This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] ieexplore infection?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running very slow. I've noted it begins to work very hard with explorer open — 100%CPU usage for ie.explore process. I can't seem to find the reason for the problem. I hope I am uploading the correct info to assess. Thank you for your assistance.
Hello User and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instruction I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
zimfree,

It looks like you tried to run GMER. Please post the log if you have it. If you had problems, try RootRepeal:

🖼Click to load external image (Posted Image) Please download RootRepeal to your desktop. If you have a GMER log to post, skip to the next step (OTL).
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
  • Click the Report tab at the bottom and then the Scan button.
  • A box will pop up, check the boxes beside Drivers, Hidden Services, Files, Processes SSDT and click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop.
  • Reconnect to the internet.
  • Post the log here in your reply.

🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to open it. Make sure all other windows are closed.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Object\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Object\{e8daaa30-6caa-4b58-9603-8e54238219e2}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
    "{C4069E3A-68F1-403E-B40E-20066696354B}"=-
    "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=-
    "{D7E97865-918F-41E4-9CD0-25AB1C574CE8}"=-
    "{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Cute Password Manager"=-
    "Performance Center=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]
    
    :Files
    c:\program files\ascentive\performance center\ApcMain.exe
    
    
    :Commands
    [purity]
    [emptytemp]
    [createrestorepoint]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, your computer will reboot when it is done

🖼Click to load external image (Posted Image) Scan with OTL:
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL Extras logfile created on: 1/11/2010 11:58:50 PM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Kila_Hau\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.15 Gb Total Space | 66.44 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KILAHAU
Current User Name: Kila_Hau
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = JSFile] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"58504:TCP" = 58504:TCP:*:Enabled:Pando Media Booster
"58504:UDP" = 58504:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\MozyHome\mozybackup.exe" = C:\Program Files\MozyHome\mozybackup.exe:*:Enabled:mozybackup – ()
"C:\Program Files\Cartoon Network\Ben 10 Bounty Hunters\RT_Multiplayer.exe" = C:\Program Files\Cartoon Network\Ben 10 Bounty Hunters\RT_Multiplayer.exe:*:Enabled:RT_Multi Application – File not found
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\NBC Direct\DirectPlayerCore.exe" = C:\Program Files\NBC Direct\DirectPlayerCore.exe:*:Enabled:NBC Direct – (NBC Universal)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\Aptana\Aptana Studio 1.2\jre\bin\javaw.exe" = C:\Program Files\Aptana\Aptana Studio 1.2\jre\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0996C331-6DCB-4E38-A3EC-0A77ABAE1361}" = Help_CTR
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel® Network Connections 13.0.42.0
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 17
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2A97D5B3-A989-47E1-B207-1CA9E3635655}" = aioprnt
"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BED0238-3A25-41AE-BC23-316914B5B048}" = aioocr
"{3EB90211-5E1E-42A6-9C27-E42C4771F7DC}" = MozyHome Remote Backup
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{73F1681F-ADE1-461F-9F18-B7640507D395}" = ksdip
"{753D852A-D86D-42C9-9978-40AE66FB8985}" = Driver Installer
"{7599B516-83D2-4B41-8DC0-25FA4ADC112F}" = HOT ALBUM MYBOX
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{791E3D44-33D3-4446-82AD-5CD4B0169083}" = aiofw
"{79E41D91-BA1C-44B9-9358-48E598263ECF}" = center
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{843081BD-351F-46FC-8A17-517A0D9117A3}" = helptut
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A65F7CF8-6F76-40CE-B44D-D5A89D9881C7}" = MSN Toolbar Platform
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B2B30EC0-FB6A-43BB-9B38-0C3B32D75B40}_is1" = Sony Download Taxi 1.5.0.0
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{C0251585-1BE8-4278-B3CB-964B6E01C59D}" = aioscnnr
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = KODAK All-in-One Printer Software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC626A21-EDF1-40C7-8F2F-D2BA7535529F}" = helpug
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.00
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1BA3CD5-89DC-4273-8603-A75F33E9B335}" = Nokia Connectivity Adapter Cable DKU-5
"{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F}" = NBC Direct
"{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"{F65FE148-FCF5-42F7-8803-FA0B7DA8B8A4}" = ubCore
"{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}" = Windows Media Connect
"{F8A3C1B6-D2E0-4CE1-80A2-555D6F71C639}" = Microsoft Search Enhancement Pack
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AOL Search Enhancement" = Search Enhancement by AOL Search
"avast!" = avast! Antivirus
"ERUNT_is1" = ERUNT 1.1j
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{7599B516-83D2-4B41-8DC0-25FA4ADC112F}" = HOT ALBUM MYBOX
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InstallShield_{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"InstallShield_{F65FE148-FCF5-42F7-8803-FA0B7DA8B8A4}" = ubCore
"IPP Port Monitor" = IPP Port Monitor
"Linksys Bi-Admin" = Linksys Bi-Admin
"MagicDisc 2.7.97" = MagicDisc 2.7.97
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MouseSuite98" = Sony USB Mouse
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Connect" = Windows Media Connect
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"idm_flash" = IDM Flash 4.4.0.468
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"NBC Direct" = NBC Direct
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 11/6/2009 1:12:42 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\MICROSOFT
FEEDS~\MICROSOFT AT WORK~.FEED-MS failed, 00000005.

Error - 11/6/2009 1:12:43 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\MICROSOFT
FEEDS~\MICROSOFT AT HOME~.FEED-MS failed, 00000005.

Error - 11/6/2009 1:12:43 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\BOOKMARKS
TOOLBAR FOLDER~\LATEST HEADLINES~.FEED-MS failed, 00000005.

[ Application Events ]
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 1:34:17 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 11/18/2009 1:34:18 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 12/9/2009 8:50:01 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 12/9/2009 8:51:32 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/3/2010 1:38:46 AM | Computer Name = KILAHAU | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.

Error - 1/4/2010 6:57:23 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/8/2010 1:45:57 AM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

[ Application Events ]
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 1:34:17 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 11/18/2009 1:34:18 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 12/9/2009 8:50:01 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 12/9/2009 8:51:32 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/3/2010 1:38:46 AM | Computer Name = KILAHAU | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.

Error - 1/4/2010 6:57:23 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/8/2010 1:45:57 AM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

[ OSession Events ]
Error - 10/17/2008 1:26:45 PM | Computer Name = KILA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 98023
seconds with 2880 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:52:27 AM | Computer Name = KILAHAU | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 1/12/2010 1:54:34 AM | Computer Name = KILAHAU | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
GREG that believes that it is the master browser for the domain on transport NetBT_Tcpip_{11317D5A-28C1-4478-A0B4.
The
master browser is stopping or an election is being forced.


