GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2009-12-30 14:16:16
Windows 5.1.2600 Service Pack 2
Running: q5zuyknf.exe; Driver: F:\DOCUME~1\DANMIL~1\LOCALS~1\Temp\awlyypow.sys
—- System - GMER 1.0.15 —-
Code 8A2F3618 ZwEnumerateKey
Code 8A2F3A80 ZwFlushInstructionCache
Code 8A2F30BE IofCallDriver
Code 8A2F2E7E IofCompleteRequest
—- Modules - GMER 1.0.15 —-
Module \systemroot\system32\drivers\H8SRTjtnaoykmvm.sys (*** hidden *** ) B5904000-B5920000 (114688 bytes)
—- Processes - GMER 1.0.15 —-
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\system32\svchost.exe [624] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\Explorer.EXE [748] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [932] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\system32\svchost.exe [1116] 0x00BA0000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\system32\svchost.exe [1196] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [1352] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [1456] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [1612] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [2060] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [2240] 0x10000000
Library \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll (*** hidden *** ) @ F:\WINDOWS\System32\svchost.exe [2508] 0x10000000
—- Services - GMER 1.0.15 —-
Service F:\WINDOWS\system32\drivers\H8SRTjtnaoykmvm.sys (*** hidden *** ) [SYSTEM] H8SRTd.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTlkbwsndrgo.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTxumltehhbm.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTixdjkwkpql.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTjtnaoykmvm.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTlkbwsndrgo.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTxumltehhbm.dat
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTbuiqrbcjlq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtbbr \\?\globalroot\systemroot\system32\H8SRTixdjkwkpql.dll
—- EOF - GMER 1.0.15 —-
Computer Name: DANANDBARB
Current User Name: Dan Miller
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
PRC - F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
PRC - F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
PRC - F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - F:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
PRC - F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe (AOL LLC)
PRC - F:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - F:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
PRC - F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
PRC - F:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
PRC - F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe (American Power Conversion Corporation)
PRC - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
========== Modules (SafeList) ==========
MOD - F:\Documents and Settings\Dan Miller\My Documents\OTL.exe (OldTimer Tools)
MOD - F:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
MOD - F:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - F:\Program Files\ScanSoft\OmniPageSE\ophook32.dll (ScanSoft, Inc)
========== Win32 Services (SafeList) ==========
SRV - (JavaQuickStarterService) – F:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (gusvc) – F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (TomTomHOMEService) – F:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (AntiVirService) – F:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (iPod Service) – F:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (PCPitstop Scheduling) – F:\Program Files\PCPitstop\PCPitstopScheduleService.exe (PC Pitstop LLC)
SRV - (Apple Mobile Device) – F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirSchedulerService) – F:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (NVSvc) – F:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Bonjour Service) – F:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (hpqcxs08) – F:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (Pml Driver HPZ12) – F:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – F:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (hpqddsvc) – F:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – F:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (AdobeActiveFileMonitor5.0) – F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe ()
SRV - (IDriverT) – F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (RetroExpLauncher) – F:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (ose) – F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (APC UPS Service) – F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
========== Driver Services (SafeList) ==========
