944 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2009/09/06 13:07:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\My Documents\Downloads
[2009/09/06 13:04:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Friend\My Documents\LimeWire
[2009/09/06 12:47:08 | 00,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2009/09/06 12:47:07 | 00,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2009/09/06 12:47:07 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/09/06 12:47:07 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/09/06 12:47:07 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[6 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Friend\My Documents\*.tmp files]
[2009/10/04 15:52:06 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/04 15:51:41 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/04 15:51:35 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/04 15:50:48 | 00,425,872 | -H-- | M] () -- C:\Documents and Settings\Friend\Local Settings\Application Data\IconCache.db
[2009/10/04 15:48:38 | 00,002,096 | ---- | M] () -- C:\Documents and Settings\Friend\My Documents\mbam-log-2009-10-04 (15-48-19)full
[2009/10/04 13:41:21 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/04 13:33:37 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/10/04 13:24:24 | 03,325,144 | R--- | M] () -- C:\Documents and Settings\Friend\Desktop\ComboFix.exe
[2009/10/04 13:21:38 | 00,121,790 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\IE_pages_without_titles_keep_popping_up_randomly_I_think_I_m_inf_t107374.ht
ml&gopid=600667.htm
[2009/10/04 10:55:10 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/10/04 10:45:05 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/10/04 10:40:16 | 00,092,646 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\IE_pages_without_titles_keep_popping_up_randomly_I_think_I_m_inf_t107374.ht
ml.htm
[2009/10/03 19:18:16 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\HijackThis.lnk
[2009/10/02 21:02:25 | 00,065,848 | ---- | M] () -- C:\Documents and Settings\Friend\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/17 21:30:36 | 00,020,877 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\coco_chanel1.jpg
[2009/09/17 20:30:03 | 00,014,433 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\alexis-Bledel-hotpictures-03.jpg
[2009/09/17 20:29:15 | 00,046,173 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\198.jpg
[2009/09/17 20:29:07 | 00,020,438 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\199.jpg
[2009/09/17 20:29:00 | 00,047,930 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\197.jpg
[2009/09/17 20:28:40 | 00,017,754 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\195.jpg
[2009/09/17 20:28:32 | 00,021,018 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\194.jpg
[2009/09/17 20:28:30 | 00,019,924 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\193.jpg
[2009/09/17 20:27:46 | 00,033,439 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\180.jpg
[2009/09/17 20:27:36 | 00,041,416 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\179.jpg
[2009/09/17 20:27:02 | 00,033,720 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\175.jpg
[2009/09/17 20:26:32 | 00,038,580 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\174.jpg
[2009/09/17 20:26:24 | 00,029,506 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\173.jpg
[2009/09/17 20:26:11 | 00,030,475 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\172.jpg
[2009/09/17 20:25:45 | 00,031,389 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\166.jpg
[2009/09/17 20:25:24 | 00,022,600 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\163.jpg
[2009/09/17 20:22:13 | 00,027,649 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\139.jpg
[2009/09/17 20:20:14 | 00,036,823 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\133.jpg
[2009/09/17 20:20:10 | 00,046,391 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\134.jpg
[2009/09/17 20:19:36 | 00,026,137 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\129.jpg
[2009/09/17 20:19:29 | 00,027,826 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\126.jpg
[2009/09/17 20:19:25 | 00,030,662 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\125.jpg
[2009/09/17 20:19:13 | 00,028,873 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\127.jpg
[2009/09/17 20:19:11 | 00,025,978 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\130.jpg
[2009/09/17 20:18:55 | 00,018,192 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\123.jpg
[2009/09/17 20:18:33 | 00,018,639 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\122.jpg
[2009/09/17 20:18:30 | 00,019,570 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\121.jpg
[2009/09/17 20:18:02 | 00,021,210 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\120.jpg
[2009/09/17 20:17:59 | 00,022,907 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\119.jpg
[2009/09/17 20:17:48 | 00,027,321 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\118.jpg
[2009/09/17 20:17:01 | 00,021,412 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\115.jpg
[2009/09/17 20:16:48 | 00,028,327 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\112.jpg