< End of report >

OTL logfile created on: 1/11/2010 11:58:50 PM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Kila_Hau\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.15 Gb Total Space | 66.44 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KILAHAU
Current User Name: Kila_Hau
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\NBC Direct\DirectPlayerCore.exe (NBC Universal)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\MozyHome\mozybackup.exe ()
PRC - C:\Program Files\Kodak\Printer\Center\KodakSvc.exe (Eastman Kodak Company)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe (PLANNING Co., Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (mozybackup) – C:\Program Files\MozyHome\mozybackup.exe ()
SRV - (KodakSvc) – C:\Program Files\Kodak\printer\center\KodakSvc.exe (Eastman Kodak Company)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (WmcCds) Windows Media Connect (WMC) – c:\Program Files\Windows Media Connect\mswmccds.exe (Microsoft Corporation)
SRV - (WmcCdsLs) Windows Media Connect (WMC) – C:\Program Files\Windows Media Connect\mswmcls.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (PzWDM) – C:\WINDOWS\system32\Drivers\PzWDM.sys (Prassi Technology)
DRV - (LMIRfsClientNP) – C:\WINDOWS\system32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (mozyFilter) – C:\WINDOWS\system32\drivers\mozy.sys (Mozy, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (lmimirr) – C:\WINDOWS\system32\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (RimVSerPort) – C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (tifmsony) – C:\WINDOWS\system32\drivers\tifmsony.sys (Texas Instruments)
DRV - (ubohci) – C:\WINDOWS\system32\drivers\ubohci.sys (Unibrain S.A.)
DRV - (ubumapi) – C:\WINDOWS\system32\drivers\UBUMAPI.sys (Unibrain S.A.)
DRV - (ubsbm) – C:\WINDOWS\system32\drivers\UBSBM.sys (Unibrain S.A.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en&source;=iglk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Crawler Search"
FF - prefs.js..browser.search.order.1: "Crawler Search"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..keyword.URL: "http://www.crawler.com/search/dispatcher.aspx?tp=aus&tbid;=60049&qkw;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/01/01 11:48:18 | 00,000,000 | —D | M]

[2008/08/10 18:14:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Extensions
[2008/11/18 22:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions
[2008/08/10 19:27:28 | 00,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2008/10/20 11:12:03 | 00,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/09/14 18:32:59 | 00,000,000 | —D | M] (deskCut) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA}
[2008/08/10 19:46:24 | 00,000,000 | —D | M] (BugMeNot) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2008/08/10 20:06:31 | 00,000,000 | —D | M] (DictionarySearch) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2008/08/10 19:33:06 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/08/10 18:49:04 | 00,000,000 | —D | M] () – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{DCBD1271-D228-4082-9FBC-36D9B7660B03}
[2008/10/02 20:09:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\[removed]