DRV - (avgntflt) – F:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (MBAMSwissArmy) – F:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – F:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – F:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – F:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ssmdrv) – F:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – F:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (GEARAspiWDM) – F:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (PxHelp20) – F:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ASCTRM) – F:\WINDOWS\system32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (nv) – F:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (avgio) – F:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hap17v2k) – F:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – F:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – F:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – F:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – F:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – F:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – F:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – F:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – F:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – F:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – F:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) – F:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – F:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) – F:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – F:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) – F:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – F:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) – F:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (Secdrv) – F:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (HPZius12) – F:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – F:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – F:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (BCM43XX) – F:\WINDOWS\system32\drivers\bcmwl5.sys (Broadcom Corporation)
DRV - (MXOPSWD) – F:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (MXOFX) USB Storage Adapter FX (MXO) – F:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (GTNDIS5) – F:\WINDOWS\system32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Ptilink) – F:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (E100B) Intel® – F:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (wanatw) WAN Miniport (ATW) – F:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (OMCI) – F:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (MODEMCSA) – F:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (SONYPVU1) Sony USB Filter Driver (SONYPVU1) – F:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (HidBatt) – F:\WINDOWS\system32\drivers\hidbatt.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
IE - HKCU\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions
[2009/07/18 10:24:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Mozilla\Extensions\[removed]
O1 HOSTS File: (734 bytes) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IEToolbarBHO Class) - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (AOL Toolbar Loader) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - F:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (LinkedIn Toolbar) - {BB670D0B-5C46-40C7-B38B-40DD26987723} - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedInIEToolbar.dll (LinkedIn)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - F:\Program Files\AOL Toolbar\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Adobe Photo Downloader] F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] F:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] F:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTHelper] F:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [HostManager] F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HP Software Update] F:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [MaxtorOneTouch] F:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [MXOBG] F:\WINDOWS\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] F:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] F:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Omnipage] F:\Program Files\ScanSoft\OmniPageSE\opware32.exe (ScanSoft, Inc)
O4 - HKLM..\Run: [QuickTime Task] F:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] F:\Program Files\SUPERAntiSpyware\8a924459-05f3-41e8-848d-af5e0bd2d781.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe (American Power Conversion Corporation)