[2009/09/17 20:16:35 | 00,023,573 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\101.jpg
[2009/09/17 20:16:26 | 00,022,954 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\103.jpg
[2009/09/17 20:16:20 | 00,013,426 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\104.jpg
[2009/09/17 20:15:58 | 00,024,507 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\110.jpg
[2009/09/17 18:34:44 | 00,030,090 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\proenza.jpg
[2009/09/17 16:14:32 | 00,275,589 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\coco-chanel.jpg
[2009/09/15 12:16:46 | 00,046,096 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\gagabub.jpg
[2009/09/15 12:08:53 | 00,046,096 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\mrbubbles.jpg
[2009/09/15 11:47:03 | 00,204,868 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\gaga.jpg
[2009/09/14 02:12:36 | 00,229,888 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2009/09/13 12:44:12 | 00,000,624 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/09/13 11:34:13 | 00,052,800 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\mp_main_wide_SylviaPlathSelfPortrait.jpg
[2009/09/12 14:22:07 | 00,000,812 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/10 03:00:53 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/09/07 14:02:46 | 00,027,944 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2009/09/06 17:20:38 | 00,211,360 | ---- | M] () -- C:\Documents and Settings\Friend\My Documents\colorful_lady_gaga_1024x768.jpg
[2009/09/06 13:08:44 | 00,001,580 | ---- | M] () -- C:\Documents and Settings\Friend\Desktop\LimeWire 5.2.13.lnk
[2009/09/06 12:46:50 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2009/09/06 12:46:50 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/09/06 12:46:50 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/09/06 12:46:50 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2009/09/06 12:46:50 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
========== Files - No Company Name ==========
[2009/10/04 15:48:38 | 00,002,096 | ---- | C] () -- C:\Documents and Settings\Friend\My Documents\mbam-log-2009-10-04 (15-48-19)full
[2009/10/04 13:41:21 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/04 13:19:00 | 00,121,790 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\IE_pages_without_titles_keep_popping_up_randomly_I_think_I_m_inf_t107374.ht
ml&gopid=600667.htm
[2009/10/04 10:45:05 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/10/04 10:45:00 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/10/04 10:43:34 | 00,229,888 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/10/04 10:43:34 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/10/04 10:43:34 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/10/04 10:43:34 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/10/04 10:40:11 | 00,092,646 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\IE_pages_without_titles_keep_popping_up_randomly_I_think_I_m_inf_t107374.ht
ml.htm
[2009/10/04 10:38:16 | 03,325,144 | R--- | C] () -- C:\Documents and Settings\Friend\Desktop\ComboFix.exe
[2009/10/03 19:18:15 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\HijackThis.lnk
[2009/09/17 21:30:34 | 00,020,877 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\coco_chanel1.jpg
[2009/09/17 20:30:02 | 00,014,433 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\alexis-Bledel-hotpictures-03.jpg
[2009/09/17 20:29:15 | 00,046,173 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\198.jpg
[2009/09/17 20:29:07 | 00,020,438 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\199.jpg
[2009/09/17 20:29:00 | 00,047,930 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\197.jpg
[2009/09/17 20:28:39 | 00,017,754 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\195.jpg
[2009/09/17 20:28:32 | 00,021,018 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\194.jpg
[2009/09/17 20:28:29 | 00,019,924 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\193.jpg
[2009/09/17 20:27:45 | 00,033,439 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\180.jpg
[2009/09/17 20:27:35 | 00,041,416 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\179.jpg
[2009/09/17 20:27:02 | 00,033,720 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\175.jpg
[2009/09/17 20:26:31 | 00,038,580 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\174.jpg
[2009/09/17 20:26:24 | 00,029,506 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\173.jpg
[2009/09/17 20:26:10 | 00,030,475 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\172.jpg
[2009/09/17 20:25:45 | 00,031,389 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\166.jpg
[2009/09/17 20:25:24 | 00,022,600 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\163.jpg
[2009/09/17 20:22:12 | 00,027,649 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\139.jpg
[2009/09/17 20:20:14 | 00,036,823 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\133.jpg
[2009/09/17 20:20:09 | 00,046,391 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\134.jpg
[2009/09/17 20:19:36 | 00,026,137 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\129.jpg