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - No CLSID value found.
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DC5F9604-C6E2-47D0-8E0F-E60FCCB334C7} - No CLSID value found.
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe File not found
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MBBalloon] C:\Program Files\HOTALBUMMyBOX\MBBalloon.exe (PLANNING Co., Ltd.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] File not found
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [PartSeal] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
O4 - HKLM..\Run: [Wireless printer] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKCU..\Run: [Cute Password Manager] File not found
O4 - HKCU..\Run: [DirectPlayerCore] C:\Program Files\NBC Direct\DirectPlayerCore.exe (NBC Universal)
O4 - HKCU..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKCU..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident\4.0; File not found
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe (PLANNING Co., Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB (VaioInfo.CMClass)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://216.84.63.34:5443/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1209522144312 (MUWebControl Class)
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} http://www.shockwave.com/content/snailmail…gwebinstall.cab (Sandlot Loader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB (TSEasyInstallX Control)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} http://onlinedesigner.hgtv.com/images/app/view22rte.cab (View22RTE Class)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/05 12:32:55 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/11 23:40:44 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/11 23:35:46 | 00,544,256 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe
[2010/01/11 18:54:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/01/10 14:24:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\Application Data\Malwarebytes
[2010/01/10 14:24:29 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/10 14:24:28 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/10 14:24:27 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/10 14:24:27 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/10 14:23:32 | 05,115,840 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Kila_Hau\Desktop\mbam-setup.exe
[2010/01/10 14:22:23 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/01/10 14:19:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/01/10 14:18:41 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Kila_Hau\Desktop\erunt_setup.exe
[2010/01/10 14:17:06 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Kila_Hau\Desktop\SysRestorePoint.exe
[2010/01/10 13:20:32 | 00,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/01/07 12:28:49 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Kila_Hau\Desktop\.picasaoriginals
[2010/01/06 13:00:38 | 00,000,000 | —D | C] – C:\Program Files\IPP Port Monitor
[2010/01/06 13:00:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\WINDOWS
[2010/01/06 12:45:04 | 00,000,000 | —D | C] – C:\Program Files\Linksys
[2010/01/06 11:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\Desktop\linksys Wireless Printer
[2010/01/01 11:48:11 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/01/01 11:47:59 | 00,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/01/01 11:47:50 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/01 11:47:38 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/01 11:46:56 | 00,000,000 | —D | C] – C:\Program Files\MSN Toolbar Installer
[2010/01/01 11:46:08 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/01 11:46:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/01 11:46:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/12/14 13:15:14 | 02,146,304 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2009/08/01 19:55:15 | 00,308,160 | —- | C] (ALWIL Software) – C:\Program Files\avast_home_setup.exe
[2009/07/23 02:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/26 18:09:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2009/06/20 19:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Bytemobile
[2009/05/21 21:32:34 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/03/15 10:30:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Eastman Kodak Company
[2009/03/14 21:03:52 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Eastman Kodak Company
[2009/02/21 23:06:43 | 45,570,152 | —- | C] (Trend Micro Inc.) – C:\Program Files\TIS_Download_SP_32bit.exe
[2009/01/15 14:14:20 | 66,644,872 | —- | C] (Trend Micro Inc.) – C:\Program Files\TrendMicro_TIS_17.00_en-US_32-bit.exe
[2008/12/06 20:36:08 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2008/10/17 12:26:10 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2008/10/17 12:26:09 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2008/08/13 05:48:55 | 04,891,216 | —- | C] (Microsoft Corporation) – C:\Program Files\Silverlight.2.0.exe
[2008/08/12 22:47:30 | 05,520,400 | —- | C] (Microsoft Corporation) – C:\Program Files\WindowsSearch-KB940157-XP-x86-enu.exe
[2008/07/27 07:18:49 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[1 C:\Documents and Settings\Kila_Hau\Desktop\*.tmp files -> C:\Documents and Settings\Kila_Hau\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/11 23:52:01 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/11 23:51:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/11 23:50:50 | 05,242,880 | -H– | M] () – C:\Documents and Settings\Kila_Hau\NTUSER.DAT
[2010/01/11 23:50:50 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Kila_Hau\ntuser.ini
[2010/01/11 23:35:48 | 00,544,256 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe
[2010/01/11 23:35:07 | 00,000,000 | —- | M] () – C:\Documents and Settings\Kila_Hau\settings.dat
[2010/01/11 23:34:44 | 00,094,720 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\pw and checks.xlsx
[2010/01/11 23:34:32 | 00,464,491 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\RootRepeal.zip
[2010/01/11 23:29:27 | 00,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A4258327-FEA4-40DE-88D7-9AF76047C84C}.job
[2010/01/11 10:08:04 | 00,000,362 | —- | M] () – C:\WINDOWS\tasks\Kodak AiO Scheduled Maintenance.job
[2010/01/11 02:30:27 | 00,003,980 | —- | M] () – C:\WINDOWS\mozy.blk
[2010/01/11 02:30:27 | 00,002,460 | —- | M] () – C:\WINDOWS\mozy.flt
[2010/01/11 00:33:55 | 00,015,960 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\greg finance.xlsx
[2010/01/11 00:19:52 | 00,111,795 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Greg LoanAmortizationSchedule.zip
[2010/01/11 00:12:11 | 00,119,873 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\loan-amortization-schedule_L.xlsx
[2010/01/11 00:09:36 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$loan-amortization-schedule_L.xlsx
[2010/01/10 17:13:24 | 00,359,929 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\dds.scr
[2010/01/10 17:12:56 | 00,001,458 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\ark.text
[2010/01/10 16:20:30 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$greg finance.xlsx
[2010/01/10 14:55:28 | 00,284,915 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\gmer.zip
[2010/01/10 14:24:32 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 14:23:42 | 05,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Kila_Hau\Desktop\mbam-setup.exe
[2010/01/10 14:22:24 | 00,000,611 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\NTREGOPT.lnk
[2010/01/10 14:22:24 | 00,000,592 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\ERUNT.lnk
[2010/01/10 14:18:43 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Kila_Hau\Desktop\erunt_setup.exe
[2010/01/10 14:17:06 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Kila_Hau\Desktop\SysRestorePoint.exe
[2010/01/10 13:40:20 | 00,014,206 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\hijackthis1.10
[2010/01/10 13:20:32 | 00,001,988 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\HiJackThis.lnk
[2010/01/09 16:02:30 | 00,347,226 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Fall09 LR activities sign up.pdf
[2010/01/09 15:40:00 | 01,282,344 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Junior%20Egyptologist%20Final.pdf
[2010/01/09 10:01:00 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\Norton PC Checkup Weekend Scanner.job
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 14:16:41 | 00,237,441 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\att.pdf
[2010/01/07 14:16:31 | 00,237,441 | —- | M] () – C:\Documents and Settings\Kila_Hau\My Documents\ATT Alice Ct 12.2009.pdf
[2010/01/06 19:05:00 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\Norton PC Checkup WeekDay Scanner.job
[2010/01/06 12:47:33 | 00,000,867 | —- | M] () – C:\WINDOWS\Common.ini
[2010/01/04 10:44:52 | 00,019,410 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\TO DO Jan 2010.xlsx
[2010/01/03 16:29:16 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$TO DO Jan 2010.xlsx
[2010/01/02 19:58:10 | 00,358,603 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Lighting.docx
[2010/01/01 13:56:17 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$pression info.docx
[2010/01/01 11:43:46 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/01/01 11:40:30 | 00,000,216 | RHS- | M] () – C:\boot.ini
[2010/01/01 11:40:29 | 00,000,461 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/01 11:40:12 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/27 10:01:08 | 00,000,442 | —- | M] () – C:\WINDOWS\tasks\EasyShare Registration Task.job
[2009/12/25 22:32:09 | 00,024,127 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\note to bh.docx
[2009/12/22 16:38:34 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$te to bh.docx
[2009/12/22 15:52:27 | 00,404,591 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\My Shape Return 12.09.docx
[2009/12/21 11:59:01 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$ Shape Return 12.09.docx
[2009/12/14 13:15:14 | 02,146,304 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[1 C:\Documents and Settings\Kila_Hau\Desktop\*.tmp files -> C:\Documents and Settings\Kila_Hau\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/11 23:35:07 | 00,000,000 | —- | C] () – C:\Documents and Settings\Kila_Hau\settings.dat
[2010/01/11 23:34:30 | 00,464,491 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\RootRepeal.zip
[2010/01/11 00:19:52 | 00,111,795 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Greg LoanAmortizationSchedule.zip
[2010/01/11 00:09:36 | 00,119,873 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\loan-amortization-schedule_L.xlsx
[2010/01/11 00:09:36 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$loan-amortization-schedule_L.xlsx
[2010/01/10 22:50:57 | 00,364,847 | —- | C] () – C:\Documents and Settings\Kila_Hau\My Documents\UltimateBuyHold.pdf
[2010/01/10 17:13:23 | 00,359,929 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\dds.scr
[2010/01/10 17:12:56 | 00,001,458 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\ark.text
[2010/01/10 16:20:30 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$greg finance.xlsx
[2010/01/10 16:20:29 | 00,015,960 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\greg finance.xlsx
[2010/01/10 14:55:25 | 00,284,915 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\gmer.zip
[2010/01/10 14:24:32 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 14:22:24 | 00,000,611 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\NTREGOPT.lnk
[2010/01/10 14:22:24 | 00,000,592 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\ERUNT.lnk
[2010/01/10 13:40:20 | 00,014,206 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\hijackthis1.10
[2010/01/10 13:20:32 | 00,001,988 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\HiJackThis.lnk
[2010/01/09 16:02:30 | 00,347,226 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Fall09 LR activities sign up.pdf
[2010/01/09 15:40:00 | 01,282,344 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Junior%20Egyptologist%20Final.pdf
[2010/01/07 14:16:41 | 00,237,441 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\att.pdf
[2010/01/07 14:16:30 | 00,237,441 | —- | C] () – C:\Documents and Settings\Kila_Hau\My Documents\ATT Alice Ct 12.2009.pdf
[2010/01/06 13:00:38 | 00,080,896 | —- | C] () – C:\WINDOWS\System32\ippnu.dll
[2010/01/06 12:45:05 | 00,000,867 | —- | C] () – C:\WINDOWS\Common.ini
[2010/01/03 16:29:16 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$TO DO Jan 2010.xlsx
[2010/01/03 16:29:15 | 00,019,410 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\TO DO Jan 2010.xlsx
[2010/01/02 19:58:10 | 00,358,603 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Lighting.docx
[2010/01/01 13:56:17 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$pression info.docx
[2009/12/22 16:38:34 | 00,024,127 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\note to bh.docx
[2009/12/22 16:38:34 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$te to bh.docx
[2009/12/21 11:59:01 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$ Shape Return 12.09.docx
[2009/12/21 11:59:00 | 00,404,591 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\My Shape Return 12.09.docx
[2009/11/01 10:07:54 | 00,012,800 | —- | C] () – C:\WINDOWS\System32\EKDeviceServices.dll
[2009/06/20 19:44:08 | 00,025,736 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/02/14 17:00:44 | 00,000,759 | —- | C] () – C:\Program Files\Picasa 3.lnk
[2008/12/13 14:57:00 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/11/05 20:04:57 | 00,008,192 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/13 08:19:06 | 00,037,532 | —- | C] () – C:\Documents and Settings\Kila_Hau\Application Data\Comma Separated Values (Windows).ADR
[2008/09/08 10:38:09 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/08/17 15:22:04 | 00,028,160 | —- | C] () – C:\WINDOWS\System32\sspdfpmd.dll
[2008/08/04 14:07:33 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2008/04/15 18:49:11 | 00,000,128 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\fusioncache.dat
[2008/04/13 22:56:11 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2008/04/13 22:54:44 | 00,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2008/04/13 22:54:12 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2008/04/13 22:54:12 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2008/04/13 22:54:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2008/04/13 22:54:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2008/04/13 22:54:12 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2008/04/13 22:54:12 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2008/04/13 22:53:18 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/04/13 22:48:01 | 00,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2008/03/19 11:35:05 | 00,000,233 | -H– | C] () – C:\WINDOWS\gvac.sys
[2008/02/05 12:28:20 | 00,000,051 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\setup.txt
[2007/09/27 09:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/01/12 16:09:14 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\DXFLib.dll
[2006/01/12 16:08:06 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\opcode.dll
[2006/01/06 05:58:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/01/06 05:24:32 | 00,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/01/06 05:17:52 | 00,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/01/05 12:38:40 | 00,000,800 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/01/05 11:16:49 | 00,000,762 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/11/01 19:53:38 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/06/12 13:21:12 | 00,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