O4 - Startup: F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = F:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\AOL Desktop.lnk = F:\Program Files\Common Files\AOL\Launch\aollaunch.exe (AOL LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL; Toolbar Search - F:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Linked&In; Search - F:\Program Files\LinkedIn\IE Toolbar\3.0.4.1100\LinkedinIEToolbar.dll (LinkedIn)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - F:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1237306142784 (WUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://intercall.webex.com/client/T26L10NS…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
http://utilities.pcpitstop.com/da2/PCPitStop2.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG9\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll - F:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - F:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/16 16:49:43 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7545388f-13f9-11de-b1df-00038a000015}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{acf46578-eccc-11de-b370-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{acf46578-eccc-11de-b370-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{acf46578-eccc-11de-b370-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{acf46579-eccc-11de-b370-00038a000015}\Shell\AutoRun\command - "" = H:\setupSNK.exe – File not found
O33 - MountPoints2\{d1fc906c-73ae-11de-b29c-00038a000015}\Shell\AutoRun\command - "" = G:\InstallTomTomHOME.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2009/12/30 14:17:11 | 00,513,536 | —- | C] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:10:17 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\gmer
[2009/12/30 11:46:56 | 00,000,000 | —D | C] – F:\Program Files\Trend Micro
[2009/12/30 10:55:14 | 00,096,104 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avipbb.sys
[2009/12/30 10:55:14 | 00,056,816 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 10:55:14 | 00,045,416 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntdd.sys
[2009/12/30 10:55:14 | 00,022,360 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntmgr.sys
[2009/12/30 10:55:13 | 00,028,520 | —- | C] (Avira GmbH) – F:\WINDOWS\System32\drivers\ssmdrv.sys
[2009/12/30 10:55:12 | 00,000,000 | —D | C] – F:\Program Files\Avira
[2009/12/30 10:55:12 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\Avira
[2009/12/30 10:29:46 | 00,000,000 | —D | M] – F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | –SD | M] – F:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/12/30 10:10:00 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/12/30 07:49:44 | 00,000,000 | —D | C] – F:\Program Files\AxBx
[2009/12/30 07:27:23 | 00,000,000 | RH-D | C] – F:\Documents and Settings\Dan Miller\Recent
[2009/12/30 07:25:21 | 00,000,000 | —D | C] – F:\Program Files\CCleaner
[2009/12/30 07:24:42 | 03,357,024 | —- | C] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 05:22:00 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\avg9
[2009/12/30 04:26:26 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\SUPERAntiSpyware.com
[2009/12/30 04:22:08 | 00,000,000 | —D | C] – F:\Program Files\SUPERAntiSpyware
[2009/12/29 18:26:19 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\AVG8
[2009/12/29 18:26:10 | 00,891,248 | —- | C] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/29 08:42:53 | 00,470,528 | —- | C] (Microsoft Corporation) – F:\WINDOWS\System32\dllcache\aclayers.dll
[2009/12/29 08:41:44 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaws.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\javaw.exe
[2009/12/29 08:41:44 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – F:\WINDOWS\System32\java.exe
[2009/12/19 13:31:45 | 00,000,000 | —D | C] – F:\Program Files\Common Files\SWF Studio
[2009/12/19 13:31:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\U3
[2009/12/18 17:22:41 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Pictures for Mom
[2009/12/14 08:10:18 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\Adobe
[2009/12/14 08:02:11 | 00,000,000 | —D | C] – F:\Documents and Settings\All Users\Documents\Adobe PDF
[2009/12/13 19:49:46 | 00,000,000 | R–D | C] – F:\Documents and Settings\Dan Miller\My Documents\My Videos
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Output
[2009/12/11 12:22:14 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\ScheduleOCR Input
[2009/12/09 14:08:55 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/12/09 14:08:49 | 00,000,000 | —D | C] – F:\Program Files\TweetDeck
[2009/12/03 17:19:23 | 00,000,000 | —D | C] – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009
[2009/03/17 11:46:53 | 00,000,000 | —D | M] – F:\Documents and Settings\LocalService\Local Settings\Application Data\AOL