[2009/09/17 20:19:29 | 00,027,826 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\126.jpg
[2009/09/17 20:19:24 | 00,030,662 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\125.jpg
[2009/09/17 20:19:13 | 00,028,873 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\127.jpg
[2009/09/17 20:19:10 | 00,025,978 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\130.jpg
[2009/09/17 20:18:54 | 00,018,192 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\123.jpg
[2009/09/17 20:18:33 | 00,018,639 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\122.jpg
[2009/09/17 20:18:28 | 00,019,570 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\121.jpg
[2009/09/17 20:18:01 | 00,021,210 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\120.jpg
[2009/09/17 20:17:58 | 00,022,907 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\119.jpg
[2009/09/17 20:17:47 | 00,027,321 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\118.jpg
[2009/09/17 20:16:59 | 00,021,412 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\115.jpg
[2009/09/17 20:16:46 | 00,028,327 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\112.jpg
[2009/09/17 20:16:33 | 00,023,573 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\101.jpg
[2009/09/17 20:16:25 | 00,022,954 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\103.jpg
[2009/09/17 20:16:19 | 00,013,426 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\104.jpg
[2009/09/17 20:15:58 | 00,024,507 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\110.jpg
[2009/09/17 18:34:41 | 00,030,090 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\proenza.jpg
[2009/09/17 16:14:26 | 00,275,589 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\coco-chanel.jpg
[2009/09/15 12:16:39 | 00,046,096 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\gagabub.jpg
[2009/09/15 12:08:51 | 00,046,096 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\mrbubbles.jpg
[2009/09/15 11:46:58 | 00,204,868 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\gaga.jpg
[2009/09/13 11:34:11 | 00,052,800 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\mp_main_wide_SylviaPlathSelfPortrait.jpg
[2009/09/12 14:22:07 | 00,000,812 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Messenger.lnk
[2009/09/06 17:20:38 | 00,211,360 | ---- | C] () -- C:\Documents and Settings\Friend\My Documents\colorful_lady_gaga_1024x768.jpg
[2009/09/06 13:08:44 | 00,001,580 | ---- | C] () -- C:\Documents and Settings\Friend\Desktop\LimeWire 5.2.13.lnk
[2009/02/18 01:45:13 | 00,003,584 | ---- | C] () -- C:\Documents and Settings\Friend\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/21 00:47:52 | 00,002,528 | ---- | C] () -- C:\Documents and Settings\Friend\Application Data\$_hpcst$.hpc
[2008/10/24 19:12:03 | 00,425,872 | -H-- | C] () -- C:\Documents and Settings\Friend\Local Settings\Application Data\IconCache.db
[2008/10/21 21:48:17 | 00,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
[2008/10/20 17:01:57 | 00,065,848 | ---- | C] () -- C:\Documents and Settings\Friend\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/10/16 19:42:08 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Friend\Application Data\desktop.ini
[2008/05/09 10:44:00 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/05/06 15:32:58 | 00,258,048 | ---- | C] () -- C:\WINDOWS\System32\shpshftr.dll
[2008/05/06 15:32:57 | 00,009,785 | ---- | C] () -- C:\WINDOWS\System32\drivers\a312.sys
[2008/05/06 15:32:42 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\igfxdgps.dll
[2008/05/06 10:06:42 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/04 05:00:00 | 00,000,624 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 05:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
========== LOP Check ==========
[2009/10/04 13:41:17 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/10/21 21:47:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2008/10/30 19:24:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Comcast
[2008/10/25 00:27:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Retrospect
[2008/10/20 17:23:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/10/25 00:28:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/10/04 13:41:25 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Friend\Application Data
[2008/10/21 21:49:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\acccore
[2009/08/11 15:09:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\ComcastToolbar
[2009/10/04 15:51:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\DNA
[2008/10/24 20:57:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\GetRightToGo
[2009/10/03 18:49:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\LimeWire
[2009/03/08 14:25:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\mIRC
[2008/10/21 21:50:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\QQ Games
[2008/10/21 21:50:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Friend\Application Data\QQ Games Plugin
[2004/08/04 05:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/04 15:51:41 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >
Once again, thank you so much for taking the time to help me.