========== LOP Check ==========

[2009/07/06 10:54:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2009/03/14 21:25:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eastman Kodak Company
[2008/08/08 20:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2009/03/14 21:30:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2008/08/08 20:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Launcher
[2009/01/05 18:29:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/04/16 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NBC Direct
[2008/05/03 00:06:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers Headquarters
[2008/05/23 12:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/10/04 16:43:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2008/05/23 12:09:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/10/17 12:49:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/18 08:38:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/15 14:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2009/02/27 18:57:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2009/05/25 13:09:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Aptana
[2009/06/26 18:11:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\AT&T;
[2009/01/12 20:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Crayon Physics Deluxe
[2009/06/20 19:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\DBUpdater
[2009/04/16 19:48:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\IDM
[2008/07/13 13:32:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\InterVideo
[2008/07/20 11:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Leadertech
[2008/10/29 14:07:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\MechCAD
[2008/08/17 14:42:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\My CuteForm RunTime
[2010/01/11 13:31:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\NBC Direct
[2008/05/23 12:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\PlayFirst
[2009/06/20 19:37:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Sierra Wireless
[2008/09/16 11:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Uniblue
[2008/08/12 22:53:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Windows Desktop Search
[2008/08/19 18:13:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Windows Search
[2009/03/05 12:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\WinPatrol
[2009/12/27 10:01:08 | 00,000,442 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/01/11 23:29:27 | 00,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{A4258327-FEA4-40DE-88D7-9AF76047C84C}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1EA8A42
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A93060EC
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DB0B938
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:028E4554
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC4C6FB4
< End of report >
OTL Extras logfile created on: 1/11/2010 11:58:50 PM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Kila_Hau\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.15 Gb Total Space | 66.44 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KILAHAU
Current User Name: Kila_Hau
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = JSFile] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"58504:TCP" = 58504:TCP:*:Enabled:Pando Media Booster
"58504:UDP" = 58504:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\MozyHome\mozybackup.exe" = C:\Program Files\MozyHome\mozybackup.exe:*:Enabled:mozybackup – ()
"C:\Program Files\Cartoon Network\Ben 10 Bounty Hunters\RT_Multiplayer.exe" = C:\Program Files\Cartoon Network\Ben 10 Bounty Hunters\RT_Multiplayer.exe:*:Enabled:RT_Multi Application – File not found
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\NBC Direct\DirectPlayerCore.exe" = C:\Program Files\NBC Direct\DirectPlayerCore.exe:*:Enabled:NBC Direct – (NBC Universal)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – File not found
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – File not found
"C:\Program Files\Aptana\Aptana Studio 1.2\jre\bin\javaw.exe" = C:\Program Files\Aptana\Aptana Studio 1.2\jre\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio DigitalMedia Data
"{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}" = HiJackThis
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0996C331-6DCB-4E38-A3EC-0A77ABAE1361}" = Help_CTR
"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
"{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel® Network Connections 13.0.42.0
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 17
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2A97D5B3-A989-47E1-B207-1CA9E3635655}" = aioprnt
"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper
"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BED0238-3A25-41AE-BC23-316914B5B048}" = aioocr
"{3EB90211-5E1E-42A6-9C27-E42C4771F7DC}" = MozyHome Remote Backup
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant
"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0
"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0
"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
"{63B8FB69-A1B6-425D-B67D-5257B7A1F663}" = Image Converter 2 Plus
"{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{73F1681F-ADE1-461F-9F18-B7640507D395}" = ksdip
"{753D852A-D86D-42C9-9978-40AE66FB8985}" = Driver Installer
"{7599B516-83D2-4B41-8DC0-25FA4ADC112F}" = HOT ALBUM MYBOX
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{785EB1D4-ECEC-4195-99B4-73C47E187721}" = VAIO Media Integrated Server 5.0
"{791E3D44-33D3-4446-82AD-5CD4B0169083}" = aiofw
"{79E41D91-BA1C-44B9-9358-48E598263ECF}" = center
"{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
"{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
"{843081BD-351F-46FC-8A17-517A0D9117A3}" = helptut
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E319E96-ED8E-4B01-9775-C521A1869A25}" = VAIO Power Management
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A65F7CF8-6F76-40CE-B44D-D5A89D9881C7}" = MSN Toolbar Platform
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio DigitalMedia Audio
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 5.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio DigitalMedia Copy
"{B2B30EC0-FB6A-43BB-9B38-0C3B32D75B40}_is1" = Sony Download Taxi 1.5.0.0
"{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
"{C0251585-1BE8-4278-B3CB-964B6E01C59D}" = aioscnnr
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = KODAK All-in-One Printer Software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC626A21-EDF1-40C7-8F2F-D2BA7535529F}" = helpug
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
"{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.5.00
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{EF3D45BB-2260-4008-88EA-492E7744A9DF}" = Sony Utilities DLL
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}" = VAIO Event Service
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1BA3CD5-89DC-4273-8603-A75F33E9B335}" = Nokia Connectivity Adapter Cable DKU-5
"{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F}" = NBC Direct
"{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"{F65FE148-FCF5-42F7-8803-FA0B7DA8B8A4}" = ubCore
"{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}" = Windows Media Connect
"{F8A3C1B6-D2E0-4CE1-80A2-555D6F71C639}" = Microsoft Search Enhancement Pack
"{FB714F13-10C9-48DB-91C9-DDBCCCBF9370}" = VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FE3BF611-9B8B-44DC-A424-F8C4BA122A1D}" = VAIO Security Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AOL Search Enhancement" = Search Enhancement by AOL Search
"avast!" = avast! Antivirus
"ERUNT_is1" = ERUNT 1.1j
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
"InstallShield_{7599B516-83D2-4B41-8DC0-25FA4ADC112F}" = HOT ALBUM MYBOX
"InstallShield_{BA46CCF2-2C59-4DEB-93DC-7000B7C53B4E}" = VAIOSurveySA
"InstallShield_{F5E4C38C-73BC-4D44-8BFC-969C2B4DABCA}" = OpenMG Secure Module 4.3.00
"InstallShield_{F65FE148-FCF5-42F7-8803-FA0B7DA8B8A4}" = ubCore
"IPP Port Monitor" = IPP Port Monitor
"Linksys Bi-Admin" = Linksys Bi-Admin
"MagicDisc 2.7.97" = MagicDisc 2.7.97
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MouseSuite98" = Sony USB Mouse
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Connect" = Windows Media Connect
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"idm_flash" = IDM Flash 4.4.0.468
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"NBC Direct" = NBC Direct
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 11/6/2009 1:12:42 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\MICROSOFT
FEEDS~\MICROSOFT AT WORK~.FEED-MS failed, 00000005.