[2008/06/27 17:26:00 | 00,010,752 | —- | C] ( ) – F:\WINDOWS\System32\a3d.dll
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009/12/30 14:26:23 | 00,000,199 | —- | M] () – F:\WINDOWS\System32\srcr.dat
[2009/12/30 14:23:47 | 00,212,641 | —- | M] () – F:\WINDOWS\System32\nvapps.xml
[2009/12/30 14:23:00 | 00,000,006 | -H– | M] () – F:\WINDOWS\tasks\SA.DAT
[2009/12/30 14:22:55 | 00,002,048 | –S- | M] () – F:\WINDOWS\bootstat.dat
[2009/12/30 14:17:14 | 00,513,536 | —- | M] (OldTimer Tools) – F:\Documents and Settings\Dan Miller\My Documents\OTL.exe
[2009/12/30 14:12:34 | 00,293,376 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 14:08:06 | 00,284,915 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\gmer.zip
[2009/12/30 14:04:39 | 00,525,946 | —- | M] () – F:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/30 14:04:39 | 00,444,028 | —- | M] () – F:\WINDOWS\System32\perfh009.dat
[2009/12/30 14:04:39 | 00,071,904 | —- | M] () – F:\WINDOWS\System32\perfc009.dat
[2009/12/30 14:02:04 | 00,000,988 | —- | M] () – F:\WINDOWS\win.ini
[2009/12/30 11:46:56 | 00,001,734 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 11:10:27 | 00,056,816 | —- | M] (Avira GmbH) – F:\WINDOWS\System32\drivers\avgntflt.sys
[2009/12/30 11:02:11 | 05,767,168 | -H– | M] () – F:\Documents and Settings\Dan Miller\NTUSER.DAT
[2009/12/30 11:02:11 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:11 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:11 | 00,030,120 | —- | M] () – F:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:11 | 00,011,564 | —- | M] () – F:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:02:10 | 00,030,912 | —- | M] () – F:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/12/30 11:01:55 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.CDF
[2009/12/30 11:01:55 | 04,958,588 | —- | M] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 10:55:27 | 00,001,707 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/12/30 08:28:16 | 00,008,640 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:35:42 | 00,071,042 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:34:31 | 00,061,044 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:32:39 | 00,018,652 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 07:24:50 | 03,357,024 | —- | M] (Piriform Ltd) – F:\Documents and Settings\Dan Miller\My Documents\ccsetup227.exe
[2009/12/30 06:35:29 | 00,891,248 | —- | M] (AVG Technologies) – F:\Documents and Settings\Dan Miller\My Documents\avg_free_stb_all_9_40_cnet.exe
[2009/12/30 04:22:10 | 00,000,780 | —- | M] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/30 04:20:51 | 00,000,675 | —- | M] () – F:\WINDOWS\System32\krl32mainweq.dll
[2009/12/29 14:26:00 | 00,000,472 | —- | M] () – F:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/12/29 14:17:55 | 00,000,696 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/29 13:52:45 | 00,000,278 | -HS- | M] () – F:\Documents and Settings\Dan Miller\ntuser.ini
[2009/12/29 08:42:40 | 00,002,422 | —- | M] () – F:\WINDOWS\System32\wpa.dbl
[2009/12/28 22:31:34 | 00,000,008 | —- | M] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:10 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 12:57:19 | 00,131,072 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/18 10:28:54 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/17 08:21:43 | 00,002,497 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Word 2003.lnk
[2009/12/16 15:01:33 | 02,418,688 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\tiger.pps
[2009/12/15 19:07:00 | 34,650,112 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settingsbkup.sfm
[2009/12/15 17:26:43 | 00,001,076 | —- | M] () – F:\WINDOWS\System32\settings.sfm
[2009/12/14 15:52:03 | 00,026,624 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/14 15:01:10 | 00,090,128 | —- | M] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/12/14 14:59:09 | 00,313,968 | —- | M] () – F:\WINDOWS\System32\FNTCACHE.DAT
[2009/12/14 13:35:22 | 00,025,600 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:48:24 | 34,648,576 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:37:15 | 34,650,624 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 11:24:07 | 34,651,648 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:56:22 | 34,651,136 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:38:31 | 34,652,160 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:36 | 03,434,269 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | M] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | M] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/14 07:59:41 | 00,053,248 | —- | M] () – F:\WINDOWS\System32\pxhpinst.exe
[2009/12/13 11:30:20 | 04,402,988 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:20:07 | 01,620,362 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/12 16:06:24 | 00,002,483 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office PowerPoint 2003.lnk
[2009/12/11 12:22:24 | 01,647,104 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:51 | 00,000,640 | —- | M] () – F:\Documents and Settings\All Users\Desktop\TweetDeck.lnk
[2009/12/09 14:08:17 | 02,652,400 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:23 | 00,963,023 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/03 16:14:06 | 00,038,224 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/03 16:13:56 | 00,019,160 | —- | M] (Malwarebytes Corporation) – F:\WINDOWS\System32\drivers\mbam.sys
[2009/12/01 20:11:41 | 00,015,360 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 20:00:00 | 00,002,495 | —- | M] () – F:\Documents and Settings\Dan Miller\Desktop\Microsoft Office Excel 2003.lnk
[2009/12/01 19:48:18 | 00,024,064 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 18:30:10 | 00,074,240 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\DanMiller_Resume.doc
[2009/12/01 11:24:35 | 00,089,088 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\CaputoValueProp.pps
[2009/12/01 11:14:39 | 00,232,448 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\Value Added Discussions.doc
[2009/12/01 10:08:28 | 00,122,412 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\2009Friends-Family.pdf
[2009/12/01 08:57:17 | 00,064,592 | —- | M] () – F:\Documents and Settings\Dan Miller\My Documents\NST-EST2008-alldata.csv
[7 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[6 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[3 F:\Documents and Settings\Dan Miller\My Documents\*.tmp files -> F:\Documents and Settings\Dan Miller\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009/12/30 14:26:23 | 00,000,199 | —- | C] () – F:\WINDOWS\System32\srcr.dat
[2009/12/30 14:12:31 | 00,293,376 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\q5zuyknf.exe
[2009/12/30 14:08:04 | 00,284,915 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\gmer.zip
[2009/12/30 11:46:56 | 00,001,734 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\HijackThis.lnk
[2009/12/30 10:55:27 | 00,001,707 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2009/12/30 08:27:55 | 00,008,640 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_082754.reg
[2009/12/30 07:38:00 | 04,958,588 | —- | C] () – F:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK
[2009/12/30 07:34:45 | 00,071,042 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073444.reg
[2009/12/30 07:33:04 | 00,061,044 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073302.reg
[2009/12/30 07:30:49 | 00,018,652 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\cc_20091230_073045.reg
[2009/12/30 07:25:22 | 00,001,548 | —- | C] () – F:\Documents and Settings\Dan Miller\Desktop\CCleaner.lnk
[2009/12/30 04:22:10 | 00,000,780 | —- | C] () – F:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/12/30 04:20:51 | 00,000,675 | —- | C] () – F:\WINDOWS\System32\krl32mainweq.dll
[2009/12/28 22:31:34 | 00,000,008 | —- | C] () – F:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/18 13:03:07 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal_Drinking_Age_-_Generational_shifts 2.xls
[2009/12/18 10:41:48 | 00,131,072 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Legal Drinking Age - Generational shifts.xls
[2009/12/16 15:01:27 | 02,418,688 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\tiger.pps
[2009/12/14 18:12:06 | 34,650,112 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 6.doc
[2009/12/14 13:01:14 | 00,025,600 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter to Mother.doc
[2009/12/14 11:39:25 | 34,648,576 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 5.doc
[2009/12/14 11:24:13 | 34,650,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 4.doc
[2009/12/14 10:59:43 | 34,651,648 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 3.doc
[2009/12/14 10:38:36 | 34,651,136 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 2.doc
[2009/12/14 10:14:50 | 34,652,160 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Christmas Addresses 2009 part 1.doc
[2009/12/14 10:11:33 | 03,434,269 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Barb and Dan for Xmas cards 2009.jpg
[2009/12/14 08:02:18 | 00,000,988 | —- | C] () – F:\Documents and Settings\Dan Miller\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2009/12/14 08:01:41 | 00,001,882 | —- | C] () – F:\Documents and Settings\All Users\Desktop\Adobe Premiere Elements 3.0.lnk
[2009/12/13 11:28:04 | 04,402,988 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Dan & Barb Xmas shot.JPG