Error - 11/6/2009 1:12:43 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\MICROSOFT
FEEDS~\MICROSOFT AT HOME~.FEED-MS failed, 00000005.

Error - 11/6/2009 1:12:43 AM | Computer Name = KILAHAU | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
C:\DOCUMENTS AND SETTINGS\KILA_HAU\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\BOOKMARKS
TOOLBAR FOLDER~\LATEST HEADLINES~.FEED-MS failed, 00000005.

[ Application Events ]
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 1:34:17 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 11/18/2009 1:34:18 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 12/9/2009 8:50:01 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 12/9/2009 8:51:32 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/3/2010 1:38:46 AM | Computer Name = KILAHAU | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.

Error - 1/4/2010 6:57:23 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/8/2010 1:45:57 AM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

[ Application Events ]
Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 12:34:15 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry
in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details:
A
device attached to the system is not functioning. (0x8007001f)

Error - 11/18/2009 1:34:17 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 11/18/2009 1:34:18 PM | Computer Name = KILAHAU | Source = Windows Search Service | ID = 3013
Description = The entry AND ANNUITIES\ANNUITIES SUMMARY OF INFO.XLSX> in the hash map cannot be updated.

Context:
Application, SystemIndex Catalog Details: A device attached to the system is not
functioning. (0x8007001f)

Error - 12/9/2009 8:50:01 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 12/9/2009 8:51:32 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/3/2010 1:38:46 AM | Computer Name = KILAHAU | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.

Error - 1/4/2010 6:57:23 PM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

Error - 1/8/2010 1:45:57 AM | Computer Name = KILAHAU | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18854, fault address 0x000d6a3b.

[ OSession Events ]
Error - 10/17/2008 1:26:45 PM | Computer Name = KILA | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 98023
seconds with 2880 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:50:47 AM | Computer Name = KILAHAU | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/12/2010 1:52:27 AM | Computer Name = KILAHAU | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
to the following error: %%3

Error - 1/12/2010 1:54:34 AM | Computer Name = KILAHAU | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
GREG that believes that it is the master browser for the domain on transport NetBT_Tcpip_{11317D5A-28C1-4478-A0B4.
The
master browser is stopping or an election is being forced.


< End of report >

OTL logfile created on: 1/11/2010 11:58:50 PM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\Kila_Hau\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 89.15 Gb Total Space | 66.44 Gb Free Space | 74.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KILAHAU
Current User Name: Kila_Hau
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files\NBC Direct\DirectPlayerCore.exe (NBC Universal)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\MozyHome\mozybackup.exe ()
PRC - C:\Program Files\Kodak\Printer\Center\KodakSvc.exe (Eastman Kodak Company)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe (PLANNING Co., Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (mozybackup) – C:\Program Files\MozyHome\mozybackup.exe ()
SRV - (KodakSvc) – C:\Program Files\Kodak\printer\center\KodakSvc.exe (Eastman Kodak Company)
SRV - (SQLWriter) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (WmcCds) Windows Media Connect (WMC) – c:\Program Files\Windows Media Connect\mswmccds.exe (Microsoft Corporation)
SRV - (WmcCdsLs) Windows Media Connect (WMC) – C:\Program Files\Windows Media Connect\mswmcls.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (NuidFltr) – C:\WINDOWS\system32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AegisP) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (PzWDM) – C:\WINDOWS\system32\Drivers\PzWDM.sys (Prassi Technology)
DRV - (LMIRfsClientNP) – C:\WINDOWS\system32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (mozyFilter) – C:\WINDOWS\system32\drivers\mozy.sys (Mozy, Inc.)
DRV - (LMIRfsDriver) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (lmimirr) – C:\WINDOWS\system32\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (NAL) – C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (w29n51) Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (RimVSerPort) – C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (tifmsony) – C:\WINDOWS\system32\drivers\tifmsony.sys (Texas Instruments)
DRV - (ubohci) – C:\WINDOWS\system32\drivers\ubohci.sys (Unibrain S.A.)
DRV - (ubumapi) – C:\WINDOWS\system32\drivers\UBUMAPI.sys (Unibrain S.A.)
DRV - (ubsbm) – C:\WINDOWS\system32\drivers\UBSBM.sys (Unibrain S.A.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (DMICall) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (SNC) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?hl=en&source;=iglk
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Crawler Search"
FF - prefs.js..browser.search.order.1: "Crawler Search"
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..keyword.URL: "http://www.crawler.com/search/dispatcher.aspx?tp=aus&tbid;=60049&qkw;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/01/01 11:48:18 | 00,000,000 | —D | M]