[2009/12/12 19:21:50 | 01,620,362 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\lourcey.jpg
[2009/12/11 12:22:21 | 01,647,104 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Gingerbread house.doc
[2009/12/09 14:08:10 | 02,652,400 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\TweetDeck_0_32.1.air
[2009/12/03 17:19:20 | 00,963,023 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CensusTestingSitesHtfdWinter2009.zip
[2009/12/01 20:02:40 | 00,015,360 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Santini Letter.xls
[2009/12/01 19:48:17 | 00,024,064 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Letter for Santini.doc
[2009/12/01 11:24:32 | 00,089,088 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\CaputoValueProp.pps
[2009/12/01 11:14:38 | 00,232,448 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\Value Added Discussions.doc
[2009/12/01 10:08:28 | 00,122,412 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\2009Friends-Family.pdf
[2009/12/01 09:46:01 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\people born by year.xls
[2009/12/01 08:57:10 | 00,064,592 | —- | C] () – F:\Documents and Settings\Dan Miller\My Documents\NST-EST2008-alldata.csv
[2009/08/15 10:40:36 | 00,005,957 | —- | C] () – F:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/07/28 10:10:06 | 00,038,460 | —- | C] () – F:\Documents and Settings\Dan Miller\Application Data\Microsoft Excel.ADR
[2009/07/18 11:53:35 | 00,025,713 | —- | C] () – F:\WINDOWS\CSTBox.INI
[2009/07/18 11:41:31 | 00,040,960 | —- | C] () – F:\WINDOWS\System32\IPPCPUID.DLL
[2009/07/18 11:41:31 | 00,000,105 | —- | C] () – F:\WINDOWS\UMXADDIN.INI
[2009/07/18 11:41:31 | 00,000,091 | —- | C] () – F:\WINDOWS\PM20.INI
[2009/07/18 11:41:15 | 00,011,776 | —- | C] () – F:\WINDOWS\System32\pmsbfn32.dll
[2009/07/18 11:40:36 | 00,000,074 | —- | C] () – F:\WINDOWS\PMINI.ini
[2009/07/18 10:45:45 | 00,000,525 | —- | C] () – F:\WINDOWS\MAXLINK.INI
[2009/04/07 17:24:56 | 00,000,133 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\fusioncache.dat
[2009/03/31 18:44:13 | 00,008,704 | —- | C] () – F:\WINDOWS\System32\CNMVS7D.DLL
[2009/03/18 19:32:35 | 00,026,624 | —- | C] () – F:\Documents and Settings\Dan Miller\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/17 11:58:25 | 00,012,288 | —- | C] () – F:\WINDOWS\System32\e100bmsg.dll
[2009/03/16 19:22:40 | 00,094,208 | —- | C] () – F:\WINDOWS\System32\GTW32N50.dll
[2009/03/16 17:01:49 | 00,000,376 | —- | C] () – F:\WINDOWS\ODBC.INI
[2009/02/18 14:44:00 | 01,724,416 | —- | C] () – F:\WINDOWS\System32\nvwdmcpl.dll
[2009/02/18 14:44:00 | 01,507,328 | —- | C] () – F:\WINDOWS\System32\nview.dll
[2009/02/18 14:44:00 | 01,101,824 | —- | C] () – F:\WINDOWS\System32\nvwimg.dll
[2009/02/18 14:44:00 | 00,466,944 | —- | C] () – F:\WINDOWS\System32\nvshell.dll
[2008/06/27 18:05:08 | 00,049,565 | —- | C] () – F:\WINDOWS\System32\instwdm.ini
[2008/06/27 18:05:06 | 00,000,054 | —- | C] () – F:\WINDOWS\System32\ctzapxx.ini
[2008/06/27 17:27:54 | 00,043,520 | —- | C] () – F:\WINDOWS\System32\CTBurst.dll
[2007/08/13 20:45:02 | 00,077,824 | —- | C] () – F:\WINDOWS\System32\ctmmactl.dll
[2006/10/02 17:25:18 | 00,000,307 | —- | C] () – F:\WINDOWS\System32\kill.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – F:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/08/31 23:19:04 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Age of Empires 3 XPack Trial
[2009/10/03 23:39:38 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Age of Empires 3 YPack Trial
[2009/12/30 11:42:15 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\avg9
[2009/03/31 18:44:18 | 00,000,000 | -H-D | M] – F:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/03/17 12:14:39 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/03/18 19:21:28 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\espionServerData
[2009/08/15 16:45:22 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Geek Squad
[2009/08/15 14:00:28 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\PCPitstop
[2009/12/30 14:26:42 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\RetroExp
[2009/07/18 10:52:18 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/08/02 10:53:21 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Sony
[2009/07/18 10:52:34 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2009/07/18 11:11:40 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\SSScanWizard
[2009/07/18 10:24:40 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\TomTom
[2009/03/17 11:46:19 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/18 13:42:28 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/03/17 12:14:00 | 00,000,000 | -H-D | M] – F:\Documents and Settings\All Users\Application Data\{66E2F539-12B6-4870-A500-7689CDE75C5E}