[2008/08/10 18:14:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Extensions
[2008/11/18 22:52:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions
[2008/08/10 19:27:28 | 00,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2008/10/20 11:12:03 | 00,000,000 | —D | M] (NoScript) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2008/09/14 18:32:59 | 00,000,000 | —D | M] (deskCut) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{9125C9CB-BE2B-4389-A0C7-46A4BDD46AEA}
[2008/08/10 19:46:24 | 00,000,000 | —D | M] (BugMeNot) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2008/08/10 20:06:31 | 00,000,000 | —D | M] (DictionarySearch) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{a0faa0a4-f1a7-4098-9a74-21efc3a92372}
[2008/08/10 19:33:06 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/08/10 18:49:04 | 00,000,000 | —D | M] () – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\{DCBD1271-D228-4082-9FBC-36D9B7660B03}
[2008/10/02 20:09:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Mozilla\Firefox\Profiles\vvye7gi4.default\extensions\[removed]

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - No CLSID value found.
O2 - BHO: (MSN Toolbar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {DC5F9604-C6E2-47D0-8E0F-E60FCCB334C7} - No CLSID value found.
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKLM..\Run: [EPSON Stylus CX6600 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe File not found
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MBBalloon] C:\Program Files\HOTALBUMMyBOX\MBBalloon.exe (PLANNING Co., Ltd.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] File not found
O4 - HKLM..\Run: [MSN Toolbar] C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe (Microsoft Corp.)
O4 - HKLM..\Run: [PartSeal] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\SONYSYS\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
O4 - HKLM..\Run: [Wireless printer] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKCU..\Run: [Cute Password Manager] File not found
O4 - HKCU..\Run: [DirectPlayerCore] C:\Program Files\NBC Direct\DirectPlayerCore.exe (NBC Universal)
O4 - HKCU..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE File not found
O4 - HKCU..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident\4.0; File not found
O4 - HKLM..\RunOnceEx: [] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MediaChecker.lnk = C:\Program Files\HOTALBUMMyBOX\MediaChecker.exe (PLANNING Co., Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 8
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB (VaioInfo.CMClass)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://216.84.63.34:5443/CACHE/stc/1/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1209522144312 (MUWebControl Class)
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} http://www.shockwave.com/content/snailmail…gwebinstall.cab (Sandlot Loader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB (TSEasyInstallX Control)
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} http://onlinedesigner.hgtv.com/images/app/view22rte.cab (View22RTE Class)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\System32\VESWinlogon.dll (Sony Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/05 12:32:55 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/11 23:40:44 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/11 23:35:46 | 00,544,256 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe
[2010/01/11 18:54:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/01/10 14:24:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\Application Data\Malwarebytes
[2010/01/10 14:24:29 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/10 14:24:28 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/10 14:24:27 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/10 14:24:27 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/10 14:23:32 | 05,115,840 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Kila_Hau\Desktop\mbam-setup.exe
[2010/01/10 14:22:23 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/01/10 14:19:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/01/10 14:18:41 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Kila_Hau\Desktop\erunt_setup.exe
[2010/01/10 14:17:06 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Kila_Hau\Desktop\SysRestorePoint.exe
[2010/01/10 13:20:32 | 00,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/01/07 12:28:49 | 00,000,000 | -H-D | C] – C:\Documents and Settings\Kila_Hau\Desktop\.picasaoriginals
[2010/01/06 13:00:38 | 00,000,000 | —D | C] – C:\Program Files\IPP Port Monitor
[2010/01/06 13:00:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\WINDOWS
[2010/01/06 12:45:04 | 00,000,000 | —D | C] – C:\Program Files\Linksys
[2010/01/06 11:35:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Kila_Hau\Desktop\linksys Wireless Printer
[2010/01/01 11:48:11 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/01/01 11:47:59 | 00,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2010/01/01 11:47:50 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/01 11:47:38 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/01 11:46:56 | 00,000,000 | —D | C] – C:\Program Files\MSN Toolbar Installer
[2010/01/01 11:46:08 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/01 11:46:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/01 11:46:08 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/12/14 13:15:14 | 02,146,304 | —- | C] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[2009/08/01 19:55:15 | 00,308,160 | —- | C] (ALWIL Software) – C:\Program Files\avast_home_setup.exe
[2009/07/23 02:00:46 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/06/26 18:09:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Bytemobile
[2009/06/20 19:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Bytemobile
[2009/05/21 21:32:34 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/03/15 10:30:25 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Eastman Kodak Company
[2009/03/14 21:03:52 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Eastman Kodak Company
[2009/02/21 23:06:43 | 45,570,152 | —- | C] (Trend Micro Inc.) – C:\Program Files\TIS_Download_SP_32bit.exe
[2009/01/15 14:14:20 | 66,644,872 | —- | C] (Trend Micro Inc.) – C:\Program Files\TrendMicro_TIS_17.00_en-US_32-bit.exe
[2008/12/06 20:36:08 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Intel
[2008/10/17 12:26:10 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2008/10/17 12:26:09 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2008/08/13 05:48:55 | 04,891,216 | —- | C] (Microsoft Corporation) – C:\Program Files\Silverlight.2.0.exe
[2008/08/12 22:47:30 | 05,520,400 | —- | C] (Microsoft Corporation) – C:\Program Files\WindowsSearch-KB940157-XP-x86-enu.exe
[2008/07/27 07:18:49 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[1 C:\Documents and Settings\Kila_Hau\Desktop\*.tmp files -> C:\Documents and Settings\Kila_Hau\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/11 23:52:01 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/11 23:51:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/11 23:50:50 | 05,242,880 | -H– | M] () – C:\Documents and Settings\Kila_Hau\NTUSER.DAT
[2010/01/11 23:50:50 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Kila_Hau\ntuser.ini
[2010/01/11 23:35:48 | 00,544,256 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kila_Hau\Desktop\OTL.exe
[2010/01/11 23:35:07 | 00,000,000 | —- | M] () – C:\Documents and Settings\Kila_Hau\settings.dat
[2010/01/11 23:34:44 | 00,094,720 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\pw and checks.xlsx
[2010/01/11 23:34:32 | 00,464,491 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\RootRepeal.zip
[2010/01/11 23:29:27 | 00,000,428 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{A4258327-FEA4-40DE-88D7-9AF76047C84C}.job
[2010/01/11 10:08:04 | 00,000,362 | —- | M] () – C:\WINDOWS\tasks\Kodak AiO Scheduled Maintenance.job
[2010/01/11 02:30:27 | 00,003,980 | —- | M] () – C:\WINDOWS\mozy.blk
[2010/01/11 02:30:27 | 00,002,460 | —- | M] () – C:\WINDOWS\mozy.flt
[2010/01/11 00:33:55 | 00,015,960 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\greg finance.xlsx
[2010/01/11 00:19:52 | 00,111,795 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Greg LoanAmortizationSchedule.zip
[2010/01/11 00:12:11 | 00,119,873 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\loan-amortization-schedule_L.xlsx
[2010/01/11 00:09:36 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$loan-amortization-schedule_L.xlsx
[2010/01/10 17:13:24 | 00,359,929 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\dds.scr
[2010/01/10 17:12:56 | 00,001,458 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\ark.text
[2010/01/10 16:20:30 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$greg finance.xlsx
[2010/01/10 14:55:28 | 00,284,915 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\gmer.zip
[2010/01/10 14:24:32 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 14:23:42 | 05,115,840 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Kila_Hau\Desktop\mbam-setup.exe
[2010/01/10 14:22:24 | 00,000,611 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\NTREGOPT.lnk
[2010/01/10 14:22:24 | 00,000,592 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\ERUNT.lnk
[2010/01/10 14:18:43 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Kila_Hau\Desktop\erunt_setup.exe
[2010/01/10 14:17:06 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Kila_Hau\Desktop\SysRestorePoint.exe
[2010/01/10 13:40:20 | 00,014,206 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\hijackthis1.10
[2010/01/10 13:20:32 | 00,001,988 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\HiJackThis.lnk
[2010/01/09 16:02:30 | 00,347,226 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Fall09 LR activities sign up.pdf
[2010/01/09 15:40:00 | 01,282,344 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Junior%20Egyptologist%20Final.pdf
[2010/01/09 10:01:00 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\Norton PC Checkup Weekend Scanner.job
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 14:16:41 | 00,237,441 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\att.pdf
[2010/01/07 14:16:31 | 00,237,441 | —- | M] () – C:\Documents and Settings\Kila_Hau\My Documents\ATT Alice Ct 12.2009.pdf
[2010/01/06 19:05:00 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\Norton PC Checkup WeekDay Scanner.job
[2010/01/06 12:47:33 | 00,000,867 | —- | M] () – C:\WINDOWS\Common.ini
[2010/01/04 10:44:52 | 00,019,410 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\TO DO Jan 2010.xlsx
[2010/01/03 16:29:16 | 00,000,165 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$TO DO Jan 2010.xlsx
[2010/01/02 19:58:10 | 00,358,603 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\Lighting.docx
[2010/01/01 13:56:17 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$pression info.docx
[2010/01/01 11:43:46 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/01/01 11:40:30 | 00,000,216 | RHS- | M] () – C:\boot.ini
[2010/01/01 11:40:29 | 00,000,461 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/01 11:40:12 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/12/27 10:01:08 | 00,000,442 | —- | M] () – C:\WINDOWS\tasks\EasyShare Registration Task.job
[2009/12/25 22:32:09 | 00,024,127 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\note to bh.docx
[2009/12/22 16:38:34 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$te to bh.docx
[2009/12/22 15:52:27 | 00,404,591 | —- | M] () – C:\Documents and Settings\Kila_Hau\Desktop\My Shape Return 12.09.docx
[2009/12/21 11:59:01 | 00,000,162 | -H– | M] () – C:\Documents and Settings\Kila_Hau\Desktop\~$ Shape Return 12.09.docx
[2009/12/14 13:15:14 | 02,146,304 | —- | M] (Google Inc.) – C:\WINDOWS\System32\GPhotos.scr
[1 C:\Documents and Settings\Kila_Hau\Desktop\*.tmp files -> C:\Documents and Settings\Kila_Hau\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/11 23:35:07 | 00,000,000 | —- | C] () – C:\Documents and Settings\Kila_Hau\settings.dat
[2010/01/11 23:34:30 | 00,464,491 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\RootRepeal.zip
[2010/01/11 00:19:52 | 00,111,795 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Greg LoanAmortizationSchedule.zip
[2010/01/11 00:09:36 | 00,119,873 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\loan-amortization-schedule_L.xlsx
[2010/01/11 00:09:36 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$loan-amortization-schedule_L.xlsx
[2010/01/10 22:50:57 | 00,364,847 | —- | C] () – C:\Documents and Settings\Kila_Hau\My Documents\UltimateBuyHold.pdf
[2010/01/10 17:13:23 | 00,359,929 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\dds.scr
[2010/01/10 17:12:56 | 00,001,458 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\ark.text
[2010/01/10 16:20:30 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$greg finance.xlsx
[2010/01/10 16:20:29 | 00,015,960 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\greg finance.xlsx
[2010/01/10 14:55:25 | 00,284,915 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\gmer.zip
[2010/01/10 14:24:32 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/10 14:22:24 | 00,000,611 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\NTREGOPT.lnk
[2010/01/10 14:22:24 | 00,000,592 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\ERUNT.lnk
[2010/01/10 13:40:20 | 00,014,206 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\hijackthis1.10
[2010/01/10 13:20:32 | 00,001,988 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\HiJackThis.lnk
[2010/01/09 16:02:30 | 00,347,226 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Fall09 LR activities sign up.pdf
[2010/01/09 15:40:00 | 01,282,344 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Junior%20Egyptologist%20Final.pdf
[2010/01/07 14:16:41 | 00,237,441 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\att.pdf
[2010/01/07 14:16:30 | 00,237,441 | —- | C] () – C:\Documents and Settings\Kila_Hau\My Documents\ATT Alice Ct 12.2009.pdf
[2010/01/06 13:00:38 | 00,080,896 | —- | C] () – C:\WINDOWS\System32\ippnu.dll
[2010/01/06 12:45:05 | 00,000,867 | —- | C] () – C:\WINDOWS\Common.ini
[2010/01/03 16:29:16 | 00,000,165 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$TO DO Jan 2010.xlsx
[2010/01/03 16:29:15 | 00,019,410 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\TO DO Jan 2010.xlsx
[2010/01/02 19:58:10 | 00,358,603 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\Lighting.docx
[2010/01/01 13:56:17 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$pression info.docx
[2009/12/22 16:38:34 | 00,024,127 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\note to bh.docx
[2009/12/22 16:38:34 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$te to bh.docx
[2009/12/21 11:59:01 | 00,000,162 | -H– | C] () – C:\Documents and Settings\Kila_Hau\Desktop\~$ Shape Return 12.09.docx
[2009/12/21 11:59:00 | 00,404,591 | —- | C] () – C:\Documents and Settings\Kila_Hau\Desktop\My Shape Return 12.09.docx
[2009/11/01 10:07:54 | 00,012,800 | —- | C] () – C:\WINDOWS\System32\EKDeviceServices.dll
[2009/06/20 19:44:08 | 00,025,736 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/02/14 17:00:44 | 00,000,759 | —- | C] () – C:\Program Files\Picasa 3.lnk
[2008/12/13 14:57:00 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/11/05 20:04:57 | 00,008,192 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/13 08:19:06 | 00,037,532 | —- | C] () – C:\Documents and Settings\Kila_Hau\Application Data\Comma Separated Values (Windows).ADR
[2008/09/08 10:38:09 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/08/17 15:22:04 | 00,028,160 | —- | C] () – C:\WINDOWS\System32\sspdfpmd.dll
[2008/08/04 14:07:33 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2008/04/15 18:49:11 | 00,000,128 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\fusioncache.dat
[2008/04/13 22:56:11 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2008/04/13 22:54:44 | 00,000,031 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2008/04/13 22:54:12 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2008/04/13 22:54:12 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2008/04/13 22:54:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2008/04/13 22:54:12 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2008/04/13 22:54:12 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2008/04/13 22:54:12 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2008/04/13 22:53:18 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/04/13 22:48:01 | 00,002,158 | —- | C] () – C:\WINDOWS\System32\tmmute.ini
[2008/03/19 11:35:05 | 00,000,233 | -H– | C] () – C:\WINDOWS\gvac.sys
[2008/02/05 12:28:20 | 00,000,051 | —- | C] () – C:\Documents and Settings\Kila_Hau\Local Settings\Application Data\setup.txt
[2007/09/27 09:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/01/12 16:09:14 | 00,090,112 | —- | C] () – C:\WINDOWS\System32\DXFLib.dll
[2006/01/12 16:08:06 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\opcode.dll
[2006/01/06 05:58:36 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/01/06 05:24:32 | 00,000,056 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/01/06 05:17:52 | 00,000,000 | —- | C] () – C:\WINDOWS\VAIOUpdt.INI
[2006/01/05 12:38:40 | 00,000,800 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/01/05 11:16:49 | 00,000,762 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/11/01 19:53:38 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2002/06/12 13:21:12 | 00,049,152 | R— | C] () – C:\WINDOWS\System32\winchip.dll