[2009/04/07 14:57:29 | 00,000,000 | —D | M] – F:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/10/30 16:51:19 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Acapela Group
[2009/03/17 11:47:21 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\acccore
[2009/07/18 13:18:46 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Canon
[2009/03/17 12:17:25 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/04/28 14:07:31 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\FoxPlayerAIR.01F2E49DE175CC541F416F2DF78BDD5E63AD0096.1
[2009/04/24 17:30:51 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\LinkedIn
[2009/09/25 09:01:09 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Opera
[2009/08/02 10:56:21 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Publish Providers
[2009/07/18 10:45:46 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\ScanSoft
[2009/08/02 11:01:26 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Sony
[2009/08/02 10:46:27 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Sony Setup
[2009/07/18 10:24:22 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\TomTom
[2009/06/29 14:53:29 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2009/12/09 14:08:55 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2009/03/17 12:13:59 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Uniblue
[2009/06/09 07:40:45 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Viewpoint
[2009/05/26 08:19:41 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\webex
[2009/10/02 11:44:20 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\WinPatrol
[2009/10/30 16:51:30 | 00,000,000 | —D | M] – F:\Documents and Settings\Dan Miller\Application Data\Xtranormal
[2009/12/29 14:26:00 | 00,000,472 | —- | M] () – F:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
< End of report >
OTL Extras logfile created on: 12/30/2009 2:25:16 PM - Run 1
OTL by OldTimer - Version 3.1.20.1 Folder = F:\Documents and Settings\Dan Miller\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): f:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 149.05 Gb Total Space | 28.22 Gb Free Space | 18.94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 931.50 Gb Total Space | 869.95 Gb Free Space | 93.39% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DANANDBARB
Current User Name: Dan Miller
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "F:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome File not found
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 File not found
htmlfile [print] – "F:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome File not found
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "F:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "F:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe" = F:\Program Files\Dantz\Retrospect Express HD\RetroExpress.exe:*:Disabled: – (Dantz Development Corporation)
"F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = F:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer – (AOL LLC)
"F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = F:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service – (AOL LLC)
"F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe" = F:\Program Files\Common Files\AOL\1237308355\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL LLC)
"F:\Program Files\Common Files\AOL\Loader\aolload.exe" = F:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"F:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = F:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL Topspeed – (AOL LLC)
"F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe" = F:\Program Files\Common Files\AOL\1237308355\ee\AOLDesktop.exe:*:Enabled:AOL Desktop – (AOL LLC)
"F:\Documents and Settings\Dan Miller\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = F:\Documents and Settings\Dan Miller\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"F:\Program Files\iTunes\iTunes.exe" = F:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"F:\Program Files\TomTom HOME 2\xulrunner\TomTomHOMERuntime.exe" = F:\Program Files\TomTom HOME 2\xulrunner\TomTomHOMERuntime.exe:*:Enabled:TomTom HOME – (Mozilla Foundation)
"F:\Program Files\Microsoft Games\Age of Empires II Trial\EMPIRES2.EXE" = F:\Program Files\Microsoft Games\Age of Empires II Trial\EMPIRES2.EXE:*:Disabled:Age of Empires II – File not found
"F:\Program Files\BitTorrent\bittorrent.exe" = F:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"F:\Documents and Settings\Dan Miller\Local Settings\Temp\StateInstaller.exe" = F:\Documents and Settings\Dan Miller\Local Settings\Temp\StateInstaller.exe:*:Enabled:Xtranormal State – (Xtranormal)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{1596D886-C831-4192-AFC6-8A8027CC895F}" = iPod mini Software Updater 1.0
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1E88F516-C8AA-4D17-9A54-8AB0768F34C1}" = Retrospect Express HD 1.0
"{1EB321CB-3D1D-4cf2-ACB5-9F20874B8E69}" = HP Officejet Pro All-In-One Series
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{231F68F4-70E4-41A6-BEDA-7E7934169B54}" = Maxtor OneTouch
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{25F3BD52-7D3E-4265-A36C-70F09854D720}" = iPod mini 1.0 for Windows User Guide
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{530AFAFF-6F0A-48BB-88D0-04F9658322D3}" = Adobe Premiere Elements 3.0
"{580183A6-FF92-11D5-9294-0050BA073EEC}" = Presto! PageManager 6
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6EACDDF4-4220-49A3-9204-984C86852C3D}" = Adobe Premiere Elements 3.0 Templates
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83E5FE05-31F4-FA91-BB29-3D987008BA49}" = TweetDeck
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{97E038E1-41AD-4C93-BCDC-6A2394AEE352}" = Vegas Movie Studio Platinum 9.0b
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{B7C7A59F-CF70-481E-A94F-7C2563AA5ADD}" = Sony DVD Architect Studio 4.5
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{BF953F1A-F946-4804-875D-94B6A6C05CE1}" = Business Card Factory Deluxe 3.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}" = ArcSoft PhotoBase 3
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C427E746-4EC9-4E3C-AACB-C6BB1F714D7F}" = Uniblue DriverScanner 2009
"{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88}" = Microsoft Plus! Digital Media Edition
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D9261CAB-3E1D-423C-9DD6-2001056DA292}" = Manual CanoScan 5000,5000F,8000F
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"AOL Regclient" = AOL Registration
"AOL Toolbar" = AOL Toolbar for Internet Explorer
"AOL Toolbar for Firefox" = AOL Toolbar for Firefox
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AolCoach" = AOL Coach Version 1.0(Build:20020823.1)
"AudioConSole" = Creative Audio Console
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2702" = Conexant SmartHSFi V92 56K Speakerphone PCI Modem
"DriverGuide DriverScan" = DriverGuide DriverScan
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"ie8" = Windows Internet Explorer 8 Release Candidate 1
"InstallShield_{1596D886-C831-4192-AFC6-8A8027CC895F}" = iPod mini Software Updater 1.0
"InstallShield_{231F68F4-70E4-41A6-BEDA-7E7934169B54}" = Maxtor OneTouch
"InstallShield_{25F3BD52-7D3E-4265-A36C-70F09854D720}" = iPod mini 1.0 for Windows User Guide
"LinkedIn Internet Explorer Toolbar" = LinkedIn Internet Explorer Toolbar
"LinkedIn Outlook Toolbar" = LinkedIn Outlook Toolbar
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Multi Virus Cleaner 2009_is1" = Multi Virus Cleaner 2009
"MXOFX" = USB Storage Adapter FX (MXO)
"NVIDIA Drivers" = NVIDIA Drivers
"PC Pitstop Driver Alert2_is1" = PC Pitstop Driver Alert2 2.0.0.0
"PC Pitstop Optimize3_is1" = PC Pitstop Optimize3 3.0
"PremElem30" = Adobe Premiere Elements 3.0
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer Basic
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SystemRequirementsLab" = System Requirements Lab
"TomTom HOME" = TomTom HOME 2.7.2.1825
"Uniblue DriverScanner 2009" = Uniblue DriverScanner 2009
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/30/2009 12:03:27 PM | Computer Name = DANANDBARB | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 12/30/2009 3:00:03 PM | Computer Name = DANANDBARB | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 12/30/2009 3:23:42 PM | Computer Name = DANANDBARB | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
[ System Events ]
Error - 12/30/2009 3:02:30 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.
Error - 12/30/2009 3:02:30 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053
Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Avira AntiVir Scheduler
service to connect.
Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Scheduler service failed to start due to the following
error: %%1053
Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Avira AntiVir Guard service
to connect.
Error - 12/30/2009 3:25:13 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The Avira AntiVir Guard service failed to start due to the following
error: %%1053
Error - 12/30/2009 3:25:48 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.
Error - 12/30/2009 3:25:48 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd
Error - 12/30/2009 3:26:19 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.
Error - 12/30/2009 3:26:19 PM | Computer Name = DANANDBARB | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053
< End of report >