========== LOP Check ==========

[2009/07/06 10:54:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2009/03/14 21:25:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eastman Kodak Company
[2008/08/08 20:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2009/03/14 21:30:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2008/08/08 20:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Launcher
[2009/01/05 18:29:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/04/16 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NBC Direct
[2008/05/03 00:06:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers Headquarters
[2008/05/23 12:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/10/04 16:43:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2008/05/23 12:09:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/10/17 12:49:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/18 08:38:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/15 14:38:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visan
[2009/02/27 18:57:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2009/05/25 13:09:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Aptana
[2009/06/26 18:11:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\AT&T;
[2009/01/12 20:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Crayon Physics Deluxe
[2009/06/20 19:47:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\DBUpdater
[2009/04/16 19:48:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\IDM
[2008/07/13 13:32:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\InterVideo
[2008/07/20 11:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Leadertech
[2008/10/29 14:07:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\MechCAD
[2008/08/17 14:42:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\My CuteForm RunTime
[2010/01/11 13:31:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\NBC Direct
[2008/05/23 12:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\PlayFirst
[2009/06/20 19:37:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Sierra Wireless
[2008/09/16 11:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Uniblue
[2008/08/12 22:53:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Windows Desktop Search
[2008/08/19 18:13:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\Windows Search
[2009/03/05 12:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Kila_Hau\Application Data\WinPatrol
[2009/12/27 10:01:08 | 00,000,442 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/01/11 23:29:27 | 00,000,428 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{A4258327-FEA4-40DE-88D7-9AF76047C84C}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 163 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1EA8A42
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A93060EC
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3DB0B938
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:028E4554
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AC4C6FB4
< End of report >
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-10 17:12:29
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Kila_Hau\LOCALS~1\Temp\fwrdqpow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA8BA66B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA8BA6574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA8BA6A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA8BA614C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA8BA664E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA8BA608C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA8BA60F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA8BA676E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA8BA672E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA8BA68AE]

—- EOF - GMER 1.0.15 —-
zimfree,

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - No CLSID value found.
    O2 - BHO: (no name) - {DC5F9604-C6E2-47D0-8E0F-E60FCCB334C7} - No CLSID value found.
    O2 - BHO: (no name) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No CLSID value found.
    O4 - HKCU..\Run: [Cute Password Manager] File not found
    O4 - HKCU..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe File not found
    O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident\4.0; File not found
    O4 - HKLM..\RunOnceEx: [] File not found
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, your computer will reboot when it is done
🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.



Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
  • Kaspersky log
  • Malwarebytes log
  • Please tell me what, if any, symptoms you are still having with your computer.
Malwarebytes' Anti-Malware 1.44 Database version: 3555 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/13/2010 1:24:34 PM mbam-log-2010-01-13 (13-24-34).txt Scan type: Quick Scan Objects scanned: 121405 Time elapsed: 6 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, January 13, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, January 13, 2010 19:09:38 Records in database: 3309644 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Here are requested scans. My computer is running much better – I am not having the ie.explorer problem. THANK YOU for all your help. Scan area - My Computer: C:\ D:\ E:\ G:\ Scan statistics: Objects scanned: 69948 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 02:23:00 No threats found. Scanned area is clean. Selected area has been scanned.
zimfree,

Good work, your logs look clean! We have some important cleanup and housekeeping to do now:

🖼Click to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
        Applications and AppletsTrace and Log Files
    • Click OK on Delete Temporary Files Window
      Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
    • Click OK to leave the Temporary Files Window
    • Click OK to leave the Java Control Panel.
    Click to load external image (Posted Image) Your Adbobe reader needs to be updated. Please visit Adobe's site and grab the newest version.

    Go HERE to scan for any other out of date and/or vulnerable applications on your computer and follow the instructions given for updating them.

    Click to load external image (Posted Image) You have Viewpoint software installed on your system. While this is not malware, it can be installed without your knowledge. See this thread for more information and removal instructions for Viewpoint.

    I also notice that you have Crawler selected as your default search provider in Firefox. That site also gets mixed reviews, (See here) for more information.

    Click to load external image (Posted Image) Clean up with OTL:
    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.
    Click to load external image (Posted Image) We need to reset your system restore
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
    • Reboot.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check Turn off System Restore.
    Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
    • Restart any anti-malware programs that we disabled while we were cleaning your machine.
    • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
    • Avoid using P2P programs, cracks and keygens! Refer back to my earlier post for more information.
    • Consider running in a limited user account. See this post for more information.
    • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
    Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI